Microsoft AZ-700 Monitor Networks Practice Test

 

AZ-700 skill 1.4 | 31 original questions

This AZ-700 practice set focuses on monitor networks through original scenario-based questions aligned to Microsoft skills measured as of July 27, 2026. The set is mapped to every official objective leaf assigned to this skill area. For broader exam preparation, review the Microsoft AZ-700 Exam Dumps page.

Instructions: Follow the selection count stated in each question. Review the rationale after answering. Every option includes a brief explanation of why it is or is not selected for the stated scenario.

Question 135

Fabrikam Logistics is reviewing a multi-subscription landing zone with centralized networking. Operators need evidence that identifies the failing hop or policy before they make a production network change. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must configure monitoring, network diagnostics, and logs in Azure Network Watcher; monitor and troubleshoot network health by using Azure Network Watcher. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the platform governance council. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7135. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  2. Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing.
  3. Use Global Reach for private site-to-site connectivity through Microsoft, FastPath to bypass the gateway data path where supported, and ExpressRoute Direct when dedicated Microsoft peering ports and very high bandwidth are required.
  4. Enable the relevant Network Watcher diagnostics, Connection Monitor, packet capture, topology, and supported flow logging, then send evidence to the approved monitoring destination.
  5. Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
  6. Publish the producer service through a Private Link Service behind a Standard internal Load Balancer, configure NAT IPs and visibility/approval, and onboard consumer private endpoints.

Correct answers: B, D

Why: 1.4.1: This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 1.4.2: This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 1.4.1, 1.4.2.

B: Correct. This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.2: Monitor and troubleshoot network health by using Azure Network Watcher.

C: Not selected. This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.4, but it does not directly satisfy the scenario requirement mapped to 1.4.1, 1.4.2.

D: Correct. This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.1: Configure monitoring, network diagnostics, and logs in Azure Network Watcher.

E: Not selected. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.7, but it does not directly satisfy the scenario requirement mapped to 1.4.1, 1.4.2.

F: Not selected. This directly satisfies the requirement to create a Private Link service. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.4, but it does not directly satisfy the scenario requirement mapped to 1.4.1, 1.4.2.

Learning point: AZ700-14-Q135: Enable the relevant Network Watcher diagnostics, Connection Monitor, packet capture, topology, and supported flow logging, then send evidence to the approved monitoring destination. | Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing.

Question 136

VanArsdel Energy is reviewing an Azure estate that must keep administrative traffic off the public internet. Operators need evidence that identifies the failing hop or policy before they make a production network change. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must monitor and troubleshoot network health by using Azure Network Watcher; monitor and troubleshoot networks by using Azure Monitor for Networks. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the network operations team. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7136. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Create a private endpoint in the selected subnet for the specific service subresource, approve the connection where required, and validate the assigned private IP.
  2. Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing.
  3. Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
  4. Configure listeners with the correct frontend IP, port, protocol, host name, and certificate settings so requests match the intended site before routing rules are evaluated.
  5. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.
  6. Use Front Door’s edge ingress and Microsoft global network path to accelerate HTTP(S) traffic, keeping origins healthy and appropriately placed rather than forcing clients to connect directly to distant regions.

Correct answers: B, E

Why: 1.4.2: This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 1.4.3: This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to create private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.2, but it does not directly satisfy the scenario requirement mapped to 1.4.2, 1.4.3.

B: Correct. This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.2: Monitor and troubleshoot network health by using Azure Network Watcher.

C: Not selected. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.7, but it does not directly satisfy the scenario requirement mapped to 1.4.2, 1.4.3.

D: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 1.4.2, 1.4.3.

E: Correct. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.3: Monitor and troubleshoot networks by using Azure Monitor for Networks.

F: Not selected. This directly satisfies the requirement to configure traffic acceleration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.7, but it does not directly satisfy the scenario requirement mapped to 1.4.2, 1.4.3.

Learning point: AZ700-14-Q136: Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing. | Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.

Question 137

Fabrikam Logistics is reviewing a zero-trust network redesign with centralized observability. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must monitor and troubleshoot networks by using Azure Monitor for Networks. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the Azure landing-zone owner. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7137. Which recommendation most directly meets the requirement? Select one answer.

  1. Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct.
  2. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.
  3. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  4. Configure the Azure VPN gateway, local network gateway, shared security parameters, and on-premises VPN device so both sides use compatible routes and IPsec/IKE settings.
  5. Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.

Correct answer: B

Why: 1.4.3: This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 1.4.3.

B: Correct. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.3: Monitor and troubleshoot networks by using Azure Monitor for Networks.

C: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 1.4.3.

D: Not selected. This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.3, but it does not directly satisfy the scenario requirement mapped to 1.4.3.

E: Not selected. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.6, but it does not directly satisfy the scenario requirement mapped to 1.4.3.

Learning point: AZ700-14-Q137: Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.

Question 138

VanArsdel Energy is reviewing a multi-subscription landing zone with centralized networking. Internet-facing endpoints need platform-level volumetric attack protection with operational telemetry and response integration. The network engineer must activate and monitor distributed denial-of-service (DDoS) protection. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the business continuity lead. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7138. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings.
  2. Choose Azure Front Door when users need a global HTTP(S) entry point with edge acceleration and resilient multi-region routing rather than a region-bound Layer 7 gateway.
  3. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  4. Choose Application Gateway when the application needs regional Layer 7 routing, TLS offload, cookie affinity, redirects/rewrites, or WAF close to Azure backends.
  5. Use Azure private peering for private VNet routes, Microsoft peering for supported Microsoft public services, or both when the requirements explicitly need both routing domains.

Correct answer: C

Why: 1.4.4: This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.5, but it does not directly satisfy the scenario requirement mapped to 1.4.4.

B: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.2, but it does not directly satisfy the scenario requirement mapped to 1.4.4.

C: Correct. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.4: Activate and monitor distributed denial-of-service (DDoS) protection.

D: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.2, but it does not directly satisfy the scenario requirement mapped to 1.4.4.

E: Not selected. This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.5, but it does not directly satisfy the scenario requirement mapped to 1.4.4.

Learning point: AZ700-14-Q138: Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.

Question 139

Fabrikam Logistics is reviewing an Azure estate that must keep administrative traffic off the public internet. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the platform governance council. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7139. Which recommendation most directly meets the requirement? Select one answer.

  1. Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
  2. Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.
  3. Enable Front Door caching only for cacheable content, set query-string and compression behavior intentionally, and use cache-control/rules so personalized or sensitive responses are not cached.
  4. Use Microsoft Defender for Cloud Secure Score recommendations to prioritize network hardening items by exposure, impact, and remediation value instead of treating every finding equally.
  5. Select the supported Standard SKU/tier and regional or global design based on zone resiliency, scale, cross-region requirements, and backend resource compatibility.

Correct answer: D

Why: 1.4.5: This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.3, but it does not directly satisfy the scenario requirement mapped to 1.4.5.

B: Not selected. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.4, but it does not directly satisfy the scenario requirement mapped to 1.4.5.

C: Not selected. This directly satisfies the requirement to configure caching. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.6, but it does not directly satisfy the scenario requirement mapped to 1.4.5.

D: Correct. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.5: Evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score.

E: Not selected. This directly satisfies the requirement to choose an Azure Load Balancer SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.3, but it does not directly satisfy the scenario requirement mapped to 1.4.5.

Learning point: AZ700-14-Q139: Use Microsoft Defender for Cloud Secure Score recommendations to prioritize network hardening items by exposure, impact, and remediation value instead of treating every finding equally.

Question 140

VanArsdel Energy is reviewing a zero-trust network redesign with centralized observability. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the network operations team. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7140. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Application Gateway rewrite rule sets to modify supported request or response headers and URLs under explicit conditions instead of changing application code for simple gateway-layer transformations.
  2. Implement the Azure networking capability named in the requirement using the supported Microsoft configuration, validate prerequisites and dependencies, and confirm the result with Azure-native diagnostics before production rollout.
  3. Use redundant ExpressRoute circuits/peerings and appropriately resilient gateways, with cross-region or disaster-recovery routing designed so a single circuit, provider edge, or region does not become a single point of failure.
  4. Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
  5. Use Defender for Cloud attack path analysis to identify exploitable chains that reach high-value assets and remediate the choke points that reduce the greatest real attack exposure.

Correct answer: E

Why: 1.4.6: This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 1.4.6.

B: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 1.4.6.

C: Not selected. This directly satisfies the requirement to design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.3, but it does not directly satisfy the scenario requirement mapped to 1.4.6.

D: Not selected. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.2, but it does not directly satisfy the scenario requirement mapped to 1.4.6.

E: Correct. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.6: Evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis.

Learning point: AZ700-14-Q140: Use Defender for Cloud attack path analysis to identify exploitable chains that reach high-value assets and remediate the choke points that reduce the greatest real attack exposure.

Question 141

Fabrikam Logistics is reviewing a multi-subscription landing zone with centralized networking. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. Operators need evidence that identifies the failing hop or policy before they make a production network change. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud; configure monitoring, network diagnostics, and logs in Azure Network Watcher; monitor and troubleshoot network health by using Azure Network Watcher. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the Azure landing-zone owner. Change window 10:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7141. Which THREE recommendations should be implemented together? Select THREE answers.

  1. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  2. Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway.
  3. Use Cloud Security Explorer to query the cloud security graph for network resources and relationships, then pivot from the results into the relevant posture or exposure investigation.
  4. Configure the Azure VPN gateway, local network gateway, shared security parameters, and on-premises VPN device so both sides use compatible routes and IPsec/IKE settings.
  5. Enable the relevant Network Watcher diagnostics, Connection Monitor, packet capture, topology, and supported flow logging, then send evidence to the approved monitoring destination.
  6. Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing.

Correct answers: C, E, F

Why: 1.4.7: This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 1.4.1: This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 1.4.2: This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 1.4.7, 1.4.1, 1.4.2.

B: Not selected. This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.6, but it does not directly satisfy the scenario requirement mapped to 1.4.7, 1.4.1, 1.4.2.

C: Correct. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.7: Identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud.

D: Not selected. This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.3, but it does not directly satisfy the scenario requirement mapped to 1.4.7, 1.4.1, 1.4.2.

E: Correct. This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.1: Configure monitoring, network diagnostics, and logs in Azure Network Watcher.

F: Correct. This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.2: Monitor and troubleshoot network health by using Azure Network Watcher.

Learning point: AZ700-14-Q141: Use Cloud Security Explorer to query the cloud security graph for network resources and relationships, then pivot from the results into the relevant posture or exposure investigation. | Enable the relevant Network Watcher diagnostics, Connection Monitor, packet capture, topology, and supported flow logging, then send evidence to the approved monitoring destination. | Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing.

Question 142

VanArsdel Energy is reviewing an Azure estate that must keep administrative traffic off the public internet. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must configure monitoring, network diagnostics, and logs in Azure Network Watcher. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the business continuity lead. Change window 13:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7142. Which recommendation most directly meets the requirement? Select one answer.

  1. Enable the relevant Network Watcher diagnostics, Connection Monitor, packet capture, topology, and supported flow logging, then send evidence to the approved monitoring destination.
  2. Deploy the required VPN, ExpressRoute, or P2S gateway into the Virtual WAN hub and size it independently for that connectivity type.
  3. Integrate a supported third-party NVA into the Virtual WAN hub using the vendor-supported deployment and routing model, then validate route propagation and symmetric traffic paths.
  4. Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
  5. Configure the Azure VPN gateway, local network gateway, shared security parameters, and on-premises VPN device so both sides use compatible routes and IPsec/IKE settings.

Correct answer: A

Why: 1.4.1: This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.1: Configure monitoring, network diagnostics, and logs in Azure Network Watcher.

B: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 1.4.1.

C: Not selected. This directly satisfies the requirement to integrate a virtual hub with a third-party NVA for cloud connectivity. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.7, but it does not directly satisfy the scenario requirement mapped to 1.4.1.

D: Not selected. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.7, but it does not directly satisfy the scenario requirement mapped to 1.4.1.

E: Not selected. This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.3, but it does not directly satisfy the scenario requirement mapped to 1.4.1.

Learning point: AZ700-14-Q142: Enable the relevant Network Watcher diagnostics, Connection Monitor, packet capture, topology, and supported flow logging, then send evidence to the approved monitoring destination.

Question 143

Fabrikam Logistics is reviewing a zero-trust network redesign with centralized observability. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must monitor and troubleshoot network health by using Azure Network Watcher. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the platform governance council. Change window 16:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7143. Which recommendation most directly meets the requirement? Select one answer.

  1. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.
  2. Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing.
  3. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  4. Create the Virtual WAN virtual hub in the target region with a nonoverlapping hub address prefix sized for the planned gateways and routing scale.
  5. Terminate or re-encrypt TLS on Application Gateway using certificates from the approved source, enforce the required TLS policy, and validate end-to-end certificate trust when HTTPS continues to the backend.

Correct answer: B

Why: 1.4.2: This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.4, but it does not directly satisfy the scenario requirement mapped to 1.4.2.

B: Correct. This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.2: Monitor and troubleshoot network health by using Azure Network Watcher.

C: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 1.4.2.

D: Not selected. This directly satisfies the requirement to create a virtual hub in Virtual WAN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.3, but it does not directly satisfy the scenario requirement mapped to 1.4.2.

E: Not selected. This directly satisfies the requirement to configure Transport Layer Security (TLS). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.9, but it does not directly satisfy the scenario requirement mapped to 1.4.2.

Learning point: AZ700-14-Q143: Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing.

Question 144

VanArsdel Energy is reviewing a multi-subscription landing zone with centralized networking. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must monitor and troubleshoot networks by using Azure Monitor for Networks. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the network operations team. Change window 19:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7144. Which recommendation most directly meets the requirement? Select one answer.

  1. Create a private endpoint in the selected subnet for the specific service subresource, approve the connection where required, and validate the assigned private IP.
  2. Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.
  3. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.
  4. Implement the Azure networking capability named in the requirement using the supported Microsoft configuration, validate prerequisites and dependencies, and confirm the result with Azure-native diagnostics before production rollout.
  5. Enable BFD on supported ExpressRoute peering to detect path failures faster than standard BGP timers and accelerate convergence.

Correct answer: C

Why: 1.4.3: This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to create private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.2, but it does not directly satisfy the scenario requirement mapped to 1.4.3.

B: Not selected. This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.2, but it does not directly satisfy the scenario requirement mapped to 1.4.3.

C: Correct. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.3: Monitor and troubleshoot networks by using Azure Monitor for Networks.

D: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 1.4.3.

E: Not selected. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.12, but it does not directly satisfy the scenario requirement mapped to 1.4.3.

Learning point: AZ700-14-Q144: Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.

Question 145

Fabrikam Logistics is reviewing an Azure estate that must keep administrative traffic off the public internet. Internet-facing endpoints need platform-level volumetric attack protection with operational telemetry and response integration. The network engineer must activate and monitor distributed denial-of-service (DDoS) protection. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the Azure landing-zone owner. Change window 22:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7145. Which recommendation most directly meets the requirement? Select one answer.

  1. Advertise only the intended, nonoverlapping prefixes through BGP, summarize where safe, and use route filters or communities on Microsoft peering rather than leaking unrelated routes.
  2. Attach a Front Door WAF policy with the required managed rule set and tuned custom rules to the relevant Front Door domains/routes, using exclusions only for well-understood false positives.
  3. Size each Virtual WAN gateway using the service’s scale units based on expected aggregate throughput, connection count, and resiliency requirements, then monitor utilization for growth.
  4. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  5. Control private-endpoint reachability with routing, DNS, NSGs where supported, and service-side public-network settings so only approved private clients can reach the resource.

Correct answer: D

Why: 1.4.4: This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.10, but it does not directly satisfy the scenario requirement mapped to 1.4.4.

B: Not selected. This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.4, but it does not directly satisfy the scenario requirement mapped to 1.4.4.

C: Not selected. This directly satisfies the requirement to choose an appropriate scale unit for each gateway type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.4, but it does not directly satisfy the scenario requirement mapped to 1.4.4.

D: Correct. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.4: Activate and monitor distributed denial-of-service (DDoS) protection.

E: Not selected. This directly satisfies the requirement to configure access to private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.3, but it does not directly satisfy the scenario requirement mapped to 1.4.4.

Learning point: AZ700-14-Q145: Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.

Question 146

VanArsdel Energy is reviewing a zero-trust network redesign with centralized observability. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the business continuity lead. Change window 2:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7146. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies.
  2. Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.
  3. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.
  4. Configure a custom health probe that targets a reliable application health endpoint with the right host, protocol, path, interval, timeout, and healthy-status criteria.
  5. Use Microsoft Defender for Cloud Secure Score recommendations to prioritize network hardening items by exposure, impact, and remediation value instead of treating every finding equally.

Correct answer: E

Why: 1.4.5: This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.5, but it does not directly satisfy the scenario requirement mapped to 1.4.5.

B: Not selected. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.4, but it does not directly satisfy the scenario requirement mapped to 1.4.5.

C: Not selected. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.4, but it does not directly satisfy the scenario requirement mapped to 1.4.5.

D: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 1.4.5.

E: Correct. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.5: Evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score.

Learning point: AZ700-14-Q146: Use Microsoft Defender for Cloud Secure Score recommendations to prioritize network hardening items by exposure, impact, and remediation value instead of treating every finding equally.

Question 147

Fabrikam Logistics is reviewing a multi-subscription landing zone with centralized networking. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the platform governance council. Change window 5:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7147. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Defender for Cloud attack path analysis to identify exploitable chains that reach high-value assets and remediate the choke points that reduce the greatest real attack exposure.
  2. Configure backend HTTP settings for protocol, port, host-name handling, cookie affinity, timeout, connection draining, and trusted backend certificates as required.
  3. Use redundant ExpressRoute circuits/peerings and appropriately resilient gateways, with cross-region or disaster-recovery routing designed so a single circuit, provider edge, or region does not become a single point of failure.
  4. Use Azure Front Door for global Layer 7 anycast entry, health-based routing, acceleration, TLS, caching, rules, and optional WAF across geographically distributed origins.
  5. Use the Microsoft-recommended private DNS zone for the service, link it to consuming VNets, and ensure hybrid DNS forwards the private namespace so the public FQDN resolves to the private endpoint address for authorized clients.

Correct answer: A

Why: 1.4.6: This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.6: Evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis.

B: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 1.4.6.

C: Not selected. This directly satisfies the requirement to design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.3, but it does not directly satisfy the scenario requirement mapped to 1.4.6.

D: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.1, but it does not directly satisfy the scenario requirement mapped to 1.4.6.

E: Not selected. This directly satisfies the requirement to integrate Private Link and Private Endpoint with DNS. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.5, but it does not directly satisfy the scenario requirement mapped to 1.4.6.

Learning point: AZ700-14-Q147: Use Defender for Cloud attack path analysis to identify exploitable chains that reach high-value assets and remediate the choke points that reduce the greatest real attack exposure.

Question 148

VanArsdel Energy is reviewing an Azure estate that must keep administrative traffic off the public internet. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud; configure monitoring, network diagnostics, and logs in Azure Network Watcher. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the network operations team. Change window 8:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7148. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Enable the relevant Network Watcher diagnostics, Connection Monitor, packet capture, topology, and supported flow logging, then send evidence to the approved monitoring destination.
  2. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.
  3. Use Cloud Security Explorer to query the cloud security graph for network resources and relationships, then pivot from the results into the relevant posture or exposure investigation.
  4. Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.
  5. Use Gateway Load Balancer to insert and scale compatible NVAs transparently in the traffic path through service chaining with a consumer frontend.
  6. Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.

Correct answers: A, C

Why: 1.4.7: This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 1.4.1: This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.1: Configure monitoring, network diagnostics, and logs in Azure Network Watcher.

B: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 1.4.7, 1.4.1.

C: Correct. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.7: Identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud.

D: Not selected. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.8, but it does not directly satisfy the scenario requirement mapped to 1.4.7, 1.4.1.

E: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 1.4.7, 1.4.1.

F: Not selected. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.7, but it does not directly satisfy the scenario requirement mapped to 1.4.7, 1.4.1.

Learning point: AZ700-14-Q148: Use Cloud Security Explorer to query the cloud security graph for network resources and relationships, then pivot from the results into the relevant posture or exposure investigation. | Enable the relevant Network Watcher diagnostics, Connection Monitor, packet capture, topology, and supported flow logging, then send evidence to the approved monitoring destination.

Question 149

Fabrikam Logistics is reviewing a zero-trust network redesign with centralized observability. Operators need evidence that identifies the failing hop or policy before they make a production network change. Operators need evidence that identifies the failing hop or policy before they make a production network change. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must configure monitoring, network diagnostics, and logs in Azure Network Watcher; monitor and troubleshoot network health by using Azure Network Watcher; monitor and troubleshoot networks by using Azure Monitor for Networks. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the Azure landing-zone owner. Change window 11:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7149. Which THREE recommendations should be implemented together? Select THREE answers.

  1. Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing.
  2. Enable BFD on supported ExpressRoute peering to detect path failures faster than standard BGP timers and accelerate convergence.
  3. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  4. Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct.
  5. Enable the relevant Network Watcher diagnostics, Connection Monitor, packet capture, topology, and supported flow logging, then send evidence to the approved monitoring destination.
  6. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.

Correct answers: A, E, F

Why: 1.4.1: This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 1.4.2: This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 1.4.3: This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.2: Monitor and troubleshoot network health by using Azure Network Watcher.

B: Not selected. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.12, but it does not directly satisfy the scenario requirement mapped to 1.4.1, 1.4.2, 1.4.3.

C: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 1.4.1, 1.4.2, 1.4.3.

D: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 1.4.1, 1.4.2, 1.4.3.

E: Correct. This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.1: Configure monitoring, network diagnostics, and logs in Azure Network Watcher.

F: Correct. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.3: Monitor and troubleshoot networks by using Azure Monitor for Networks.

Learning point: AZ700-14-Q149: Enable the relevant Network Watcher diagnostics, Connection Monitor, packet capture, topology, and supported flow logging, then send evidence to the approved monitoring destination. | Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing. | Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.

Question 150

VanArsdel Energy is reviewing a multi-subscription landing zone with centralized networking. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must monitor and troubleshoot network health by using Azure Network Watcher. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the business continuity lead. Change window 14:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7150. Which recommendation most directly meets the requirement? Select one answer.

  1. Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention.
  2. Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing.
  3. Use Front Door’s edge ingress and Microsoft global network path to accelerate HTTP(S) traffic, keeping origins healthy and appropriately placed rather than forcing clients to connect directly to distant regions.
  4. Configure backend HTTP settings for protocol, port, host-name handling, cookie affinity, timeout, connection draining, and trusted backend certificates as required.
  5. Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.

Correct answer: B

Why: 1.4.2: This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.1, but it does not directly satisfy the scenario requirement mapped to 1.4.2.

B: Correct. This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.2: Monitor and troubleshoot network health by using Azure Network Watcher.

C: Not selected. This directly satisfies the requirement to configure traffic acceleration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.7, but it does not directly satisfy the scenario requirement mapped to 1.4.2.

D: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 1.4.2.

E: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 1.4.2.

Learning point: AZ700-14-Q150: Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing.

Question 151

Fabrikam Logistics is reviewing an Azure estate that must keep administrative traffic off the public internet. Operators need evidence that identifies the failing hop or policy before they make a production network change. Internet-facing endpoints need platform-level volumetric attack protection with operational telemetry and response integration. The network engineer must monitor and troubleshoot networks by using Azure Monitor for Networks; activate and monitor distributed denial-of-service (DDoS) protection. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the platform governance council. Change window 17:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7151. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Configure backend HTTP settings for protocol, port, host-name handling, cookie affinity, timeout, connection draining, and trusted backend certificates as required.
  2. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  3. Deploy the required VPN, ExpressRoute, or P2S gateway into the Virtual WAN hub and size it independently for that connectivity type.
  4. Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct.
  5. Configure the load-balancing rule with the correct frontend, backend pool, protocol, ports, health probe, session persistence, and floating-IP settings for the workload.
  6. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.

Correct answers: B, F

Why: 1.4.3: This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 1.4.4: This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 1.4.3, 1.4.4.

B: Correct. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.4: Activate and monitor distributed denial-of-service (DDoS) protection.

C: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 1.4.3, 1.4.4.

D: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 1.4.3, 1.4.4.

E: Not selected. This directly satisfies the requirement to implement a load balancing rule. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.9, but it does not directly satisfy the scenario requirement mapped to 1.4.3, 1.4.4.

F: Correct. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.3: Monitor and troubleshoot networks by using Azure Monitor for Networks.

Learning point: AZ700-14-Q151: Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time. | Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.

Question 152

VanArsdel Energy is reviewing a zero-trust network redesign with centralized observability. Internet-facing endpoints need platform-level volumetric attack protection with operational telemetry and response integration. The network engineer must activate and monitor distributed denial-of-service (DDoS) protection. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the network operations team. Change window 20:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7152. Which recommendation most directly meets the requirement? Select one answer.

  1. Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.
  2. Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations.
  3. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  4. Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.
  5. Deploy the required VPN, ExpressRoute, or P2S gateway into the Virtual WAN hub and size it independently for that connectivity type.

Correct answer: C

Why: 1.4.4: This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.3, but it does not directly satisfy the scenario requirement mapped to 1.4.4.

B: Not selected. This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.6, but it does not directly satisfy the scenario requirement mapped to 1.4.4.

C: Correct. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.4: Activate and monitor distributed denial-of-service (DDoS) protection.

D: Not selected. This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.3, but it does not directly satisfy the scenario requirement mapped to 1.4.4.

E: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 1.4.4.

Learning point: AZ700-14-Q152: Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.

Question 153

Fabrikam Logistics is reviewing a multi-subscription landing zone with centralized networking. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the Azure landing-zone owner. Change window 23:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7153. Which recommendation most directly meets the requirement? Select one answer.

  1. Enable BFD on supported ExpressRoute peering to detect path failures faster than standard BGP timers and accelerate convergence.
  2. Use a regional load balancer for backends in one Azure region and a cross-region load balancer when a global Layer 4 entry point must distribute to regional load balancers.
  3. Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.
  4. Use Microsoft Defender for Cloud Secure Score recommendations to prioritize network hardening items by exposure, impact, and remediation value instead of treating every finding equally.
  5. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.

Correct answer: D

Why: 1.4.5: This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.12, but it does not directly satisfy the scenario requirement mapped to 1.4.5.

B: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 1.4.5.

C: Not selected. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.8, but it does not directly satisfy the scenario requirement mapped to 1.4.5.

D: Correct. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.5: Evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score.

E: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 1.4.5.

Learning point: AZ700-14-Q153: Use Microsoft Defender for Cloud Secure Score recommendations to prioritize network hardening items by exposure, impact, and remediation value instead of treating every finding equally.

Question 154

VanArsdel Energy is reviewing an Azure estate that must keep administrative traffic off the public internet. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the business continuity lead. Change window 3:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7154. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure backend HTTP settings for protocol, port, host-name handling, cookie affinity, timeout, connection draining, and trusted backend certificates as required.
  2. Choose the ExpressRoute SKU and bandwidth/tier that meet geographic reach, route-scale, FastPath/Direct requirements, and expected throughput without paying for unsupported features.
  3. Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct.
  4. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.
  5. Use Defender for Cloud attack path analysis to identify exploitable chains that reach high-value assets and remediate the choke points that reduce the greatest real attack exposure.

Correct answer: E

Why: 1.4.6: This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 1.4.6.

B: Not selected. This directly satisfies the requirement to select an appropriate ExpressRoute SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.2, but it does not directly satisfy the scenario requirement mapped to 1.4.6.

C: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 1.4.6.

D: Not selected. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.4, but it does not directly satisfy the scenario requirement mapped to 1.4.6.

E: Correct. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.6: Evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis.

Learning point: AZ700-14-Q154: Use Defender for Cloud attack path analysis to identify exploitable chains that reach high-value assets and remediate the choke points that reduce the greatest real attack exposure.

Question 155

Fabrikam Logistics is reviewing a zero-trust network redesign with centralized observability. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud; configure monitoring, network diagnostics, and logs in Azure Network Watcher. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the platform governance council. Change window 6:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7155. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Enable the relevant Network Watcher diagnostics, Connection Monitor, packet capture, topology, and supported flow logging, then send evidence to the approved monitoring destination.
  2. Use a public frontend when clients arrive from the internet and an internal frontend when the service should be reachable only through private networking.
  3. Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.
  4. Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.
  5. Deploy the required VPN, ExpressRoute, or P2S gateway into the Virtual WAN hub and size it independently for that connectivity type.
  6. Use Cloud Security Explorer to query the cloud security graph for network resources and relationships, then pivot from the results into the relevant posture or exposure investigation.

Correct answers: A, F

Why: 1.4.7: This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 1.4.1: This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.1: Configure monitoring, network diagnostics, and logs in Azure Network Watcher.

B: Not selected. This directly satisfies the requirement to choose between public and internal load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.4, but it does not directly satisfy the scenario requirement mapped to 1.4.7, 1.4.1.

C: Not selected. This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.2, but it does not directly satisfy the scenario requirement mapped to 1.4.7, 1.4.1.

D: Not selected. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.6, but it does not directly satisfy the scenario requirement mapped to 1.4.7, 1.4.1.

E: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 1.4.7, 1.4.1.

F: Correct. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.7: Identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud.

Learning point: AZ700-14-Q155: Use Cloud Security Explorer to query the cloud security graph for network resources and relationships, then pivot from the results into the relevant posture or exposure investigation. | Enable the relevant Network Watcher diagnostics, Connection Monitor, packet capture, topology, and supported flow logging, then send evidence to the approved monitoring destination.

Question 156

VanArsdel Energy is reviewing a multi-subscription landing zone with centralized networking. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must configure monitoring, network diagnostics, and logs in Azure Network Watcher. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the network operations team. Change window 9:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7156. Which recommendation most directly meets the requirement? Select one answer.

  1. Enable the relevant Network Watcher diagnostics, Connection Monitor, packet capture, topology, and supported flow logging, then send evidence to the approved monitoring destination.
  2. Use redundant ExpressRoute circuits/peerings and appropriately resilient gateways, with cross-region or disaster-recovery routing designed so a single circuit, provider edge, or region does not become a single point of failure.
  3. Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.
  4. Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements.
  5. Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct.

Correct answer: A

Why: 1.4.1: This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.1: Configure monitoring, network diagnostics, and logs in Azure Network Watcher.

B: Not selected. This directly satisfies the requirement to design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.3, but it does not directly satisfy the scenario requirement mapped to 1.4.1.

C: Not selected. This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.2, but it does not directly satisfy the scenario requirement mapped to 1.4.1.

D: Not selected. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.3, but it does not directly satisfy the scenario requirement mapped to 1.4.1.

E: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 1.4.1.

Learning point: AZ700-14-Q156: Enable the relevant Network Watcher diagnostics, Connection Monitor, packet capture, topology, and supported flow logging, then send evidence to the approved monitoring destination.

Question 157

Fabrikam Logistics is reviewing an Azure estate that must keep administrative traffic off the public internet. Operators need evidence that identifies the failing hop or policy before they make a production network change. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must monitor and troubleshoot network health by using Azure Network Watcher; monitor and troubleshoot networks by using Azure Monitor for Networks. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the Azure landing-zone owner. Change window 12:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7157. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.
  2. Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing.
  3. Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements.
  4. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.
  5. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  6. Configure backend HTTP settings for protocol, port, host-name handling, cookie affinity, timeout, connection draining, and trusted backend certificates as required.

Correct answers: B, D

Why: 1.4.2: This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 1.4.3: This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 1.4.2, 1.4.3.

B: Correct. This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.2: Monitor and troubleshoot network health by using Azure Network Watcher.

C: Not selected. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.3, but it does not directly satisfy the scenario requirement mapped to 1.4.2, 1.4.3.

D: Correct. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.3: Monitor and troubleshoot networks by using Azure Monitor for Networks.

E: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 1.4.2, 1.4.3.

F: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 1.4.2, 1.4.3.

Learning point: AZ700-14-Q157: Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing. | Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.

Question 158

VanArsdel Energy is reviewing a zero-trust network redesign with centralized observability. Operators need evidence that identifies the failing hop or policy before they make a production network change. Internet-facing endpoints need platform-level volumetric attack protection with operational telemetry and response integration. The network engineer must monitor and troubleshoot networks by using Azure Monitor for Networks; activate and monitor distributed denial-of-service (DDoS) protection. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the business continuity lead. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7158. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Terminate or re-encrypt TLS on Application Gateway using certificates from the approved source, enforce the required TLS policy, and validate end-to-end certificate trust when HTTPS continues to the backend.
  2. Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements.
  3. Implement the Azure networking capability named in the requirement using the supported Microsoft configuration, validate prerequisites and dependencies, and confirm the result with Azure-native diagnostics before production rollout.
  4. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.
  5. Create the VNet-to-ExpressRoute connection between the ExpressRoute gateway and the provisioned circuit, then validate learned and advertised routes.
  6. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.

Correct answers: D, F

Why: 1.4.3: This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 1.4.4: This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure Transport Layer Security (TLS). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.9, but it does not directly satisfy the scenario requirement mapped to 1.4.3, 1.4.4.

B: Not selected. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.3, but it does not directly satisfy the scenario requirement mapped to 1.4.3, 1.4.4.

C: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 1.4.3, 1.4.4.

D: Correct. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.3: Monitor and troubleshoot networks by using Azure Monitor for Networks.

E: Not selected. This directly satisfies the requirement to connect a virtual network to an ExpressRoute circuit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.9, but it does not directly satisfy the scenario requirement mapped to 1.4.3, 1.4.4.

F: Correct. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.4: Activate and monitor distributed denial-of-service (DDoS) protection.

Learning point: AZ700-14-Q158: Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time. | Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.

Question 159

Fabrikam Logistics is reviewing a multi-subscription landing zone with centralized networking. Internet-facing endpoints need platform-level volumetric attack protection with operational telemetry and response integration. The network engineer must activate and monitor distributed denial-of-service (DDoS) protection. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the platform governance council. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7159. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure the Application Gateway WAF policy with the required managed OWASP rule set, custom rules, exclusions, and policy settings, then associate it at the intended gateway/listener/path scope.
  2. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  3. Choose a VPN gateway SKU that supports the required point-to-site user scale, aggregate throughput, zone resiliency, and protocol/authentication features.
  4. Create a private endpoint in the selected subnet for the specific service subresource, approve the connection where required, and validate the assigned private IP.
  5. Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements.

Correct answer: B

Why: 1.4.4: This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.5, but it does not directly satisfy the scenario requirement mapped to 1.4.4.

B: Correct. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.4: Activate and monitor distributed denial-of-service (DDoS) protection.

C: Not selected. This directly satisfies the requirement to select an appropriate virtual network gateway SKU for point-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.1, but it does not directly satisfy the scenario requirement mapped to 1.4.4.

D: Not selected. This directly satisfies the requirement to create private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.2, but it does not directly satisfy the scenario requirement mapped to 1.4.4.

E: Not selected. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.3, but it does not directly satisfy the scenario requirement mapped to 1.4.4.

Learning point: AZ700-14-Q159: Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.

Question 160

VanArsdel Energy is reviewing an Azure estate that must keep administrative traffic off the public internet. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the network operations team. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7160. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.
  2. Use Front Door’s edge ingress and Microsoft global network path to accelerate HTTP(S) traffic, keeping origins healthy and appropriately placed rather than forcing clients to connect directly to distant regions.
  3. Use Microsoft Defender for Cloud Secure Score recommendations to prioritize network hardening items by exposure, impact, and remediation value instead of treating every finding equally.
  4. Create a private endpoint in the selected subnet for the specific service subresource, approve the connection where required, and validate the assigned private IP.
  5. Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies.

Correct answer: C

Why: 1.4.5: This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.4, but it does not directly satisfy the scenario requirement mapped to 1.4.5.

B: Not selected. This directly satisfies the requirement to configure traffic acceleration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.7, but it does not directly satisfy the scenario requirement mapped to 1.4.5.

C: Correct. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.5: Evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score.

D: Not selected. This directly satisfies the requirement to create private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.2, but it does not directly satisfy the scenario requirement mapped to 1.4.5.

E: Not selected. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.5, but it does not directly satisfy the scenario requirement mapped to 1.4.5.

Learning point: AZ700-14-Q160: Use Microsoft Defender for Cloud Secure Score recommendations to prioritize network hardening items by exposure, impact, and remediation value instead of treating every finding equally.

Question 161

Fabrikam Logistics is reviewing a zero-trust network redesign with centralized observability. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the Azure landing-zone owner. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7161. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Global Reach for private site-to-site connectivity through Microsoft, FastPath to bypass the gateway data path where supported, and ExpressRoute Direct when dedicated Microsoft peering ports and very high bandwidth are required.
  2. Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
  3. Use Application Gateway rewrite rule sets to modify supported request or response headers and URLs under explicit conditions instead of changing application code for simple gateway-layer transformations.
  4. Use Defender for Cloud attack path analysis to identify exploitable chains that reach high-value assets and remediate the choke points that reduce the greatest real attack exposure.
  5. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.

Correct answer: D

Why: 1.4.6: This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.4, but it does not directly satisfy the scenario requirement mapped to 1.4.6.

B: Not selected. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.7, but it does not directly satisfy the scenario requirement mapped to 1.4.6.

C: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 1.4.6.

D: Correct. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.6: Evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis.

E: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 1.4.6.

Learning point: AZ700-14-Q161: Use Defender for Cloud attack path analysis to identify exploitable chains that reach high-value assets and remediate the choke points that reduce the greatest real attack exposure.

Question 162

VanArsdel Energy is reviewing a multi-subscription landing zone with centralized networking. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. Operators need evidence that identifies the failing hop or policy before they make a production network change. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud; configure monitoring, network diagnostics, and logs in Azure Network Watcher; monitor and troubleshoot network health by using Azure Network Watcher. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the business continuity lead. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7162. The branch edge uses dual ISPs with independent public addresses, and a quarterly failover exercise requires tunnel recovery without editing routes by hand. Which THREE recommendations should be implemented together? Select THREE answers.

  1. Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.
  2. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  3. Enable the relevant Network Watcher diagnostics, Connection Monitor, packet capture, topology, and supported flow logging, then send evidence to the approved monitoring destination.
  4. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.
  5. Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing.
  6. Use Cloud Security Explorer to query the cloud security graph for network resources and relationships, then pivot from the results into the relevant posture or exposure investigation.

Correct answers: C, E, F

Why: 1.4.7: This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 1.4.1: This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 1.4.2: This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.6, but it does not directly satisfy the scenario requirement mapped to 1.4.7, 1.4.1, 1.4.2.

B: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 1.4.7, 1.4.1, 1.4.2.

C: Correct. This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.1: Configure monitoring, network diagnostics, and logs in Azure Network Watcher.

D: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 1.4.7, 1.4.1, 1.4.2.

E: Correct. This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.2: Monitor and troubleshoot network health by using Azure Network Watcher.

F: Correct. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.7: Identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud.

Learning point: AZ700-14-Q162: Use Cloud Security Explorer to query the cloud security graph for network resources and relationships, then pivot from the results into the relevant posture or exposure investigation. | Enable the relevant Network Watcher diagnostics, Connection Monitor, packet capture, topology, and supported flow logging, then send evidence to the approved monitoring destination. | Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing.

Question 163

Fabrikam Logistics is reviewing an Azure estate that must keep administrative traffic off the public internet. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must configure monitoring, network diagnostics, and logs in Azure Network Watcher. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the platform governance council. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7163. Which recommendation most directly meets the requirement? Select one answer.

  1. Size each Virtual WAN gateway using the service’s scale units based on expected aggregate throughput, connection count, and resiliency requirements, then monitor utilization for growth.
  2. Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway.
  3. Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.
  4. Publish the producer service through a Private Link Service behind a Standard internal Load Balancer, configure NAT IPs and visibility/approval, and onboard consumer private endpoints.
  5. Enable the relevant Network Watcher diagnostics, Connection Monitor, packet capture, topology, and supported flow logging, then send evidence to the approved monitoring destination.

Correct answer: E

Why: 1.4.1: This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to choose an appropriate scale unit for each gateway type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.4, but it does not directly satisfy the scenario requirement mapped to 1.4.1.

B: Not selected. This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.6, but it does not directly satisfy the scenario requirement mapped to 1.4.1.

C: Not selected. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.8, but it does not directly satisfy the scenario requirement mapped to 1.4.1.

D: Not selected. This directly satisfies the requirement to create a Private Link service. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.4, but it does not directly satisfy the scenario requirement mapped to 1.4.1.

E: Correct. This directly satisfies the requirement to configure monitoring, network diagnostics, and logs in Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.1: Configure monitoring, network diagnostics, and logs in Azure Network Watcher.

Learning point: AZ700-14-Q163: Enable the relevant Network Watcher diagnostics, Connection Monitor, packet capture, topology, and supported flow logging, then send evidence to the approved monitoring destination.

Question 164

VanArsdel Energy is reviewing a zero-trust network redesign with centralized observability. Operators need evidence that identifies the failing hop or policy before they make a production network change. Operators need evidence that identifies the failing hop or policy before they make a production network change. Internet-facing endpoints need platform-level volumetric attack protection with operational telemetry and response integration. The network engineer must monitor and troubleshoot network health by using Azure Network Watcher; monitor and troubleshoot networks by using Azure Monitor for Networks; activate and monitor distributed denial-of-service (DDoS) protection. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the network operations team. Change window 10:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7164. Which THREE recommendations should be implemented together? Select THREE answers.

  1. Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.
  2. Use Front Door’s edge ingress and Microsoft global network path to accelerate HTTP(S) traffic, keeping origins healthy and appropriately placed rather than forcing clients to connect directly to distant regions.
  3. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.
  4. Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing.
  5. Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
  6. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.

Correct answers: C, D, F

Why: 1.4.2: This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 1.4.3: This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 1.4.4: This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.8, but it does not directly satisfy the scenario requirement mapped to 1.4.2, 1.4.3, 1.4.4.

B: Not selected. This directly satisfies the requirement to configure traffic acceleration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.7, but it does not directly satisfy the scenario requirement mapped to 1.4.2, 1.4.3, 1.4.4.

C: Correct. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.3: Monitor and troubleshoot networks by using Azure Monitor for Networks.

D: Correct. This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.2: Monitor and troubleshoot network health by using Azure Network Watcher.

E: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 1.4.2, 1.4.3, 1.4.4.

F: Correct. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.4: Activate and monitor distributed denial-of-service (DDoS) protection.

Learning point: AZ700-14-Q164: Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing. | Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time. | Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.

Question 165

Fabrikam Logistics is reviewing a multi-subscription landing zone with centralized networking. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must monitor and troubleshoot networks by using Azure Monitor for Networks. The design must meet the requirement without exposing broad network connectivity, and the decision will be reviewed by the Azure landing-zone owner. Change window 13:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7165. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.
  2. Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.
  3. Provide on-premises clients a private routed path to the consumer VNet and hybrid DNS resolution for the private endpoint, rather than trying to route directly to the provider-side Private Link Service NAT addresses.
  4. Advertise only the intended, nonoverlapping prefixes through BGP, summarize where safe, and use route filters or communities on Microsoft peering rather than leaking unrelated routes.
  5. Configure a custom health probe that targets a reliable application health endpoint with the right host, protocol, path, interval, timeout, and healthy-status criteria.

Correct answer: A

Why: 1.4.3: This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 1.4.3: Monitor and troubleshoot networks by using Azure Monitor for Networks.

B: Not selected. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.6, but it does not directly satisfy the scenario requirement mapped to 1.4.3.

C: Not selected. This directly satisfies the requirement to integrate a Private Link service with on-premises clients. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.6, but it does not directly satisfy the scenario requirement mapped to 1.4.3.

D: Not selected. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.10, but it does not directly satisfy the scenario requirement mapped to 1.4.3.

E: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 1.4.3.

Learning point: AZ700-14-Q165: Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.

img