exam questions

Exam AZ-700 All Questions

View all questions & answers for the AZ-700 exam

Exam AZ-700 topic 1 question 35 discussion

Actual exam question from Microsoft's AZ-700
Question #: 35
Topic #: 1
[All AZ-700 Questions]

HOTSPOT -

Your on-premises network uses an IP address range of 10.1.0.0 to 10.1.255.255.

You plan to deploy a new Azure virtual network solution that will include the following elements:

• A virtual network named VNet1
• A Site-to-Site (S2S) VPN connection between VNet1 and the on-premises network
• GatewaySubnet in VNet1, which will be used as a route-based virtual network gateway

You need to recommend which subnet masks to assign to VNet1 and GatewaySubnet. The solution must meet the following requirements:

• Maximize the number of available IP addresses on VNet1.
• Minimize the number of available IP addresses on GatewaySubnet.

Which address spaces should you assign to VNet1 and GatewaySubnet? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Jackdisuin
Highly Voted 1 year, 3 months ago
Maximize the number of available IP addresses on VNet1 10.0.0.0/16 Minimize the number of available IP addresses on GatewaySubnet 10.0.0.0/27
upvoted 27 times
poullb
6 months, 4 weeks ago
Está correto: VNet1 - Correto → 10.0.0.0/16 (VNET) GatewaySubnet - Correto → 10.0.0.0/27 (SUBNET) Incorreto - VNet1 10.0.0.0/8 → Because overlap with local address 10.1.0.0/16. 10.0.0.0/24 → Need to maximize the number of available IP addresses in VNet1. 10.0.0.0/27 → Need to maximize the number of available IP addresses in VNet1. Note: What may cause confusion is that the question refers to VNet (Address Space) and not SUBNet. Therefore, the VNet should be 10.0.0.0/16 where multiple subnets can be created, which includes the GatewaySubnet 10.0.0.0/27. The smallest gateway subnet recommended by MS is /27.
upvoted 4 times
...
...
uridex
Highly Voted 1 year, 3 months ago
10.0.0.0/16 - largest that doesn't overlap with on-prem address 10.0.0.0/27 - the minimum for gateway subnet
upvoted 13 times
thekhijir
1 year, 1 month ago
You can create a gateway subnet as small as /29, we recommend that you create a gateway subnet of /27 or larger https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-vpn-faq
upvoted 4 times
...
...
itmaster
Most Recent 7 months, 3 weeks ago
Maximize the number of available IP addresses on VNet1, so I don't see a problem with 10.0.0.0/24
upvoted 2 times
...
BradFelmey
7 months, 4 weeks ago
Although the question doesn't mention which gateway SKU is to be chosen, it DOES say that route-based policy is a requirement, and since the gateway Basic SKU does not support BGP, we can surmise that a non-Basic SKU must be chosen. Ref. this matrix for BGP support by gateway SKU: https://learn.microsoft.com/en-us/azure/vpn-gateway/about-gateway-skus#benchmark If we accept this premise, then the documentation further states the *only* gateway SKU which supports a /29 is the Basic SKU, which we have determined cannot be chosen. All other gateway SKUs have a minimum requirement of /27. Reference this section: https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpn-gateway-settings#gwsub Since 10.1/16 and 10.0/16 do not overlap, but 10.0/8 do, the correct selection for the maximum VNet is 10.0/16, and the given answer to the question is in error.
upvoted 4 times
...
620b351
8 months, 1 week ago
it is obvious that the answer is 10.0.0.0/16. so that it will start from 10.0.0.0 to 10.0.255.255. This is the maximum amount. Why /29 is not the answer is explained very well by the others.
upvoted 3 times
...
Octocon
1 year, 2 months ago
"While it's possible to create a gateway subnet as small as /29 (applicable to the Basic SKU only), all other SKUs require a gateway subnet of size /27 or larger (/27, /26, /25 etc.). You might want to create a gateway subnet larger than /27 so that the subnet has enough IP addresses to accommodate possible future configurations." https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpn-gateway-settings As we are only creating a s2s wouldn't we would be minimizing the addresses used by using a /29 ? The only thing is the sku isn't specified.
upvoted 3 times
...
fodocel235
1 year, 2 months ago
VNet1: 10.0.0.0/24 GatewaySubnet: 10.0.0.0/29, when you are making use of the Basic SKU. With the Basic SKU, you can setup a S2S VPN connection. When you're planning your gateway subnet size, refer to the documentation for the configuration that you're planning to create. For example, the ExpressRoute/VPN Gateway coexist configuration requires a larger gateway subnet than most other configurations. While it's possible to create a gateway subnet as small as /29 (applicable to the Basic SKU only), all other SKUs require a gateway subnet of size /27 or larger (/27, /26, /25 etc.). You might want to create a gateway subnet larger than /27 so that the subnet has enough IP addresses to accommodate possible future configurations. https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpn-gateway-settings Generation1 Basic, Max 10 S2S tunnels https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpngateways
upvoted 4 times
fodocel235
1 year, 2 months ago
Sorry, VNet can be 10.0.0.0/16. So answer is then 10.0.0.0/16 and 10.0.0.0/29.
upvoted 4 times
thekhijir
1 year, 1 month ago
You can create a gateway subnet as small as /29, we recommend that you create a gateway subnet of /27 or larger https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-vpn-faq
upvoted 1 times
...
...
...
Leinad78
1 year, 3 months ago
Why not 10.0.0.0/29 for Gatewaysubnet?
upvoted 2 times
thekhijir
1 year, 1 month ago
You can create a gateway subnet as small as /29, we recommend that you create a gateway subnet of /27 or larger https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-vpn-faq
upvoted 1 times
...
HoangNam2711
1 year, 3 months ago
Mimimum for GatewaySubnet is /27
upvoted 1 times
...
...
UncleBenzz
1 year, 3 months ago
Correct answer should be /16 since it doesn't overlap with the on-premise address space 10.1.0.0/16
upvoted 7 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago