AZ-700 exam dumps

AZ-700 practice question 179 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 179

Select 2

A company wants to deploy a network virtual appliance (NVA) for firewall inspection using an Azure Gateway Load Balancer in front of their web servers. They also plan to force outbound traffic through the NVA for additional monitoring. Which two of the following configurations must be implemented to ensure that both inbound and outbound traffic flows pass through the NVA for inspection?

  1. A

    Configure user-defined routes (UDRs) on the web server subnets to forward outbound traffic to the NVA� private IP address using the Virtual Appliance next-hop type

  2. B

    Encapsulate inbound traffic in VXLAN between the Gateway Load Balancer and the web servers by binding VXLAN settings on each web server

  3. C

    Use an HA ports load-balancing rule on the Gateway Load Balancer to forward all TCP and UDP traffic to the NVA

  4. D

    Associate a Static Public IP directly with the NVA� network interface so that inbound traffic bypasses the Gateway Load Balancer

Show answer and explanation

Correct answers: A, C

Explanation

To inspect both inbound and outbound traffic, the Gateway Load Balancer must sit between external clients and the NVA, as well as between the NVA and internal web servers. Azure Gateway Load Balancer uses VXLAN to encapsulate traffic to the NVA, but this is automatically configured on the load balancer side. For outbound traffic, user-defined routes directing traffic to the NVA are needed. HA ports allow the Gateway Load Balancer to forward multiple protocols and ports to the same backend. Refer to Azure documentation on 'Gateway Load Balancer' and 'User-defined routes' for more details.

  • A. Correct.

    Correct. A user-defined route on the workload subnet with the NVA as the next hop is required so that all outbound traffic from the web servers is routed through the NVA. This ensures inspection of outbound flows.

  • B. Incorrect.

    Incorrect. While Azure Gateway Load Balancer uses VXLAN encapsulation for traffic between the Gateway Load Balancer and the NVA, it does not require the web servers themselves to handle or configure VXLAN. The web servers remain unaware of any VXLAN encapsulation.

  • C. Correct.

    Correct. An HA ports rule on the Gateway Load Balancer ensures that traffic from any TCP or UDP port is forwarded to the NVA for inspection. This is essential for comprehensive traffic inspection on multiple ports/protocols.

  • D. Incorrect.

    Incorrect. Associating a Static Public IP directly to the NVA� NIC would bypass the Gateway Load Balancer for inbound traffic, defeating the purpose of having the inspection path go through the Gateway Load Balancer.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam