โ† All AZ-700 Flashcard Decks

Troubleshooting and Performance Optimization Flashcards

7 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Troubleshooting and Performance Optimization flashcards as text
  1. An Azure Firewall is deployed in a hub VNet. Spoke VMs can reach the internet but not each other through the firewall. What is likely missing?

    Answer: A network rule allowing spoke-to-spoke traffic in Azure Firewall

    Azure Firewall blocks all traffic by default; a network rule explicitly allowing spoke-to-spoke traffic must be added.

  2. You are troubleshooting high latency on an ExpressRoute circuit. Azure Monitor shows low utilization. What tool helps identify if the latency is within Microsoft's network or on the provider segment?

    Answer: Network Performance Monitor with ExpressRoute monitoring

    Network Performance Monitor with the ExpressRoute monitoring solution measures latency across each circuit segment including provider and Microsoft network legs.

  3. A VM behind an internal Standard Load Balancer cannot initiate outbound connections to the internet. What is the recommended fix?

    Answer: Attach a NAT Gateway to the subnet

    Standard internal Load Balancers do not provide outbound SNAT; a NAT Gateway on the subnet is the recommended solution for outbound connectivity.

  4. After enabling Azure DDoS Protection Standard on a VNet, legitimate traffic spikes are being dropped. What should you configure to prevent this?

    Answer: Configure DDoS protection policies with custom thresholds using adaptive tuning

    DDoS Protection Standard uses adaptive tuning to learn normal traffic patterns, but custom threshold policies can be set to accommodate known legitimate traffic patterns.

  5. A BGP route learned over a site-to-site VPN takes priority over a static route to the same prefix. You need the static route to always win. What should you do?

    Answer: Disable BGP route propagation on the route table and use only static routes

    Disabling BGP route propagation on the subnet route table prevents dynamically learned BGP routes from overriding manually configured static routes.

  6. An Azure Front Door origin health probe is failing, causing all traffic to fail over to a secondary origin. The primary origin responds correctly to direct requests. What should you check?

    Answer: Whether the origin's NSG or firewall blocks Front Door's probe IP ranges

    Front Door health probes come from specific Microsoft IP ranges; if the origin's firewall blocks those ranges, probes will fail even if the origin is healthy.

  7. A packet capture taken with Network Watcher shows TCP SYN packets reaching a VM but no SYN-ACK is returned. The NSG allows the traffic. What is the next thing to investigate?

    Answer: Whether the OS firewall (Windows Firewall / iptables) is blocking the port

    If NSG rules permit traffic but the VM doesn't respond, the guest OS firewall is the next layer that could silently drop SYN packets.