Microsoft Azure Administrator AZ-104 Azure Virtual Networks Practice Test 1

 

Topic 11 Practice Test 1 covers Azure Virtual Networks for Microsoft Azure Administrator AZ-104 and maps to the objective: Configure and manage virtual networks in Azure. For broader exam preparation, review the Microsoft AZ-104 Exam Dumps. Every option includes focused technical reasoning explaining both the Azure concept and its fit to the scenario.

Question 1

Woodgrove Bank is adding an application tier and needs its own IP range carved from the existing virtual network address space. Which action fits? Choose ONE.

  1. Create or modify the virtual network and its subnets
  2. Create virtual network peering between the two virtual networks
  3. Associate an Azure public IP address with the internet-facing resource
  4. Add a user-defined route with Virtual appliance as the next hop

Correct Answer: A

Correct Answer

 

 

Answer A is correct because A virtual network provides the private Azure IP address space, and subnets divide that space into nonoverlapping ranges to organize workloads and apply network controls. Woodgrove Bank must define a nonoverlapping subnet address range inside the virtual network for the new workload. The service behavior matches the constraint.

Incorrect Answers

 

Answer B is incorrect because Virtual network peering connects Azure virtual networks over the Microsoft backbone so resources can communicate using private IP addresses without a gateway in the traffic path. Woodgrove Bank must define a nonoverlapping subnet address range inside the virtual network for the new workload. This does not satisfy that condition.

Answer C is incorrect because A public IP address provides an Azure resource with an internet-routable address when the resource type supports public IP association. Woodgrove Bank must define a nonoverlapping subnet address range inside the virtual network for the new workload. It would leave the requirement unmet.

Answer D is incorrect because A user-defined route can send matching traffic to a network virtual appliance by selecting Virtual appliance as the next-hop type and specifying the appliance private IP. Woodgrove Bank must define a nonoverlapping subnet address range inside the virtual network for the new workload. Its function is different in this case.

 

Question 2

Litware needs to segment workloads into a dedicated subnet without creating a second virtual network. Choose the best change. Choose ONE.

  1. Create virtual network peering between the two virtual networks
  2. Create or modify the virtual network and its subnets
  3. Associate an Azure public IP address with the internet-facing resource
  4. Add a user-defined route with Virtual appliance as the next hop

Correct Answer: B

Correct Answer

 

 

Answer B is correct because A virtual network provides the private Azure IP address space, and subnets divide that space into nonoverlapping ranges to organize workloads and apply network controls. Litware must define a nonoverlapping subnet address range inside the virtual network for the new workload. This meets the stated administration goal.

Incorrect Answers

 

Answer A is incorrect because Virtual network peering connects Azure virtual networks over the Microsoft backbone so resources can communicate using private IP addresses without a gateway in the traffic path. Litware must define a nonoverlapping subnet address range inside the virtual network for the new workload. Its purpose differs from that need.

Answer C is incorrect because A public IP address provides an Azure resource with an internet-routable address when the resource type supports public IP association. Litware must define a nonoverlapping subnet address range inside the virtual network for the new workload. That behavior does not fit here.

Answer D is incorrect because A user-defined route can send matching traffic to a network virtual appliance by selecting Virtual appliance as the next-hop type and specifying the appliance private IP. Litware must define a nonoverlapping subnet address range inside the virtual network for the new workload. The option targets another design goal.

 

Question 3

An Azure administrator at Fourth Coffee learns that the organization needs low-overhead private connectivity between a management VNet and an application VNet. What should the administrator do? Choose ONE.

  1. Create global virtual network peering
  2. Create the additional required peering connection
  3. Create virtual network peering between the two virtual networks
  4. Add a user-defined route with Virtual appliance as the next hop

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Virtual network peering connects Azure virtual networks over the Microsoft backbone so resources can communicate using private IP addresses without a gateway in the traffic path. Fourth Coffee must connect two virtual networks in the same Azure region using private IP addresses over the Microsoft backbone. It aligns with the required Azure outcome.

Incorrect Answers

 

Answer A is incorrect because Global virtual network peering connects supported virtual networks in different Azure regions while preserving private IP connectivity over the Microsoft backbone. Fourth Coffee must connect two virtual networks in the same Azure region using private IP addresses over the Microsoft backbone. Its function is different in this case.

Answer B is incorrect because Virtual network peering is not transitive; two spokes that only peer with the same hub do not automatically gain direct connectivity through those peerings. Fourth Coffee must connect two virtual networks in the same Azure region using private IP addresses over the Microsoft backbone. The feature solves a different problem.

Answer D is incorrect because A user-defined route can send matching traffic to a network virtual appliance by selecting Virtual appliance as the next-hop type and specifying the appliance private IP. Fourth Coffee must connect two virtual networks in the same Azure region using private IP addresses over the Microsoft backbone. This is not the requested capability.

 

Question 4

At Wingtip Toys, the organization has two same-region virtual networks whose VMs must communicate directly without a VPN gateway. What should be configured? Choose ONE.

  1. Create global virtual network peering
  2. Create the additional required peering connection
  3. Add a user-defined route with Virtual appliance as the next hop
  4. Create virtual network peering between the two virtual networks

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Virtual network peering connects Azure virtual networks over the Microsoft backbone so resources can communicate using private IP addresses without a gateway in the traffic path. Wingtip Toys must connect two virtual networks in the same Azure region using private IP addresses over the Microsoft backbone. The option supplies the needed behavior.

Incorrect Answers

 

Answer A is incorrect because Global virtual network peering connects supported virtual networks in different Azure regions while preserving private IP connectivity over the Microsoft backbone. Wingtip Toys must connect two virtual networks in the same Azure region using private IP addresses over the Microsoft backbone. The option targets another design goal.

Answer B is incorrect because Virtual network peering is not transitive; two spokes that only peer with the same hub do not automatically gain direct connectivity through those peerings. Wingtip Toys must connect two virtual networks in the same Azure region using private IP addresses over the Microsoft backbone. This does not satisfy that condition.

Answer C is incorrect because A user-defined route can send matching traffic to a network virtual appliance by selecting Virtual appliance as the next-hop type and specifying the appliance private IP. Wingtip Toys must connect two virtual networks in the same Azure region using private IP addresses over the Microsoft backbone. It would leave the requirement unmet.

 

Question 5

Lucerne Publishing has application VNets in West Europe and North Europe that require private backbone connectivity. Choose the best change. Choose ONE.

  1. Create global virtual network peering
  2. Create virtual network peering between the two virtual networks
  3. Create the additional required peering connection
  4. Associate an Azure public IP address with the internet-facing resource

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Global virtual network peering connects supported virtual networks in different Azure regions while preserving private IP connectivity over the Microsoft backbone. Lucerne Publishing must connect virtual networks in different Azure regions using supported Azure virtual network peering. This is the precise operational fit.

Incorrect Answers

 

Answer B is incorrect because Virtual network peering connects Azure virtual networks over the Microsoft backbone so resources can communicate using private IP addresses without a gateway in the traffic path. Lucerne Publishing must connect virtual networks in different Azure regions using supported Azure virtual network peering. This is not the requested capability.

Answer C is incorrect because Virtual network peering is not transitive; two spokes that only peer with the same hub do not automatically gain direct connectivity through those peerings. Lucerne Publishing must connect virtual networks in different Azure regions using supported Azure virtual network peering. Its purpose differs from that need.

Answer D is incorrect because A public IP address provides an Azure resource with an internet-routable address when the resource type supports public IP association. Lucerne Publishing must connect virtual networks in different Azure regions using supported Azure virtual network peering. That behavior does not fit here.

 

Question 6

Fabrikam needs private IP communication between nonoverlapping VNets deployed in separate Azure regions. Which option is appropriate? Choose ONE.

  1. Create virtual network peering between the two virtual networks
  2. Create global virtual network peering
  3. Create the additional required peering connection
  4. Associate an Azure public IP address with the internet-facing resource

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Global virtual network peering connects supported virtual networks in different Azure regions while preserving private IP connectivity over the Microsoft backbone. Fabrikam must connect virtual networks in different Azure regions using supported Azure virtual network peering. That capability fits the scenario directly.

Incorrect Answers

 

Answer A is incorrect because Virtual network peering connects Azure virtual networks over the Microsoft backbone so resources can communicate using private IP addresses without a gateway in the traffic path. Fabrikam must connect virtual networks in different Azure regions using supported Azure virtual network peering. It would leave the requirement unmet.

Answer C is incorrect because Virtual network peering is not transitive; two spokes that only peer with the same hub do not automatically gain direct connectivity through those peerings. Fabrikam must connect virtual networks in different Azure regions using supported Azure virtual network peering. Its function is different in this case.

Answer D is incorrect because A public IP address provides an Azure resource with an internet-routable address when the resource type supports public IP association. Fabrikam must connect virtual networks in different Azure regions using supported Azure virtual network peering. The feature solves a different problem.

 

Question 7

A cloud engineer at Tailspin Toys is working with an environment that must connect two application spokes without relying on transitive behavior from their separate hub peerings. Select the correct configuration. Choose ONE.

  1. Create virtual network peering between the two virtual networks
  2. Synchronize the peering after the address-space change
  3. Create the additional required peering connection
  4. Add a user-defined route with Virtual appliance as the next hop

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Virtual network peering is not transitive; two spokes that only peer with the same hub do not automatically gain direct connectivity through those peerings. Tailspin Toys must provide direct private connectivity between two spoke virtual networks because hub peering does not make peering transitive. It therefore matches the requested outcome.

Incorrect Answers

 

Answer A is incorrect because Virtual network peering connects Azure virtual networks over the Microsoft backbone so resources can communicate using private IP addresses without a gateway in the traffic path. Tailspin Toys must provide direct private connectivity between two spoke virtual networks because hub peering does not make peering transitive. That behavior does not fit here.

Answer B is incorrect because After a peered virtual network address space changes, the peering must be synchronized so the remote peer learns the updated prefixes and system routes. Tailspin Toys must provide direct private connectivity between two spoke virtual networks because hub peering does not make peering transitive. The option targets another design goal.

Answer D is incorrect because A user-defined route can send matching traffic to a network virtual appliance by selecting Virtual appliance as the next-hop type and specifying the appliance private IP. Tailspin Toys must provide direct private connectivity between two spoke virtual networks because hub peering does not make peering transitive. This does not satisfy that condition.

 

Question 8

An Azure administrator at Northwind Traders learns that the organization has two spokes that each peer with a hub but cannot communicate directly through those peering relationships. What should the administrator do? Choose ONE.

  1. Create virtual network peering between the two virtual networks
  2. Synchronize the peering after the address-space change
  3. Add a user-defined route with Virtual appliance as the next hop
  4. Create the additional required peering connection

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Virtual network peering is not transitive; two spokes that only peer with the same hub do not automatically gain direct connectivity through those peerings. Northwind Traders must provide direct private connectivity between two spoke virtual networks because hub peering does not make peering transitive. It is the strongest fit here.

Incorrect Answers

 

Answer A is incorrect because Virtual network peering connects Azure virtual networks over the Microsoft backbone so resources can communicate using private IP addresses without a gateway in the traffic path. Northwind Traders must provide direct private connectivity between two spoke virtual networks because hub peering does not make peering transitive. The feature solves a different problem.

Answer B is incorrect because After a peered virtual network address space changes, the peering must be synchronized so the remote peer learns the updated prefixes and system routes. Northwind Traders must provide direct private connectivity between two spoke virtual networks because hub peering does not make peering transitive. This is not the requested capability.

Answer C is incorrect because A user-defined route can send matching traffic to a network virtual appliance by selecting Virtual appliance as the next-hop type and specifying the appliance private IP. Northwind Traders must provide direct private connectivity between two spoke virtual networks because hub peering does not make peering transitive. Its purpose differs from that need.

 

Question 9

Woodgrove Bank added a new prefix to one VNet but the remote peer still shows the previous address space. Which option is appropriate? Choose ONE.

  1. Synchronize the peering after the address-space change
  2. Create virtual network peering between the two virtual networks
  3. Create global virtual network peering
  4. Inspect the effective routes on the affected network interface

Correct Answer: A

Correct Answer

 

 

Answer A is correct because After a peered virtual network address space changes, the peering must be synchronized so the remote peer learns the updated prefixes and system routes. Woodgrove Bank must update peering route information after changing the address space of a peered virtual network. The service behavior matches the constraint.

Incorrect Answers

 

Answer B is incorrect because Virtual network peering connects Azure virtual networks over the Microsoft backbone so resources can communicate using private IP addresses without a gateway in the traffic path. Woodgrove Bank must update peering route information after changing the address space of a peered virtual network. This does not satisfy that condition.

Answer C is incorrect because Global virtual network peering connects supported virtual networks in different Azure regions while preserving private IP connectivity over the Microsoft backbone. Woodgrove Bank must update peering route information after changing the address space of a peered virtual network. It would leave the requirement unmet.

Answer D is incorrect because Effective routes show the combined routes that apply to a network interface, including system, peering, BGP, and user-defined routes, which is useful for routing diagnosis. Woodgrove Bank must update peering route information after changing the address space of a peered virtual network. Its function is different in this case.

 

Question 10

In Litware’s Azure environment, the organization changed a hub VNet address range and needs each spoke peering to learn the updated prefixes. What is required? Choose ONE.

  1. Create virtual network peering between the two virtual networks
  2. Synchronize the peering after the address-space change
  3. Create global virtual network peering
  4. Inspect the effective routes on the affected network interface

Correct Answer: B

Correct Answer

 

 

Answer B is correct because After a peered virtual network address space changes, the peering must be synchronized so the remote peer learns the updated prefixes and system routes. Litware must update peering route information after changing the address space of a peered virtual network. This meets the stated administration goal.

Incorrect Answers

 

Answer A is incorrect because Virtual network peering connects Azure virtual networks over the Microsoft backbone so resources can communicate using private IP addresses without a gateway in the traffic path. Litware must update peering route information after changing the address space of a peered virtual network. Its purpose differs from that need.

Answer C is incorrect because Global virtual network peering connects supported virtual networks in different Azure regions while preserving private IP connectivity over the Microsoft backbone. Litware must update peering route information after changing the address space of a peered virtual network. That behavior does not fit here.

Answer D is incorrect because Effective routes show the combined routes that apply to a network interface, including system, peering, BGP, and user-defined routes, which is useful for routing diagnosis. Litware must update peering route information after changing the address space of a peered virtual network. The option targets another design goal.

 

Question 11

Fourth Coffee is implementing forced routing to an NVA private IP for a particular destination prefix. Which Azure feature fits? Choose ONE.

  1. Add a user-defined route with None as the next hop
  2. Inspect the effective routes on the affected network interface
  3. Add a user-defined route with Virtual appliance as the next hop
  4. Create virtual network peering between the two virtual networks

Correct Answer: C

Correct Answer

 

 

Answer C is correct because A user-defined route can send matching traffic to a network virtual appliance by selecting Virtual appliance as the next-hop type and specifying the appliance private IP. Fourth Coffee must send traffic for a specified prefix through a network virtual appliance by using a route table. It aligns with the required Azure outcome.

Incorrect Answers

 

Answer A is incorrect because A user-defined route whose next hop is None drops traffic for the matching prefix and is used when the design intentionally blackholes that destination range. Fourth Coffee must send traffic for a specified prefix through a network virtual appliance by using a route table. Its function is different in this case.

Answer B is incorrect because Effective routes show the combined routes that apply to a network interface, including system, peering, BGP, and user-defined routes, which is useful for routing diagnosis. Fourth Coffee must send traffic for a specified prefix through a network virtual appliance by using a route table. The feature solves a different problem.

Answer D is incorrect because Virtual network peering connects Azure virtual networks over the Microsoft backbone so resources can communicate using private IP addresses without a gateway in the traffic path. Fourth Coffee must send traffic for a specified prefix through a network virtual appliance by using a route table. This is not the requested capability.

 

Question 12

A cloud engineer at Wingtip Toys is working with an environment that must steer application-subnet traffic to a firewall appliance before it reaches a protected destination range. Select the correct configuration. Choose ONE.

  1. Add a user-defined route with None as the next hop
  2. Inspect the effective routes on the affected network interface
  3. Create virtual network peering between the two virtual networks
  4. Add a user-defined route with Virtual appliance as the next hop

Correct Answer: D

Correct Answer

 

 

Answer D is correct because A user-defined route can send matching traffic to a network virtual appliance by selecting Virtual appliance as the next-hop type and specifying the appliance private IP. Wingtip Toys must send traffic for a specified prefix through a network virtual appliance by using a route table. The option supplies the needed behavior.

Incorrect Answers

 

Answer A is incorrect because A user-defined route whose next hop is None drops traffic for the matching prefix and is used when the design intentionally blackholes that destination range. Wingtip Toys must send traffic for a specified prefix through a network virtual appliance by using a route table. The option targets another design goal.

Answer B is incorrect because Effective routes show the combined routes that apply to a network interface, including system, peering, BGP, and user-defined routes, which is useful for routing diagnosis. Wingtip Toys must send traffic for a specified prefix through a network virtual appliance by using a route table. This does not satisfy that condition.

Answer C is incorrect because Virtual network peering connects Azure virtual networks over the Microsoft backbone so resources can communicate using private IP addresses without a gateway in the traffic path. Wingtip Toys must send traffic for a specified prefix through a network virtual appliance by using a route table. It would leave the requirement unmet.

 

Question 13

In Lucerne Publishing’s Azure environment, the organization is publishing a supported Azure resource that requires its own internet-routable address. What is required? Choose ONE.

  1. Associate an Azure public IP address with the internet-facing resource
  2. Create virtual network peering between the two virtual networks
  3. Add a user-defined route with Virtual appliance as the next hop
  4. Create or modify the virtual network and its subnets

Correct Answer: A

Correct Answer

 

 

Answer A is correct because A public IP address provides an Azure resource with an internet-routable address when the resource type supports public IP association. Lucerne Publishing must provide an internet-routable Azure address to a supported resource that must be reachable directly from the internet. This is the precise operational fit.

Incorrect Answers

 

Answer B is incorrect because Virtual network peering connects Azure virtual networks over the Microsoft backbone so resources can communicate using private IP addresses without a gateway in the traffic path. Lucerne Publishing must provide an internet-routable Azure address to a supported resource that must be reachable directly from the internet. This is not the requested capability.

Answer C is incorrect because A user-defined route can send matching traffic to a network virtual appliance by selecting Virtual appliance as the next-hop type and specifying the appliance private IP. Lucerne Publishing must provide an internet-routable Azure address to a supported resource that must be reachable directly from the internet. Its purpose differs from that need.

Answer D is incorrect because A virtual network provides the private Azure IP address space, and subnets divide that space into nonoverlapping ranges to organize workloads and apply network controls. Lucerne Publishing must provide an internet-routable Azure address to a supported resource that must be reachable directly from the internet. That behavior does not fit here.

 

Question 14

Fabrikam is replacing a private-only endpoint because the supported resource must accept connections through an Azure public address. Which action fits? Choose ONE.

  1. Create virtual network peering between the two virtual networks
  2. Associate an Azure public IP address with the internet-facing resource
  3. Add a user-defined route with Virtual appliance as the next hop
  4. Create or modify the virtual network and its subnets

Correct Answer: B

Correct Answer

 

 

Answer B is correct because A public IP address provides an Azure resource with an internet-routable address when the resource type supports public IP association. Fabrikam must provide an internet-routable Azure address to a supported resource that must be reachable directly from the internet. That capability fits the scenario directly.

Incorrect Answers

 

Answer A is incorrect because Virtual network peering connects Azure virtual networks over the Microsoft backbone so resources can communicate using private IP addresses without a gateway in the traffic path. Fabrikam must provide an internet-routable Azure address to a supported resource that must be reachable directly from the internet. It would leave the requirement unmet.

Answer C is incorrect because A user-defined route can send matching traffic to a network virtual appliance by selecting Virtual appliance as the next-hop type and specifying the appliance private IP. Fabrikam must provide an internet-routable Azure address to a supported resource that must be reachable directly from the internet. Its function is different in this case.

Answer D is incorrect because A virtual network provides the private Azure IP address space, and subnets divide that space into nonoverlapping ranges to organize workloads and apply network controls. Fabrikam must provide an internet-routable Azure address to a supported resource that must be reachable directly from the internet. The feature solves a different problem.

 

Question 15

At Tailspin Toys, the organization must distinguish a route-selection problem from a downstream reachability failure using two Network Watcher views. What should be configured? Choose TWO.

  1. Inspect the effective routes on the affected network interface
  2. Run Network Watcher IP flow verify
  3. Associate an Azure public IP address with the internet-facing resource
  4. Run Network Watcher Connection troubleshoot
  5. Synchronize the peering after the address-space change

Correct Answers: A, D

Correct Answers

 

 

Answer A is correct because Effective routes show the combined routes that apply to a network interface, including system, peering, BGP, and user-defined routes, which is useful for routing diagnosis. Tailspin Toys must collect both the effective routing view and an active source-to-destination connectivity test for a routing investigation. It therefore matches the requested outcome.

Answer D is correct because Connection troubleshoot actively tests connectivity between a source and destination and reports reachability, latency, and relevant routing or security findings. Tailspin Toys must collect both the effective routing view and an active source-to-destination connectivity test for a routing investigation. The option supplies the needed behavior.

Incorrect Answers

 

Answer B is incorrect because IP flow verify evaluates whether a specific inbound or outbound packet would be allowed or denied by the effective network security rules on a virtual machine network interface. Tailspin Toys must collect both the effective routing view and an active source-to-destination connectivity test for a routing investigation. The option targets another design goal.

Answer C is incorrect because A public IP address provides an Azure resource with an internet-routable address when the resource type supports public IP association. Tailspin Toys must collect both the effective routing view and an active source-to-destination connectivity test for a routing investigation. This does not satisfy that condition.

Answer E is incorrect because After a peered virtual network address space changes, the peering must be synchronized so the remote peer learns the updated prefixes and system routes. Tailspin Toys must collect both the effective routing view and an active source-to-destination connectivity test for a routing investigation. It would leave the requirement unmet.

 

Question 16

Northwind Traders has an unexpected next hop and also needs to prove whether the destination is currently reachable. Which Azure feature fits? Choose TWO.

  1. Run Network Watcher IP flow verify
  2. Inspect the effective routes on the affected network interface
  3. Associate an Azure public IP address with the internet-facing resource
  4. Synchronize the peering after the address-space change
  5. Run Network Watcher Connection troubleshoot

Correct Answers: B, E

Correct Answers

 

 

Answer B is correct because Effective routes show the combined routes that apply to a network interface, including system, peering, BGP, and user-defined routes, which is useful for routing diagnosis. Northwind Traders must collect both the effective routing view and an active source-to-destination connectivity test for a routing investigation. It is the strongest fit here.

Answer E is correct because Connection troubleshoot actively tests connectivity between a source and destination and reports reachability, latency, and relevant routing or security findings. Northwind Traders must collect both the effective routing view and an active source-to-destination connectivity test for a routing investigation. This is the precise operational fit.

Incorrect Answers

 

Answer A is incorrect because IP flow verify evaluates whether a specific inbound or outbound packet would be allowed or denied by the effective network security rules on a virtual machine network interface. Northwind Traders must collect both the effective routing view and an active source-to-destination connectivity test for a routing investigation. This is not the requested capability.

Answer C is incorrect because A public IP address provides an Azure resource with an internet-routable address when the resource type supports public IP association. Northwind Traders must collect both the effective routing view and an active source-to-destination connectivity test for a routing investigation. Its purpose differs from that need.

Answer D is incorrect because After a peered virtual network address space changes, the peering must be synchronized so the remote peer learns the updated prefixes and system routes. Northwind Traders must collect both the effective routing view and an active source-to-destination connectivity test for a routing investigation. That behavior does not fit here.

 

Question 17

Woodgrove Bank needs an end-to-end test showing whether a VM can reach a remote endpoint and where the path fails. Which action fits? Choose ONE.

  1. Run Network Watcher Connection troubleshoot
  2. Inspect the effective routes on the affected network interface
  3. Run Network Watcher IP flow verify
  4. Verify that the effective route uses the Virtual network peering next hop

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Connection troubleshoot actively tests connectivity between a source and destination and reports reachability, latency, and relevant routing or security findings. Woodgrove Bank must actively test reachability between a source and destination and obtain routing or security diagnostics. The service behavior matches the constraint.

Incorrect Answers

 

Answer B is incorrect because Effective routes show the combined routes that apply to a network interface, including system, peering, BGP, and user-defined routes, which is useful for routing diagnosis. Woodgrove Bank must actively test reachability between a source and destination and obtain routing or security diagnostics. This does not satisfy that condition.

Answer C is incorrect because IP flow verify evaluates whether a specific inbound or outbound packet would be allowed or denied by the effective network security rules on a virtual machine network interface. Woodgrove Bank must actively test reachability between a source and destination and obtain routing or security diagnostics. It would leave the requirement unmet.

Answer D is incorrect because When peering routes are functioning, the remote virtual network address prefixes appear in effective routes with Virtual network peering as the next-hop type. Woodgrove Bank must actively test reachability between a source and destination and obtain routing or security diagnostics. Its function is different in this case.

 

Question 18

Litware must validate reachability and receive diagnostic information about next hops or blocking conditions. Choose the best change. Choose ONE.

  1. Inspect the effective routes on the affected network interface
  2. Run Network Watcher Connection troubleshoot
  3. Run Network Watcher IP flow verify
  4. Verify that the effective route uses the Virtual network peering next hop

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Connection troubleshoot actively tests connectivity between a source and destination and reports reachability, latency, and relevant routing or security findings. Litware must actively test reachability between a source and destination and obtain routing or security diagnostics. This meets the stated administration goal.

Incorrect Answers

 

Answer A is incorrect because Effective routes show the combined routes that apply to a network interface, including system, peering, BGP, and user-defined routes, which is useful for routing diagnosis. Litware must actively test reachability between a source and destination and obtain routing or security diagnostics. Its purpose differs from that need.

Answer C is incorrect because IP flow verify evaluates whether a specific inbound or outbound packet would be allowed or denied by the effective network security rules on a virtual machine network interface. Litware must actively test reachability between a source and destination and obtain routing or security diagnostics. That behavior does not fit here.

Answer D is incorrect because When peering routes are functioning, the remote virtual network address prefixes appear in effective routes with Virtual network peering as the next-hop type. Litware must actively test reachability between a source and destination and obtain routing or security diagnostics. The option targets another design goal.

 

Question 19

An Azure administrator at Fourth Coffee learns that the organization must test one inbound packet tuple against the rules applied to a virtual machine NIC. What should the administrator do? Choose ONE.

  1. Run Network Watcher Connection troubleshoot
  2. Inspect the effective routes on the affected network interface
  3. Run Network Watcher IP flow verify
  4. Verify that the effective route uses the Virtual network peering next hop

Correct Answer: C

Correct Answer

 

 

Answer C is correct because IP flow verify evaluates whether a specific inbound or outbound packet would be allowed or denied by the effective network security rules on a virtual machine network interface. Fourth Coffee must determine whether effective network security rules allow or deny a specific packet flow for a VM network interface. It aligns with the required Azure outcome.

Incorrect Answers

 

Answer A is incorrect because Connection troubleshoot actively tests connectivity between a source and destination and reports reachability, latency, and relevant routing or security findings. Fourth Coffee must determine whether effective network security rules allow or deny a specific packet flow for a VM network interface. Its function is different in this case.

Answer B is incorrect because Effective routes show the combined routes that apply to a network interface, including system, peering, BGP, and user-defined routes, which is useful for routing diagnosis. Fourth Coffee must determine whether effective network security rules allow or deny a specific packet flow for a VM network interface. The feature solves a different problem.

Answer D is incorrect because When peering routes are functioning, the remote virtual network address prefixes appear in effective routes with Virtual network peering as the next-hop type. Fourth Coffee must determine whether effective network security rules allow or deny a specific packet flow for a VM network interface. This is not the requested capability.

 

Question 20

At Wingtip Toys, the organization knows the source, destination, protocol, and port and wants to see whether NSG processing permits that packet. What should be configured? Choose ONE.

  1. Run Network Watcher Connection troubleshoot
  2. Inspect the effective routes on the affected network interface
  3. Verify that the effective route uses the Virtual network peering next hop
  4. Run Network Watcher IP flow verify

Correct Answer: D

Correct Answer

 

 

Answer D is correct because IP flow verify evaluates whether a specific inbound or outbound packet would be allowed or denied by the effective network security rules on a virtual machine network interface. Wingtip Toys must determine whether effective network security rules allow or deny a specific packet flow for a VM network interface. The option supplies the needed behavior.

Incorrect Answers

 

Answer A is incorrect because Connection troubleshoot actively tests connectivity between a source and destination and reports reachability, latency, and relevant routing or security findings. Wingtip Toys must determine whether effective network security rules allow or deny a specific packet flow for a VM network interface. The option targets another design goal.

Answer B is incorrect because Effective routes show the combined routes that apply to a network interface, including system, peering, BGP, and user-defined routes, which is useful for routing diagnosis. Wingtip Toys must determine whether effective network security rules allow or deny a specific packet flow for a VM network interface. This does not satisfy that condition.

Answer C is incorrect because When peering routes are functioning, the remote virtual network address prefixes appear in effective routes with Virtual network peering as the next-hop type. Wingtip Toys must determine whether effective network security rules allow or deny a specific packet flow for a VM network interface. It would leave the requirement unmet.

 

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!