Microsoft AZ-700 Implement And Manage Network Security Groups Practice Test
AZ-700 skill 5.1 | 48 original questions
This AZ-700 practice set focuses on implement and manage network security groups through original scenario-based questions aligned to Microsoft skills measured as of July 27, 2026. The set is mapped to every official objective leaf assigned to this skill area. For broader exam preparation, review the Microsoft AZ-700 Exam Dumps page.
Instructions: Follow the selection count stated in each question. Review the rationale after answering. Every option includes a brief explanation of why it is or is not selected for the stated scenario.
Proseware Media is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create a network security group (NSG). The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7481. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 5.1.1: This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
B: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.2, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
C: Not selected. This directly satisfies the requirement to configure virtual hub routing. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.6, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
D: Correct. This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.1: Create a network security group (NSG).
E: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
Learning point: AZ700-51-Q481: Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.
Wingtip Services is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must associate a NSG to a subnet or network interface. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7482. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 5.1.2: This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to choose between public and internal load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.2.
B: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 5.1.2.
C: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.1.2.
D: Not selected. This directly satisfies the requirement to design and implement Azure DNS Private Resolver. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.7, but it does not directly satisfy the scenario requirement mapped to 5.1.2.
E: Correct. This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.2: Associate a NSG to a subnet or network interface.
Learning point: AZ700-51-Q482: Associate the NSG at the subnet for consistent workload policy, at the NIC for justified host-specific policy, or at both only when the combined effective rules are intentionally understood.
Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create an application security group (ASG); associate an ASG to a network interface. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7483. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, F
Why: 5.1.3: This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.4: This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.4: Associate an ASG to a network interface.
B: Not selected. This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.4, but it does not directly satisfy the scenario requirement mapped to 5.1.3, 5.1.4.
C: Not selected. This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.6, but it does not directly satisfy the scenario requirement mapped to 5.1.3, 5.1.4.
D: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 5.1.3, 5.1.4.
E: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 5.1.3, 5.1.4.
F: Correct. This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.3: Create an application security group (ASG).
Learning point: AZ700-51-Q483: Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists. | Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role.
Wingtip Services is reviewing a global application estate serving users on three continents. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must associate an ASG to a network interface; create and configure NSG inbound and outbound security rules. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7484. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, E
Why: 5.1.4: This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.5: This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.4: Associate an ASG to a network interface.
B: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 5.1.4, 5.1.5.
C: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.4, 5.1.5.
D: Not selected. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.5, but it does not directly satisfy the scenario requirement mapped to 5.1.4, 5.1.5.
E: Correct. This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.5: Create and configure NSG inbound and outbound security rules.
F: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure NAT Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.9, but it does not directly satisfy the scenario requirement mapped to 5.1.4, 5.1.5.
Learning point: AZ700-51-Q484: Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role. | Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes.
Proseware Media is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create and configure NSG inbound and outbound security rules. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7485. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 5.1.5: This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.5: Create and configure NSG inbound and outbound security rules.
B: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.1.5.
C: Not selected. This directly satisfies the requirement to select an appropriate virtual network gateway SKU for point-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.1, but it does not directly satisfy the scenario requirement mapped to 5.1.5.
D: Not selected. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.12, but it does not directly satisfy the scenario requirement mapped to 5.1.5.
E: Not selected. This directly satisfies the requirement to choose when to use a public IP address prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.7, but it does not directly satisfy the scenario requirement mapped to 5.1.5.
Learning point: AZ700-51-Q485: Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes.
Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must implement virtual network flow logs; interpret virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 10:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7486. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: B, E
Why: 5.1.6: This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.7: This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 5.1.6, 5.1.7.
B: Correct. This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.6: Implement virtual network flow logs.
C: Not selected. This directly satisfies the requirement to create and configure an Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.6, but it does not directly satisfy the scenario requirement mapped to 5.1.6, 5.1.7.
D: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 5.1.6, 5.1.7.
E: Correct. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.7: Interpret virtual network flow logs.
F: Not selected. This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.13, but it does not directly satisfy the scenario requirement mapped to 5.1.6, 5.1.7.
Learning point: AZ700-51-Q486: Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations. | Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.
Proseware Media is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must interpret virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 13:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7487. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 5.1.7: This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure access to private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.3, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
B: Correct. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.7: Interpret virtual network flow logs.
C: Not selected. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
D: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
E: Not selected. This directly satisfies the requirement to create a backend pool. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
Learning point: AZ700-51-Q487: Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.
Wingtip Services is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must verify IP flow; configure an NSG for remote server administration, including Azure Bastion. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 16:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7488. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, C
Why: 5.1.8: This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.9: This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.8: Verify IP flow.
B: Not selected. This directly satisfies the requirement to integrate a Private Link service with on-premises clients. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.6, but it does not directly satisfy the scenario requirement mapped to 5.1.8, 5.1.9.
C: Correct. This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.9: Configure an NSG for remote server administration, including Azure Bastion.
D: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.8, 5.1.9.
E: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.8, 5.1.9.
F: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 5.1.8, 5.1.9.
Learning point: AZ700-51-Q488: Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible. | Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.
Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must configure an NSG for remote server administration, including Azure Bastion. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 19:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7489. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 5.1.9: This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.1.9.
B: Not selected. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.12, but it does not directly satisfy the scenario requirement mapped to 5.1.9.
C: Correct. This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.9: Configure an NSG for remote server administration, including Azure Bastion.
D: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 5.1.9.
E: Not selected. This directly satisfies the requirement to create a backend pool. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.9.
Learning point: AZ700-51-Q489: Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.
Wingtip Services is reviewing a global application estate serving users on three continents. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must implement and manage virtual network security by using Azure Virtual Network Manager. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 22:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7490. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 5.1.10: This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to design name resolution inside a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.1, but it does not directly satisfy the scenario requirement mapped to 5.1.10.
B: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 5.1.10.
C: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 5.1.10.
D: Correct. This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.10: Implement and manage virtual network security by using Azure Virtual Network Manager.
E: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.10.
Learning point: AZ700-51-Q490: Use Azure Virtual Network Manager security admin configurations for centrally enforced baseline rules across network groups, while leaving NSGs for workload-specific controls.
Proseware Media is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create a network security group (NSG). The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 2:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7491. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 5.1.1: This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
B: Not selected. This directly satisfies the requirement to design and implement user-defined routes (UDRs). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.4, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
C: Not selected. This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.13, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
D: Not selected. This directly satisfies the requirement to configure routing rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.7, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
E: Correct. This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.1: Create a network security group (NSG).
Learning point: AZ700-51-Q491: Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.
Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must associate a NSG to a subnet or network interface. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 5:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7492. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 5.1.2: This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.2: Associate a NSG to a subnet or network interface.
B: Not selected. This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.6, but it does not directly satisfy the scenario requirement mapped to 5.1.2.
C: Not selected. This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.6, but it does not directly satisfy the scenario requirement mapped to 5.1.2.
D: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.2, but it does not directly satisfy the scenario requirement mapped to 5.1.2.
E: Not selected. This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.7, but it does not directly satisfy the scenario requirement mapped to 5.1.2.
Learning point: AZ700-51-Q492: Associate the NSG at the subnet for consistent workload policy, at the NIC for justified host-specific policy, or at both only when the combined effective rules are intentionally understood.
Proseware Media is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create an application security group (ASG). The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 8:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7493. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 5.1.3: This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.3.
B: Correct. This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.3: Create an application security group (ASG).
C: Not selected. This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.1, but it does not directly satisfy the scenario requirement mapped to 5.1.3.
D: Not selected. This directly satisfies the requirement to choose when to use a public IP address prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.7, but it does not directly satisfy the scenario requirement mapped to 5.1.3.
E: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 5.1.3.
Learning point: AZ700-51-Q493: Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.
Wingtip Services is reviewing a regulated production subscription with strict change control. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must associate an ASG to a network interface; create and configure NSG inbound and outbound security rules. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 11:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7494. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: D, E
Why: 5.1.4: This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.5: This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 5.1.4, 5.1.5.
