Microsoft AZ-720 Troubleshooting Microsoft Azure Connectivity Online Training
Microsoft AZ-720 Online Training
The questions for AZ-720 were last updated at Nov 23,2024.
- Exam Code: AZ-720
- Exam Name: Troubleshooting Microsoft Azure Connectivity
- Certification Provider: Microsoft
- Latest update: Nov 23,2024
HOTSPOT
A company deploys an Azure Firewall.
The company reports the following log entry:
For each of the following questions, select Yes or No.
DRAG DROP
A customer has an Azure subscription. Microsoft Defender for servers is enabled for the subscription. The customer has not configured network security groups.
The customer configures a resource group named RG1 that contains the following resources:
• A virtual machine named VM1.
• A network interface named NIC1 that is attached to VM1.
The customer grants a user named Admin1 the following permission for RG1:
Microsoft.Security/locations/jitNetworkAccessPolicies/write.
Admin1 reports that the JIT VM access pane in the Azure portal does not show any entries.
When you view the same pane, VM1 appears on the Unsupported tab.
You need to ensure that Admin1 can enable just-in-time (JIT) VM access for VM1. The solution must adhere to the principle of least privilege.
Which three actions should you recommend be performed in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
DRAG DROP
A company has an Azure virtual network (VNet). An administrator creates a subet in the VNet named AzureSastionSubnet. The administrator deploys Azure Bastion to AzureBastionSubnet.
The administrator creates a default network security group named nsg-Bastion. The following error message display when the administrator attempts to assign nsg-Bastion to AzureBastionSubnet:
Network security group nsg-Bastion does not have necessary rules for Azure Bastion Subnet AzureBastionSubnet
You need to resolve the issues with the inbound security rules.
Which port or set of ports should you configure?
A company uses Azure virtual machines (VMs) in multiple regions.
The VMs have the following configuration:
The backend pool of an internal Azure Load Balancer (ILB) named ILB1 contains VM1 and VM2. The ILB uses the Basic SKU and is in a resource group RG2.
Virtual network peering has been configured between VNet1 and VNet2.
Users report that they are unable to connect to resources on VM1 and VM2 by using ILB1 from VM3.
You need to resolve the connectivity issues.
What should you do?
- A . Redeploy VM1 and VM2 into availability zones.
- B . Move ILB1 to RG1.
- C . Redeploy the ILB using the Standard SKU.
- D . Move VM1 and VM2 into RG3.