AZ-700 exam dumps

AZ-700 practice question 180 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 180

Select 2

Your company hosts a multi-tier web application in Azure with a public load balancer accepting external traffic. You need to insert a third-party network virtual appliance (NVA) for deep packet inspection before traffic reaches your backend VMs. You decide to implement Azure Gateway Load Balancer to route traffic through the NVA. Which of the following configuration steps must you perform to ensure the traffic flows through the NVA for inspection?

  1. A

    A. Enable IP forwarding on the NVA� network interface to accept and inspect traffic before forwarding it to the backend

  2. B

    B. Configure the NVA to use a Public IP address for its interface so inbound traffic can pass directly to the NVA

  3. C

    C. Attach the NVA� network interface to the Gateway Load Balancer� backend pool

  4. D

    D. Deploy the Gateway Load Balancer and public load balancer in different regions to isolate inspection traffic from client traffic

Show answer and explanation

Correct answers: A, C

Explanation

When implementing a Gateway Load Balancer for an inline network virtual appliance scenario, you must attach the NVA� NIC to the Gateway Load Balancer's backend pool and enable IP forwarding on the NVA� interface. This setup ensures inbound traffic is routed to the NVA for inspection before reaching the backend resources. See the official Azure documentation at https://learn.microsoft.com/azure/load-balancer/gateway-overview for more configuration details and best practices.

  • A. Correct.

    A. Correct. You must enable IP forwarding (and often set a user-defined route) on the NVA� NIC so it can receive traffic from the Gateway Load Balancer and forward it to the backend.

  • B. Incorrect.

    B. Incorrect. A Gateway Load Balancer uses private IP addressing and does not require the NVA to have a separate Public IP for traffic inspection. The public-facing endpoint remains on the existing load balancer.

  • C. Correct.

    C. Correct. The Gateway Load Balancer will direct traffic to the NVA� NIC by including it in the backend pool, ensuring all inbound packets are intercepted for inspection.

  • D. Incorrect.

    D. Incorrect. You typically deploy the public load balancer and the Gateway Load Balancer in the same region for traffic flow. Placing them in different regions complicates routing and is not a recommended best practice.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam