Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bigdisc65

AZ-700 Exam Dumps - Microsoft Certified: Azure Network Engineer Associate Questions and Answers

Question # 64

Task 9

You plan to use VNET4 for an Azure API Management implementation.

You need to configure a policy that can be used by an Azure application gateway to protect against known web attack vectors. The policy must only allow requests that originate from IP addresses in Canada. You do NOT need to create the application gateway to complete this task.

Options:

Buy Now
Question # 65

Task 2

You need to create an Azure Firewall instance named FW1 that meets the following requirements:

• Has an IP address from the address range of 10.1.255.0/24

• Uses a new Premium firewall policy named FW-pohcy1

• Routes traffic directly to the internet

Options:

Buy Now
Question # 66

Task 11

You are preparing to connect your on-premises network to VNET4 by using a Site-to-Site VPN. The on-premises endpoint of the VPN will be created on a firewall named Firewall 1.

The on-premises network has the following configurations:

• Internal address range: 10.10.0.0/16.

• Firewall 1 internal IP address: 10.10.1.1.

• Firewall1 public IP address: 131.107.50.60.

BGP is NOT used.

You need to create the object that will provide the IP addressing configuration of the on-premises network to the Site-to-Site VPN. You do NOT need to create a virtual network gateway to complete this task.

Options:

Buy Now
Question # 67

Task 4

You need to ensure that the owner of VNET3 receives an alert if an administrative operation is performed on the virtual network.

Options:

Buy Now
Question # 68

Task 10

You need to configure VNET1 to log all events and metrics. The solution must ensure that you can query the events and metrics directly from the Azure portal by using KQL.

Options:

Buy Now
Question # 69

You have an Azure virtual network and an on-premises datacenter that connect by using a Site-to-Site VPN tunnel.

You need to ensure that all traffic from the virtual network to the internet is routed through the datacenter.

How should you complete the PowerShell script to configure forced tunneling? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Question # 70

You have an Azure subscription. The subscription contains an Azure application gateway that has the following configurations:

• Name: AppGW1

• Tier Standard V2

• Autoscaling: Disabled

You create a user named User1.

You need to ensure that User1 can change the tier of AppGW1. The solution must use the principle of least privilege.

Which role should you assign to User1. and to which tiers can AppGW1 be changed? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Question # 71

Task 5

You need to archive all the metrics of VNET1 to an existing storage account.

Options:

Buy Now
Exam Code: AZ-700
Exam Name: Designing and Implementing Microsoft Azure Networking Solutions
Last Update: Dec 11, 2025
Questions: 306
AZ-700 pdf

AZ-700 PDF

$33.25  $94.99
AZ-700 Engine

AZ-700 Testing Engine

$38.5  $109.99
AZ-700 PDF + Engine

AZ-700 PDF + Testing Engine

$50.75  $144.99