You have an Azure Web Application Firewall (WAF) policy in prevention mode that is associated to an Azure Front Door instance. You need to configure the policy to meet the following requirements:
1.
Log all connections from Australia.
2.
Deny all connections from New Zealand.
3.
Deny all further connections from a network of 131.107.100.0/24 if there are more than 100 connections during one minute. What is the minimum number of objects you should create?
A. three custom rules that each has one condition
B. one custom rule that has three conditions
C. one custom rule that has one condition
D. one rule that has two conditions and another rule that has one condition
You have an Azure virtual network that contains two subnets named Subnet1 and Subnet2. Subnet1 contains a virtual machine named VM1. Subnet2 contains a virtual machine named VM2.
You have two network security groups (NSGs) named NSG1 and NSG2. NSG1 has 100 inbound security rules and is associated to VM1. NSG2 has 200 inbound security rules and is associated to Subnet1.
VM2 cannot connect to VM1.
You suspect that an NSG rule blocks connectivity.
You need to identify which rule blocks the connection. The issue must be resolved as quickly as possible.
Which Azure Network Watcher feature should you use?
A. Effective security rules
B. Connection troubleshoot
C. NSG diagnostic
D. NSG flow logs
You have the Azure virtual networks shown in the following table.
You have the Azure resources shown in the following table.
You need to check latency between the resources by using connection monitors in Azure Network Watcher.
What is the minimum number of connection monitors that you must create?
A. 1
B. 2
C. 3
D. 4
E. 5
You have a web application that will be deployed to an Azure App Service Web App.
You need to optimize web application responsiveness and reliability by routing HTTP request and responses to the endpoint with the lowest network latency for the client.
What should you consider?
A. Use Azure Application Gateway
B. Use Azure Monitor
C. Use Azure Security Centre
D. Use Azure Traffic Manager
You need to identify a security rule that prevents a network packet from reaching an Azure virtual machine. What should you use?
A. IP flow verify
B. Next hop
C. Packet capture
D. Security group view
E. Traffic Analytics
You have an Azure subscription that contains a virtual network named VNet1. VNet1 has a subnet mask of/24. You plan to implement an Azure application gateway that will have the following configurations:
1.
Public endpoints: 1
2.
Private endpoints: 1
3.
Minimum instances: 1
4.
Maximum instances: 10
You need to configure the address space for the subnet of the application gateway. The solution must minimize the number of IP addresses allocated to the application gateway subnet.
What is the minimum number of assignable IP addresses required?
A. 1
B. 2
C. 11
D. 12
E. 20
You need to provide access to storage2. The solution must meet the PaaS networking requirements and the business requirements. Which connectivity method should you use?
A. a private endpoint
B. Azure Firewall
C. Azure Front Door
D. a service endpoint
HOTSPOT
You configure a route table named RT1 that has the routes shown in the following table.
You have an Azure virtual network named Vnet1 that has the subnets shown in the following table.
You have the resources shown in the following table.
Vnet1 connects to an ExpressRoute circuit. The on-premises router advertises the following routes:
1.
0.0.0.0/0
2.
10.0.0.0/16
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
HOTSPOT
You have an Azure subscription. The subscription contains virtual machines that host websites as shown in the following table.
You have the Azure Traffic Manager profiles shown in the following table.
You have the endpoints shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
HOTSPOT
You have an Azure subscription that contains the virtual networks shown in the following table.
You have a virtual machine named VM5 that has the following IP address configurations:
1.
IP address:10.4.0.5
2.
Subnet mask:255.255.255.0
3.
Default gateway: 10.4.0.1
4.
DNS server: 168.63.129.16
You have an Azure Private DNS zone named fabrikam.com that contains the records shown in the following table.
The virtual network links in the fabrikam.com DNS zone are configured as shown in the exhibit. (Click the Exhibit tab.)
VM5 fails to resolve the IP address for app1.fabrikam.com.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area: