โ† All AZ-700 Flashcard Decks

Troubleshooting and Performance Optimization Flashcards

7 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Troubleshooting and Performance Optimization flashcards as text
  1. You need to optimize throughput for a VM running network-intensive workloads. The VM size supports it but throughput is still limited. What feature should you verify is enabled on the NIC?

    Answer: Accelerated Networking

    Accelerated Networking bypasses the host vSwitch using SR-IOV, significantly reducing latency and increasing network throughput for supported VM sizes.

  2. An Azure VPN Gateway is showing 'P2S client connections failing' after a certificate rotation. What is the most likely cause?

    Answer: The VPN client profile was not re-downloaded after the new root certificate was uploaded

    After uploading a new root certificate to the VPN gateway, clients must download and install the updated VPN client profile to trust the new certificate chain.

  3. Traffic between two peered VNets is passing through an NVA in a hub VNet. After adding a new spoke, traffic from the new spoke bypasses the NVA. What is missing?

    Answer: A UDR on the new spoke's subnet pointing to the NVA as next hop

    Without a UDR directing traffic to the NVA's IP as the next hop, traffic will route directly between peered VNets, bypassing inspection.

  4. A customer reports that their ExpressRoute-connected on-premises network can reach Azure VMs but cannot reach Azure PaaS services via private endpoints. What should be verified?

    Answer: That the private DNS zone is linked to the VNet and on-premises DNS forwards to Azure DNS Private Resolver

    Private endpoint DNS resolution requires on-premises DNS to forward private DNS zone queries to Azure, typically via DNS Private Resolver, and the zone must be linked to the VNet.

  5. An Azure Application Gateway WAF is blocking requests that should be legitimate. Logs show rule group 'REQUEST-942-APPLICATION-ATTACK-SQLI' is triggering. What is the best immediate mitigation without disabling WAF?

    Answer: Create a custom WAF exclusion for the specific rule or request attribute causing false positives

    WAF exclusions allow specific rules or request attributes to be excluded, eliminating false positives while keeping all other WAF protections active.

  6. You run Network Watcher Next Hop for a VM and the result is 'None'. What does this indicate?

    Answer: The traffic will be dropped because no route exists for that destination

    A Next Hop result of 'None' means Azure has no valid route for that destination prefix and the traffic will be dropped.

  7. Two Azure regions are connected via Global VNet Peering. Users report higher-than-expected latency. What is a key consideration specific to Global VNet Peering performance?

    Answer: Traffic traverses Microsoft's global backbone but incurs cross-region bandwidth charges and unavoidable WAN latency

    Global VNet peering uses Microsoft's private backbone, but physical distance between regions introduces unavoidable WAN latency that cannot be eliminated.