Skip to content

Implement and manage virtual networking Questions

Practice questions for Implement and manage virtual networking topic in Microsoft Certified: Azure Administrator Associate. 39 questions covering this domain.

39 questions10 easy20 medium9 hard
Q1
medium

An organization wants to deny general outbound internet traffic from a subnet but still allow outbound access only to Azure Storage. How should the NS...

Q2
hard

A spoke virtual network is configured to use gateway transit through a hub virtual network. What must be true about the spoke virtual network?

Q3
easy

Which Azure service hosts and manages public DNS zones and private DNS zones for name resolution?

Q4
easy

Which default inbound NSG rule denies all inbound traffic that wasn't allowed by a higher-priority rule?

Q5
hard

An administrator needs to determine the route and next hop type that a VM uses to reach a specific destination IP address. Which Azure Network Watcher...

Q6
easy

Which service lets administrators connect to Azure virtual machines by RDP or SSH over TLS through the Azure portal without assigning the VMs public I...

Q7
medium

An administrator wants traffic from a subnet to Azure Storage to stay on the Azure backbone and use the subnet's private identity when reaching the st...

Q8
medium

A storage account must be reachable over a private IP address from a virtual network and from on-premises through VPN or ExpressRoute. Which networkin...

Q9
medium

Two virtual networks in the same region are peered. Which statement about traffic between virtual machines in those networks is correct?

Q10
medium

Which DNS construct lets workloads in a VNet resolve names of Azure private endpoints to their private IPs automatically?

Q11
medium

A user-defined route (UDR) on a subnet has a route 0.0.0.0/0 with next hop type Virtual appliance. What is the effect on traffic from the subnet to th...

Q12
easy

An administrator must connect on-premises to Azure with private peering, dedicated bandwidth, and traffic that bypasses the public internet. Which ser...

Q13
hard

A team's Azure Firewall must block egress from a subnet to all FQDNs except *.contoso.com. Which Azure Firewall capability fits?

Q14
easy

Which Azure service provides Layer 7 load balancing with URL-based routing, WAF, and TLS termination for HTTP(S) workloads?

Q15
easy

Which Azure Load Balancer SKU is required to use availability zones and zone redundancy for a frontend IP?

Q16
medium

An NSG has both subnet-level and NIC-level rules. For inbound traffic, in what order are NSGs evaluated?

Q17
medium

An organization wants outbound internet connectivity for many VMs in a subnet that is scalable, predictable, and uses static SNAT ports without a publ...

Q18
hard

Two VNets in different regions must be connected so VMs can reach each other privately and resources in one VNet can use a hub VPN gateway in the othe...

Q19
medium

A site-to-site VPN must support multiple on-premises tunnels and BGP for dynamic routing. Which Azure VPN gateway SKU category supports BGP?

Q20
easy

Which NSG rule property determines which rule is evaluated first when multiple rules match the same traffic?

Sign in to see all 39 questions

Create a free account to browse all questions — completely free during our launch phase.