exam questions

Exam AZ-700 All Questions

View all questions & answers for the AZ-700 exam

Exam AZ-700 topic 2 question 51 discussion

Actual exam question from Microsoft's AZ-700
Question #: 51
Topic #: 2
[All AZ-700 Questions]

HOTSPOT -

You have an Azure subscription that contains the resources shown in the following table.



The virtual network topology is shown in the following exhibit.



Firewall1 is configured as shown in following exhibit.



FirewallPolicy1 contains the following rules:

• Allow outbound traffic from Vnet1 and Vnet2 to the internet.
• Allow any traffic between Vnet1 and Vnet2.

No custom private endpoints, service endpoints, routing tables, or network security groups (NSGs) were created.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
_fvt
Highly Voted 1 year, 7 months ago
Should be YNY Y - You need to add User Defined Route to the Firewall Appliance from the subnets (https://learn.microsoft.com/en-us/azure/firewall/tutorial-firewall-deploy-portal) N - The firewall is not a VPN Gateway, and we do not have any connection with On-Premises here (https://learn.microsoft.com/en-us/answers/questions/516530/how-to-set-up-a-multi-spoke-virtual-network-in-azu) Y - Azure Firewall can filter by web categories (https://learn.microsoft.com/en-us/azure/firewall/web-categories)
upvoted 48 times
...
KyleHodg
Highly Voted 1 year, 5 months ago
The Firewall SKU states standard. Wouldn't Premium be required for filtering by category? Meaning YNN?
upvoted 8 times
Azused
1 year, 2 months ago
To filter Web categories standard is enough.
upvoted 3 times
...
Apptech
1 year, 5 months ago
Standard SKU supports category filtering. "Azure Firewall Standard is recommended for customers looking for Layer 3–Layer 7 firewall and needs autoscaling to handle peak traffic periods of up to 30 Gbps. It supports enterprise features like threat intelligence, DNS proxy, custom DNS, and web categories." https://learn.microsoft.com/en-us/azure/firewall/choose-firewall-sku
upvoted 7 times
...
...
toto74500
Most Recent 10 months, 1 week ago
YNY 1- Yes because the route priority for the same adress prefix is 1. UDR 2. BGP 3. System-route here the 3rd option will take place because we have a vnet peering between Vnet1 and Vnet2 so to "force" traffic between them to reach each other via FW, you need to assign UDR to both subnets. 2- No because FW is an NVA not a VNG 3- yes Azure Firewall standard can handle web content filtering
upvoted 3 times
...
GBAU
1 year ago
YNY 1: SN1 required RT to change 0.0.0.0/0 to Virtual Appliance of FW otherwise it will go out the Wire Service. SN2 required RT to change 0.0.0.0/0 to point to Firewall somehow otherwise it will also go out its wire service. Not sure if this would be a Virtual Appliance or Internal IP route without trying it. 2: N: Route table in 1 will get it to the Firewall interface, otherwise it doesn't know it exists and will go out the wire service of its own subnet. 3: Seems so, Standard can do web site category filtering. = Y 700 is all we need right?
upvoted 1 times
...
ConanBarb
1 year, 1 month ago
NNY 1. No, not a routing table, but a UDR would be needed (at least for VM2) 2. No, that wont help for that. Again a UDR 3. Yes. https://learn.microsoft.com/en-us/azure/firewall/choose-firewall-sku
upvoted 1 times
volto
1 year ago
You need a Routing Table or Azure Route Server to add UDR.
upvoted 3 times
...
...
Lazylinux
1 year, 3 months ago
YNY 1- Y - because - routing table is required- You need to create routing table, add a router - next hop type select VNA and put the firewall local ip - in this case the private IP 2- N Because there is no VPN GWY but alos you need one vNET2 to tick use REMOTE GWY and one vNET1 tick allow GWY Transit 3- YES as per this link https://learn.microsoft.com/en-us/azure/firewall/choose-firewall-sku check the table at bottom
upvoted 6 times
...
TheBigMan
1 year, 5 months ago
Think it should be NNN 1) Question is about gateway nor UDR 3) Firewall is standard, only premium has categories
upvoted 1 times
makkelijkzat
1 year, 4 months ago
3) Standard has categories https://learn.microsoft.com/en-us/azure/firewall/choose-firewall-sku
upvoted 3 times
daemon101
1 year, 4 months ago
The support for Web Categories with standard SKU must be implemented recently. It used to be only with Premium SKU. Anyway, thank you for the reference.
upvoted 2 times
...
...
...
occupatissimo
1 year, 5 months ago
question ask for a routing table, not for a udr, be aware ....NNY
upvoted 3 times
...
khanda
1 year, 7 months ago
Answer should be YNY, see @_fvt comment.
upvoted 2 times
...
ckyap
1 year, 7 months ago
YNN - Yes - routing table is required- Create a routing table, add a router - next hop type select Virtual Appliance and put the firewall1 local ip (https://learn.microsoft.com/en-us/azure/firewall/tutorial-firewall-deploy-portal#create-a-default-route) No - Vnet1 and Vnet2 is not used for Virtual network gateway or route server, the remote gateway setting will be greyed out if you try to configure the settings in the Peering. No - Network rule is prioritised before application rules thus application rules like website blocking will not be enforced(https://learn.microsoft.com/en-us/training/modules/design-implement-network-security-monitoring/6-azure-firewall#:~:text=Outbound%20connectivity%20using%20network%20rules%20and%20application%20rules)
upvoted 1 times
Tasli6
1 year, 4 months ago
But in the question it says "Firewall1 can be configured to limit access to websites by categories." Technically it can be by removing the network rule and configuring an applicaiton rule instead.
upvoted 2 times
...
...
ajinkyap
1 year, 7 months ago
it should be YNY
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago