AZ-700 exam dumps

AZ-700 practice question 92 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 92

Single answer

You have configured a site-to-site VPN between your on-premises environment and Azure. To meet strict compliance requirements, you created an IPsec/IKE policy using AES256 for encryption, SHA256 for integrity, and DHGroup14 for perfect forward secrecy. Despite successfully creating this policy, you notice the tunnel is not enforcing these cryptographic settings. Which action must you take to ensure the IPsec/IKE policy applies to the VPN connection in Azure?

  1. A

    Apply the IPsec/IKE policy to the local network gateway on the on-premises side.

  2. B

    Use the �Set-AzVirtualNetworkGateway� command to attach the policy directly to the Azure VPN Gateway.

  3. C

    Attach the IPsec/IKE policy at the time of creating or updating the VPN connection with �New-AzVirtualNetworkGatewayConnection� or �Set-AzVirtualNetworkGatewayConnection�.

  4. D

    Allow Azure to automatically detect and enforce the new cryptographic settings once the policy is created.

Show answer and explanation

Correct answer: C

Explanation

In Azure, an IPsec/IKE policy is enforced at the VPN connection resource level. Even after creating the policy with the desired cryptographic parameters (e.g., AES256, SHA256, DHGroup14), you must explicitly attach the policy to your connection (site-to-site, VNet-to-VNet, or ExpressRoute with IPsec enabled) to have the policy take effect. Refer to Microsoft� documentation on configuring custom IPsec/IKE policies with �New-AzVirtualNetworkGatewayConnection� or �Set-AzVirtualNetworkGatewayConnection� to properly enforce custom cryptographic settings.

  • A. Incorrect.

    Incorrect. The local network gateway represents the on-premises endpoint configuration, but you cannot enforce an Azure IPsec/IKE policy there. The policy must be applied on the Azure side to govern the tunnel settings from Azure� perspective.

  • B. Incorrect.

    Incorrect. While the command �Set-AzVirtualNetworkGateway� configures properties of the gateway, the policy enforcement occurs at the VPN connection resource level rather than the gateway level.

  • C. Correct.

    Correct. Azure IPsec/IKE policies must be associated with the VPN connection resource. You use �New-AzVirtualNetworkGatewayConnection� or �Set-AzVirtualNetworkGatewayConnection� to apply this policy so that the tunnel enforces the specified cryptographic settings.

  • D. Incorrect.

    Incorrect. Azure will not automatically apply the new settings. You must explicitly associate the IPsec/IKE policy with the connection for enforcement.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam