Microsoft Certified:Azure Network Engineer Associate
Domain 5Objective 1
Implement and Manage Network Security Groups AZ-700 Practice Questions (Page 5)
Part of the Design and implement Azure network security services domain, which accounts for 15–20% of the AZ-700 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~6–13 in this domain), expect 2–4 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
10concepts
15–20%of the exam
Questions 21–25
- 21
You have a subnet that contains domain controllers. You need to allow inbound traffic from the corporate network on TCP 389 (LDAP) and TCP 445 (SMB) to the domain controllers, but block all other inbound traffic from the internet. You also need to ensure that the domain controllers can communicate with each other on any port. What is the most efficient way to configure the NSG?
Select an answer first - 22
You have a three-tier application with web servers, application servers, and database servers. You need to configure NSG rules so that only web servers can communicate with application servers on TCP 443, and only application servers can communicate with database servers on TCP 1433. You want to minimize the number of NSG rules and make it easy to add new servers to each tier. What should you do?
Select an answer first - 23
You have an NSG associated to a subnet that contains a database VM. The NSG has a rule that allows inbound traffic from a specific application subnet on port 1433. Users report that they cannot connect to the database from the application subnet. You verify that the application subnet is correctly configured and that the VM is running. What should you do to troubleshoot the issue?
Select an answer first - 24
You have multiple VMs in different subnets that run the same web application. You need to create a security rule that allows traffic to all of these VMs on TCP 443, but you want to avoid maintaining a list of individual IP addresses or updating the rule whenever a new VM is added. What should you do?
Select an answer first - 25
You have enabled virtual network flow logs for an NSG and are analyzing the logs in Log Analytics. You notice that a large number of flows are being denied by a rule named 'DenyAll'. You need to identify which specific source IP addresses are generating the most denied traffic. What should you do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “AZ-700” is a trademark of its owner, used for identification only.