B: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 5.1.4, 5.1.5.
C: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 5.1.4, 5.1.5.
D: Correct. This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.5: Create and configure NSG inbound and outbound security rules.
E: Correct. This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.4: Associate an ASG to a network interface.
F: Not selected. This directly satisfies the requirement to integrate a Private Link service with on-premises clients. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.6, but it does not directly satisfy the scenario requirement mapped to 5.1.4, 5.1.5.
Learning point: AZ700-51-Q494: Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role. | Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes.
Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create and configure NSG inbound and outbound security rules. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 14:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7495. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 5.1.5: This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to design name resolution inside a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.1, but it does not directly satisfy the scenario requirement mapped to 5.1.5.
B: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.5.
C: Correct. This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.5: Create and configure NSG inbound and outbound security rules.
D: Not selected. This directly satisfies the requirement to implement Azure NAT Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.10, but it does not directly satisfy the scenario requirement mapped to 5.1.5.
E: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.5.
Learning point: AZ700-51-Q495: Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes.
Wingtip Services is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must implement virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 17:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7496. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 5.1.6: This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 5.1.6.
B: Not selected. This directly satisfies the requirement to configure Transport Layer Security (TLS). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.9, but it does not directly satisfy the scenario requirement mapped to 5.1.6.
C: Not selected. This directly satisfies the requirement to create and configure an ExpressRoute gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.8, but it does not directly satisfy the scenario requirement mapped to 5.1.6.
D: Correct. This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.6: Implement virtual network flow logs.
E: Not selected. This directly satisfies the requirement to choose an appropriate scale unit for each gateway type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.4, but it does not directly satisfy the scenario requirement mapped to 5.1.6.
Learning point: AZ700-51-Q496: Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations.
Proseware Media is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must interpret virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 20:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7497. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 5.1.7: This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
B: Not selected. This directly satisfies the requirement to choose an appropriate scale unit for each gateway type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.4, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
C: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
D: Not selected. This directly satisfies the requirement to create a public IP address. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.9, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
E: Correct. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.7: Interpret virtual network flow logs.
Learning point: AZ700-51-Q497: Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.
Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must verify IP flow. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 23:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7498. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 5.1.8: This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.8: Verify IP flow.
B: Not selected. This directly satisfies the requirement to choose an appropriate scale unit for each gateway type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.4, but it does not directly satisfy the scenario requirement mapped to 5.1.8.
C: Not selected. This directly satisfies the requirement to implement and manage virtual network connectivity by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.3, but it does not directly satisfy the scenario requirement mapped to 5.1.8.
D: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 5.1.8.
E: Not selected. This directly satisfies the requirement to create a backend pool. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.8.
Learning point: AZ700-51-Q498: Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.
Proseware Media is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must configure an NSG for remote server administration, including Azure Bastion. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 3:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7499. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 5.1.9: This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 5.1.9.
B: Correct. This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.9: Configure an NSG for remote server administration, including Azure Bastion.
C: Not selected. This directly satisfies the requirement to integrate a Private Link service with on-premises clients. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.6, but it does not directly satisfy the scenario requirement mapped to 5.1.9.
D: Not selected. This directly satisfies the requirement to create a Private Link service. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.9.
E: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.9.
Learning point: AZ700-51-Q499: Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.
Wingtip Services is reviewing a regulated production subscription with strict change control. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must implement and manage virtual network security by using Azure Virtual Network Manager. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 6:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7500. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 5.1.10: This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 5.1.10.
B: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.1.10.
C: Correct. This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.10: Implement and manage virtual network security by using Azure Virtual Network Manager.
D: Not selected. This directly satisfies the requirement to configure DNS settings for a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.2, but it does not directly satisfy the scenario requirement mapped to 5.1.10.
E: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.1.10.
Learning point: AZ700-51-Q500: Use Azure Virtual Network Manager security admin configurations for centrally enforced baseline rules across network groups, while leaving NSGs for workload-specific controls.
Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create a network security group (NSG). The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 9:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7501. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 5.1.1: This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
B: Not selected. This directly satisfies the requirement to configure an Azure Front Door, including routing, origins, and endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.4, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
C: Not selected. This directly satisfies the requirement to implement Azure NAT Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.10, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
D: Correct. This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.1: Create a network security group (NSG).
E: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
Learning point: AZ700-51-Q501: Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.
Wingtip Services is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must associate a NSG to a subnet or network interface. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 12:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7502. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 5.1.2: This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to diagnose and resolve routing issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.7, but it does not directly satisfy the scenario requirement mapped to 5.1.2.
B: Not selected. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.5, but it does not directly satisfy the scenario requirement mapped to 5.1.2.
C: Not selected. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.2.
D: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 5.1.2.
E: Correct. This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.2: Associate a NSG to a subnet or network interface.
Learning point: AZ700-51-Q502: Associate the NSG at the subnet for consistent workload policy, at the NIC for justified host-specific policy, or at both only when the combined effective rules are intentionally understood.
Proseware Media is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create an application security group (ASG). The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7503. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 5.1.3: This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.3: Create an application security group (ASG).
B: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.3.
C: Not selected. This directly satisfies the requirement to implement rules, URL rewrite, and URL redirect. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.8, but it does not directly satisfy the scenario requirement mapped to 5.1.3.
D: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.1.3.
E: Not selected. This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.5, but it does not directly satisfy the scenario requirement mapped to 5.1.3.
Learning point: AZ700-51-Q503: Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.
Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must associate an ASG to a network interface. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7504. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 5.1.4: This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.5, but it does not directly satisfy the scenario requirement mapped to 5.1.4.
B: Correct. This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.4: Associate an ASG to a network interface.
C: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 5.1.4.
D: Not selected. This directly satisfies the requirement to plan and configure shared or dedicated subnets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.5, but it does not directly satisfy the scenario requirement mapped to 5.1.4.
E: Not selected. This directly satisfies the requirement to design private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.4.
Learning point: AZ700-51-Q504: Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role.
Proseware Media is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create and configure NSG inbound and outbound security rules. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7505. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 5.1.5: This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.1.5.
B: Not selected. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.5.
C: Correct. This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.5: Create and configure NSG inbound and outbound security rules.
D: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.2, but it does not directly satisfy the scenario requirement mapped to 5.1.5.
E: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.2, but it does not directly satisfy the scenario requirement mapped to 5.1.5.
Learning point: AZ700-51-Q505: Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes.
Wingtip Services is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must implement virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7506. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 5.1.6: This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure TLS termination and end-to-end TLS encryption. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.5, but it does not directly satisfy the scenario requirement mapped to 5.1.6.
B: Not selected. This directly satisfies the requirement to plan and configure subnet delegation. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.6.
C: Not selected. This directly satisfies the requirement to create a public IP address. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.9, but it does not directly satisfy the scenario requirement mapped to 5.1.6.
D: Correct. This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.6: Implement virtual network flow logs.
E: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.6.
Learning point: AZ700-51-Q506: Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations.
Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must interpret virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7507. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 5.1.7: This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
B: Not selected. This directly satisfies the requirement to configure public and private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.5, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
C: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
D: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
E: Correct. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.7: Interpret virtual network flow logs.
Learning point: AZ700-51-Q507: Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.
Wingtip Services is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must verify IP flow. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7508. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 5.1.8: This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.8: Verify IP flow.
B: Not selected. This directly satisfies the requirement to design and implement user-defined routes (UDRs). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.4, but it does not directly satisfy the scenario requirement mapped to 5.1.8.
C: Not selected. This directly satisfies the requirement to design and implement Azure Route Server. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.8, but it does not directly satisfy the scenario requirement mapped to 5.1.8.
D: Not selected. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.8.
E: Not selected. This directly satisfies the requirement to create a Private Link service. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.8.
Learning point: AZ700-51-Q508: Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.
Proseware Media is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must configure an NSG for remote server administration, including Azure Bastion. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 10:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7509. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 5.1.9: This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.7, but it does not directly satisfy the scenario requirement mapped to 5.1.9.
B: Correct. This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.9: Configure an NSG for remote server administration, including Azure Bastion.
C: Not selected. This directly satisfies the requirement to plan and implement a Custom IP address prefix (bring your own IP). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.8, but it does not directly satisfy the scenario requirement mapped to 5.1.9.
D: Not selected. This directly satisfies the requirement to select a Virtual WAN SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.1, but it does not directly satisfy the scenario requirement mapped to 5.1.9.
E: Not selected. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.10, but it does not directly satisfy the scenario requirement mapped to 5.1.9.
Learning point: AZ700-51-Q509: Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.
Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must implement and manage virtual network security by using Azure Virtual Network Manager; create a network security group (NSG). The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 13:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7510. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: B, C
Why: 5.1.10: This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.1: This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.10, 5.1.1.
B: Correct. This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.1: Create a network security group (NSG).
C: Correct. This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.10: Implement and manage virtual network security by using Azure Virtual Network Manager.
D: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.1.10, 5.1.1.
E: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.1.10, 5.1.1.
F: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.10, 5.1.1.
Learning point: AZ700-51-Q510: Use Azure Virtual Network Manager security admin configurations for centrally enforced baseline rules across network groups, while leaving NSGs for workload-specific controls. | Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.
Proseware Media is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create a network security group (NSG). The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 16:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7511. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 5.1.1: This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
B: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
C: Correct. This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.1: Create a network security group (NSG).
D: Not selected. This directly satisfies the requirement to choose an Azure Load Balancer SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.3, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
E: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
Learning point: AZ700-51-Q511: Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.
Wingtip Services is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must associate a NSG to a subnet or network interface. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 19:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7512. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 5.1.2: This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 5.1.2.
B: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 5.1.2.
C: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.2.
D: Correct. This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.2: Associate a NSG to a subnet or network interface.
E: Not selected. This directly satisfies the requirement to secure an origin by using Azure Private Link in Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.9, but it does not directly satisfy the scenario requirement mapped to 5.1.2.
Learning point: AZ700-51-Q512: Associate the NSG at the subnet for consistent workload policy, at the NIC for justified host-specific policy, or at both only when the combined effective rules are intentionally understood.
Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create an application security group (ASG). The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 22:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7513. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 5.1.3: This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.6, but it does not directly satisfy the scenario requirement mapped to 5.1.3.
B: Not selected. This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.2, but it does not directly satisfy the scenario requirement mapped to 5.1.3.
C: Not selected. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.12, but it does not directly satisfy the scenario requirement mapped to 5.1.3.
D: Not selected. This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.8, but it does not directly satisfy the scenario requirement mapped to 5.1.3.
E: Correct. This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.3: Create an application security group (ASG).
Learning point: AZ700-51-Q513: Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.
Wingtip Services is reviewing a global application estate serving users on three continents. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must associate an ASG to a network interface. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 2:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7514. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 5.1.4: This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.4: Associate an ASG to a network interface.
B: Not selected. This directly satisfies the requirement to plan and configure subnet delegation. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.4.
C: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.4.
D: Not selected. This directly satisfies the requirement to configure caching. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.6, but it does not directly satisfy the scenario requirement mapped to 5.1.4.
E: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 5.1.4.
Learning point: AZ700-51-Q514: Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role.
Proseware Media is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create and configure NSG inbound and outbound security rules. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 5:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7515. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 5.1.5: This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.5.
B: Correct. This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.5: Create and configure NSG inbound and outbound security rules.
C: Not selected. This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.1, but it does not directly satisfy the scenario requirement mapped to 5.1.5.
D: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 5.1.5.
E: Not selected. This directly satisfies the requirement to integrate a virtual hub with a third-party NVA for cloud connectivity. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.7, but it does not directly satisfy the scenario requirement mapped to 5.1.5.
Learning point: AZ700-51-Q515: Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes.
Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must implement virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 8:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7516. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 5.1.6: This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.6, but it does not directly satisfy the scenario requirement mapped to 5.1.6.
B: Not selected. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.6.
C: Correct. This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.6: Implement virtual network flow logs.
D: Not selected. This directly satisfies the requirement to choose an appropriate scale unit for each gateway type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.4, but it does not directly satisfy the scenario requirement mapped to 5.1.6.
E: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.6.
Learning point: AZ700-51-Q516: Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations.
Proseware Media is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must interpret virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 11:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7517. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 5.1.7: This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
B: Not selected. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.10, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
C: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
D: Correct. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.7: Interpret virtual network flow logs.
E: Not selected. This directly satisfies the requirement to design and implement Azure DNS Private Resolver. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.7, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
Learning point: AZ700-51-Q517: Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.
Wingtip Services is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must verify IP flow. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 14:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7518. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 5.1.8: This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.1.8.
B: Not selected. This directly satisfies the requirement to create a virtual network (VNet). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.2, but it does not directly satisfy the scenario requirement mapped to 5.1.8.
C: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 5.1.8.
D: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.2, but it does not directly satisfy the scenario requirement mapped to 5.1.8.
E: Correct. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.8: Verify IP flow.
Learning point: AZ700-51-Q518: Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.
Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must configure an NSG for remote server administration, including Azure Bastion. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 17:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7519. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 5.1.9: This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.9: Configure an NSG for remote server administration, including Azure Bastion.
B: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 5.1.9.
C: Not selected. This directly satisfies the requirement to integrate a Private Link service with on-premises clients. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.6, but it does not directly satisfy the scenario requirement mapped to 5.1.9.
D: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 5.1.9.
E: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.1.9.
Learning point: AZ700-51-Q519: Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.
Wingtip Services is reviewing a global application estate serving users on three continents. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must implement and manage virtual network security by using Azure Virtual Network Manager. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 20:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7520. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 5.1.10: This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to create a backend pool. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.10.
B: Correct. This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.10: Implement and manage virtual network security by using Azure Virtual Network Manager.
C: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.1.10.
D: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.1.10.
E: Not selected. This directly satisfies the requirement to create a Private Link service. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.10.
Learning point: AZ700-51-Q520: Use Azure Virtual Network Manager security admin configurations for centrally enforced baseline rules across network groups, while leaving NSGs for workload-specific controls.
Proseware Media is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create a network security group (NSG). The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 23:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7521. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 5.1.1: This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
B: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
C: Correct. This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.1: Create a network security group (NSG).
D: Not selected. This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.7, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
E: Not selected. This directly satisfies the requirement to configure virtual hub routing. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.6, but it does not directly satisfy the scenario requirement mapped to 5.1.1.
Learning point: AZ700-51-Q521: Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.
Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must associate a NSG to a subnet or network interface; create an application security group (ASG). The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 3:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7522. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, E
Why: 5.1.2: This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.3: This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.3: Create an application security group (ASG).
B: Not selected. This directly satisfies the requirement to specify Azure requirements for Always On VPN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.8, but it does not directly satisfy the scenario requirement mapped to 5.1.2, 5.1.3.
C: Not selected. This directly satisfies the requirement to design and implement Azure Route Server. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.8, but it does not directly satisfy the scenario requirement mapped to 5.1.2, 5.1.3.
D: Not selected. This directly satisfies the requirement to diagnose and resolve routing issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.7, but it does not directly satisfy the scenario requirement mapped to 5.1.2, 5.1.3.
E: Correct. This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.2: Associate a NSG to a subnet or network interface.
F: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.1.2, 5.1.3.
Learning point: AZ700-51-Q522: Associate the NSG at the subnet for consistent workload policy, at the NIC for justified host-specific policy, or at both only when the combined effective rules are intentionally understood. | Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.
Proseware Media is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create an application security group (ASG). The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 6:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7523. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 5.1.3: This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 5.1.3.
B: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 5.1.3.
C: Not selected. This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.4, but it does not directly satisfy the scenario requirement mapped to 5.1.3.
D: Correct. This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.3: Create an application security group (ASG).
E: Not selected. This directly satisfies the requirement to select a Virtual WAN SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.1, but it does not directly satisfy the scenario requirement mapped to 5.1.3.
Learning point: AZ700-51-Q523: Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.
Wingtip Services is reviewing a regulated production subscription with strict change control. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must associate an ASG to a network interface. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 9:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7524. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 5.1.4: This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.4.
B: Not selected. This directly satisfies the requirement to diagnose and resolve routing issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.7, but it does not directly satisfy the scenario requirement mapped to 5.1.4.
C: Not selected. This directly satisfies the requirement to specify Azure requirements for Always On VPN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.8, but it does not directly satisfy the scenario requirement mapped to 5.1.4.
D: Not selected. This directly satisfies the requirement to create and configure inbound NAT rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.10, but it does not directly satisfy the scenario requirement mapped to 5.1.4.
E: Correct. This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.4: Associate an ASG to a network interface.
Learning point: AZ700-51-Q524: Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role.
Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must create and configure NSG inbound and outbound security rules; implement virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 12:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7525. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, B
Why: 5.1.5: This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.6: This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.6: Implement virtual network flow logs.
B: Correct. This directly satisfies the requirement to create and configure NSG inbound and outbound security rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.5: Create and configure NSG inbound and outbound security rules.
C: Not selected. This directly satisfies the requirement to link a private DNS zone to a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.6, but it does not directly satisfy the scenario requirement mapped to 5.1.5, 5.1.6.
D: Not selected. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.10, but it does not directly satisfy the scenario requirement mapped to 5.1.5, 5.1.6.
E: Not selected. This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.1, but it does not directly satisfy the scenario requirement mapped to 5.1.5, 5.1.6.
F: Not selected. This directly satisfies the requirement to specify Azure requirements for Always On VPN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.8, but it does not directly satisfy the scenario requirement mapped to 5.1.5, 5.1.6.
Learning point: AZ700-51-Q525: Create least-privilege NSG rules with explicit source, destination, protocol, port, direction, action, and priority, leaving a clear gap between priorities for future changes. | Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations.
Wingtip Services is reviewing a global application estate serving users on three continents. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must implement virtual network flow logs; interpret virtual network flow logs; verify IP flow. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7526. Which THREE recommendations should be implemented together? Select THREE answers.
Correct answers: A, B, D
Why: 5.1.6: This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.7: This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.8: This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.6: Implement virtual network flow logs.
B: Correct. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.7: Interpret virtual network flow logs.
C: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.2, but it does not directly satisfy the scenario requirement mapped to 5.1.6, 5.1.7, 5.1.8.
D: Correct. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.8: Verify IP flow.
E: Not selected. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.10, but it does not directly satisfy the scenario requirement mapped to 5.1.6, 5.1.7, 5.1.8.
F: Not selected. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.6, 5.1.7, 5.1.8.
Learning point: AZ700-51-Q526: Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations. | Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy. | Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.
Proseware Media is reviewing a regulated production subscription with strict change control. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The network engineer must interpret virtual network flow logs. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7527. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 5.1.7: This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.7: Interpret virtual network flow logs.
B: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
C: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
D: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.1, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
E: Not selected. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.4, but it does not directly satisfy the scenario requirement mapped to 5.1.7.
Learning point: AZ700-51-Q527: Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.
Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The team must enforce and prove least-privilege Layer 3/4 access without opening broad management or application ports. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must verify IP flow; configure an NSG for remote server administration, including Azure Bastion; implement and manage virtual network security by using Azure Virtual Network Manager. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7528. Which THREE recommendations should be implemented together? Select THREE answers.
Correct answers: A, B, E
Why: 5.1.8: This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.9: This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.1.10: This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.9: Configure an NSG for remote server administration, including Azure Bastion.
B: Correct. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.8: Verify IP flow.
C: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 5.1.8, 5.1.9, 5.1.10.
D: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.1.8, 5.1.9, 5.1.10.
E: Correct. This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.1.10: Implement and manage virtual network security by using Azure Virtual Network Manager.
F: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.1.8, 5.1.9, 5.1.10.
Learning point: AZ700-51-Q528: Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible. | Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window. | Use Azure Virtual Network Manager security admin configurations for centrally enforced baseline rules across network groups, while leaving NSGs for workload-specific controls.
Popular posts
Recent Posts
