AZ-700 exam dumps

AZ-700 practice question 111 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 111

Single answer

Your organization recently set up an Azure VPN Gateway with a certificate-based point-to-site (P2S) configuration to allow remote users to securely connect to a virtual network. You have already created a root certificate, uploaded the public key to Azure, and configured the address pool for the VPN gateway. You now want to provide a VPN client installation package to multiple Windows users so they can easily configure and connect to the VPN. Which action should you perform in the Azure portal to generate the VPN client configuration file?

  1. A

    Create a self-signed certificate in Azure Key Vault, then navigate to Key Vault > Certificates > Download to retrieve the client package.

  2. B

    Under the point-to-site configuration for the Virtual Network Gateway, specify the root certificate, configure the address pool, and select �Download VPN Client�.

  3. C

    Use the Azure CLI command az network vpn-gateway create-client-config, which downloads the VPN client settings directly.

  4. D

    In Azure Active Directory, select �Enterprise applications� and download the P2S VPN client from the configured application.

Show answer and explanation

Correct answer: B

Explanation

To implement a VPN client configuration file for a point-to-site VPN in Azure, you must first configure the P2S settings in the Azure Virtual Network Gateway, including the root certificate and VPN address pool. Once configured, select �Download VPN Client� under the point-to-site configuration section of the VPN Gateway blade in the Azure portal. This will generate a client installer package that you can distribute to user devices. For more information, refer to Microsoft� official documentation: https://learn.microsoft.com/azure/vpn-gateway/vpn-gateway-howto-point-to-site-resource-manager-portal

  • A. Incorrect.

    Incorrect. While you can store certificates in Azure Key Vault, there is no direct option to generate or download a VPN client package from Key Vault.

  • B. Correct.

    Correct. From the Azure portal, within the point-to-site configuration section of your Virtual Network Gateway, you can specify the necessary certificates and address pool settings, then select �Download VPN Client� to generate the package.

  • C. Incorrect.

    Incorrect. Although Azure CLI can be used to manage many aspects of Azure resources, the dedicated VPN client configuration package is downloaded directly from the Azure portal under the P2S configuration, not via a generic VPN gateway creation command.

  • D. Incorrect.

    Incorrect. Azure Active Directory is not where you generate or download the P2S VPN client package. AAD can be used for VPN authentication in some scenarios, but the actual package must come from the VPN Gateway� point-to-site configuration page.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam