AZ-700 exam dumps

AZ-700 practice question 47 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 47

Single answer

Your company has multiple Azure subscriptions hosting virtual networks in East US, West US, and Western Europe. They plan to use Azure Virtual Network Manager (AVNM) to unify connectivity across these VNets. After creating the network manager instance, they want to ensure that only specific VNets in these regions can communicate in a mesh pattern. Which step should you implement to achieve secure, region-based connectivity with Azure Virtual Network Manager?

  1. A

    Create a connectivity configuration in the network manager and specify a mesh topology that includes newly created network groups for East US, West US, and Western Europe, then apply the configuration to the appropriate scope.

  2. B

    Set up custom route tables and user-defined routes in each VNet to route traffic to a single virtual network gateway, ignoring the network manager.

  3. C

    Enable ExpressRoute or VPN gateway for each region and rely on BGP to automatically discover and route traffic across all VNets.

  4. D

    Use Azure Firewall in each VNet to control inbound and outbound traffic, skipping the connectivity configuration in Azure Virtual Network Manager.

Show answer and explanation

Correct answer: A

Explanation

Azure Virtual Network Manager allows you to create network groups and apply connectivity configurations�either mesh or hub-and-spoke�to those groups. By configuring each region� VNets as part of specific network groups and associating them with a mesh connectivity configuration, you centralize management and ensure only designated VNets can communicate. For detailed guidance, see the official Microsoft documentation on Azure Virtual Network Manager.

  • A. Correct.

    Option 1: Correct. Defining a connectivity configuration with a mesh topology and grouping VNets by region is the recommended way to unify and secure connectivity using AVNM. Applying the configuration at the scope of the subscriptions ensures that only those specific VNets in each region can communicate with one another.

  • B. Incorrect.

    Option 2: Incorrect. While user-defined routes can direct traffic, managing connectivity solely through custom route tables does not leverage AVNM� group-based management and meshed connectivity features. This approach fails to deliver centralized, region-based connectivity as described in the scenario.

  • C. Incorrect.

    Option 3: Incorrect. ExpressRoute or VPN gateways configured with BGP are typically for hybrid connectivity to on-premises environments. This setup does not utilize AVNM� granular grouping and connectivity policy capabilities for a secured mesh among Azure VNets.

  • D. Incorrect.

    Option 4: Incorrect. Although Azure Firewall can control and protect traffic at the network level, it does not inherently create or manage connectivity among VNets. You still need a defined connectivity configuration, such as the one provided by AVNM, to specify which VNets can communicate.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam