Microsoft AZ-700 Implement And Manage Network Security Groups Practice Test

 

AZ-700 skill 5.1 | 48 original questions

This AZ-700 practice set focuses on implement and manage network security groups through original scenario-based questions aligned to Microsoft skills measured as of July 27, 2026. The set is mapped to every official objective leaf assigned to this skill area. For broader exam preparation, review the Microsoft AZ-700 Exam Dumps page.

Instructions: Follow the selection count stated in each question. Review the rationale after answering. Every option includes a brief explanation of why it is or is not selected for the stated scenario.

Question 481

Proseware Media is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create a network security group (NSG). The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7481. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Azure Traffic Manager for DNS-based global traffic distribution when endpoints can be public and the design needs priority, performance, weighted, geographic, or subnet routing.
  2. Choose Azure Front Door when users need a global HTTP(S) entry point with edge acceleration and resilient multi-region routing rather than a region-bound Layer 7 gateway.
  3. Use Virtual WAN hub route tables, labels, propagation, and association to control which connections learn which routes and to implement the intended segmentation.
  4. Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.
  5. Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct.

Correct answer: D

Why: 5.1.1: This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

B: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.2, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

C: Not selected. This directly satisfies the requirement to configure virtual hub routing. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.6, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

D: Correct. This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.1: Create a network security group (NSG).

E: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

Learning point: AZ700-51-Q481: Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.

Question 482

Wingtip Services is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must associate a NSG to a subnet or network interface. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7482. Which recommendation most directly meets the requirement? Select one answer.

  1. Use a public frontend when clients arrive from the internet and an internal frontend when the service should be reachable only through private networking.
  2. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  3. Implement the Azure networking capability named in the requirement using the supported Microsoft configuration, validate prerequisites and dependencies, and confirm the result with Azure-native diagnostics before production rollout.
  4. Deploy Azure DNS Private Resolver with inbound and outbound endpoints and a forwarding ruleset so hybrid DNS queries can traverse between Azure private zones and on-premises DNS without custom DNS VMs.
  5. Associate the NSG at the subnet for consistent workload policy, at the NIC for justified host-specific policy, or at both only when the combined effective rules are intentionally understood.

Correct answer: E

Why: 5.1.2: This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to choose between public and internal load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.2.

B: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 5.1.2.

C: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.1.2.

D: Not selected. This directly satisfies the requirement to design and implement Azure DNS Private Resolver. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.7, but it does not directly satisfy the scenario requirement mapped to 5.1.2.

E: Correct. This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.2: Associate a NSG to a subnet or network interface.

Learning point: AZ700-51-Q482: Associate the NSG at the subnet for consistent workload policy, at the NIC for justified host-specific policy, or at both only when the combined effective rules are intentionally understood.

Question 483

Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create an application security group (ASG); associate an ASG to a network interface. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7483. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role.
  2. Use Global Reach for private site-to-site connectivity through Microsoft, FastPath to bypass the gateway data path where supported, and ExpressRoute Direct when dedicated Microsoft peering ports and very high bandwidth are required.
  3. Configure Azure private peering with the provider using unique VLAN and /30 addressing plus BGP ASNs, then verify advertised private prefixes before attaching VNets.
  4. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.
  5. Advertise or configure a default route toward the required NVA, VPN, or ExpressRoute path and verify return routing so internet-bound traffic is forced through the inspection point without asymmetry.
  6. Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.

Correct answers: A, F

Why: 5.1.3: This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.4: This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.4: Associate an ASG to a network interface.

B: Not selected. This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.4, but it does not directly satisfy the scenario requirement mapped to 5.1.3, 5.1.4.

C: Not selected. This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.6, but it does not directly satisfy the scenario requirement mapped to 5.1.3, 5.1.4.

D: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 5.1.3, 5.1.4.

E: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 5.1.3, 5.1.4.

F: Correct. This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.3: Create an application security group (ASG).

Learning point: AZ700-51-Q483: Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists. | Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role.

Question 484

Wingtip Services is reviewing a global application estate serving users on three continents. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must associate an ASG to a network interface; create and configure NSG inbound and outbound security rules. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7484. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role.
  2. Use Azure Traffic Manager for DNS-based global traffic distribution when endpoints can be public and the design needs priority, performance, weighted, geographic, or subnet routing.
  3. Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct.
  4. Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings.
  5. Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes.
  6. Choose Azure NAT Gateway when private-subnet workloads need scalable, predictable outbound SNAT and do not require unsolicited inbound connectivity.

Correct answers: A, E

Why: 5.1.4: This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.5: This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.4: Associate an ASG to a network interface.

B: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 5.1.4, 5.1.5.

C: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.4, 5.1.5.

D: Not selected. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.5, but it does not directly satisfy the scenario requirement mapped to 5.1.4, 5.1.5.

E: Correct. This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.5: Create and configure NSG inbound and outbound security rules.

F: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure NAT Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.9, but it does not directly satisfy the scenario requirement mapped to 5.1.4, 5.1.5.

Learning point: AZ700-51-Q484: Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role. | Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes.

Question 485

Proseware Media is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create and configure NSG inbound and outbound security rules. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7485. Which recommendation most directly meets the requirement? Select one answer.

  1. Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes.
  2. Implement the Azure networking capability named in the requirement using the supported Microsoft configuration, validate prerequisites and dependencies, and confirm the result with Azure-native diagnostics before production rollout.
  3. Choose a VPN gateway SKU that supports the required point-to-site user scale, aggregate throughput, zone resiliency, and protocol/authentication features.
  4. Enable BFD on supported ExpressRoute peering to detect path failures faster than standard BGP timers and accelerate convergence.
  5. Use a Public IP Prefix when you need predictable contiguous Azure public addresses for scaling, partner allowlisting, or simplified public-IP lifecycle management.

Correct answer: A

Why: 5.1.5: This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.5: Create and configure NSG inbound and outbound security rules.

B: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.1.5.

C: Not selected. This directly satisfies the requirement to select an appropriate virtual network gateway SKU for point-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.1, but it does not directly satisfy the scenario requirement mapped to 5.1.5.

D: Not selected. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.12, but it does not directly satisfy the scenario requirement mapped to 5.1.5.

E: Not selected. This directly satisfies the requirement to choose when to use a public IP address prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.7, but it does not directly satisfy the scenario requirement mapped to 5.1.5.

Learning point: AZ700-51-Q485: Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes.

Question 486

Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must implement virtual network flow logs; interpret virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 10:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7486. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Associate the route table with the intended subnet so its UDRs participate in effective routing for resources in that subnet.
  2. Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations.
  3. Create the Standard Load Balancer with the required frontend, backend pool, health probe, and load-balancing or NAT rules, then validate NSG and return-path behavior.
  4. Configure backend HTTP settings for protocol, port, host-name handling, cookie affinity, timeout, connection draining, and trusted backend certificates as required.
  5. Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.
  6. Check circuit/provider provisioning, peering/BGP state, gateway health, route advertisements, FastPath eligibility, and effective routes to isolate the failing ExpressRoute segment.

Correct answers: B, E

Why: 5.1.6: This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.7: This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 5.1.6, 5.1.7.

B: Correct. This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.6: Implement virtual network flow logs.

C: Not selected. This directly satisfies the requirement to create and configure an Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.6, but it does not directly satisfy the scenario requirement mapped to 5.1.6, 5.1.7.

D: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 5.1.6, 5.1.7.

E: Correct. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.7: Interpret virtual network flow logs.

F: Not selected. This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.13, but it does not directly satisfy the scenario requirement mapped to 5.1.6, 5.1.7.

Learning point: AZ700-51-Q486: Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations. | Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.

Question 487

Proseware Media is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must interpret virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 13:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7487. Which recommendation most directly meets the requirement? Select one answer.

  1. Control private-endpoint reachability with routing, DNS, NSGs where supported, and service-side public-network settings so only approved private clients can reach the resource.
  2. Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.
  3. Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.
  4. Use Azure Front Door for global Layer 7 anycast entry, health-based routing, acceleration, TLS, caching, rules, and optional WAF across geographically distributed origins.
  5. Create a backend pool containing the intended IPs, FQDNs, VMSS, or supported targets, keeping host-name and DNS behavior consistent with backend HTTP settings.

Correct answer: B

Why: 5.1.7: This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure access to private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.3, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

B: Correct. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.7: Interpret virtual network flow logs.

C: Not selected. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

D: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

E: Not selected. This directly satisfies the requirement to create a backend pool. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

Learning point: AZ700-51-Q487: Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.

Question 488

Wingtip Services is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must verify IP flow; configure an NSG for remote server administration, including Azure Bastion. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 16:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7488. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.
  2. Provide on-premises clients a private routed path to the consumer VNet and hybrid DNS resolution for the private endpoint, rather than trying to route directly to the provider-side Private Link Service NAT addresses.
  3. Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.
  4. Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
  5. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.
  6. Use Gateway Load Balancer to insert and scale compatible NVAs transparently in the traffic path through service chaining with a consumer frontend.

Correct answers: A, C

Why: 5.1.8: This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.9: This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.8: Verify IP flow.

B: Not selected. This directly satisfies the requirement to integrate a Private Link service with on-premises clients. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.6, but it does not directly satisfy the scenario requirement mapped to 5.1.8, 5.1.9.

C: Correct. This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.9: Configure an NSG for remote server administration, including Azure Bastion.

D: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.8, 5.1.9.

E: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.8, 5.1.9.

F: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 5.1.8, 5.1.9.

Learning point: AZ700-51-Q488: Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible. | Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.

Question 489

Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must configure an NSG for remote server administration, including Azure Bastion. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 19:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7489. Which recommendation most directly meets the requirement? Select one answer.

  1. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.
  2. Enable BFD on supported ExpressRoute peering to detect path failures faster than standard BGP timers and accelerate convergence.
  3. Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.
  4. Use Gateway Load Balancer to insert and scale compatible NVAs transparently in the traffic path through service chaining with a consumer frontend.
  5. Create a backend pool containing the intended IPs, FQDNs, VMSS, or supported targets, keeping host-name and DNS behavior consistent with backend HTTP settings.

Correct answer: C

Why: 5.1.9: This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.1.9.

B: Not selected. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.12, but it does not directly satisfy the scenario requirement mapped to 5.1.9.

C: Correct. This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.9: Configure an NSG for remote server administration, including Azure Bastion.

D: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 5.1.9.

E: Not selected. This directly satisfies the requirement to create a backend pool. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.9.

Learning point: AZ700-51-Q489: Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.

Question 490

Wingtip Services is reviewing a global application estate serving users on three continents. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must implement and manage virtual network security by using Azure Virtual Network Manager. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 22:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7490. Which recommendation most directly meets the requirement? Select one answer.

  1. Choose Azure-provided DNS, Azure Private DNS, or custom DNS based on the namespace and hybrid requirements, and ensure private names resolve to private addresses from every required VNet.
  2. Configure a custom health probe that targets a reliable application health endpoint with the right host, protocol, path, interval, timeout, and healthy-status criteria.
  3. Configure listeners with the correct frontend IP, port, protocol, host name, and certificate settings so requests match the intended site before routing rules are evaluated.
  4. Use Azure Virtual Network Manager security admin configurations for centrally enforced baseline rules across network groups, while leaving NSGs for workload-specific controls.
  5. Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct.

Correct answer: D

Why: 5.1.10: This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design name resolution inside a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.1, but it does not directly satisfy the scenario requirement mapped to 5.1.10.

B: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 5.1.10.

C: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 5.1.10.

D: Correct. This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.10: Implement and manage virtual network security by using Azure Virtual Network Manager.

E: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.10.

Learning point: AZ700-51-Q490: Use Azure Virtual Network Manager security admin configurations for centrally enforced baseline rules across network groups, while leaving NSGs for workload-specific controls.

Question 491

Proseware Media is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create a network security group (NSG). The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 2:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7491. Which recommendation most directly meets the requirement? Select one answer.

  1. Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct.
  2. Create a route table with UDRs for the required prefixes and next-hop types, avoid routes that cause loops or asymmetric paths, and validate the resulting effective routes.
  3. Check circuit/provider provisioning, peering/BGP state, gateway health, route advertisements, FastPath eligibility, and effective routes to isolate the failing ExpressRoute segment.
  4. Configure basic or path-based routing rules that connect the intended listener to the correct backend pool and HTTP settings, with redirects or rewrites only where required.
  5. Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.

Correct answer: E

Why: 5.1.1: This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

B: Not selected. This directly satisfies the requirement to design and implement user-defined routes (UDRs). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.4, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

C: Not selected. This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.13, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

D: Not selected. This directly satisfies the requirement to configure routing rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.7, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

E: Correct. This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.1: Create a network security group (NSG).

Learning point: AZ700-51-Q491: Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.

Question 492

Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must associate a NSG to a subnet or network interface. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 5:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7492. Which recommendation most directly meets the requirement? Select one answer.

  1. Associate the NSG at the subnet for consistent workload policy, at the NIC for justified host-specific policy, or at both only when the combined effective rules are intentionally understood.
  2. Configure Azure private peering with the provider using unique VLAN and /30 addressing plus BGP ASNs, then verify advertised private prefixes before attaching VNets.
  3. Configure a custom IPsec/IKE policy only when interoperability or security requirements demand it, and make encryption, integrity, DH/PFS, and lifetime settings compatible on both peers.
  4. Choose Azure Load Balancer when the requirement is regional or cross-region Layer 4 load distribution for TCP/UDP services and application-layer inspection is unnecessary.
  5. Check the client logs, profile version, tunnel protocol, certificate or Entra/RADIUS state, DNS/routes, and gateway diagnostics to isolate whether the failure is local, identity-related, or network-related.

Correct answer: A

Why: 5.1.2: This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.2: Associate a NSG to a subnet or network interface.

B: Not selected. This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.6, but it does not directly satisfy the scenario requirement mapped to 5.1.2.

C: Not selected. This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.6, but it does not directly satisfy the scenario requirement mapped to 5.1.2.

D: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.2, but it does not directly satisfy the scenario requirement mapped to 5.1.2.

E: Not selected. This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.7, but it does not directly satisfy the scenario requirement mapped to 5.1.2.

Learning point: AZ700-51-Q492: Associate the NSG at the subnet for consistent workload policy, at the NIC for justified host-specific policy, or at both only when the combined effective rules are intentionally understood.

Question 493

Proseware Media is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create an application security group (ASG). The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 8:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7493. Which recommendation most directly meets the requirement? Select one answer.

  1. Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
  2. Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.
  3. Enable the relevant Network Watcher diagnostics, Connection Monitor, packet capture, topology, and supported flow logging, then send evidence to the approved monitoring destination.
  4. Use a Public IP Prefix when you need predictable contiguous Azure public addresses for scaling, partner allowlisting, or simplified public-IP lifecycle management.
  5. Configure a custom health probe that targets a reliable application health endpoint with the right host, protocol, path, interval, timeout, and healthy-status criteria.

Correct answer: B

Why: 5.1.3: This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.3.

B: Correct. This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.3: Create an application security group (ASG).

C: Not selected. This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.1, but it does not directly satisfy the scenario requirement mapped to 5.1.3.

D: Not selected. This directly satisfies the requirement to choose when to use a public IP address prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.7, but it does not directly satisfy the scenario requirement mapped to 5.1.3.

E: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 5.1.3.

Learning point: AZ700-51-Q493: Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.

Question 494

Wingtip Services is reviewing a regulated production subscription with strict change control. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must associate an ASG to a network interface; create and configure NSG inbound and outbound security rules. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 11:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7494. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  2. Peer VNets with nonoverlapping address spaces, configure forwarded-traffic and gateway options only as required, and validate effective routes on both sides.
  3. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.
  4. Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes.
  5. Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role.
  6. Provide on-premises clients a private routed path to the consumer VNet and hybrid DNS resolution for the private endpoint, rather than trying to route directly to the provider-side Private Link Service NAT addresses.

Correct answers: D, E

Why: 5.1.4: This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.5: This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 5.1.4, 5.1.5.

B: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 5.1.4, 5.1.5.

C: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 5.1.4, 5.1.5.

D: Correct. This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.5: Create and configure NSG inbound and outbound security rules.

E: Correct. This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.4: Associate an ASG to a network interface.

F: Not selected. This directly satisfies the requirement to integrate a Private Link service with on-premises clients. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.6, but it does not directly satisfy the scenario requirement mapped to 5.1.4, 5.1.5.

Learning point: AZ700-51-Q494: Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role. | Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes.

Question 495

Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create and configure NSG inbound and outbound security rules. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 14:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7495. Which recommendation most directly meets the requirement? Select one answer.

  1. Choose Azure-provided DNS, Azure Private DNS, or custom DNS based on the namespace and hybrid requirements, and ensure private names resolve to private addresses from every required VNet.
  2. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.
  3. Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes.
  4. Create the NAT Gateway with a public IP or prefix and associate it to the required subnets so outbound flows use the managed SNAT path.
  5. Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.

Correct answer: C

Why: 5.1.5: This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design name resolution inside a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.1, but it does not directly satisfy the scenario requirement mapped to 5.1.5.

B: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.5.

C: Correct. This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.5: Create and configure NSG inbound and outbound security rules.

D: Not selected. This directly satisfies the requirement to implement Azure NAT Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.10, but it does not directly satisfy the scenario requirement mapped to 5.1.5.

E: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.5.

Learning point: AZ700-51-Q495: Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes.

Question 496

Wingtip Services is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must implement virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 17:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7496. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Application Gateway rewrite rule sets to modify supported request or response headers and URLs under explicit conditions instead of changing application code for simple gateway-layer transformations.
  2. Terminate or re-encrypt TLS on Application Gateway using certificates from the approved source, enforce the required TLS policy, and validate end-to-end certificate trust when HTTPS continues to the backend.
  3. Create the ExpressRoute virtual network gateway in GatewaySubnet with the SKU and resiliency model required for the circuit bandwidth and feature set.
  4. Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations.
  5. Size each Virtual WAN gateway using the service’s scale units based on expected aggregate throughput, connection count, and resiliency requirements, then monitor utilization for growth.

Correct answer: D

Why: 5.1.6: This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 5.1.6.

B: Not selected. This directly satisfies the requirement to configure Transport Layer Security (TLS). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.9, but it does not directly satisfy the scenario requirement mapped to 5.1.6.

C: Not selected. This directly satisfies the requirement to create and configure an ExpressRoute gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.8, but it does not directly satisfy the scenario requirement mapped to 5.1.6.

D: Correct. This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.6: Implement virtual network flow logs.

E: Not selected. This directly satisfies the requirement to choose an appropriate scale unit for each gateway type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.4, but it does not directly satisfy the scenario requirement mapped to 5.1.6.

Learning point: AZ700-51-Q496: Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations.

Question 497

Proseware Media is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must interpret virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 20:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7497. Which recommendation most directly meets the requirement? Select one answer.

  1. Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements.
  2. Size each Virtual WAN gateway using the service’s scale units based on expected aggregate throughput, connection count, and resiliency requirements, then monitor utilization for growth.
  3. Peer VNets with nonoverlapping address spaces, configure forwarded-traffic and gateway options only as required, and validate effective routes on both sides.
  4. Create a Standard public IP address with the required allocation, zone, and routing preference settings, then protect and monitor the resource as part of the workload design.
  5. Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.

Correct answer: E

Why: 5.1.7: This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

B: Not selected. This directly satisfies the requirement to choose an appropriate scale unit for each gateway type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.4, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

C: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

D: Not selected. This directly satisfies the requirement to create a public IP address. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.9, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

E: Correct. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.7: Interpret virtual network flow logs.

Learning point: AZ700-51-Q497: Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.

Question 498

Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must verify IP flow. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 23:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7498. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.
  2. Size each Virtual WAN gateway using the service’s scale units based on expected aggregate throughput, connection count, and resiliency requirements, then monitor utilization for growth.
  3. Place VNets in Azure Virtual Network Manager network groups and deploy a connectivity configuration so hub-and-spoke or mesh connectivity is centrally governed at scale.
  4. Use Application Gateway rewrite rule sets to modify supported request or response headers and URLs under explicit conditions instead of changing application code for simple gateway-layer transformations.
  5. Create a backend pool containing the intended IPs, FQDNs, VMSS, or supported targets, keeping host-name and DNS behavior consistent with backend HTTP settings.

