AZ-700 exam dumps

AZ-700 practice question 100 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 100

Select 2

Your organization wants to implement a secure point-to-site (P2S) VPN solution in Azure using certificate-based authentication. You have created a self-signed root certificate and used it to sign client certificates for your corporate laptops. Which two of the following steps must you complete to ensure that users can successfully connect to the corporate resources over the P2S VPN?

  1. A

    Upload the public portion of the root certificate to the Azure VPN gateway.

  2. B

    Import the root certificate� private key into the Azure VPN gateway.

  3. C

    Install the client certificate in the user certificate store on each client device that needs to connect.

  4. D

    Manually enable NAT-T on the gateway subnet by editing the local client configuration file.

Show answer and explanation

Correct answers: A, C

Explanation

To successfully configure a point-to-site VPN in Azure using certificate-based authentication, you must upload only the public portion of the root certificate to Azure and install the signed client certificates on each client device. Refer to Microsoft documentation (https://learn.microsoft.com/azure/vpn-gateway/vpn-gateway-howto-point-to-site-classic-azure-cert) for detailed steps on generating, installing, and configuring certificates for point-to-site VPNs.

  • A. Correct.

    Correct. Azure requires the public portion of the root certificate to validate client certificates during the point-to-site connection process. This allows the gateway to verify that the client certificates presented come from a trusted root.

  • B. Incorrect.

    Incorrect. You should never upload or share the private key of the root certificate with Azure. Only the public component of the certificate is required for verification by the Azure VPN gateway.

  • C. Correct.

    Correct. Each client machine that needs to connect via the P2S VPN must have the signed client certificate installed. Typically, this goes into the user or local machine certificate store. Without the client certificate, authentication will fail.

  • D. Incorrect.

    Incorrect. Point-to-site connections automatically handle NAT traversal (NAT-T) for supported VPN protocols, and manually enabling NAT-T on the gateway subnet is not a required step for typical P2S setups.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam