Microsoft Practice Questions, Discussions & Exam Topics by our Authors
SNAPSHOT
-
You have an Azure subscription that contains the resource groups shown in the following table.
You have the virtual networks shown in the following table.
You have the subnets shown in the following table.
For each of the following state...
Author: Emma Brown · Last updated Sep 30, 2026
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Azure Username: User-12345678@cloudslice.onmicrosoft.com
Azure Password: xxxxxxxxxx
-
If the Azure portal does not load successfully in the browser, press CTRL-K to reload the
portal in a new browser tab.
The following information is for technical support purposes only:
Lab Instance: 12345678
-
...
Author: Victoria · Last updated Sep 30, 2026
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Azure Username: User-12345678@cloudslice.onmicrosoft.com
Azure Password: xxxxxxxxxx
-
If the Azure portal does not load successfully in the browser, press CTRL-K to reload the
portal in a new browser ta...
Author: Lucas Carter · Last updated Sep 30, 2026
You are planning the IP addressing for the subnets in Azure virtual networks.
Which type of resou...
Problem Breakdown:
When planning IP addressing for subnets in Azure virtual networks, you need to consider which resources require IP addresses in the subnets. Each resource or service may have different requirements based on its function and how it interacts with your network.
---
Option Analysis:
A) Internal Load Balancers
- Role: An internal load balancer (ILB) is used to distribute traffic within a virtual network or to on-premises resources. It requires IP addresses from the subnet where it's deployed to function correctly. The load balancer assigns its IP address from the subnet's address range to provide connectivity to backend resources.
- IP Address Requirement: Yes, ILBs require an IP address in the subnet to handle traffic distribution internally.
- Conclusion: This option requires IP addresses from the subnet.
B) Azure DDoS Protection for Virtual Networks
- Role: Azure DDoS Protection is a security service that helps protect your virtual network against Distributed Denial of Service (DDoS) attacks. However, DDoS protection is a service applied at the network level and does not consume IP addresses itself.
- IP Address Requirement: No, DDoS protection does not require IP addresses in the subnet. It protects resources but does not use IP addresses.
- Conclusion: This option does not require IP addresses in the subn...
Author: Manish · Last updated Sep 30, 2026
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Azure Username: User-12345678@cloudslice.onmicrosoft.com
Azure Password: xxxxxxxxxx
-
If the Azure portal does not load successfully in the browser, press CTRL-K to reload the
portal in a new browser tab.
The following information is for technical support purposes only:
Lab Instance: 12345678
-
You need to ensure that virtual machi...
Author: Leo · Last updated Sep 30, 2026
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Azure Username: User-12345678@cloudslice.onmicrosoft.com
Azure Password: xxxxxxxxxx
-
If the Azure portal does not load successfully in the browser, press CTRL-K to reload the
portal in a new browser tab.
The following information is for technical support purposes only:
Lab Instance: 12345678
-
You need to ensure that...
Author: IronLion88 · Last updated Sep 30, 2026
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Azure Username: User-12345678@cloudslice.onmicrosoft.com
Azure Password: xxxxxxxxxx
-
If the Azure portal does not load successfully in the browser, press CTRL-K to reload the
portal in a new browser tab.
The following information is for technical...
Author: Liam · Last updated Sep 30, 2026
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Azure Username: User-12345678@cloudslice.onmicrosoft.com
Azure Password: xxxxxxxxxx
-
If the Azure portal does not load successfully in the browser, press CTRL-K to reload the
portal in a new browser tab.
The following information is for technica...
Author: Rohan · Last updated Sep 30, 2026
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Azure Username: User-12345678@cloudslice.onmicrosoft.com
Azure Password: xxxxxxxxxx
-
If the Azure portal does not load successfully in the browser, press CTRL-K to reload the
portal in a new browser tab.
The ...
Author: Sofia · Last updated Sep 30, 2026
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Azure Username: User-12345678@cloudslice.onmicrosoft.com
Azure Password: xxxxxxxxxx
-
If the Azure portal does not load successfully in the browser, press CTRL-K to reload the
portal in a new browser tab.
The following information is for technical support purposes only:
Lab Instance: 12345678
-
You plan to deploy 100 virtual machines to subnet-1. The virtual machines will NOT be assigned a public IP address. Th...
Author: Andrew · Last updated Sep 30, 2026
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Azure Username: User-12345678@cloudslice.onmicrosoft.com
Azure Password: xxxxxxxxxx
-
If the Azure portal does not load successfully in the browser, press CTRL-K to reload the
portal in a new browser tab.
The following information is for technical support purposes only:
Lab Instance: 12345678
-
You plan ...
Author: Sophia · Last updated Sep 30, 2026
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Azure Username: User-12345678@cloudslice.onmicrosoft.com
Azure Password: xxxxxxxxxx
-
If the Azure portal does not load successfully in the browser, press CTRL-K to reload the
portal in a new browser tab.
The following information is for technical support purposes only:
L...
Author: Mia · Last updated Sep 30, 2026
SNAPSHOT
-
You have an Azure virtual network named Vnet1 that contains two subnets named Subnet1 and Subnet2. Both subnets contain virtual machines.
You create a NAT gateway named NATgateway1 as shown in the following exhibit.
Use the drop-down menus to select the answer choice that...
Author: Vikram · Last updated Sep 30, 2026
SNAPSHOT -
You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains the resources shown in the following table.
You need to publish App1 by using AG1 and a URL of https://app1.contoso.com. The solution must meet the following requirements:
* TLS connections must terminate on AG1.
* Minimize the number of targets in the backend pool of AG1.
* Minimize the number of deployed copies of the SSL certificate of App1.
How many locations shou...
Author: StarryEagle42 · Last updated Sep 30, 2026
SNAPSHOT
-
You have an Azure subscription that contains a virtual network named Vnet1. Vnet1 has a /24 IPv4 address space.
You need to subdivide Vnet1. The solution must maximize the number of usable subnets.
What is the maximum number of IPv4 subnets you can create, and how many usable IP addresses will b...
Author: Sara · Last updated Sep 30, 2026
SNAPSHOT -
You have an Azure subscription that contains the resources shown in the following table.
The virtual network topology is shown in the following exhibit.
Firewall1 is configured as shown in following exhibit.
FirewallPolicy1 contains the following rules:
* Allow outbound traffic from Vnet1 and Vnet2 to the internet.
* Allow any traffic between Vnet1 and Vnet2.
No custom private endpoints, service endpoints, routing tables...
Author: Aria · Last updated Sep 30, 2026
SNAPSHOT -
Your company has 40 branch offices across North America and Europe.
You have an Azure subscription that contains the following virtual networks:
* Two networks in the East US Azure region
* Three networks in the West Europe Azure region
You need to implement Azure Virtual WAN. The solution must meet the following requirements:
* Each branch office in North America must have an ExpressRoute circuit and a Site-to-Site VPN that connects to the East US region.
* Each branch office in Europe must have an ExpressRoute circuit and a Site-to-Site VPN that connects to the West Europe region.
* Transitive connections must b...
Author: Ethan · Last updated Sep 30, 2026
DRAG DROP
-
You have a DNS domain named contoso.com that is hosted by a third-party domain name registrar.
You have an Azure subscription.
You need to ensure that all DNS queries for the contoso.com domain are resolved by using Azure DNS.
What should you create in the registrar, and what should you create in Azure? To answer, drag the appropriate options to the correct targets. Each option m...
Author: GlowingTiger · Last updated Sep 30, 2026
SNAPSHOT
-
You have an on-premises network.
You have an Azure subscription that contains the resources shown in the following table.
You need to implement an ExpressRoute circuit to access the resources in the subscription. The solution must ensure that the on-premises network connects to the Azure resources by using the ExpressRoute circuit.
Which type ...
Author: Alexander · Last updated Sep 30, 2026
You are planning the IP addressing for the subnets in Azure virtual networks.
Which type of resou...
Correct answer: B) internal load balancers
---
Scenario Summary:
You are designing subnet IP ranges in Azure and need to know which resources require actual IP addresses from the subnet. This is essential to avoid IP exhaustion and ensure subnet sizing is correct.
---
✅ Option B – Internal Load Balancers
- Correct: An Internal Load Balancer (ILB) is deployed inside a virtual network, and its frontend IP is a private IP that comes from the subnet's address space.
- This IP is reserved exclusively for the load balancer, meaning it consumes one of the available IPs in the subnet.
- Used to load balance traffic within a VNet (for example, between app and data tiers).
✔ Key Factor:
> Internal Load Balancers reserve and use a private IP from the subnet, making them a clear consumer of subnet IP addresses.
---
❌ Why the other options are rejected:
A) Storage Account
- Incorrect: Azure Storage Accounts are platform-managed services that have their own public endpoints or private endpoints.
- They are not deployed into your VNe...
Author: Emma · Last updated Sep 30, 2026
You have the on-premises networks shown in the following table.
You have an Azure subscription that contains an Azure virtual WAN named VWAN1 and a virtual network named VNet1. VWAN is connected to the on-premises networks and VNet1 in a full mesh topology. The virtual hub r...
Author: Grace · Last updated Sep 30, 2026
SNAPSHOT
-
Case Study
-
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study
-
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question.
Overview
-
Con...
Author: Lucas · Last updated Sep 30, 2026
SNAPSHOT
-
You have an Azure subscription that contain a storage account named st1 in the East US Azure region.
You have the virtual networks shown in the following table.
You have the subnets shown in the following table.
For each of the following stat...
Author: FrostFalcon88 · Last updated Sep 30, 2026
You are planning the IP addressing for the subnets in Azure virtual networks.
Which type of resou...
Correct answer: B) internal load balancers
---
Scenario Summary:
You're planning IP addressing for subnets in Azure virtual networks and need to identify which resource type actually consumes IP addresses from the subnet's address range. This is important for accurate subnet sizing and capacity planning.
---
✅ Option B – Internal Load Balancers
- Correct: An Internal Load Balancer (ILB) in Azure is assigned a private IP address from the subnet it resides in.
- This IP is statically or dynamically allocated and is used as the frontend IP for load balancing internal traffic.
- ILBs are deployed into subnets, meaning they consume IP addresses from the subnet just like VMs or NICs.
✔ Key Factors:
- Consumes a private IP from the subnet.
- Directly impacts subnet capacity planning.
- Common in internal application tiers, e.g., frontend → backend traffic distribution.
---
❌ Why the other options are rejected:
A) Storage Account
- Incorrect: A storage account is a platform-managed PaaS service that is not deployed inside a VNet subnet.
- Even when using Private Endpoints, it’s the private endpoint that consumes an IP, not the storage acc...
Author: Zara · Last updated Sep 30, 2026
You have the Azure virtual networks shown in the following table.
You deploy Azure Firewall to Vnet3.
You need to ensure that the traffic from Subnet1-1 ...
Author: Liam · Last updated Sep 30, 2026
You plan to implement an Azure virtual network that will contain 10 virtual subnets. The subnets will use IPv6 addresses. Each subnet will host up to 200 load-balanced virtual machines.
You need to recom...
Correct answer: A) /64
---
Scenario Summary:
You're designing an Azure virtual network with 10 subnets, each using IPv6, and each hosting up to 200 load-balanced VMs. You need to choose an appropriate IPv6 subnet mask size that supports:
- Enough IPs for 200 VMs per subnet.
- Azure platform requirements and best practices.
---
✅ Option A – /64
- Correct: A /64 subnet is the smallest subnet size recommended and supported for IPv6 in Azure.
- It provides a massive number of addresses (~1.8×10¹⁹), more than enough for 200 VMs.
- Azure requires IPv6 subnets to use a /64 mask—smaller subnets (e.g., /120) are not supported in Azure virtual networks.
- Aligns with the standard in IPv6 networking, where a /64 is typically used for each subnet or LAN segment.
✔ Key Factors:
- Azure mandates /64 as the standard size for IPv6 subnets.
- Provides maximum compatibility and future-proofing.
- Well-suited for load-balanced scenarios and scales far beyond 200 VMs.
---
❌ Why other options are rejected:
B) /120
- Incorrect:...
Author: Kunal · Last updated Sep 30, 2026
DRAG DROP
-
You have two on-premises datacenters.
You have an Azure subscription that contains four virtual networks named VNet1, VNet2, VNet3, and VNet4.
You create an Azure virtual WAN named VWAN1. VWAN1 contains a single virtual hub that is connected to both on-premises datacenters and all the virtual networks in a full mesh topology.
You create a route table named RT1.
You need to configure VWAN1 to meet the following requirements:
* Connectivity between VNet1 and VNet2 and both on-premises datacenters must be allowed.
* Connectivity between VNet3 and VNet4 and both on-premises datacenters must be allowed.
* VNet1 and VNet2 must be isolated from VNet3 and VNet4.
How should you configure routing for VNet1 and VNet2 and for both on-premises da...
Author: Ethan · Last updated Sep 30, 2026
You are planning the IP addressing for the subnets in Azure virtual networks.
Which type of resou...
When planning IP addressing for subnets in Azure Virtual Networks (VNets), it's important to understand which resources require specific IP addresses in the subnets. Let’s go through each option in detail and evaluate which one requires IP addresses, and why others might not.
A) Azure Virtual Network NAT (Network Address Translation)
Azure Virtual Network NAT allows outbound connectivity for resources in a private subnet to the internet, but it does not require IP addresses for resources within the subnet. The NAT service uses public IP addresses for outbound connectivity but does not consume private IPs in the subnet directly for the services running in the private subnet.
Reasoning for rejection: While it facilitates outbound connectivity, it doesn't require specific IP addresses in the subnet for its operation.
B) Service Endpoint Policies
Service endpoint policies enable you to control the traffic to specific Azure services over a private endpoint. These policies do not require IP addresses for the services themselves, as they are just rules that govern how traffic flows to the service. Service endpoints typically use private IP addresses but don't consume them directly for defining the policy.
Reasoning for rejection: Service endpoint policies do not need dedicated IP addresses in the subnet to function. They are more about routing and security policies rather than directly consuming IP addresses.
C) Internal Load Balancers (ILBs)
Internal Load Balancers (ILBs) are used for load balancing traffic within a virtual network or across multiple subnets. The ILB itself...
Author: Liam123 · Last updated Sep 30, 2026
SNAPSHOT
-
You have an Azure subscription that contains an Azure key vault named Vault1 and an app registration for an Azure AD app named App1.
You have a DNS domain named contoso.com that is hosted by a third-party DNS provider.
You plan to deploy App1 by using Azure App Service. App1 will have the following configurations:
* App1 will be hosted across five App Service apps.
* Users will access App1 by using a URL of https://app1.contoso.com.
* The user traffic of App1 will be managed by using Azure Front Door.
* The traffic between Front Door and the App Service apps will be sent by using HTTP.
* App1 will be secured by using an SSL certificate from a third-party...
Author: Carlos Garcia · Last updated Sep 30, 2026
You have an Azure subscription that contains a virtual network named VNet1. VNet1 has a subnet mask of/24.
You plan to implement an Azure application gateway that will have the following configurations:
* Public endpoints: 1
* Private endpoints: 1
* Minimum instances: 1
* Maximum instances: 10
You need to configure the address space for the subnet of the application gateway...
When configuring the address space for the subnet of the Azure Application Gateway, the minimum number of IP addresses required depends on the number of public and private IP endpoints, as well as the minimum and maximum instances.
Key Factors:
1. Public endpoint: The Application Gateway will require at least 1 IP address for the public endpoint.
2. Private endpoint: The Application Gateway will need 1 IP address for the private endpoint.
3. Minimum instances: The Application Gateway will have at least 1 instance, and each instance typically requires an IP address.
4. Maximum instances: The Application Gateway can scale up to 10 instances, and each instance also typically requires an IP address.
So, the minimum number of IP addresses required is:
- 1 IP address for the public endpoint.
- 1 IP address for the private endpoint.
- 1 IP address for the minimum instance (1 instance).
- 10 IP addresses for the maximum 10 instances (if all are used).
Total IP addresses required:
- 1 (public IP)
- 1 (private IP)
- 1 (minimum instance)
- 10 (maximum instances)
This gives a total of 13 IP addresses. However, in A...
Author: Isabella · Last updated Sep 30, 2026
SNAPSHOT
-
Your on-premises network contains a server named DNS1 that runs Windows Server 2022. DNS1 has the DNS server role and an IP address of 10.1.0.1. The network contains computers that use DNS1 for name resolution.
You have an Azure subscription that contains the resources shown in the following table.
The on-premises network connects to Vnet1 by using a Site-to-Site VPN.
You need to ensure that the computers on the on-premises network can resolve the IP address for sql1.private.fabrikam.com.
What should you do on DNS1 and DNS2? To answ...
Author: Nathan · Last updated Sep 30, 2026
DRAG DROP
-
You have an Azure subscription that contains the resources shown in the following table.
You need to associate Gateway1 with Subnet1. The solution must minimize downtime on VM1.
Which three actions should you perform in sequence? To answe...
Author: Maya2022 · Last updated Sep 30, 2026
SNAPSHOT
-
Your on-premises network contains the subnets shown in the following table.
The network contains a firewall named FW1 that uses a public IP address of 131.107.100.200.
You have an Azure subscription that contains the resources shown in the following table.
You plan to configure a Site-to-Site (S2S) VPN named VPN1 that will connect GW1 to FW1.
You need to configure LNG1 to support VPN1. The solution must meet the following requirements:
* Ensure that the resources on Subnet1 and Subnet2 ...
Author: Aria · Last updated Sep 30, 2026
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Azure Username: User-12345678@cloudslice.onmicrosoft.com
Azure Password: xxxxxxxxxx
-
If the Azure portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support purposes only:
Lab Instance: 12345678
-
You plan to configure a VPN tun...
Author: Aarav · Last updated Sep 30, 2026
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Azure Username: User-12345678@cloudslice.onmicrosoft.com
Azure Password: xxxxxxxxxx
-
If the Azure portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support purposes only:
Lab Instance: 12345678
-
You plan to deploy two DNS servers to subnet2-1. Each server will host a DNS zone for fabrikam,com. T...
Author: Olivia · Last updated Sep 30, 2026
SNAPSHOT
-
You have an Azure subscription that contains the resources shown in the following table.
You create a service endpoint policy as shown in the Policy exhibit. (Click the Policy tab.)
You configure the Service Endpoints settings for Subnet3 as shown in the Subnets exhibit. (Click the Subnets tab.)
For...
Author: Kunal · Last updated Sep 30, 2026
You have an on-premises DNS server named Server that hosts a primary DNS zone named fabrikam.com.
You have an Azure subscription that contains the resources shown in the following table.
Users on the on-premises network access resources on all the virtual networks by using a Site-to-Site (S2S) VPN.
You need to deploy an Azure DNS Private Resolver solution that meets the following requirements:
* Resources connected to the virtual networks must be able to resolve DNS names for fabr...
Author: Emma · Last updated Sep 30, 2026
SNAPSHOT
-
You have an Azure subscription that contains a dual-stack virtual network named VNet1. VNet1 has the following IP address spaces:
* IPv4: 192.168.0.0/24
* IPv6: fd00:db8:deca:deed:/48
You plan to deploy an Azure VPN gateway and multiple virtual machines to VNet1.
You need to configure the subnet masks for VNet1. The solution must meet the following requirements:
* Maximize the number of usable IP addresses.
* Support the deployment of the VPN ga...
Author: Olivia · Last updated Sep 30, 2026
You have an Azure subscription that contains a virtual network named VNet1 and the resources shown in the following table.
You need to implement a solution for the traffic originating from VNet1. The solution must meet the following requirements:
* Perform transparent proxying to exte...
Author: Emma · Last updated Sep 30, 2026
SNAPSHOT
-
You have an on-premises network.
You have an Azure subscription that contains the resources shown in the following table.
You need to ensure that on-premises devices can communicate with Azure resources that are connected to Subnet4.
What should you do on each...
Author: Daniel · Last updated Sep 30, 2026
DRAG DROP -
You have an on-premises network.
You have an Azure subscription that contains a virtual network named VNet1. VNet1 is connected to an Azure Virtual WAN hub named Hub1.
You need to enable connectivity between the on-premises network and VNet1 by using Hub1.
Which three actions should you perfor...
Author: Aarav · Last updated Sep 30, 2026
You have an Azure subscription. The subscription contains a locally-redundant storage (LRS) account named storage1 that is deployed to the US East Azure region and has a Microsoft.Storage service endpoint.
You set Redundancy for storage1 to Read-access geo-redundant storage (RA-GRS).
You need to ensure that the contents of storage1...
To ensure that the contents of the Azure Storage account storage1 (which is set to RA-GRS) are accessible using a service endpoint in a paired region, let's break down the situation and evaluate the options step-by-step.
Background Context:
- RA-GRS (Read-Access Geo-Redundant Storage) provides geo-redundancy across paired Azure regions, allowing you to read data from a secondary region in case of failure.
- The storage account is deployed in the US East region, and you want to make the storage accessible using a service endpoint in a paired region.
- Since RA-GRS provides read access to the secondary region, you want to ensure that service endpoints can access the storage in that secondary region (the paired region).
---
Evaluating the Options:
1. A) Create an object replication rule for storage.
- What does this do?
Object replication rules are used to replicate data between storage accounts in different regions, primarily for geo-replication of blobs (e.g., between two storage accounts).
- Does this solve the problem?
No, object replication is used for replicating data between storage accounts and does not directly address service endpoint accessibility or configuring endpoints across regions.
- Rejection reason: This is not relevant to configuring a service endpoint to ensure access in the secondary region.
---
2. B) Delete the existing service endpoint.
- What does this do?
Deleting the service endpoint would remove the configuration that allows access to the storage account over the VNet.
- Does this solve the problem?
No, deleting the service endpoint would break access. The goal is to ensure the storage is accessible from the paired region, and deleting the service endpoint would remove any access.
- Reject...
Author: Amira · Last updated Sep 30, 2026
SNAPSHOT
-
You have two Azure subscriptions.
You need to perform the following actions in the East US Azure region of each subscription:
* Deploy 50 virtual machines to availability zone 1.
* Deploy 50 virtual machines to availability zone 2.
* Deploy 50 virtual machines to availability zone 3.
What is the minimum number of virtual netwo...
Author: SolarFalcon11 · Last updated Sep 30, 2026
SNAPSHOT
-
You have an Azure subscription that contains the resources shown in the following table.
You need to ensure that remote users can establish RDP connections to the virtual machines by using Bastion1.
How should you configure the rules for NSG1 for traffic from the internet to AzureBastionSubnet and for traffic fro...
Author: Kunal · Last updated Sep 30, 2026
DRAG DROP
-
You have the resources shown in the following table.
From the Microsoft Entra admin center, you register the Azure VPN application as an enterprise application.
You need to enable Microsoft Entra authentication for the P2S VPN connections. The solution must meet the following requirements:
* Ensure that only the members of Group1 can establish VPN connections to VPNGW1.
* Ensure that only the members of Group2 can est...
Author: Ella · Last updated Sep 30, 2026
DRAG DROP
-
You have an on-premises network.
You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains an ExpressRoute gateway named Gateway1.
You need to implement an ExpressRoute solution from a third-party provider named Fabrikam, Inc. The solution must ensure that devices on the on-premises network can connect to the Azure resources on VNet1.
Wh...
Author: Benjamin · Last updated Sep 30, 2026
SNAPSHOT
-
You have an Azure subscription that contains a virtual network named VNet1.
Your on-premises network connects to VNet1 by using a Site-to-Site (S2S) VPN connection.
You need to ensure that Azure Network Watcher generates an alert if the VPN connection fails.
Which Network Watcher feature should you use to generate the alert, and whi...
Author: Zara · Last updated Sep 30, 2026
You have the Azure subscriptions shown in the following table.
Each virtual network contains 20 internet-accessible resources that are assigned public IP addresses.
You need to implement Azure DDoS Network Protection to protect the resources. The ...
Author: Aarav2020 · Last updated Sep 30, 2026
SNAPSHOT
-
You have an Azure subscription that contains the resources shown in the following table.
Each virtual network contains 20 virtual machines and a subnet that has an IP address space of /24.
You need to ensure that you can access the virtual machines from the internet by using Azure Bastion.
What is the minimum number of bastion subnets you should deploy, and what is the s...
Author: Aditya · Last updated Sep 30, 2026
You have an Azure subscription that contains 100 network security groups (NSGs).
You need to ensure that you log the application of sp...
To ensure that you log the application of specific NSG rules, the correct log type you should configure is A) flow log. Here’s why:
Key factors:
1. Flow Logs: Flow logs capture and record the traffic flow through your Network Security Groups (NSGs). They are essential for monitoring and analyzing the actual traffic that hits the NSG and shows whether traffic was allowed or denied based on the rules defined in the NSG. This is the most relevant log type for your scenario, as you specifically want to log the application of NSG rules.
- Use case: Flow logs are ideal for logging network traffic, which is what you need for monitoring the specific application of NSG rules. By enabling flow logs, you can track both inbound and outbound network traffic, including the source and destination IP addresses, ports, and protocols.
2. Activity Logs: Activity logs are Azure's record of control-plane operations related to resources in your subscription. They typically record operations such as creating, updating, or deleting resources and administrative actions like managing access control. These logs do not capture specific details about network traffic or the application of NSG rules.
- Rejected use case: Activity logs track management-level ...