AZ-700 exam dumps

AZ-700 practice question 161 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 161

Select 2

You are an Azure network engineer responsible for integrating a third-party network virtual appliance (NVA) with an existing Azure Virtual WAN. The NVA is deployed in a separate virtual network connected to the same Virtual WAN hub. You want all inbound traffic from your on-premises site to be inspected by the NVA before it reaches other Azure resources. Which two actions must you take to ensure traffic flows from the on-premises site through the NVA for inspection?

  1. A

    Create a custom route table in the Virtual WAN hub and associate it with the on-premises site connection, specifying the NVA� private IP address as the next hop.

  2. B

    Enable forced tunneling so that all traffic, including Azure-bound traffic, automatically goes to the NVA� public IP in the Virtual WAN hub.

  3. C

    Enable IP forwarding on the network interface (NIC) of the virtual machine running the NVA.

  4. D

    Create a custom route table in the Virtual WAN hub for the NVA� VNet connection to forward traffic to your on-premises gateway IP address.

Show answer and explanation

Correct answers: A, C

Explanation

To integrate a third-party NVA with Azure Virtual WAN for traffic inspection, you must configure a custom route table in the Virtual WAN hub that associates the on-premises site connection with the NVA� private IP as the next hop, ensuring inbound traffic is routed through the device. Additionally, the NVA� NIC must have IP forwarding enabled to allow transit traffic. For more details, refer to the Microsoft documentation on configuring custom route tables for Azure Virtual WAN and enabling IP forwarding in Azure VMs.

  • A. Correct.

    Option 1 is correct. When using Azure Virtual WAN, you need to create a custom route table in the Virtual WAN hub and associate it with the site connection to your on-premises environment. This table should contain a route pointing to the private IP address of the NVA for traffic you want inspected. This ensures traffic from on-premises is directed to the NVA for inspection.

  • B. Incorrect.

    Option 2 is incorrect. Forced tunneling in Virtual WAN would route all traffic, including Azure-bound traffic, to a public IP or an external site. This is not the recommended approach for directing traffic to a third-party NVA deployed in a VNet. Instead, you specify routes to the NVA� private IP using a custom route table.

  • C. Correct.

    Option 3 is correct. For the NVA to function as a router or firewall, you must enable IP forwarding on its NIC in Azure. Without IP forwarding, the virtual machine will drop any traffic that is not addressed to its own IP addresses rather than forwarding it to another destination.

  • D. Incorrect.

    Option 4 is incorrect. Creating a custom route table associated with the NVA� VNet connection that forwards traffic to your on-premises gateway does not accomplish the goal of routing inbound on-premises traffic through the NVA for inspection. You need to set the next hop to the NVA� IP in the on-premises site� route table to direct traffic correctly.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam