Skip to content

Design and implement core networking infrastructure Questions

Practice questions for Design and implement core networking infrastructure topic in Microsoft Certified: Azure Network Engineer Associate. 56 questions covering this domain.

56 questions14 easy30 medium12 hard
Q1
medium

A hub virtual network contains BGP-capable SD-WAN and security appliances. The network team wants Azure routing to update automatically as those appli...

Q2
easy

What is the recommended Azure service for explicit outbound internet connectivity from a subnet?

Q3
hard

A subnet uses an Azure NAT Gateway for outbound internet access. An engineer then adds a user-defined route for 0.0.0.0/0 that points to a virtual app...

Q4
hard

A virtual machine can't reach a destination, and the engineer needs to know whether a packet is being allowed or denied and which security rule is res...

Q5
easy

A company wants fully managed hybrid DNS resolution between Azure virtual networks and on-premises networks without deploying custom DNS virtual machi...

Q6
medium

An enterprise wants on-premises DNS servers to resolve records in Azure Private DNS zones. Which Azure DNS Private Resolver component should the on-pr...

Q7
medium

A company wants all private virtual machines in a subnet to reach the internet by using a predictable contiguous set of public source IP addresses. Wh...

Q8
medium

A team needs Azure workloads to forward queries for an on-premises DNS namespace to corporate DNS servers. What should they configure in Azure DNS Pri...

Q9
medium

A network engineer needs ongoing end-to-end monitoring between Azure and hybrid endpoints to understand latency and reachability trends. Which Network...

Q10
easy

Which Azure service automatically exchanges routes between BGP-capable network virtual appliances and Azure virtual networks?

Q11
easy

Which Azure Network Watcher diagnostic tool shows the next hop type, next hop IP address, and route table ID for traffic to a destination IP?

Q12
medium

A subscription contains many public IP resources inside one virtual network. The security team wants all of them protected by an auto-tuned DDoS plan ...

Q13
hard

A team tries to place an Azure DNS Private Resolver outbound endpoint in a subnet that already hosts other resources. The deployment fails. What must ...

Q14
medium

An administrator wants to test right now whether a virtual machine can reach an external FQDN and see the result immediately, not over time. Which Net...

Q15
medium

An Azure DNS Private Resolver inbound endpoint is deployed. The team wants on-prem servers to forward only the contoso.internal namespace to it, leavi...

Q16
medium

Which feature must be enabled on a hub VNet peering so that gateway transit lets spokes use the hub's VPN/ER gateway?

Q17
easy

Which type of VNet peering is required to peer two virtual networks in different Azure regions?

Q18
medium

An AVNM security admin rule with action Always Allow is applied to a VNet that also has an NSG denying the same traffic. What is the result?

Q19
hard

A team peers two VNets with overlapping IP ranges resolved through an NVA performing NAT. Which Azure feature is required for the spokes' return traff...

Q20
medium

Which monitoring data captures connection-level allow/deny decisions for traffic crossing a subnet's NSG and is required input for Traffic Analytics?

Sign in to see all 56 questions

Create a free account to browse all questions — completely free during our launch phase.