Exam2pass
0 items Sign In or Register
  • Home
  • IT Exams
  • Guarantee
  • FAQs
  • Reviews
  • Contact Us
  • Demo
Exam2pass > Microsoft > Microsoft Certifications > AZ-720 > AZ-720 Online Practice Questions and Answers

AZ-720 Online Practice Questions and Answers

Questions 4

HOTSPOT

A company uses an Azure Backup agent to back up specific files and folder from an Azure virtual machine (VM) and an on-premises VM.

An administrator reports that the backup job fails on both VMs. Errors are returned in Microsoft Azure Recovery Services (MARS).

You need to troubleshoot the backup issues.

Which troubleshooting solution should you use?

Hot Area:

Buy Now

Correct Answer:

Questions 5

HOTSPOT

A company uses Azure Active Directory (Azure AD) with Azure role-based access control (RBAC) for access to resources.

Some users report that they are unable to grant RBAC roles to other users.

You need to troubleshoot the issue.

How should you complete the Azure Monitor query?

Hot Area:

Buy Now

Correct Answer:

Questions 6

HOTSPOT

A company develops an Azure Cosmos DB solution. The solution has the following components:

1.

A virtual network named VNet1 in a resource group named RG1.

2.

A subnet named Subnet1 in VNet1.

3.

A Private Link service.

4.

The company is unable to configure a source IP address for the Private Link service from Subnet1.

You need to resolve the issue for Subnet1.

How should you complete the PowerShell commands?

Hot Area:

Buy Now

Correct Answer:

Questions 7

A company has an Azure Virtual Network gateway named VNetGW1. The company enables point-to-site connectivity on VNetGW1. An administrator configures VNetGW1 for the following:

1.

OpenVPN for the tunnel type.

2.

Azure certificate for the authentication type.

Users receive a certificate mismatch error when connecting by using a VPN client.

You need to resolve the certificate mismatch error.

What should you do?

A. Configure the tunnel type for IKEv2 and OpenVPN on VNetGW1.

B. Create a profile manually, add the server FQDN and reissue the client certificate.

C. Install a Secure Socket Tunneling Protocol (SSTP) VPN client on the user's computers.

D. Configure preshared key for authentication on the VPN profile.

Buy Now

Correct Answer: B

To resolve the certificate mismatch error, you should create a profile manually, add the server FQDN and reissue the client certificate. According to 1, when you use OpenVPN for tunnel type on point-to-site VPN connections, you need to ensure that your client certificates have the correct server FQDN as one of their subject alternative names (SANs). Otherwise, you will receive a certificate mismatch error when connecting by using a VPN client.

Questions 8

A company has users in Azure Active Directory (Azure AD). The company enables the users to use Azure AD multi-factor authentication (MFA).

A user named User1 reports they receive the following error while setting up additional security verification settings for MFA:

Sorry! We can't process your request. Your session is invalid or expired. There was an error processing your request because your session is invalid or expired. Please try again.

You need to help the user complete the MFA setup.

What should you do?

A. From the Microsoft 365 Admin portal, clear the Block this user from signing in option for the user.

B. Instruct the user to complete the setup process within 10 minutes.

C. Instruct the user to enter the correct verification code.

D. Instruct the user to clear their web browser cache.

E. From the Azure AD portal, reset the user's password.

Buy Now

Correct Answer: B

https://learn.microsoft.com/en-us/microsoft-365/troubleshoot/active-directory/sorry-we-cant-process-your-request-error

Questions 9

A company connects their on-premises network by using Azure VPN Gateway. The on- premises environment includes three VPN devices that separately tunnel to the gateway by using Border Gateway Protocol (BGP).

A new subnet should be unreachable from the on-premises network.

You need to implement a solution.

Solution: Configure subnet delegation.

Does the solution meet the goal?

A. Yes

B. No

Buy Now

Correct Answer: B

The proposed solution, which is to configure subnet delegation, does not meet the goal of making the new subnet unreachable from the on-premises network. Subnet delegation is a mechanism to delegate management of a subnet to another

resource such as a Network Virtual Appliance or a Service Endpoint. It does not provide any means to restrict or isolate a subnet from the rest of the network.

To meet the goal, you can use Network Security Groups (NSGs) to restrict traffic to and from the new subnet. NSGs allow you to define inbound and outbound security rules that specify the type of traffic that is allowed or denied based on

different criteria such as source or destination IP address, protocol, port number, etc. By creating a custom NSG and defining rules that deny traffic to and from the new subnet, you can effectively make that subnet unreachable from the on-

premises network.

Therefore, the correct answer is option B, "No".

Reference:

https://docs.microsoft.com/en-us/azure/virtual-network/security-overview

https://docs.microsoft.com/en-us/azure/virtual-network/network-security-groups-overview

Questions 10

A company has an ExpressRoute gateway between their on-premises site and Azure. The ExpressRoute gateway is on a virtual network named VNet1. The company enables FastPath on the gateway. You associate a network security group

(NSG) with all of the subnets.

Users report issues connecting to VM1 from the on-premises environment. VM1 is on a virtual network named VNet2. Virtual network peering is enabled between VNet1 and VNet2.

You create a flow log named FlowLog1 and enable it on the NSG associated with the gateway subnet.

You discover that FlowLog1 is not reporting outbound flow traffic.

You need to resolve the issue with FlowLog1.

What should you do?

A. Configure FlowLog1 for version 2.

B. Create the storage account for FlowLog1 as a premium block blob.

C. Configure the FlowTimeoutInMinutes property on VNet2 to a non-null value.

D. Enable FlowLog1 in a network security group associated with the network interface of VM1.

Buy Now

Correct Answer: A

According to 1, flow logging using ExpressRoute Traffic Collector requires version 2 of flow logs. Version 1 of flow logs does not support ExpressRoute Traffic Collector. You can configure the version of flow logs when you enable them on a network security group (NSG).

Questions 11

A company plans to use an Azure PaaS service by using Azure Private Link service. The azure Private Link service and an endpoint have been configured.

The company reports that the endpoint is unable to connect to the service.

You need to resolve the connectivity issue.

What should you do?

A. Disable the endpoint network policies.

B. Validate the VPN device.

C. Approve the connection state.

D. Disable the service network policies.

Buy Now

Correct Answer: C

To resolve the connectivity issue, you should approve the connection state. According to 1, Azure Private Link service requires manual approval of connection requests from private endpoints by default. You can approve or reject a connection request by using PowerShell cmdlets or Azure portal.

Questions 12

A company connects their on-premises network by using Azure VPN Gateway. The on- premises environment includes three VPN devices that separately tunnel to the gateway by using Border Gateway Protocol (BGP).

A new subnet should be unreachable from the on-premises network.

You need to implement a solution.

Solution: Scale the gateway to Generation2.

Does the solution meet the goal?

A. Yes

B. No

Buy Now

Correct Answer: B

Scaling the gateway to Generation2 will not prevent the on-premises network from reaching the new subnet. Scaling the gateway changes the hardware configuration of the VPN gateway, but it does not affect the routing or connectivity

between the on- premises network and the virtual network.

A better solution would be to create a network security group (NSG) and associate it with the new subnet. The NSG can be configured to deny traffic from the on-premises network to the new subnet. This way, the new subnet will be isolated

from the on-premises network.

Reference:

VPN Gateway Generation: https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpngateways#gwgen2

Questions 13

A company has two subnet in a virtual network named VNe1m the subnet are named SubnetA and SubnetB. The company uses a site-to-site (S2) VPN in SubnetB to connect its on-premises environment to Azure. You deploy an Azure SQL Database named SQL1. You configure a service endpoint in SubnetA for Microsft.SqL

A. Configure a DNS record for the private IP address of SQL1.

B. Configure a network security group (NSG) to allow port 1433 on SubnetA

C. Configure a service endpoint on SubnetB.

D. Deploy a private endpoint for SQL1.

E. Deploy an Azure ExpressRoute circuit for VNet1.

Buy Now

Correct Answer: D

To allow the on-premises environment to access the Azure SQL Database named SQL1 over a site-to-site (S2S) VPN in SubnetB, you should deploy a private endpoint for SQL1. A private endpoint is a network interface that connects you

privately and securely to a service powered by Azure Private Link. Private Link allows you to access Azure PaaS services (for example, Azure Storage and SQL Database) and Azure-hosted customer/partner services over a private endpoint

in your virtual network. So the correct answer is D. Deploy a private endpoint for SQL1.

You can find more information about private endpoints in the official Microsoft documentation.

Exam Code: AZ-720
Exam Name: Troubleshooting Microsoft Azure Connectivity
Last Update: Mar 12, 2024
Questions: 109

PDF (Q&A)

$45.99
ADD TO CART

VCE

$49.99
ADD TO CART

PDF + VCE

$59.99
ADD TO CART

Exam2Pass----The Most Reliable Exam Preparation Assistance

There are tens of thousands of certification exam dumps provided on the internet. And how to choose the most reliable one among them is the first problem one certification candidate should face. Exam2Pass provide a shot cut to pass the exam and get the certification. If you need help on any questions or any Exam2Pass exam PDF and VCE simulators, customer support team is ready to help at any time when required.

Home | Guarantee & Policy |  Privacy & Policy |  Terms & Conditions |  How to buy |  FAQs |  About Us |  Contact Us |  Demo |  Reviews

2025 Copyright @ exam2pass.com All trademarks are the property of their respective vendors. We are not associated with any of them.