← All AZ-700 Flashcard Decks

Mixed Deck — All AZ-700 Topics Flashcards

100 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All AZ-700 Topics flashcards as text
  1. Which Azure Monitor feature provides metrics and logs for your virtual networks, including data about traffic, throughput, and network latency?

    Answer: Network Performance Monitor

    Network Performance Monitor (NPM) is a feature within Azure Monitor specifically designed to provide comprehensive visibility into network health and performance. It collects metrics and logs related to network connectivity, latency, and packet loss across your Azure virtual networks and hybrid connections. This makes NPM the ideal tool for diagnosing and troubleshooting network-related issues within your Azure infrastructure.

  2. Which policy must be enabled on a subnet to apply NSG rules and UDRs to Private Endpoint traffic?

    Answer: PrivateEndpointNetworkPolicies = Enabled

    Setting PrivateEndpointNetworkPolicies to 'Enabled' on a subnet allows NSGs and UDRs to be applied to traffic destined for private endpoints in that subnet.

  3. Which tool can you use to validate effective routes on a VM's NIC in Azure?

    Answer: Network Watcher — Effective Routes

    Azure Network Watcher's 'Effective Routes' feature shows the combined routing table applied to a specific NIC.

  4. When configuring BGP (Border Gateway Protocol) on Azure, what is the purpose of specifying AS (Autonomous System) numbers?

    Answer: To identify and differentiate routing domains

    In BGP (Border Gateway Protocol), Autonomous System (AS) numbers are unique identifiers assigned to routing domains. They are crucial for BGP to establish peering relationships and exchange routing information between different administrative entities. This differentiation allows for scalable and controlled inter-domain routing on the internet and in cloud environments like Azure.

  5. What is the purpose of the Azure DNS Private Resolver outbound endpoint?

    Answer: Forwards DNS queries from Azure to on-premises or external DNS servers

    The outbound endpoint of Azure DNS Private Resolver allows DNS queries originating in Azure to be conditionally forwarded to on-premises or external DNS servers.

  6. When configuring a Point-to-Site VPN, which authentication method uses certificates stored in Azure AD?

    Answer: Azure AD authentication

    Azure AD authentication for P2S VPN allows users to authenticate using their Azure AD credentials via the OpenVPN protocol.

  7. Which backend member type is supported by Azure Application Gateway backend pools?

    Answer: Virtual machines and VM scale set instances

    Application Gateway backend pools support virtual machines, VM scale sets, App Service web apps, and on-premises servers accessible via IP or FQDN.

  8. What happens to a Private Endpoint if the linked Azure resource (e.g., storage account) is deleted?

    Answer: The Private Endpoint remains and shows a 'disconnected' state

    When the underlying resource is deleted, the associated Private Endpoint enters a 'disconnected' state and must be manually deleted.

  9. Which VNet peering option allows a spoke VNet to route traffic through a hub VNet to on-premises networks?

    Answer: Use remote gateways

    'Use remote gateways' on the spoke VNet allows it to use the hub's VPN or ExpressRoute gateway to reach on-premises networks.

  10. What are the two operating modes available for Azure WAF on Application Gateway?

    Answer: Detection mode and Prevention mode

    WAF operates in Detection mode (logs threats without blocking) or Prevention mode (logs and actively blocks malicious requests).

  11. What is required to enable encryption over an ExpressRoute private peering connection?

    Answer: Run a VPN Gateway over the ExpressRoute circuit using IPsec/IKE

    To encrypt traffic over ExpressRoute private peering, you layer an IPsec/IKE VPN tunnel on top of the ExpressRoute circuit using a VPN Gateway.

  12. Which Azure feature allows you to delegate a subdomain to Azure DNS while keeping the parent zone with another registrar?

    Answer: NS record delegation

    By creating NS records for the subdomain at the parent registrar pointing to Azure DNS name servers, you delegate that subdomain to Azure DNS.

  13. Can a Private Endpoint be accessed from an on-premises network connected via ExpressRoute or VPN?

    Answer: Yes — on-premises clients can reach Private Endpoints via ExpressRoute or VPN with proper DNS forwarding

    On-premises clients can access Private Endpoints over ExpressRoute or VPN; DNS must be configured to resolve the privatelink FQDN to the private IP.

  14. When you configure a URL redirect rule in Application Gateway, what does the gateway send to the client?

    Answer: An HTTP redirect response instructing the browser to navigate to a different URL

    URL redirect sends an HTTP 301 or 302 redirect response to the client, instructing the browser to request a different URL.

  15. Which scenario requires configuring a DNS forwarding ruleset in Azure DNS Private Resolver?

    Answer: Resolving on-premises DNS names from Azure workloads using outbound endpoint forwarding rules

    A DNS forwarding ruleset attached to the outbound endpoint defines rules that forward Azure-originated DNS queries for specific domains to on-premises resolvers.

  16. How are WAF custom rules evaluated relative to managed ruleset rules in Azure Application Gateway?

    Answer: Custom rules are evaluated before managed ruleset rules and take priority

    WAF custom rules are evaluated before managed ruleset rules, allowing you to define precise allow or deny logic that takes priority over the default ruleset.

  17. Which Azure DNS record type is used to map a domain name to an Azure resource and automatically updates when the resource's IP changes?

    Answer: Alias record

    Azure DNS Alias records are aware of Azure resource lifecycle and automatically reflect IP changes for resources like Public IPs, Traffic Manager, and CDN.

  18. How many BGP sessions does a standard ExpressRoute private peering configuration use?

    Answer: 2 — one primary and one secondary for redundancy

    ExpressRoute private peering requires two BGP sessions (primary and secondary) for built-in redundancy across the two physical links.

  19. Which Application Gateway routing rule type allows you to direct requests with '/images/*' to one backend pool and '/video/*' to another?

    Answer: Path-based routing

    Path-based routing rules direct traffic to different backend pools based on the URL path segment in the HTTP request.

  20. Which VPN type should you use when you need to support multiple VNet-to-VNet and cross-premises connections with dynamic routing?

    Answer: Route-based VPN

    Route-based VPNs use dynamic routing and support multiple connections, VNet-to-VNet, and BGP — required for most modern scenarios.