โ† All AZ-700 Flashcard Decks

Troubleshooting and Performance Optimization Flashcards

7 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Troubleshooting and Performance Optimization flashcards as text
  1. A virtual machine cannot reach the internet despite having a public IP assigned. Network Watcher IP flow verify returns 'Access Denied'. What is the most likely cause?

    Answer: An NSG rule is blocking outbound traffic on port 80/443

    IP flow verify identifies which NSG rule is denying traffic, so a blocking outbound NSG rule is the most likely cause.

  2. You notice intermittent packet loss between two Azure VMs in the same VNet. Which Network Watcher tool provides hop-by-hop latency and packet loss statistics?

    Answer: Connection Monitor

    Connection Monitor continuously measures latency, packet loss, and reachability between endpoints including hop-by-hop metrics.

  3. An Azure Load Balancer health probe is marking all backend VMs as unhealthy. The VMs are running and their application is listening. What should you check first?

    Answer: Whether an NSG is blocking the health probe source IP 168.63.129.16

    Azure health probes originate from 168.63.129.16 and NSGs blocking this IP will cause all probes to fail.

  4. A site-to-site VPN tunnel shows as connected but no traffic passes. You confirm routing on the Azure side is correct. What on-premises configuration should you verify?

    Answer: That the on-premises firewall permits the Azure VNet address space

    A connected tunnel with no traffic flow typically indicates the on-premises firewall is not permitting the remote (Azure) address space.

  5. Users report that name resolution fails for private endpoints from on-premises machines connected via ExpressRoute. DNS queries go to on-premises DNS servers. What is required?

    Answer: Deploy Azure DNS Private Resolver with inbound endpoints in the VNet

    Azure DNS Private Resolver with inbound endpoints allows on-premises DNS servers to forward queries into Azure's private DNS zones.

  6. An Application Gateway returns HTTP 502 errors for some requests but not others. What is the most common root cause?

    Answer: Backend pool members are unhealthy or timing out

    HTTP 502 from Application Gateway indicates the gateway could not get a valid response from a backend server, typically due to unhealthy or slow backends.

  7. A VNet peering shows status 'Disconnected'. What is the most likely cause?

    Answer: One side of the peering was deleted

    Peering enters 'Disconnected' state when one side of the bidirectional peering link has been deleted.