Exam Details

  • Exam Code
    :AZ-720
  • Exam Name
    :Troubleshooting Microsoft Azure Connectivity
  • Certification
    :Microsoft Certified: Azure Support Engineer for Connectivity Specialty
  • Vendor
    :Microsoft
  • Total Questions
    :109 Q&As
  • Last Updated
    :Mar 12, 2024

Microsoft Microsoft Certified: Azure Support Engineer for Connectivity Specialty AZ-720 Questions & Answers

  • Question 21:

    A company connects their on-premises network by using Azure VPN Gateway. The on- premises environment includes three VPN devices that separately tunnel to the gateway by using Border Gateway Protocol (BGP).

    A new subnet should be unreachable from the on-premises network.

    You need to implement a solution.

    Solution: Scale the gateway to Generation2.

    Does the solution meet the goal?

    A. Yes

    B. No

  • Question 22:

    A company uses an Azure Virtual Network (VNet) gateway named VNetGW1. VNetGW1 connects to a partner site by using a site-to-site VPN connection with dynamic routing.

    The company observes that the VPN disconnects from time to time. You need to troubleshoot the cause for the disconnections.

    What should you verify?

    A. The partner's VPN device and VNetGW1 are configured using the same shared key.

    B. VNetGW1 has exceeded the subnet Security Association pairs.

    C. The partner's VPN device and VNetGW1 are configured with the same virtual network address space.

    D. The public IP address of the partner's VPN device is configured in the local network gateway address space on VNetGW1.

  • Question 23:

    A company uses an Azure Virtual Network (VNet) gateway named VNetGW1. VNetGW1 connects to a partner site by using a site-to-site VPN connection with dynamic routing.

    The company observes that the VPN disconnects from time to time.

    You need to troubleshoot the cause for the disconnections.

    What should you verify?

    A. The partner's VPN device and VNetGW1 are configured using the same shared key.

    B. The partner's VPN device is configured for one VPN tunnel per subnet pair.

    C. The public IP address of the partner's VPN device is configured in the local network gateway address space on VNetGW1.

    D. The partner's VPN device and VNetGW1 are configured with the same virtual network address space.

  • Question 24:

    A company plans to use an Azure PaaS service by using Azure Private Link service. The azure Private Link service and an endpoint have been configured.

    The company reports that the endpoint is unable to connect to the service.

    You need to resolve the connectivity issue.

    What should you do?

    A. Disable the endpoint network policies.

    B. Validate the VPN device.

    C. Approve the connection state.

    D. Disable the service network policies.

  • Question 25:

    A company enables just-in-time (JIT) virtual machine (VM) access in Azure.

    An administrator observes a list of VMs on the Unsupported tab of the JIT VM access page in the Microsoft Defender for Cloud portal.

    You need to determine why some VMs are not supported for JIT VM access.

    What should you conclude?

    A. The administrator does not have the SecurityReader role.

    B. The administrator is using the Microsoft Defender for Cloud free tier.

    C. The client firewall does not allow port 22 on the VMs.

    D. A network security group is not associated with the VMs.

  • Question 26:

    A company deploys a new file sharing application on four Standard_D2_v3 virtual machines (VMs) behind an Azure Load Balancer. The company implements Azure Firewall.

    Users report that the application is slow during peak usage periods. An engineer reports that the peak usage for each VM is approximately 1 Gbps.

    You need to implement a solution that support a minimum of 10 Gbps.

    What should you do to increase the throughput?

    A. Request an increase in networking quotas.

    B. Increase the size of the VM instance.

    C. Disable the Azure Firewall and implement network security groups in its place.

    D. Move two of the servers behind a separate load balancer and configure round robin routing in Traffic Manager.

  • Question 27:

    A company hosts a network virtual appliance (VNA) and Azure Route Server in different virtual networks (VNets). Border Gateway Protocol (BGP) peering is enabled between the NVA loses internet connectivity after it advertises the default

    route to the route server.

    You need to resolve the problem with the NVA.

    What should you do?

    A. Configure a user-defined route on the NVA subnet.

    B. Move the route server to the same VNet as the NVA.

    C. Configure a unique autonomous system number (ASN) on the NVA.

    D. Configure a public IP address on the route server.

  • Question 28:

    A company migrates an on-premises Windows virtual machine (VM) to Azure. An administrator enables backups for the VM by using the Azure portal.

    The company reports that the Azure VM backup job is failing.

    You need to troubleshoot the issue.

    Solution: Create a new manual backup in Backup center.

    Does the solution meet the goal?

    A. Yes

    B. No

  • Question 29:

    A company migrates existing Ubuntu Linux servers from their on-premises vSphere infrastructure to Azure.

    The virtual machines (VMs) are experiencing a low network throughput of 20 Mbps. The VMs are expected to sustain 300 Mbps.

    You need to ensure that the VMs are compatible with Azure.

    Which change should you make?

    A. Install a kernel name that ends with -azure.

    B. Configure the network interfaces to 1000 Mbps/full duplex.

    C. Redeploy the VM with Accelerated Networking enabled.

    D. Increase the TCP buffers and window size kernel parameters.

  • Question 30:

    A company uses Azure virtual machines (VMs) in multiple regions. The VMs have the following configuration:

    The backend pool of an internal Azure Load Balancer (ILB) named ILB1 contains VM1 and VM2. The ILB uses the Basic SKU and is in a resource group RG2.

    Virtual network peering has been configured between VNet1 and VNet2.

    Users report that they are unable to connect to resources on VM1 and VM2 by using ILB1 from VM3.

    You need to resolve the connectivity issues.

    What should you do?

    A. Redeploy VM1 and VM2 into availability zones.

    B. Move ILB1 to RG1.

    C. Redeploy the ILB using the Standard SKU.

    D. Move VM1 and VM2 into RG3.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your AZ-720 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.