Networking Services Flashcards
7 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Networking Services flashcards as text
A network architect needs to provide DDoS protection for a virtual network with advanced mitigation, telemetry, and cost protection. Which Azure DDoS Protection plan should they deploy?
Answer: DDoS Network Protection
DDoS Network Protection provides adaptive tuning, attack analytics, rapid response support, and cost protection guarantees for the entire VNet.
Which type of Azure Private Endpoint connection approval is required when the Private Endpoint and the target resource are in different Azure AD tenants?
Answer: Manual approval
When a Private Endpoint and target resource are in different Azure AD tenants, the resource owner must manually approve the connection request.
What happens to existing TCP connections through an Azure Load Balancer when a backend VM becomes unhealthy according to health probes?
Answer: Existing connections persist until they time out or are closed; new connections go to healthy backends
Azure Load Balancer drains unhealthy backends — existing established connections continue until they close naturally, while new connections are only sent to healthy backends.
An engineer configures a VNet with address space 10.1.0.0/16. Azure reserves 5 IP addresses in every subnet. In a /24 subnet, how many usable host IPs are available?
Answer: 251
Azure reserves 5 IPs per subnet (network address, gateway, two DNS, broadcast), so a /24 (256 addresses) yields 256 - 5 = 251 usable host IPs.
Which connectivity option in Azure provides a private, dedicated connection from an on-premises network to Azure with bandwidth options up to 100 Gbps?
Answer: ExpressRoute
ExpressRoute provides a private, dedicated connection through a connectivity provider with bandwidth up to 100 Gbps and does not traverse the public internet.
A company wants to use Azure Application Gateway to route traffic to different backend pools based on the URL path. For example, /images/* goes to one pool and /video/* to another. Which feature enables this?
Answer: URL path-based routing
URL path-based routing in Azure Application Gateway uses path maps to route requests with different URL paths to different backend server pools.
In Azure, what is the maximum transmission unit (MTU) supported for traffic within a virtual network, and what value should be configured to avoid fragmentation over VPN tunnels?
Answer: 1500 MTU for VNet; 1400 for VPN tunnels
Azure VNets support 1500 MTU for intra-VNet traffic, but VPN tunnels add overhead so 1400 MTU is recommended for guest OS settings to avoid fragmentation.