AZ-700 exam dumps

AZ-700 practice question 112 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 112

Single answer

Your organization has deployed an Azure Virtual Network Gateway configured for Point-to-Site VPN using certificate-based authentication. You need to provide your Windows-based users with a functioning VPN client configuration so they can securely connect to the Azure VNet from their personal devices. Which action should you take to properly generate and distribute the VPN client configuration file?

  1. A

    Use the Azure portal to download the VPN client package from the configured Virtual Network Gateway and distribute the downloaded package to end users.

  2. B

    Export the user's private certificate from each device and embed it into an XML file that you manually create, then share that file with all other users.

  3. C

    Use a PowerShell script to enable Site-to-Site VPN on each user's computer, which automatically writes the necessary VPN configuration into the registry.

  4. D

    Generate a Remote Desktop Protocol (RDP) file that includes the Azure VM IP address and distribute it to all users for direct remote connectivity.

Show answer and explanation

Correct answer: A

Explanation

Azure supports creating a Point-to-Site VPN client package that includes certificates (for certificate-based authentication) and network settings. You can download this client package from the Virtual Network Gateway in the Azure portal or via PowerShell, then distribute the installer to users. This is the recommended method per Microsoft documentation (see the official Azure documentation on configuring Point-to-Site VPN connections).

  • A. Correct.

    Correct. Once your Point-to-Site configuration is established in Azure, you can generate the client configuration directly from the Virtual Network Gateway in the Azure portal. This package (often a self-extracting installer for Windows) includes all necessary settings�such as certificates and routing configuration�ensuring users can install and connect without manual file edits.

  • B. Incorrect.

    Incorrect. Embedding private keys in a manually created file is both insecure and unnecessary. Azure automatically handles certificate inclusion in the client package, ensuring only trusted root certificates are used.

  • C. Incorrect.

    Incorrect. Site-to-Site VPN is a different configuration intended for connecting entire on-premises networks to Azure. It does not generate an individual user VPN client package, and modifying the registry manually is error-prone and not recommended.

  • D. Incorrect.

    Incorrect. RDP files simply provide remote desktop connections to virtual machines; they do not configure VPN connectivity. While you can use RDP over a VPN, the RDP file itself is not a VPN client configuration.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam