← All AZ-700 Flashcard Decks

Networking Services Flashcards

7 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Networking Services flashcards as text
  1. A network architect needs to provide DDoS protection for a virtual network with advanced mitigation, telemetry, and cost protection. Which Azure DDoS Protection plan should they deploy?

    Answer: DDoS Network Protection

    DDoS Network Protection provides adaptive tuning, attack analytics, rapid response support, and cost protection guarantees for the entire VNet.

  2. Which type of Azure Private Endpoint connection approval is required when the Private Endpoint and the target resource are in different Azure AD tenants?

    Answer: Manual approval

    When a Private Endpoint and target resource are in different Azure AD tenants, the resource owner must manually approve the connection request.

  3. What happens to existing TCP connections through an Azure Load Balancer when a backend VM becomes unhealthy according to health probes?

    Answer: Existing connections persist until they time out or are closed; new connections go to healthy backends

    Azure Load Balancer drains unhealthy backends — existing established connections continue until they close naturally, while new connections are only sent to healthy backends.

  4. An engineer configures a VNet with address space 10.1.0.0/16. Azure reserves 5 IP addresses in every subnet. In a /24 subnet, how many usable host IPs are available?

    Answer: 251

    Azure reserves 5 IPs per subnet (network address, gateway, two DNS, broadcast), so a /24 (256 addresses) yields 256 - 5 = 251 usable host IPs.

  5. Which connectivity option in Azure provides a private, dedicated connection from an on-premises network to Azure with bandwidth options up to 100 Gbps?

    Answer: ExpressRoute

    ExpressRoute provides a private, dedicated connection through a connectivity provider with bandwidth up to 100 Gbps and does not traverse the public internet.

  6. A company wants to use Azure Application Gateway to route traffic to different backend pools based on the URL path. For example, /images/* goes to one pool and /video/* to another. Which feature enables this?

    Answer: URL path-based routing

    URL path-based routing in Azure Application Gateway uses path maps to route requests with different URL paths to different backend server pools.

  7. In Azure, what is the maximum transmission unit (MTU) supported for traffic within a virtual network, and what value should be configured to avoid fragmentation over VPN tunnels?

    Answer: 1500 MTU for VNet; 1400 for VPN tunnels

    Azure VNets support 1500 MTU for intra-VNet traffic, but VPN tunnels add overhead so 1400 MTU is recommended for guest OS settings to avoid fragmentation.