AZ-720 Exam Questions - Online Test


AZ-720 Premium VCE File

Learn More 100% Pass Guarantee - Dumps Verified - Instant Download
150 Lectures, 20 Hours

certleader.com

we provide Actual Microsoft AZ-720 pdf exam which are the best for clearing AZ-720 test, and to get certified by Microsoft Troubleshooting Microsoft Azure Connectivity. The AZ-720 Questions & Answers covers all the knowledge points of the real AZ-720 exam. Crack your Microsoft AZ-720 Exam with latest dumps, guaranteed!

Check AZ-720 free dumps before getting the full version:

NEW QUESTION 1
A company has an Azure tenant. The company deploys an Azure firewall named FW1 to control access from an on-premises datacenter to an Azure virtual machine named VM1.
The company troubleshoots ICMP connectivity from the on-premises datacenter to VM1. You are unable to ping VM1 from an on-premises server.
You need to determine if ICMP connectivity to VM1 is allow on FW1. What should you do?

  • A. Use the ping command targeting the IP address of VM1 and review the Infrastructure rules log of FW1.
  • B. Use the ping command targeting the IP address of VM1 and review the command's response.
  • C. Use the ping command targeting the IP address of VM1 and review the Network rules log of FW1.
  • D. Use the ping command targeting the fully qualified domain name of VM1 and review the command's response.

Answer: B

NEW QUESTION 2
A company migrates an on-premises Windows virtual machine (VM) to Azure. An administrator enables backups for the VM by using the Azure portal.
The company reports that the Azure VM backup job is failing. You need to troubleshoot the issue.
Solution: Configure the retention range for the current VM backup policy. Does the solution meet the goal?

  • A. Yes
  • B. No

Answer: A

NEW QUESTION 3
A company named Contoso connects its on-premises resources to Azure by using ExpressRoute. An administrator reports that the circuit is in a failed state.
You need to resolve the issue.
How should you complete the PowerShell commands?
AZ-720 dumps exhibit


Solution:
AZ-720 dumps exhibit

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 4
A company uses Azure AD Connect. The company plans to implement self-service password reset (SSPR). An administrator receives an error that password writeback cloud not be enabled during the Azure AD Connect configuration. The administrator observes the following event log error:
Error getting auth token
You need to resolve the issue.
Solution: Disable password writeback and then enable password writeback. Does the solution meet the goal?

  • A. Yes
  • B. No

Answer: B

NEW QUESTION 5
A company uses Azure Active Directory (Azure AD) with Azure role-based access control (RBAC) for access to resources.
Some users report that they are unable to grant RBAC roles to other users. You need to troubleshoot the issue.
How should you complete the Azure Monitor query?
AZ-720 dumps exhibit


Solution:
AZ-720 dumps exhibit

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 6
A company has an Azure Virtual Network gateway named VNetGW1. The company enables point-to-site connectivity on VNetGW1. An administrator configures VNetGW1 for the following:
AZ-720 dumps exhibit OpenVPN for the tunnel type.
AZ-720 dumps exhibit Azure certificate for the authentication type.
Users receive a certificate mismatch error when connecting by using a VPN client. You need to resolve the certificate mismatch error.
What should you do?

  • A. Install an IKEv2 VPN client on the user's computers.
  • B. Reissue the client certificate with client authentication enabled.
  • C. Create a profile manually, add the server FQDN and reissue the client certificate.
  • D. Configure the tunnel type for IKEv2 and OpenVPN on VNetGW1.

Answer: D

NEW QUESTION 7
A company connects their on-premises network by using Azure VPN Gateway. The on-premises environment includes three VPN devices that separately tunnel to the gateway by using Border Gateway Protocol (BGP).
A new subnet should be unreachable from the on-premises network. You need to implement a solution.
Solution: Configure subnet delegation. Does the solution meet the goal?

  • A. Yes
  • B. No

Answer: B

NEW QUESTION 8
A company deploys a new application and places the application behind an Azure Application Gateway Web Application Firewall (WAF).
A user with client IP 203.0.113.26 reports that they cannot access the application. You need to troubleshoot the issue.
How should you complete the query?
AZ-720 dumps exhibit


Solution:
AZ-720 dumps exhibit

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 9
A company has an Azure point-to-site virtual private network (VPN) that uses certificate-based authentication. A user reports that the following error message when they try to connect to the VPN by using a VPN client on
a Windows 11 machine:
A certificate could not be found
You need to resolve the issue.
Which three actions should you perform?

  • A. Configure an Azure Active Directory (Azure AD) tenant.
  • B. Install a root certificate on the user's device.
  • C. Generate a root certificate.
  • D. Install a client certificate on the VPN gateway.
  • E. Enable Azure AD authentication on the gateway
  • F. Generate a client certificate.
  • G. Install a client certificate on the user's device.

Answer: ACE

NEW QUESTION 10
A company uses an Azure Virtual Network (VNet) gateway named VNetGW1. VNetGW1 connects to a partner site by using a site-to-site VPN connection with dynamic routing.
The company observes that the VPN disconnects from time to time. You need to troubleshoot the cause for the disconnections.
What should you verify?

  • A. The partner's VPN device and VNetGW1 are configured using the same shared key.
  • B. The partner's VPN device is configured for one VPN tunnel per subnet pair.
  • C. The public IP address of the partner's VPN device is configured in the local network gateway address space on VNetGW1.
  • D. The partner's VPN device and VNetGW1 are configured with the same virtual network address space.

Answer: A

NEW QUESTION 11
A company has two virtual networks (VNets) that reside in the same Azure region.
An administrator reports that virtual machines (VMs) in each VNet are unable to connect to VMs in the other VNet.
You need to configure a connection between the two networks that maximizes throughput and minimizes latency.
What should you do?

  • A. Configure a VPN gateway.
  • B. Create a site-to-site VPN connection.
  • C. Configure virtual network peering.
  • D. Create a point-to-site VPN connection.

Answer: B

NEW QUESTION 12
A company has an Azure Virtual Network gateway named VNetGW1. The company enables point-to-site connectivity on VNetGW1. An administrator configures VNetGW1 for the following:
AZ-720 dumps exhibit OpenVPN for the tunnel type.
AZ-720 dumps exhibit Azure certificate for the authentication type.
Users receive a certificate mismatch error when connecting by using a VPN client. You need to resolve the certificate mismatch error.
What should you do?

  • A. Configure the tunnel type for IKEv2 and OpenVPN on VNetGW1.
  • B. Create a profile manually, add the server FQDN and reissue the client certificate.
  • C. Install a Secure Socket Tunneling Protocol (SSTP) VPN client on the user's computers.
  • D. Configure preshared key for authentication on the VPN profile.

Answer: B

NEW QUESTION 13
A customer has an Azure Virtual Network named VNet1 that contains an internal standard SKU load balancer named LB1. The backend pool for LB1 includes the following virtual machines: VM1, VM2.
The customer configures a rule named Rul1 to load balance incoming HTTPS requests for VM1 and VM2. Rule1 is associated with an HTTPS health probe. The path for the probe is set to /.
The network adapters of VM1 and VM2 are associated with a network security named NSG1 that contains the following rules:
AZ-720 dumps exhibit
You connect to https://VM1 and https://VM2 from VNet1. Attempts to connect using the front-end IP address of LB1 are failing.
You need to resolve the issue. What should you do?

  • A. Change the health probe associated with Rule1 to use HTTP.
  • B. Add an NSG1 rule with the source set to VirtualNetwork.
  • C. Change the health probe associated with Rule1 to use TCP.
  • D. Add an NSG1 rule with the source set to AzureLoadBalancer.

Answer: A

NEW QUESTION 14
A company migrates an on-premises Windows virtual machine (VM) to Azure. An administrator enables backups for the VM by using the Azure portal.
The company reports that the Azure VM backup job is failing. You need to troubleshoot the issue.
What should you do?

  • A. Create a new manual backup in Backup center.
  • B. Run chkdsk on the VM.
  • C. Configure the retention range of the current backup policy for the VM.
  • D. Install the VM guest agent with administrative permissions.
  • E. Enable replication and create a recovery plan for the backup vault.

Answer: D

NEW QUESTION 15
A company enables just-in-time (JIT) virtual machine (VM) access in Azure.
An administrator observes a list of VMs on the Unsupported tab of the JIT VM access page in the Microsoft Defender for Cloud portal.
You need to determine why some VMs are not supported for JIT VM access. What should you conclude?

  • A. The administrator is using the Microsoft Defender for Cloud free tier.
  • B. The VMs were provisioned by using a classic deployment.
  • C. The administrator does not have the SecurityReader role.
  • D. The administrator does not have permissions to request JIT access to the VMs.

Answer: B

NEW QUESTION 16
A company deploys the Azure Application Gateway Web Application Firewall (WAF) to protect their web applications.
Users in a remote office location report the following issues:
AZ-720 dumps exhibit Unable to access part of a web application.
AZ-720 dumps exhibit Part of the web application is failing to load.
AZ-720 dumps exhibit Parts of the web application has activities that are not performing as expected.
You need to troubleshoot the issue. Which diagnostic log should you review?

  • A. Performance
  • B. Firewall
  • C. Access
  • D. Azure Activity

Answer: D

NEW QUESTION 17
A company has an Azure tenant. The company deploys an Azure Firewall named FW1 using the Standard SKU. You configure FW1 using classic firewall rules.
The company creates an application rule collection with the following settings: Priority: 100
Action: Deny Rule type: FQDN
Source type: IP address Source: *
Protocol: http:80,https:443
Target FQDN: *.cloud.contoso.com
An engineer observes that traffic to console.cloud.conotoso.com is still allowed by FW1. You need to determine why the traffic is allowed.
What should you review?

  • A. Network rules
  • B. Web categories
  • C. Infrastructure rules
  • D. Application rules

Answer: C

NEW QUESTION 18
A company has an ExpressRoute gateway between their on-premises site and Azure. The ExpressRoute gateway is on a virtual network named VNet1. The company enables FastPath on the gateway. You associate a network security group (NSG) with all of the subnets.
Users report issues connecting to VM1 from the on-premises environment. VM1 is on a virtual network named VNet2. Virtual network peering is enabled between VNet1 and VNet2.
You create a flow log named FlowLog1 and enable it on the NSG associated with the gateway subnet. You discover that FlowLog1 is not reporting outbound flow traffic.
You need to resolve the issue with FlowLog1. What should you do?

  • A. Configure FlowLog1 for version 2.
  • B. Create the storage account for FlowLog1 as a premium block blob.
  • C. Configure the FlowTimeoutInMinutes property on VNet2 to a non-null value.
  • D. Enable FlowLog1 in a network security group associated with the network interface of VM1.

Answer: A

NEW QUESTION 19
A company uses an Azure Backup agent to back up specific files and folder from an Azure virtual machine (VM) and an on-premises VM.
An administrator reports that the backup job fails on both VMs. Errors are returned in Microsoft Azure Recovery Services (MARS).
You need to troubleshoot the backup issues. Which troubleshooting solution should you use?
AZ-720 dumps exhibit


Solution:
AZ-720 dumps exhibit

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 20
A company plans to implement ExpressRoute by using the provider connectivity model.
The company creates an ExpressRoute circuit. You are unable to connect to resources through the circuit. You need to determine the provisioning state of the service provider.
Which PowerShell cmdlet should you run?

  • A. Get-AzExpressRouteCircuitPeeringConfig
  • B. Get-AzExpressRouteCircuitRouteTable
  • C. Get-AzExpressRouteCircuitConnectionConfig
  • D. Get-AzExpressRouteCircuit
  • E. Get-AzExpressRouteCircuitARPTable

Answer: C

NEW QUESTION 21
......

P.S. Easily pass AZ-720 Exam with 81 Q&As Surepassexam Dumps & pdf Version, Welcome to Download the Newest Surepassexam AZ-720 Dumps: https://www.surepassexam.com/AZ-720-exam-dumps.html (81 New Questions)