Correct answer: A

Why: 5.1.8: This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.8: Verify IP flow.

B: Not selected. This directly satisfies the requirement to choose an appropriate scale unit for each gateway type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.4, but it does not directly satisfy the scenario requirement mapped to 5.1.8.

C: Not selected. This directly satisfies the requirement to implement and manage virtual network connectivity by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.3, but it does not directly satisfy the scenario requirement mapped to 5.1.8.

D: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 5.1.8.

E: Not selected. This directly satisfies the requirement to create a backend pool. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.8.

Learning point: AZ700-51-Q498: Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.

Question 499

Proseware Media is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must configure an NSG for remote server administration, including Azure Bastion. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 3:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7499. Which recommendation most directly meets the requirement? Select one answer.

  1. Associate the public IP to the supported frontend resource that actually needs internet reachability, such as a load balancer frontend, gateway, firewall, or NIC, instead of assigning public IPs broadly.
  2. Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.
  3. Provide on-premises clients a private routed path to the consumer VNet and hybrid DNS resolution for the private endpoint, rather than trying to route directly to the provider-side Private Link Service NAT addresses.
  4. Publish the producer service through a Private Link Service behind a Standard internal Load Balancer, configure NAT IPs and visibility/approval, and onboard consumer private endpoints.
  5. Use autoscale for variable or unpredictable traffic and configure sensible minimum/maximum capacity; use fixed/manual capacity only when load is stable and explicitly controlled.

Correct answer: B

Why: 5.1.9: This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 5.1.9.

B: Correct. This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.9: Configure an NSG for remote server administration, including Azure Bastion.

C: Not selected. This directly satisfies the requirement to integrate a Private Link service with on-premises clients. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.6, but it does not directly satisfy the scenario requirement mapped to 5.1.9.

D: Not selected. This directly satisfies the requirement to create a Private Link service. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.9.

E: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.9.

Learning point: AZ700-51-Q499: Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.

Question 500

Wingtip Services is reviewing a regulated production subscription with strict change control. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must implement and manage virtual network security by using Azure Virtual Network Manager. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 6:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7500. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure listeners with the correct frontend IP, port, protocol, host name, and certificate settings so requests match the intended site before routing rules are evaluated.
  2. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  3. Use Azure Virtual Network Manager security admin configurations for centrally enforced baseline rules across network groups, while leaving NSGs for workload-specific controls.
  4. Configure the VNet to use the intended Azure-provided or custom DNS servers and ensure clients renew their DHCP configuration so the new resolver settings take effect.
  5. Implement the Azure networking capability named in the requirement using the supported Microsoft configuration, validate prerequisites and dependencies, and confirm the result with Azure-native diagnostics before production rollout.

Correct answer: C

Why: 5.1.10: This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 5.1.10.

B: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.1.10.

C: Correct. This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.10: Implement and manage virtual network security by using Azure Virtual Network Manager.

D: Not selected. This directly satisfies the requirement to configure DNS settings for a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.2, but it does not directly satisfy the scenario requirement mapped to 5.1.10.

E: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.1.10.

Learning point: AZ700-51-Q500: Use Azure Virtual Network Manager security admin configurations for centrally enforced baseline rules across network groups, while leaving NSGs for workload-specific controls.

Question 501

Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create a network security group (NSG). The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 9:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7501. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure listeners with the correct frontend IP, port, protocol, host name, and certificate settings so requests match the intended site before routing rules are evaluated.
  2. Create the Front Door profile, endpoint, origin group, origins, health probes, and routes so host/path matching and origin priorities implement the required global traffic flow.
  3. Create the NAT Gateway with a public IP or prefix and associate it to the required subnets so outbound flows use the managed SNAT path.
  4. Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.
  5. Use a regional load balancer for backends in one Azure region and a cross-region load balancer when a global Layer 4 entry point must distribute to regional load balancers.

Correct answer: D

Why: 5.1.1: This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

B: Not selected. This directly satisfies the requirement to configure an Azure Front Door, including routing, origins, and endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.4, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

C: Not selected. This directly satisfies the requirement to implement Azure NAT Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.10, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

D: Correct. This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.1: Create a network security group (NSG).

E: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

Learning point: AZ700-51-Q501: Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.

Question 502

Wingtip Services is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must associate a NSG to a subnet or network interface. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 12:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7502. Which recommendation most directly meets the requirement? Select one answer.

  1. Inspect effective routes and next-hop results in Network Watcher, then verify peering, BGP advertisements, UDR precedence, and return paths before changing the design.
  2. Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings.
  3. Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.
  4. Advertise or configure a default route toward the required NVA, VPN, or ExpressRoute path and verify return routing so internet-bound traffic is forced through the inspection point without asymmetry.
  5. Associate the NSG at the subnet for consistent workload policy, at the NIC for justified host-specific policy, or at both only when the combined effective rules are intentionally understood.

Correct answer: E

Why: 5.1.2: This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to diagnose and resolve routing issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.7, but it does not directly satisfy the scenario requirement mapped to 5.1.2.

B: Not selected. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.5, but it does not directly satisfy the scenario requirement mapped to 5.1.2.

C: Not selected. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.2.

D: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 5.1.2.

E: Correct. This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.2: Associate a NSG to a subnet or network interface.

Learning point: AZ700-51-Q502: Associate the NSG at the subnet for consistent workload policy, at the NIC for justified host-specific policy, or at both only when the combined effective rules are intentionally understood.

Question 503

Proseware Media is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create an application security group (ASG). The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7503. Which recommendation most directly meets the requirement? Select one answer.

  1. Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.
  2. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.
  3. Implement Front Door rules with explicit match conditions and actions for header changes, URL rewrites, or redirects, and verify rule-set ordering to avoid unexpected routing behavior.
  4. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  5. Use Azure private peering for private VNet routes, Microsoft peering for supported Microsoft public services, or both when the requirements explicitly need both routing domains.

Correct answer: A

Why: 5.1.3: This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.3: Create an application security group (ASG).

B: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.3.

C: Not selected. This directly satisfies the requirement to implement rules, URL rewrite, and URL redirect. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.8, but it does not directly satisfy the scenario requirement mapped to 5.1.3.

D: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.1.3.

E: Not selected. This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.5, but it does not directly satisfy the scenario requirement mapped to 5.1.3.

Learning point: AZ700-51-Q503: Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.

Question 504

Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must associate an ASG to a network interface. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7504. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings.
  2. Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role.
  3. Peer VNets with nonoverlapping address spaces, configure forwarded-traffic and gateway options only as required, and validate effective routes on both sides.
  4. Use dedicated subnets when a service requires delegation, special routing, or isolation; share only where supported and where policy and scale requirements are compatible.
  5. Use Azure Private DNS zones for internal namespaces and private-endpoint records, planning VNet links so only the required networks can resolve those names.

Correct answer: B

Why: 5.1.4: This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.5, but it does not directly satisfy the scenario requirement mapped to 5.1.4.

B: Correct. This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.4: Associate an ASG to a network interface.

C: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 5.1.4.

D: Not selected. This directly satisfies the requirement to plan and configure shared or dedicated subnets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.5, but it does not directly satisfy the scenario requirement mapped to 5.1.4.

E: Not selected. This directly satisfies the requirement to design private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.4.

Learning point: AZ700-51-Q504: Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role.

Question 505

Proseware Media is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create and configure NSG inbound and outbound security rules. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7505. Which recommendation most directly meets the requirement? Select one answer.

  1. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  2. Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements.
  3. Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes.
  4. Choose Azure Front Door when users need a global HTTP(S) entry point with edge acceleration and resilient multi-region routing rather than a region-bound Layer 7 gateway.
  5. Choose Application Gateway when the application needs regional Layer 7 routing, TLS offload, cookie affinity, redirects/rewrites, or WAF close to Azure backends.

Correct answer: C

Why: 5.1.5: This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.1.5.

B: Not selected. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.5.

C: Correct. This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.5: Create and configure NSG inbound and outbound security rules.

D: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.2, but it does not directly satisfy the scenario requirement mapped to 5.1.5.

E: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.2, but it does not directly satisfy the scenario requirement mapped to 5.1.5.

Learning point: AZ700-51-Q505: Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes.

Question 506

Wingtip Services is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must implement virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7506. Which recommendation most directly meets the requirement? Select one answer.

  1. Terminate TLS at the Front Door edge with the managed or customer certificate and use HTTPS to origins with valid certificates when end-to-end encryption is required.
  2. Delegate the target subnet to the required Azure platform service and ensure the subnet meets that service’s delegation and coexistence constraints.
  3. Create a Standard public IP address with the required allocation, zone, and routing preference settings, then protect and monitor the resource as part of the workload design.
  4. Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations.
  5. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.

Correct answer: D

Why: 5.1.6: This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure TLS termination and end-to-end TLS encryption. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.5, but it does not directly satisfy the scenario requirement mapped to 5.1.6.

B: Not selected. This directly satisfies the requirement to plan and configure subnet delegation. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.6.

C: Not selected. This directly satisfies the requirement to create a public IP address. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.9, but it does not directly satisfy the scenario requirement mapped to 5.1.6.

D: Correct. This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.6: Implement virtual network flow logs.

E: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.6.

Learning point: AZ700-51-Q506: Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations.

Question 507

Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must interpret virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7507. Which recommendation most directly meets the requirement? Select one answer.

  1. Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
  2. Create the appropriate Azure DNS zones and record sets, separating public authoritative records from private records and applying the required TTL and VNet-link configuration.
  3. Use a regional load balancer for backends in one Azure region and a cross-region load balancer when a global Layer 4 entry point must distribute to regional load balancers.
  4. Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct.
  5. Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.

Correct answer: E

Why: 5.1.7: This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

B: Not selected. This directly satisfies the requirement to configure public and private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.5, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

C: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

D: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

E: Correct. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.7: Interpret virtual network flow logs.

Learning point: AZ700-51-Q507: Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.

Question 508

Wingtip Services is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must verify IP flow. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7508. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.
  2. Create a route table with UDRs for the required prefixes and next-hop types, avoid routes that cause loops or asymmetric paths, and validate the resulting effective routes.
  3. Deploy Azure Route Server in its required dedicated subnet and establish BGP sessions with supported NVAs so dynamic routes are exchanged without maintaining large UDR sets.
  4. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.
  5. Publish the producer service through a Private Link Service behind a Standard internal Load Balancer, configure NAT IPs and visibility/approval, and onboard consumer private endpoints.

Correct answer: A

Why: 5.1.8: This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.8: Verify IP flow.

B: Not selected. This directly satisfies the requirement to design and implement user-defined routes (UDRs). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.4, but it does not directly satisfy the scenario requirement mapped to 5.1.8.

C: Not selected. This directly satisfies the requirement to design and implement Azure Route Server. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.8, but it does not directly satisfy the scenario requirement mapped to 5.1.8.

D: Not selected. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.8.

E: Not selected. This directly satisfies the requirement to create a Private Link service. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.8.

Learning point: AZ700-51-Q508: Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.

Question 509

Proseware Media is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must configure an NSG for remote server administration, including Azure Bastion. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 10:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7509. Which recommendation most directly meets the requirement? Select one answer.

  1. Check the client logs, profile version, tunnel protocol, certificate or Entra/RADIUS state, DNS/routes, and gateway diagnostics to isolate whether the failure is local, identity-related, or network-related.
  2. Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.
  3. Onboard the organization-owned public range as a Custom IP Prefix, complete Microsoft validation and provisioning, and then allocate public IP prefixes or addresses from the BYOIP range.
  4. Choose Basic only for the limited branch-connectivity scenario; choose Standard when the architecture needs features such as ExpressRoute, P2S, inter-hub transit, Azure Firewall, or broader routing capabilities.
  5. Advertise only the intended, nonoverlapping prefixes through BGP, summarize where safe, and use route filters or communities on Microsoft peering rather than leaking unrelated routes.

Correct answer: B

Why: 5.1.9: This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.7, but it does not directly satisfy the scenario requirement mapped to 5.1.9.

B: Correct. This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.9: Configure an NSG for remote server administration, including Azure Bastion.

C: Not selected. This directly satisfies the requirement to plan and implement a Custom IP address prefix (bring your own IP). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.8, but it does not directly satisfy the scenario requirement mapped to 5.1.9.

D: Not selected. This directly satisfies the requirement to select a Virtual WAN SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.1, but it does not directly satisfy the scenario requirement mapped to 5.1.9.

E: Not selected. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.10, but it does not directly satisfy the scenario requirement mapped to 5.1.9.

Learning point: AZ700-51-Q509: Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.

Question 510

Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must implement and manage virtual network security by using Azure Virtual Network Manager; create a network security group (NSG). The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 13:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7510. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Use a hub-and-spoke design with peering options such as forwarded traffic and gateway transit so spokes can consume shared gateways or NVAs without creating unsupported transitive peering assumptions.
  2. Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.
  3. Use Azure Virtual Network Manager security admin configurations for centrally enforced baseline rules across network groups, while leaving NSGs for workload-specific controls.
  4. Use supported IPsec over Microsoft peering or MACsec on ExpressRoute Direct, depending on the encryption boundary and circuit type, instead of assuming private peering is inherently encrypted.
  5. Implement the Azure networking capability named in the requirement using the supported Microsoft configuration, validate prerequisites and dependencies, and confirm the result with Azure-native diagnostics before production rollout.
  6. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.

Correct answers: B, C

Why: 5.1.10: This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.1: This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.10, 5.1.1.

B: Correct. This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.1: Create a network security group (NSG).

C: Correct. This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.10: Implement and manage virtual network security by using Azure Virtual Network Manager.

D: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.1.10, 5.1.1.

E: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.1.10, 5.1.1.

F: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.10, 5.1.1.

Learning point: AZ700-51-Q510: Use Azure Virtual Network Manager security admin configurations for centrally enforced baseline rules across network groups, while leaving NSGs for workload-specific controls. | Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.

Question 511

Proseware Media is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create a network security group (NSG). The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 16:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7511. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Azure Front Door for global Layer 7 anycast entry, health-based routing, acceleration, TLS, caching, rules, and optional WAF across geographically distributed origins.
  2. Use autoscale for variable or unpredictable traffic and configure sensible minimum/maximum capacity; use fixed/manual capacity only when load is stable and explicitly controlled.
  3. Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.
  4. Select the supported Standard SKU/tier and regional or global design based on zone resiliency, scale, cross-region requirements, and backend resource compatibility.
  5. Use Gateway Load Balancer to insert and scale compatible NVAs transparently in the traffic path through service chaining with a consumer frontend.

Correct answer: C

Why: 5.1.1: This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

B: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

C: Correct. This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.1: Create a network security group (NSG).

D: Not selected. This directly satisfies the requirement to choose an Azure Load Balancer SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.3, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

E: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

Learning point: AZ700-51-Q511: Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.

Question 512

Wingtip Services is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must associate a NSG to a subnet or network interface. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 19:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7512. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure listeners with the correct frontend IP, port, protocol, host name, and certificate settings so requests match the intended site before routing rules are evaluated.
  2. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.
  3. Use autoscale for variable or unpredictable traffic and configure sensible minimum/maximum capacity; use fixed/manual capacity only when load is stable and explicitly controlled.
  4. Associate the NSG at the subnet for consistent workload policy, at the NIC for justified host-specific policy, or at both only when the combined effective rules are intentionally understood.
  5. Use Front Door Premium Private Link to reach the supported origin privately, approve the private endpoint connection, and restrict the origin so it does not also accept unintended public traffic.

Correct answer: D

Why: 5.1.2: This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 5.1.2.

B: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 5.1.2.

C: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.2.

D: Correct. This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.2: Associate a NSG to a subnet or network interface.

E: Not selected. This directly satisfies the requirement to secure an origin by using Azure Private Link in Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.9, but it does not directly satisfy the scenario requirement mapped to 5.1.2.

Learning point: AZ700-51-Q512: Associate the NSG at the subnet for consistent workload policy, at the NIC for justified host-specific policy, or at both only when the combined effective rules are intentionally understood.

Question 513

Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create an application security group (ASG). The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 22:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7513. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure Azure private peering with the provider using unique VLAN and /30 addressing plus BGP ASNs, then verify advertised private prefixes before attaching VNets.
  2. Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing.
  3. Enable BFD on supported ExpressRoute peering to detect path failures faster than standard BGP timers and accelerate convergence.
  4. Validate gateway and connection status, shared keys, IKE/IPsec proposals, BGP or prefix advertisements, effective routes, and on-premises firewall/NAT before redeploying the gateway.
  5. Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.

Correct answer: E

Why: 5.1.3: This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.6, but it does not directly satisfy the scenario requirement mapped to 5.1.3.

B: Not selected. This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.2, but it does not directly satisfy the scenario requirement mapped to 5.1.3.

C: Not selected. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.12, but it does not directly satisfy the scenario requirement mapped to 5.1.3.

D: Not selected. This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.8, but it does not directly satisfy the scenario requirement mapped to 5.1.3.

E: Correct. This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.3: Create an application security group (ASG).

Learning point: AZ700-51-Q513: Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.

Question 514

Wingtip Services is reviewing a global application estate serving users on three continents. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must associate an ASG to a network interface. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 2:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7514. Which recommendation most directly meets the requirement? Select one answer.

  1. Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role.
  2. Delegate the target subnet to the required Azure platform service and ensure the subnet meets that service’s delegation and coexistence constraints.
  3. Use a hub-and-spoke design with peering options such as forwarded traffic and gateway transit so spokes can consume shared gateways or NVAs without creating unsupported transitive peering assumptions.
  4. Enable Front Door caching only for cacheable content, set query-string and compression behavior intentionally, and use cache-control/rules so personalized or sensitive responses are not cached.
  5. Use Gateway Load Balancer to insert and scale compatible NVAs transparently in the traffic path through service chaining with a consumer frontend.

Correct answer: A

Why: 5.1.4: This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.4: Associate an ASG to a network interface.

B: Not selected. This directly satisfies the requirement to plan and configure subnet delegation. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.4.

C: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.4.

D: Not selected. This directly satisfies the requirement to configure caching. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.6, but it does not directly satisfy the scenario requirement mapped to 5.1.4.

E: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 5.1.4.

Learning point: AZ700-51-Q514: Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role.

Question 515

Proseware Media is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create and configure NSG inbound and outbound security rules. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 5:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7515. Which recommendation most directly meets the requirement? Select one answer.

  1. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.
  2. Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes.
  3. Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention.
  4. Associate the public IP to the supported frontend resource that actually needs internet reachability, such as a load balancer frontend, gateway, firewall, or NIC, instead of assigning public IPs broadly.
  5. Integrate a supported third-party NVA into the Virtual WAN hub using the vendor-supported deployment and routing model, then validate route propagation and symmetric traffic paths.

Correct answer: B

Why: 5.1.5: This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.5.

B: Correct. This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.5: Create and configure NSG inbound and outbound security rules.

C: Not selected. This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.1, but it does not directly satisfy the scenario requirement mapped to 5.1.5.

D: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 5.1.5.

E: Not selected. This directly satisfies the requirement to integrate a virtual hub with a third-party NVA for cloud connectivity. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.7, but it does not directly satisfy the scenario requirement mapped to 5.1.5.

Learning point: AZ700-51-Q515: Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes.

Question 516

Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must implement virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 8:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7516. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure Azure private peering with the provider using unique VLAN and /30 addressing plus BGP ASNs, then verify advertised private prefixes before attaching VNets.
  2. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.
  3. Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations.
  4. Size each Virtual WAN gateway using the service’s scale units based on expected aggregate throughput, connection count, and resiliency requirements, then monitor utilization for growth.
  5. Use Azure Front Door for global Layer 7 anycast entry, health-based routing, acceleration, TLS, caching, rules, and optional WAF across geographically distributed origins.

Correct answer: C

Why: 5.1.6: This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.6, but it does not directly satisfy the scenario requirement mapped to 5.1.6.

B: Not selected. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.6.

C: Correct. This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.6: Implement virtual network flow logs.

D: Not selected. This directly satisfies the requirement to choose an appropriate scale unit for each gateway type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.4, but it does not directly satisfy the scenario requirement mapped to 5.1.6.

E: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.6.

Learning point: AZ700-51-Q516: Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations.

Question 517

Proseware Media is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must interpret virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 11:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7517. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Azure Traffic Manager for DNS-based global traffic distribution when endpoints can be public and the design needs priority, performance, weighted, geographic, or subnet routing.
  2. Advertise only the intended, nonoverlapping prefixes through BGP, summarize where safe, and use route filters or communities on Microsoft peering rather than leaking unrelated routes.
  3. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.
  4. Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.
  5. Deploy Azure DNS Private Resolver with inbound and outbound endpoints and a forwarding ruleset so hybrid DNS queries can traverse between Azure private zones and on-premises DNS without custom DNS VMs.

Correct answer: D

Why: 5.1.7: This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

B: Not selected. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.10, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

C: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

D: Correct. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.7: Interpret virtual network flow logs.

E: Not selected. This directly satisfies the requirement to design and implement Azure DNS Private Resolver. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.7, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

Learning point: AZ700-51-Q517: Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.

Question 518

Wingtip Services is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must verify IP flow. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 14:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7518. Which recommendation most directly meets the requirement? Select one answer.

  1. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  2. Create the VNet with the approved regional address space, define required subnets, and apply governance before attaching workloads.
  3. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  4. Choose Application Gateway when the application needs regional Layer 7 routing, TLS offload, cookie affinity, redirects/rewrites, or WAF close to Azure backends.
  5. Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.

Correct answer: E

Why: 5.1.8: This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.1.8.

B: Not selected. This directly satisfies the requirement to create a virtual network (VNet). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.2, but it does not directly satisfy the scenario requirement mapped to 5.1.8.

C: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 5.1.8.

D: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.2, but it does not directly satisfy the scenario requirement mapped to 5.1.8.

E: Correct. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.8: Verify IP flow.

Learning point: AZ700-51-Q518: Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.

Question 519

Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must configure an NSG for remote server administration, including Azure Bastion. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 17:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7519. Which recommendation most directly meets the requirement? Select one answer.

  1. Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.
  2. Deploy the required VPN, ExpressRoute, or P2S gateway into the Virtual WAN hub and size it independently for that connectivity type.
  3. Provide on-premises clients a private routed path to the consumer VNet and hybrid DNS resolution for the private endpoint, rather than trying to route directly to the provider-side Private Link Service NAT addresses.
  4. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  5. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.

Correct answer: A

Why: 5.1.9: This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.9: Configure an NSG for remote server administration, including Azure Bastion.

B: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 5.1.9.

C: Not selected. This directly satisfies the requirement to integrate a Private Link service with on-premises clients. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.6, but it does not directly satisfy the scenario requirement mapped to 5.1.9.

D: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 5.1.9.

E: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.9.

Learning point: AZ700-51-Q519: Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.

Question 520

Wingtip Services is reviewing a global application estate serving users on three continents. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must implement and manage virtual network security by using Azure Virtual Network Manager. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 20:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7520. Which recommendation most directly meets the requirement? Select one answer.

  1. Create a backend pool containing the intended IPs, FQDNs, VMSS, or supported targets, keeping host-name and DNS behavior consistent with backend HTTP settings.
  2. Use Azure Virtual Network Manager security admin configurations for centrally enforced baseline rules across network groups, while leaving NSGs for workload-specific controls.
  3. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  4. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.
  5. Publish the producer service through a Private Link Service behind a Standard internal Load Balancer, configure NAT IPs and visibility/approval, and onboard consumer private endpoints.

Correct answer: B

Why: 5.1.10: This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to create a backend pool. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.10.

B: Correct. This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.10: Implement and manage virtual network security by using Azure Virtual Network Manager.

C: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.1.10.

D: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.1.10.

E: Not selected. This directly satisfies the requirement to create a Private Link service. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.10.

Learning point: AZ700-51-Q520: Use Azure Virtual Network Manager security admin configurations for centrally enforced baseline rules across network groups, while leaving NSGs for workload-specific controls.

Question 521

Proseware Media is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create a network security group (NSG). The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 23:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7521. Which recommendation most directly meets the requirement? Select one answer.

  1. Use supported IPsec over Microsoft peering or MACsec on ExpressRoute Direct, depending on the encryption boundary and circuit type, instead of assuming private peering is inherently encrypted.
  2. Use Gateway Load Balancer to insert and scale compatible NVAs transparently in the traffic path through service chaining with a consumer frontend.
  3. Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.
  4. Configure Microsoft peering with validated public prefixes, BGP, route filters for the required service communities, and provider-side VLAN/IP settings that match the circuit.
  5. Use Virtual WAN hub route tables, labels, propagation, and association to control which connections learn which routes and to implement the intended segmentation.

Correct answer: C

Why: 5.1.1: This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

B: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

C: Correct. This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.1: Create a network security group (NSG).

D: Not selected. This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.7, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

E: Not selected. This directly satisfies the requirement to configure virtual hub routing. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.6, but it does not directly satisfy the scenario requirement mapped to 5.1.1.

Learning point: AZ700-51-Q521: Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.

Question 522

Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must associate a NSG to a subnet or network interface; create an application security group (ASG). The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 3:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7522. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.
  2. For Always On VPN, ensure Azure provides the required VPN gateway capacity, routes, authentication reachability, DNS, and supported tunnel configuration while device/user tunnel policy remains a Windows client design concern.
  3. Deploy Azure Route Server in its required dedicated subnet and establish BGP sessions with supported NVAs so dynamic routes are exchanged without maintaining large UDR sets.
  4. Inspect effective routes and next-hop results in Network Watcher, then verify peering, BGP advertisements, UDR precedence, and return paths before changing the design.
  5. Associate the NSG at the subnet for consistent workload policy, at the NIC for justified host-specific policy, or at both only when the combined effective rules are intentionally understood.
  6. Use supported IPsec over Microsoft peering or MACsec on ExpressRoute Direct, depending on the encryption boundary and circuit type, instead of assuming private peering is inherently encrypted.

Correct answers: A, E

Why: 5.1.2: This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.3: This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.3: Create an application security group (ASG).

B: Not selected. This directly satisfies the requirement to specify Azure requirements for Always On VPN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.8, but it does not directly satisfy the scenario requirement mapped to 5.1.2, 5.1.3.

C: Not selected. This directly satisfies the requirement to design and implement Azure Route Server. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.8, but it does not directly satisfy the scenario requirement mapped to 5.1.2, 5.1.3.

D: Not selected. This directly satisfies the requirement to diagnose and resolve routing issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.7, but it does not directly satisfy the scenario requirement mapped to 5.1.2, 5.1.3.

E: Correct. This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.2: Associate a NSG to a subnet or network interface.

F: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.1.2, 5.1.3.

Learning point: AZ700-51-Q522: Associate the NSG at the subnet for consistent workload policy, at the NIC for justified host-specific policy, or at both only when the combined effective rules are intentionally understood. | Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.

Question 523

Proseware Media is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create an application security group (ASG). The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 6:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7523. Which recommendation most directly meets the requirement? Select one answer.

  1. Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
  2. Deploy the required VPN, ExpressRoute, or P2S gateway into the Virtual WAN hub and size it independently for that connectivity type.
  3. Use Global Reach for private site-to-site connectivity through Microsoft, FastPath to bypass the gateway data path where supported, and ExpressRoute Direct when dedicated Microsoft peering ports and very high bandwidth are required.
  4. Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.
  5. Choose Basic only for the limited branch-connectivity scenario; choose Standard when the architecture needs features such as ExpressRoute, P2S, inter-hub transit, Azure Firewall, or broader routing capabilities.

Correct answer: D

Why: 5.1.3: This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.3.

B: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 5.1.3.

C: Not selected. This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.4, but it does not directly satisfy the scenario requirement mapped to 5.1.3.

D: Correct. This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.3: Create an application security group (ASG).

E: Not selected. This directly satisfies the requirement to select a Virtual WAN SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.1, but it does not directly satisfy the scenario requirement mapped to 5.1.3.

Learning point: AZ700-51-Q523: Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.

Question 524

Wingtip Services is reviewing a regulated production subscription with strict change control. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must associate an ASG to a network interface. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 9:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7524. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.
  2. Inspect effective routes and next-hop results in Network Watcher, then verify peering, BGP advertisements, UDR precedence, and return paths before changing the design.
  3. For Always On VPN, ensure Azure provides the required VPN gateway capacity, routes, authentication reachability, DNS, and supported tunnel configuration while device/user tunnel policy remains a Windows client design concern.
  4. Use inbound NAT rules when specific frontend ports must map to individual backend instances for management or specialized per-instance access rather than load-balanced service traffic.
  5. Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role.

Correct answer: E

Why: 5.1.4: This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.4.

B: Not selected. This directly satisfies the requirement to diagnose and resolve routing issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.7, but it does not directly satisfy the scenario requirement mapped to 5.1.4.

C: Not selected. This directly satisfies the requirement to specify Azure requirements for Always On VPN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.8, but it does not directly satisfy the scenario requirement mapped to 5.1.4.

D: Not selected. This directly satisfies the requirement to create and configure inbound NAT rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.10, but it does not directly satisfy the scenario requirement mapped to 5.1.4.

E: Correct. This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.4: Associate an ASG to a network interface.

Learning point: AZ700-51-Q524: Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role.

Question 525

Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create and configure NSG inbound and outbound security rules; implement virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 12:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7525. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations.
  2. Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes.
  3. Create a virtual network link from the Private DNS zone to the required VNet and enable auto-registration only when that VNet should register VM host records.
  4. Advertise only the intended, nonoverlapping prefixes through BGP, summarize where safe, and use route filters or communities on Microsoft peering rather than leaking unrelated routes.
  5. Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention.
  6. For Always On VPN, ensure Azure provides the required VPN gateway capacity, routes, authentication reachability, DNS, and supported tunnel configuration while device/user tunnel policy remains a Windows client design concern.

Correct answers: A, B

Why: 5.1.5: This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.6: This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.6: Implement virtual network flow logs.

B: Correct. This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.5: Create and configure NSG inbound and outbound security rules.

C: Not selected. This directly satisfies the requirement to link a private DNS zone to a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.6, but it does not directly satisfy the scenario requirement mapped to 5.1.5, 5.1.6.

D: Not selected. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.10, but it does not directly satisfy the scenario requirement mapped to 5.1.5, 5.1.6.

E: Not selected. This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.1, but it does not directly satisfy the scenario requirement mapped to 5.1.5, 5.1.6.

F: Not selected. This directly satisfies the requirement to specify Azure requirements for Always On VPN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.8, but it does not directly satisfy the scenario requirement mapped to 5.1.5, 5.1.6.

Learning point: AZ700-51-Q525: Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes. | Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations.

Question 526

Wingtip Services is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must implement virtual network flow logs; interpret virtual network flow logs; verify IP flow. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7526. Which THREE recommendations should be implemented together? Select THREE answers.

  1. Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations.
  2. Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.
  3. Choose Application Gateway when the application needs regional Layer 7 routing, TLS offload, cookie affinity, redirects/rewrites, or WAF close to Azure backends.
  4. Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.
  5. Advertise only the intended, nonoverlapping prefixes through BGP, summarize where safe, and use route filters or communities on Microsoft peering rather than leaking unrelated routes.
  6. Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.

Correct answers: A, B, D

Why: 5.1.6: This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.7: This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.8: This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.6: Implement virtual network flow logs.

B: Correct. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.7: Interpret virtual network flow logs.

C: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.2, but it does not directly satisfy the scenario requirement mapped to 5.1.6, 5.1.7, 5.1.8.

D: Correct. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.8: Verify IP flow.

E: Not selected. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.10, but it does not directly satisfy the scenario requirement mapped to 5.1.6, 5.1.7, 5.1.8.

F: Not selected. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.6, 5.1.7, 5.1.8.

Learning point: AZ700-51-Q526: Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations. | Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy. | Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.

Question 527

Proseware Media is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must interpret virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7527. Which recommendation most directly meets the requirement? Select one answer.

  1. Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.
  2. Configure backend HTTP settings for protocol, port, host-name handling, cookie affinity, timeout, connection draining, and trusted backend certificates as required.
  3. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  4. Use Application Gateway for regional Layer 7 HTTP(S) delivery with host/path routing, TLS termination, autoscale, and optional WAF in front of private or public backends.
  5. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.

Correct answer: A

Why: 5.1.7: This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.7: Interpret virtual network flow logs.

B: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

C: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

D: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.1, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

E: Not selected. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.7.

Learning point: AZ700-51-Q527: Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.

Question 528

Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must verify IP flow; configure an NSG for remote server administration, including Azure Bastion; implement and manage virtual network security by using Azure Virtual Network Manager. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7528. Which THREE recommendations should be implemented together? Select THREE answers.

  1. Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.
  2. Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.
  3. Associate the route table with the intended subnet so its UDRs participate in effective routing for resources in that subnet.
  4. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.
  5. Use Azure Virtual Network Manager security admin configurations for centrally enforced baseline rules across network groups, while leaving NSGs for workload-specific controls.
  6. Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct.

Correct answers: A, B, E

Why: 5.1.8: This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.9: This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.10: This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.9: Configure an NSG for remote server administration, including Azure Bastion.

B: Correct. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.8: Verify IP flow.

C: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 5.1.8, 5.1.9, 5.1.10.

D: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.1.8, 5.1.9, 5.1.10.

E: Correct. This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.10: Implement and manage virtual network security by using Azure Virtual Network Manager.

F: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.8, 5.1.9, 5.1.10.

Learning point: AZ700-51-Q528: Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible. | Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window. | Use Azure Virtual Network Manager security admin configurations for centrally enforced baseline rules across network groups, while leaving NSGs for workload-specific controls.

Popular posts

img