โ† All AZ-700 Flashcard Decks

Networking Fundamentals Flashcards

7 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Networking Fundamentals flashcards as text
  1. You need to capture and analyze network traffic flowing through a VM's NIC in Azure. Which tool provides this capability natively?

    Answer: Azure Network Watcher packet capture

    Azure Network Watcher's packet capture feature allows you to remotely capture network traffic to/from a VM's NIC for troubleshooting and analysis.

  2. What is the primary difference between Azure VNet peering and Azure VPN Gateway for connecting two VNets?

    Answer: VNet peering uses the Microsoft backbone with low latency; VPN uses encrypted tunnels with higher latency

    VNet peering uses the Azure backbone for low-latency, high-bandwidth private connectivity, while VPN Gateway establishes encrypted IPsec tunnels with higher latency.

  3. Which Azure service enables you to centrally manage routing across multiple VNets using a hub-and-spoke topology as a managed service?

    Answer: Azure Virtual WAN

    Azure Virtual WAN provides a managed hub-and-spoke networking service that automates branch connectivity, routing, and security across multiple VNets and sites.

  4. An NSG rule has priority 100 and allows port 80 inbound. Another rule has priority 200 and denies all inbound traffic. What is the result for HTTP traffic?

    Answer: Traffic is allowed because the lower priority number (100) is evaluated first

    NSG rules are evaluated in order from lowest priority number to highest; the allow rule at priority 100 is matched first, so HTTP traffic is permitted.

  5. What mechanism does Azure use to prevent IP spoofing on virtual machine network interfaces?

    Answer: IP forwarding disabled by default

    Azure blocks IP spoofing by default because IP forwarding is disabled on NICs; any packet with a source IP not matching the NIC's assigned IP is dropped by the hypervisor.

  6. Which type of Azure VPN Gateway supports active-active configuration for higher availability and redundancy?

    Answer: VpnGw1 and higher SKUs

    Active-active VPN Gateway configuration requires VpnGw1 or higher (Generation 1 or 2); the Basic SKU only supports active-standby mode.

  7. What does Azure Route Server enable in a hub virtual network?

    Answer: It allows NVAs to exchange routes with Azure's SDN via BGP without route tables

    Azure Route Server enables network virtual appliances (NVAs) to peer with Azure's virtual network router using BGP, dynamically propagating routes without needing manual UDRs.