← All AZ-700 Flashcard Decks

Mixed Deck — All AZ-700 Topics Flashcards

100 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All AZ-700 Topics flashcards as text
  1. What is the primary purpose of standardized procedures in Load Balancing and DNS?

    Answer: To ensure consistency, safety, and quality across all practitioners

    Standardized procedures ensure that all practitioners deliver consistent, safe, and high-quality outcomes.

  2. Which port does Azure Service Bus use for AMQP communication, and which alternative port is used when port 5671 is blocked?

    Answer: 5671 and 443

    Azure Service Bus uses AMQP on port 5671, and when blocked, it falls back to AMQP over WebSockets on port 443.

  3. A company deployed Azure Route Server in their hub VNet. What protocol does Azure Route Server use to exchange routes with Network Virtual Appliances (NVAs)?

    Answer: BGP

    Azure Route Server uses BGP (Border Gateway Protocol) to dynamically exchange routes with NVAs deployed in the VNet.

  4. You need to allow Azure Monitor to collect diagnostic logs from resources in a private VNet without public internet exposure. What should you configure?

    Answer: Deploy Private Endpoints for Azure Monitor (Azure Monitor Private Link Scope)

    Azure Monitor Private Link Scope (AMPLS) uses Private Endpoints to allow diagnostic data collection from VNet resources without traversing the public internet.

  5. Which connectivity option in Azure provides a private, dedicated connection from an on-premises network to Azure with bandwidth options up to 100 Gbps?

    Answer: ExpressRoute

    ExpressRoute provides a private, dedicated connection through a connectivity provider with bandwidth up to 100 Gbps and does not traverse the public internet.

  6. Which protocol is used by Azure VPN Gateway for site-to-site connections to establish IPsec tunnels?

    Answer: IKEv1 and IKEv2

    Azure VPN Gateway supports both IKEv1 and IKEv2 for establishing IPsec/IKE tunnels in site-to-site VPN connections.

  7. Which approach is most effective for problem-solving in Load Balancing and DNS?

    Answer: Systematic analysis followed by evidence-based decision making

    Systematic, evidence-based approaches lead to more reliable solutions than ad hoc methods.

  8. You need to optimize throughput for a VM running network-intensive workloads. The VM size supports it but throughput is still limited. What feature should you verify is enabled on the NIC?

    Answer: Accelerated Networking

    Accelerated Networking bypasses the host vSwitch using SR-IOV, significantly reducing latency and increasing network throughput for supported VM sizes.

  9. How many private endpoints can reference the same Private Link resource?

    Answer: Multiple private endpoints can connect to the same resource

    Multiple private endpoints in different VNets or subscriptions can all connect to the same Private Link resource simultaneously.

  10. You are configuring Azure Application Gateway WAF in Prevention mode. A legitimate request is being blocked. What is the quickest way to allow it without disabling WAF?

    Answer: Add a WAF exclusion rule for the specific request attribute

    WAF exclusion rules allow you to exclude specific request attributes (headers, cookies, query strings) from WAF evaluation without disabling protection.

  11. Which BGP attribute is used by Azure ExpressRoute to prefer one path over another when multiple paths exist?

    Answer: AS Path prepending

    AS path prepending is the BGP attribute used to influence inbound route selection in Azure ExpressRoute, making one path appear longer (less preferred) than another.

  12. Which Azure service is designed for web application security, providing protection against common web-based attacks?

    Answer: Azure Application Gateway with WAF (Web Application Firewall

    Azure Application Gateway with Web Application Firewall (WAF) is specifically designed to protect web applications from common web-based attacks. The WAF component inspects incoming web traffic for threats like SQL injection, cross-site scripting, and other OWASP Top 10 vulnerabilities. It acts as a reverse proxy, securing your web applications before traffic reaches your backend servers.

  13. What are the key regulatory requirements affecting Connectivity Solutions?

    Answer: Compliance with applicable laws, industry standards, and licensing requirements specific to the field

    Practitioners must comply with all applicable regulations, which may include federal, state, and industry-specific requirements.

  14. How should risk be managed in Connectivity Solutions?

    Answer: Through identification, assessment, mitigation strategies, and ongoing monitoring of potential risks

    Effective risk management involves a systematic process of identifying, evaluating, and addressing potential threats.

  15. What is the importance of communication skills in Network Security?

    Answer: Clear communication prevents errors, builds relationships, and ensures understanding among all parties

    Effective communication is essential for coordination, error prevention, and stakeholder relationships.

  16. When two VNets are connected via VNet peering with 'Allow Gateway Transit' enabled on the hub and 'Use Remote Gateways' on the spoke, what happens to the spoke VNet's routing?

    Answer: The spoke VNet's subnets learn routes from the hub's connected gateways automatically

    With 'Allow Gateway Transit' on the hub peering and 'Use Remote Gateways' on the spoke peering, the spoke subnets automatically receive routes from the hub's VPN or ExpressRoute gateway.

  17. An Azure Application Gateway WAF is blocking requests that should be legitimate. Logs show rule group 'REQUEST-942-APPLICATION-ATTACK-SQLI' is triggering. What is the best immediate mitigation without disabling WAF?

    Answer: Create a custom WAF exclusion for the specific rule or request attribute causing false positives

    WAF exclusions allow specific rules or request attributes to be excluded, eliminating false positives while keeping all other WAF protections active.

  18. What is the purpose of the AzurePlatformDNS service tag in NSG rules?

    Answer: Represents Azure's internal DNS infrastructure IP ranges for NSG rules

    The AzurePlatformDNS service tag represents the IP address ranges used by Azure's DNS infrastructure, used in NSG rules to allow DNS resolution for platform services.

  19. Which feature of Azure Firewall Premium allows inspection of encrypted HTTPS traffic for threats?

    Answer: TLS Inspection with a CA certificate

    TLS Inspection in Azure Firewall Premium decrypts outbound HTTPS traffic using an intermediate CA certificate to inspect content for threats.

  20. What is the purpose of enabling 'Branch-to-Branch' traffic in Azure Virtual WAN?

    Answer: Enables traffic flow between connected branch sites (VPN/ExpressRoute) through the Virtual WAN hub

    Enabling Branch-to-Branch in Virtual WAN allows traffic to transit the managed hub between connected branch sites, such as between two VPN sites or between VPN and ExpressRoute.