AZ-700 exam dumps

AZ-700 practice question 108 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 108

Single answer

You have deployed an Azure VPN gateway for remote users who connect to your organization� network. You need to configure RADIUS authentication for these Point-to-Site (P2S) VPN connections using a Network Policy Server (NPS) hosted on an Azure virtual machine. Which of the following actions is essential to ensure successful authentication traffic flow from the VPN gateway to the NPS server?

  1. A

    A. Enable the Azure VPN gateway to use TCP port 443 for RADIUS communication

  2. B

    B. Configure the Azure VPN gateway� public IP address as a RADIUS client on the NPS server and open UDP port 1812 on the Network Security Group (NSG)

  3. C

    C. Enable BGP peering between the Azure VPN gateway and the NPS server� subnet

  4. D

    D. Configure Azure Private Link on the Azure VPN gateway to forward RADIUS requests

Show answer and explanation

Correct answer: B

Explanation

To configure RADIUS authentication for Point-to-Site VPN connections, the Azure VPN gateway must send authentication requests to the NPS server. The NPS server must recognize the gateway� IP address as an authorized RADIUS client, and you must ensure the appropriate RADIUS UDP ports (1812 for authentication and optionally 1813 for accounting) are opened in the platform firewall on the VM and in the Network Security Group. For more details, refer to the Microsoft documentation on 'Configure a Point-to-Site VPN connection to an Azure Virtual Network' and 'RADIUS authentication with Azure VPN gateways.'

  • A. Incorrect.

    Option A: Incorrect. RADIUS typically uses UDP ports 1812/1813 (or 1645/1646 in some cases), not TCP 443. Using TCP 443 is most commonly for HTTPS traffic, not RADIUS.

  • B. Correct.

    Option B: Correct. When setting up an NPS server to handle RADIUS requests, you must add the Azure VPN gateway� public IP address as a client in the NPS server configuration and allow inbound UDP port 1812 (and 1813 for accounting if needed) in both the server� firewall and the NSG.

  • C. Incorrect.

    Option C: Incorrect. BGP peering is for routing advertisement rather than RADIUS authentication flows. RADIUS authentication needs the correct ports open, not BGP peering.

  • D. Incorrect.

    Option D: Incorrect. Azure Private Link provides private endpoints for services, but is not used for RADIUS traffic flows to an NPS server. You still need to register the VPN gateway as a RADIUS client and explicitly allow RADIUS ports.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam