AZ-700 exam dumps

AZ-700 practice question 230 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 230

Select 2

Your company hosts a custom solution on a set of Azure virtual machines behind a Standard Load Balancer. You want to offer private connectivity to multiple external consumers in separate Azure subscriptions, ensuring that all traffic remains on the Microsoft backbone network. You decide to implement an Azure Private Link service. Which two actions are necessary to successfully configure Azure Private Link for your custom solution?

  1. A

    Create a Private Link service in the same region as the Standard Load Balancer, referencing the front-end IP configuration of the load balancer. Approve each private endpoint connection request from consumers.

  2. B

    Use a Basic Load Balancer for your back-end VMs, as it fully supports Azure Private Link without configuration changes.

  3. C

    Create a private endpoint in the same subnet as the virtual machines, pointing directly to each VM� network interface instead of the load balancer.

  4. D

    Set up a private DNS zone for your Private Link service fully qualified domain name (FQDN) and configure DNS records so external consumers can resolve the private endpoint domain name to the private IP.

Show answer and explanation

Correct answers: A, D

Explanation

To implement Azure Private Link for a custom application behind a Standard Load Balancer, you create a Private Link service that references the Standard Load Balancer in the same region. External consumers then create private endpoints that connect to this Private Link service. DNS resolution must be configured so that traffic destined for the service resolves to private IP addresses. For more details, see Azure� official documentation on �Create a Private Link service using Azure CLI� and �DNS configuration for Private Link�.

  • A. Correct.

    Option 1 is correct. With Azure Private Link service, you must have a Standard Load Balancer in place and then deploy a Private Link service resource in the same region. This Private Link service references the load balancer� front-end IP configuration. When external consumers create their private endpoints, you must approve each connection if the auto-approval setting is not used.

  • B. Incorrect.

    Option 2 is incorrect. Azure Private Link service requires a Standard Load Balancer, not a Basic Load Balancer. Basic Load Balancers do not support Private Link capabilities, so this option would fail to provide the necessary private connectivity.

  • C. Incorrect.

    Option 3 is incorrect. A private endpoint must be created in the consumer network, referencing the Private Link service, not directly mapping to individual VM network interfaces. The endpoint references the service behind the load balancer, ensuring private access over the Microsoft backbone network.

  • D. Correct.

    Option 4 is correct. Proper DNS configuration is critical in any Private Link deployment. You typically create a private DNS zone and configure records for the Private Link service FQDN so that consumers' DNS resolution points to the private IP instead of a public endpoint.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam