Microsoft Designing and Implementing Microsoft Azure Networking Solutions (AZ-700 Korean Version) - AZ-700 Korean Exam Practice Test
あなたの会社はニューヨークに単一のオンプレミスデータセンターを持っています。米国東部のAzureリージョンは、ニューヨークにピアリングの場所があります。
同社は、米国東部地域にのみAzureリソースを持っています。
最大1Gbpsをサポートするには、ExpressRouteを実装する必要があります。 ExpressRouteUnlimitedデータプランのみを使用する必要があります。ソリューションはコストを最小限に抑える必要があります。
どのタイプのExpressRoute回線を作成する必要がありますか?
同社は、米国東部地域にのみAzureリソースを持っています。
最大1Gbpsをサポートするには、ExpressRouteを実装する必要があります。 ExpressRouteUnlimitedデータプランのみを使用する必要があります。ソリューションはコストを最小限に抑える必要があります。
どのタイプのExpressRoute回線を作成する必要がありますか?
Correct Answer: A
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
次の表に示すリソースを含む Azure サブスクリプションがあります。

NSG1 を使用して storage1 へのアクセスを制御する必要があります。最初に何を構成する必要がありますか?

NSG1 を使用して storage1 へのアクセスを制御する必要があります。最初に何を構成する必要がありますか?
Correct Answer: D
Vote an answer
タスク7
サブネット4-1に100台の仮想マシンをデプロイする予定です。これらの仮想マシンにはパブリックIPアドレスは割り当てられません。これらの仮想マシンは、サードパーティがホストする同じAPIを呼び出します。仮想マシンは、このAPIに対して1分あたり10,000回以上の呼び出しを行う予定です。
SNATポート枯渇のリスクを最小限に抑える必要があります。ソリューションは管理作業を最小限に抑える必要があります。
サブネット4-1に100台の仮想マシンをデプロイする予定です。これらの仮想マシンにはパブリックIPアドレスは割り当てられません。これらの仮想マシンは、サードパーティがホストする同じAPIを呼び出します。仮想マシンは、このAPIに対して1分あたり10,000回以上の呼び出しを行う予定です。
SNATポート枯渇のリスクを最小限に抑える必要があります。ソリューションは管理作業を最小限に抑える必要があります。
Correct Answer:
See the Explanation below for step by step instructions.
Explanation:
To minimize the risk of SNAT port exhaustion for your 100 virtual machines in subnet4-1, while ensuring minimal administrative effort, you can use an Azure NAT Gateway. This service provides scalable and resilient outbound connectivity for virtual networks, dynamically allocating SNAT ports to avoid exhaustion.
Navigate to the Azure Portal.
Search for "NAT gateways" and select it.
Click on "Create".
Enter the following details:
Subscription: Select your subscription.
Resource Group: Select an existing resource group or create a new one.
Name: Enter a name for the NAT gateway (e.g., NATGateway-Subnet4-1).
Region: Select the region where your virtual network is located.
Click on "Next: Outbound IP".
Choose whether to use existing public IP addresses or create new ones.
If creating new ones, click on "Add new" and configure the new public IP addresses.
Click on "Next: Subnet".
Click on "Associate subnet".
Select the virtual network that contains subnet4-1.
Select subnet4-1 from the list of subnets.
Click on "OK".
Review your settings to ensure everything is correct.
Click on "Review + create" and then "Create".
Azure NAT Gateway: This service provides outbound connectivity for virtual networks, dynamically allocating SNAT ports across all VM instances within a subnet. This dynamic allocation helps prevent SNAT port exhaustion, especially in scenarios with high outbound connection volumes12.
Dynamic SNAT Port Allocation: Unlike static allocation methods, NAT Gateway dynamically allocates SNAT ports based on demand, ensuring efficient use of available ports and reducing the risk of exhaustion2.
Step-by-Step SolutionStep 1: Create a NAT GatewayStep 2: Configure Outbound IP AddressesStep 3:
Associate the NAT Gateway with Subnet4-1Step 4: Review and CreateExplanationBy following these steps, you can ensure that your 100 virtual machines in subnet4-1 can make the necessary API calls without running into SNAT port exhaustion, all while minimizing administrative effort.
Explanation:
To minimize the risk of SNAT port exhaustion for your 100 virtual machines in subnet4-1, while ensuring minimal administrative effort, you can use an Azure NAT Gateway. This service provides scalable and resilient outbound connectivity for virtual networks, dynamically allocating SNAT ports to avoid exhaustion.
Navigate to the Azure Portal.
Search for "NAT gateways" and select it.
Click on "Create".
Enter the following details:
Subscription: Select your subscription.
Resource Group: Select an existing resource group or create a new one.
Name: Enter a name for the NAT gateway (e.g., NATGateway-Subnet4-1).
Region: Select the region where your virtual network is located.
Click on "Next: Outbound IP".
Choose whether to use existing public IP addresses or create new ones.
If creating new ones, click on "Add new" and configure the new public IP addresses.
Click on "Next: Subnet".
Click on "Associate subnet".
Select the virtual network that contains subnet4-1.
Select subnet4-1 from the list of subnets.
Click on "OK".
Review your settings to ensure everything is correct.
Click on "Review + create" and then "Create".
Azure NAT Gateway: This service provides outbound connectivity for virtual networks, dynamically allocating SNAT ports across all VM instances within a subnet. This dynamic allocation helps prevent SNAT port exhaustion, especially in scenarios with high outbound connection volumes12.
Dynamic SNAT Port Allocation: Unlike static allocation methods, NAT Gateway dynamically allocates SNAT ports based on demand, ensuring efficient use of available ports and reducing the risk of exhaustion2.
Step-by-Step SolutionStep 1: Create a NAT GatewayStep 2: Configure Outbound IP AddressesStep 3:
Associate the NAT Gateway with Subnet4-1Step 4: Review and CreateExplanationBy following these steps, you can ensure that your 100 virtual machines in subnet4-1 can make the necessary API calls without running into SNAT port exhaustion, all while minimizing administrative effort.
Subscription1 と Subscription2 という名前の 2 つの Azure サブスクリプションがあります。
2 つのサブスクリプション内の仮想ネットワーク間に接続はありません。
プライベート リンク サービスは、privatelinkservice1 の図に示すように構成します。(privatelinkservice1 タブをクリックします。)

Subscription1 にロード バランサー名を作成し、lb1 の図に示されているバックエンド プールを構成します。
(tie 1b1 タブをクリックします。)

図示の privateendpoint4 のように、Subscription2 にプライベートエンドポイントを作成します。(privateendpoint4 をクリックします)

以下の各文について、正しい場合は「はい」を選択してください。そうでない場合は「いいえ」を選択してください。

2 つのサブスクリプション内の仮想ネットワーク間に接続はありません。
プライベート リンク サービスは、privatelinkservice1 の図に示すように構成します。(privatelinkservice1 タブをクリックします。)

Subscription1 にロード バランサー名を作成し、lb1 の図に示されているバックエンド プールを構成します。
(tie 1b1 タブをクリックします。)

図示の privateendpoint4 のように、Subscription2 にプライベートエンドポイントを作成します。(privateendpoint4 をクリックします)

以下の各文について、正しい場合は「はい」を選択してください。そうでない場合は「いいえ」を選択してください。

Correct Answer:

Explanation:
Yes, Yes, No
注: この質問は、同じシナリオを提示する一連の質問の一部です。一連の質問にはそれぞれ、定められた目標を満たす可能性のある独自の解答が含まれています。質問セットによっては、複数の正解が存在する場合もあれば、正解がない場合もあります。
このセクションの質問に回答した後は、その質問に戻ることはできません。そのため、これらの質問はレビュー画面に表示されません。
VWAN1 という名前の Azure Virtual WAN を含む Azure サブスクリプションがあります。VWAN1 には、Hub1 という名前のハブが含まれています。
Hub! のセキュリティ ステータスは「保護されていない」です。
Hub1 のセキュリティ ステータスが「Secured」とマークされていることを確認する必要があります。
解決策: Azure Firewall を実装します。
これは要件を満たしていますか?
このセクションの質問に回答した後は、その質問に戻ることはできません。そのため、これらの質問はレビュー画面に表示されません。
VWAN1 という名前の Azure Virtual WAN を含む Azure サブスクリプションがあります。VWAN1 には、Hub1 という名前のハブが含まれています。
Hub! のセキュリティ ステータスは「保護されていない」です。
Hub1 のセキュリティ ステータスが「Secured」とマークされていることを確認する必要があります。
解決策: Azure Firewall を実装します。
これは要件を満たしていますか?
Correct Answer: B
Vote an answer
P2S VPN ユーザーのネットワーク セキュリティ要件を満たすように GW1 を構成する必要があります。
GW1 のポイントツーサイト構成設定ではどのトンネル タイプを選択する必要がありますか?
GW1 のポイントツーサイト構成設定ではどのトンネル タイプを選択する必要がありますか?
Correct Answer: E
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
1,000 台の仮想マシンを含む Azure サブスクリプションがあります。
ネットワーク セキュリティ グループ (NSG) フロー ログを収集します。
過去 30 日間に Azure 以外のパブリック IP アドレスとやり取りしたすべての仮想マシンを特定する必要があります。クエリをどのように完了する必要がありますか? 回答するには、回答領域で適切なオプションを選択します。注: 正しい選択ごとに 1 ポイントが加算されます。

ネットワーク セキュリティ グループ (NSG) フロー ログを収集します。
過去 30 日間に Azure 以外のパブリック IP アドレスとやり取りしたすべての仮想マシンを特定する必要があります。クエリをどのように完了する必要がありますか? 回答するには、回答領域で適切なオプションを選択します。注: 正しい選択ごとに 1 ポイントが加算されます。

Correct Answer:

Explanation:

Azureサブスクリプションをお持ちです。このサブスクリプションには、App1とApp2という2つのアプリをホストする2つの仮想マシンスケールセット、PLS1というAzure Private Linkサービス、そしてLB1というAzureロードバランサーが含まれています。
PLS1 は LB1 を使用し、TCP Proxy V2 は無効になっています。PLS1 は App1 へのアクセスのみを提供します。
次のアクションを実行する必要があります。
* App1 と App2 へのアクセスを提供します。
* サポートされるプライベート エンドポイント接続の数を増やします。
App2 へのアクセスを提供するには何を変更する必要がありますか。また、サポートされる接続の数を増やすには何を変更する必要がありますか。回答するには、回答領域で適切なオプションを選択してください。
注意: 正しい選択ごとに 1 ポイントが加算されます。

PLS1 は LB1 を使用し、TCP Proxy V2 は無効になっています。PLS1 は App1 へのアクセスのみを提供します。
次のアクションを実行する必要があります。
* App1 と App2 へのアクセスを提供します。
* サポートされるプライベート エンドポイント接続の数を増やします。
App2 へのアクセスを提供するには何を変更する必要がありますか。また、サポートされる接続の数を増やすには何を変更する必要がありますか。回答するには、回答領域で適切なオプションを選択してください。
注意: 正しい選択ごとに 1 ポイントが加算されます。

Correct Answer:

Explanation:

Windows Server を実行する Server1 という名前のオンプレミス サーバーがあります。
VNet1 という名前の仮想ネットワークを含む Azure サブスクリプションがあります。
Azure ネットワーク アダプターを使用して Server1 を VNet1 に接続する予定です。
アダプターを Server1 にデプロイするのにかかる時間を最小限に抑える必要があります。
最初に何を作成すればよいですか?
VNet1 という名前の仮想ネットワークを含む Azure サブスクリプションがあります。
Azure ネットワーク アダプターを使用して Server1 を VNet1 に接続する予定です。
アダプターを Server1 にデプロイするのにかかる時間を最小限に抑える必要があります。
最初に何を作成すればよいですか?
Correct Answer: C
Vote an answer
RG1というリソースグループとVNet1という仮想ネットワークを含むAzureサブスクリプションがあります。RG1にAzure Firewallをデプロイする必要があります。このソリューションは管理作業を最小限に抑える必要があります。まず何をすべきでしょうか?
Correct Answer: A
Vote an answer
귀하의 Azure 구독에는 다음 표에 표시된 리소스가 포함되어 있습니다.

Poticy1은 다음과 같은 설정을 가지고 있습니다:
* 서비스: Microsoft.Storage
* 허용된 리소스: storage1
Subnet!에는 다음과 같은 설정이 있습니다.
* 이름: 서브넷1
* 서브넷 주소 범위: 10.0.0.0/24
* NAT 게이트웨이: 없음
* 네트워크 보안 그룹: 없음
* 라우팅 테이블: 없음
* 서비스 엔드포인트
* 서비스: Microsoft.Storage
* 서비스 엔드포인트 정책: 정책1
* 서브넷 위임
* 서비스에 서브넷 위임: 없음
Subnet2는 다음과 같은 설정을 가지고 있습니다.
* 이름: 서브넷
* 서브넷 주소 범위: 10.0.1.0/24
* NAT 게이트웨이: 없음
* 네트워크 보안 그룹: 없음
* 라우팅 테이블: 없음
* 서비스 엔드포인트
* 서비스: 0개 선택됨
* 서브넷 위임
* 서비스에 서브넷 위임: 없음
다음 각 문장에 대해, 문장이 사실이면 '예'를 선택하고, 그렇지 않으면 '아니요'를 선택하십시오.
참고: 정답 하나당 1점입니다.


Poticy1은 다음과 같은 설정을 가지고 있습니다:
* 서비스: Microsoft.Storage
* 허용된 리소스: storage1
Subnet!에는 다음과 같은 설정이 있습니다.
* 이름: 서브넷1
* 서브넷 주소 범위: 10.0.0.0/24
* NAT 게이트웨이: 없음
* 네트워크 보안 그룹: 없음
* 라우팅 테이블: 없음
* 서비스 엔드포인트
* 서비스: Microsoft.Storage
* 서비스 엔드포인트 정책: 정책1
* 서브넷 위임
* 서비스에 서브넷 위임: 없음
Subnet2는 다음과 같은 설정을 가지고 있습니다.
* 이름: 서브넷
* 서브넷 주소 범위: 10.0.1.0/24
* NAT 게이트웨이: 없음
* 네트워크 보안 그룹: 없음
* 라우팅 테이블: 없음
* 서비스 엔드포인트
* 서비스: 0개 선택됨
* 서브넷 위임
* 서비스에 서브넷 위임: 없음
다음 각 문장에 대해, 문장이 사실이면 '예'를 선택하고, 그렇지 않으면 '아니요'를 선택하십시오.
참고: 정답 하나당 1점입니다.

Correct Answer:

タスク4
10.1.1.0/24 の範囲の IP アドレスと storage34280945.pnvatelinlcblob.core.windows.net という名前を使用して、storage34280945 ストレージ アカウントへの接続が可能であることを確認する必要があります。
10.1.1.0/24 の範囲の IP アドレスと storage34280945.pnvatelinlcblob.core.windows.net という名前を使用して、storage34280945 ストレージ アカウントへの接続が可能であることを確認する必要があります。
Correct Answer:
See the Explanation below for step by step instructions.
Explanation:
Here are the steps and explanations for ensuring that connections to the storage34280945 storage account can be made by using an IP address in the 10.1.1.0/24 range and the name stor-age34280945.pnvatelinlcblob.core.
windows.net:
To allow access from a specific IP address range, you need to configure the Azure Storage firewall and virtual network settings for your storage account. You can do this in the Azure portal by selecting your storage account and then selecting Networking under Settings1.
On the Networking page, select Firewalls and virtual networks, and then select Selected networks under Allow access from1. This will block all access to your storage account except from the networks or resources that you specify.
Under Firewall, select Add rule, and then enter 10.1.1.0/24 as the IP address or range. You can also enter an optional rule name and description1. This will allow access from any IP address in the 10.1.1.0/24 range.
Select Save to apply your changes1.
To map a custom domain name to your storage account, you need to create a CNAME record with your domain provider that points to your storage account endpoint2. A CNAME record is a type of DNS record that maps a source domain name to a destination domain name.
Sign in to your domain registrar's website, and then go to the page for managing DNS settings2.
Create a CNAME record with the following information2:
Source domain name: stor-age34280945.pnvatelinlcblob.core.windows.net
Destination domain name: stor-age34280945.pnvatelinlcblob.core.windows.net Save your changes and wait for the DNS propagation to take effect2.
To register the custom domain name with Azure, you need to go back to the Azure portal and select your storage account. Then select Custom domain under Blob service2.
On the Custom domain page, enter stor-age34280945.pnvatelinlcblob.core.windows.net as the custom domain name and select Save2.
Explanation:
Here are the steps and explanations for ensuring that connections to the storage34280945 storage account can be made by using an IP address in the 10.1.1.0/24 range and the name stor-age34280945.pnvatelinlcblob.core.
windows.net:
To allow access from a specific IP address range, you need to configure the Azure Storage firewall and virtual network settings for your storage account. You can do this in the Azure portal by selecting your storage account and then selecting Networking under Settings1.
On the Networking page, select Firewalls and virtual networks, and then select Selected networks under Allow access from1. This will block all access to your storage account except from the networks or resources that you specify.
Under Firewall, select Add rule, and then enter 10.1.1.0/24 as the IP address or range. You can also enter an optional rule name and description1. This will allow access from any IP address in the 10.1.1.0/24 range.
Select Save to apply your changes1.
To map a custom domain name to your storage account, you need to create a CNAME record with your domain provider that points to your storage account endpoint2. A CNAME record is a type of DNS record that maps a source domain name to a destination domain name.
Sign in to your domain registrar's website, and then go to the page for managing DNS settings2.
Create a CNAME record with the following information2:
Source domain name: stor-age34280945.pnvatelinlcblob.core.windows.net
Destination domain name: stor-age34280945.pnvatelinlcblob.core.windows.net Save your changes and wait for the DNS propagation to take effect2.
To register the custom domain name with Azure, you need to go back to the Azure portal and select your storage account. Then select Custom domain under Blob service2.
On the Custom domain page, enter stor-age34280945.pnvatelinlcblob.core.windows.net as the custom domain name and select Save2.