AZ-700 exam dumps

AZ-700 practice question 70 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 70

Single answer

You manage a multi-tier application deployed in Azure. The front-end virtual machine (VM) resides in one subnet, while the back-end database VM is in a different subnet. Users report intermittent connectivity problems when the front-end VM tries to communicate with the database VM. You suspect a combination of Network Security Group (NSG) rules and routing issues. Which action in Azure Monitor Network Insights best helps you troubleshoot and isolate the root cause of these connection failures?

  1. A

    Use the Connectivity Check feature within Azure Monitor Network Insights to test communication paths and identify any NSG or route blockages.

  2. B

    Enable Just-in-Time (JIT) VM Access in Azure Security Center to investigate if the VMs have proper network access rules.

  3. C

    Deploy an Azure Load Balancer in front of both VMs to automatically resolve any connectivity issues for inbound and outbound traffic.

  4. D

    Lower the NSG priority for all inbound traffic rules to ensure there are no blocks and then monitor traffic using Network Insights.

Show answer and explanation

Correct answer: A

Explanation

Connectivity Check within Azure Monitor Network Insights is specifically designed to diagnose and troubleshoot connectivity between Azure resources. It synthesizes information from Network Watcher tools to show where packets might be dropped, whether by NSG rules, route tables, or other network constraints. Refer to Microsoft Docs (e.g., https://docs.microsoft.com/azure/azure-monitor/insights/network-insights-overview) for detailed guidance on leveraging Connectivity Check to isolate and resolve network issues in multi-tier architectures.

  • A. Correct.

    Correct. The Connectivity Check feature (part of Azure Monitor Network Insights) runs network-level tests to identify whether network paths have NSG denials, misconfigured routes, or other blocks. This helps confirm if traffic is being dropped by security rules or incorrect routes between the source and destination.

  • B. Incorrect.

    Incorrect. Just-in-Time VM Access helps restrict or open management ports (such as RDP or SSH) for VM administration. It does not directly diagnose or resolve application-level connectivity paths between front-end and back-end VMs.

  • C. Incorrect.

    Incorrect. Deploying an Azure Load Balancer and placing both VMs behind it is not a guaranteed solution to internal subnet communication issues. Load Balancers primarily distribute external or internal front-end traffic, not troubleshoot or fix fundamental NSG or route misconfigurations between existing subnets.

  • D. Incorrect.

    Incorrect. Lowering the NSG priority for all inbound traffic rules is a blanket approach that can compromise security by opening up too many port ranges. It also fails to pinpoint the actual source of intermittent connectivity issues. Azure Monitor Network Insights offers more precise diagnostic data without exposing the VMs to unnecessary risk.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam