AZ-700 exam dumps

AZ-700 practice question 72 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 72

Select 2

You manage a high-traffic web application hosted on Azure Virtual Machines behind an Azure Load Balancer. Your organization has just purchased Azure DDoS Protection Standard to protect against distributed denial-of-service attacks. Which two actions should you take to ensure the DDoS protection is activated and that you can monitor potential DDoS events?

  1. A

    Associate the DDoS plan with the virtual network containing your load balancer and virtual machines.

  2. B

    Enable an 'Enhanced DDoS' feature within Azure Firewall� advanced settings.

  3. C

    Configure Diagnostic Settings for DDoS in Azure Monitor to send mitigation logs to a Log Analytics workspace or storage account.

  4. D

    Switch your public IP addresses to Basic SKU addresses on the load balancer to minimize cost while retaining full DDoS capabilities.

  5. E

    Enable 'Application Gateway DDoS' from a dedicated toggle in the Azure portal.

Show answer and explanation

Correct answers: A, C

Explanation

To activate Azure DDoS Protection Standard, you must associate the purchased DDoS plan with the virtual networks hosting your resources (such as VMs behind a load balancer). You also need to configure Diagnostic Settings in Azure Monitor to route DDoS logs to a preferred logging destination (e.g., Log Analytics) so you can track mitigation actions and attacks. For more details, see the official Azure DDoS Protection documentation at https://learn.microsoft.com/azure/ddos-protection/.

  • A. Correct.

    Correct. For Azure DDoS Protection Standard to safeguard your resources, you must associate the DDoS plan with the appropriate virtual networks. This step enables the DDoS service to actively monitor and mitigate attacks on resources within those VNets.

  • B. Incorrect.

    Incorrect. There is no feature called 'Enhanced DDoS' within Azure Firewall� advanced settings. Configuring Azure Firewall alone does not activate Azure DDoS Protection Standard.

  • C. Correct.

    Correct. To monitor DDoS mitigation activities and threats, you need to enable Diagnostic Settings for DDoS in Azure Monitor. Sending logs to a Log Analytics workspace or a storage account gives you visibility into potential attacks and helps with troubleshooting.

  • D. Incorrect.

    Incorrect. Basic SKU public IP addresses receive default protection from Azure DDoS but do not fully utilize DDoS Protection Standard� capabilities, especially detailed logging and mitigation analytics. Standard SKU public IP addresses are recommended for production workloads.

  • E. Incorrect.

    Incorrect. There is no separate 'Application Gateway DDoS' toggle. When a DDoS plan is associated with the virtual network where Application Gateway (or load balancers) reside, they are automatically protected by the DDoS Standard service. There's no standalone switch for Application Gateway.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam