2024 Realistic AZ-720 Dumps are Available for Instant Access [Q58-Q81]

Share

2024 Realistic AZ-720 Dumps are Available for Instant Access

Download Exam AZ-720 Practice Test Questions with 100% Verified Answers


The AZ-720 exam is intended for IT professionals with experience in implementing, managing, and monitoring Azure solutions. Candidates are expected to have a deep understanding of Azure networking concepts and be familiar with common connectivity scenarios, such as hybrid cloud environments and multi-region deployments. AZ-720 exam consists of multiple-choice questions and requires candidates to demonstrate their knowledge of Azure connectivity troubleshooting best practices. Passing AZ-720 exam requires a score of at least 700 out of a possible 1000 points. Certification in AZ-720 not only validates one's expertise in Azure connectivity troubleshooting but also helps IT professionals advance their careers by demonstrating their commitment to continuous learning and professional development.


The AZ-720 (Troubleshooting Microsoft Azure Connectivity) exam is an essential certification for IT professionals who work with the Azure platform. It covers a range of topics related to connectivity issues and tests the skills and knowledge of candidates who are responsible for troubleshooting these issues. By earning this certification, IT professionals can demonstrate their expertise in troubleshooting connectivity issues on the Azure platform and help their organizations to maximize the benefits of cloud computing.


The AZ-720 exam focuses on various topics such as troubleshooting Azure virtual network connectivity, identifying and resolving Azure DNS configuration issues, and troubleshooting Azure ExpressRoute connectivity problems. AZ-720 exam also covers other essential topics such as troubleshooting Azure load balancer and Azure Application Gateway issues. Candidates will be required to demonstrate their skills in diagnosing and resolving connectivity issues related to Azure VPN and Azure Site Recovery.

 

NEW QUESTION # 58
You need to troubleshoot the issues with the SharePoint workload in VNet2.
What should you do? To answer, select the appropriate option in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 59
A company uses an Azure Virtual Network (VNet) gateway named VNetGW1. VNetGW1 connects to a
partner site by using a site-to-site VPN connection with dynamic routing.
The company observes that the VPN disconnects from time to time.
You need to troubleshoot the cause for the disconnections.
What should you verify?

  • A. The public IP address of the partner's VPN device is configured in the local network gateway address
    space on VNetGW1.
  • B. The partner's VPN device and VNetGW1 are configured using the same shared key.
  • C. The partner's VPN device is configured for one VPN tunnel per subnet pair.
  • D. The partner's VPN device and VNetGW1 are configured with the same virtual network address space.

Answer: B


NEW QUESTION # 60
A company uses Azure AD Connect. The company plans to implement self-service password reset (SSPR).
An administrator receives an error that password writeback could not be enabled during the Azure AD Connect configuration. The administrator observes the following event log error:
Error getting auth token
You need to resolve the issue.
What should you do?

  • A. Configure Azure AD Connect using a global administrator account that is not federated.
  • B. Disable password writeback and then enable password writeback using the Azure AD Connect configuration.
  • C. Configure Azure AD Connect using a global administrator account with a password that is less than 256 characters.
  • D. Restart the Azure AD Connect service.

Answer: D

Explanation:
The error message "Error getting auth token" occurs when you specify an incorrect password for the global administrator account provided at the beginning of the Azure AD Connect installation process To resolve this issue, you should check that you have specified the correct password for your global administrator account. If you have specified an incorrect password, update it and then restart the Azure AD Connect service


NEW QUESTION # 61
A company is deploying Azure Bastion to provide secure clientless access to its Azure VMs. The company configures a network security group named NSG1.
During deployment, the following error displays: Network security group NSG1 does not have necessary rules for Azure Bastion Subnet AzureBastionSubnet.
You need to fix the inbound rules for NSG1.
How should you complete the configuration?

Answer:

Explanation:


NEW QUESTION # 62
A company deploys the Azure Application Gateway Web Application Firewall (WAF) to protect their web applications.
Users in a remote office location report the following issues:
Unable to access part of a web application.
Part of the web application is failing to load.
Parts of the web application has activities that are not performing as expected.
You need to troubleshoot the issue.
Which diagnostic log should you review?

  • A. Azure Activity
  • B. Performance
  • C. Access
  • D. Firewall

Answer: D

Explanation:
To troubleshoot the issue, you should review the Firewall diagnostic log. According to 2, Azure Application Gateway Web Application Firewall (WAF) logs requests that are logged through either detection or prevention mode of an application gateway that is configured with WAF. You can use this log to view and analyze blocked requests and identify false positives or false negatives.


NEW QUESTION # 63
A company has an Azure tenant. The company deploys an Azure firewall named FW1 to control access from
an on-premises datacenter to an Azure virtual machine named VM1.
The company troubleshoots ICMP connectivity from the on-premises datacenter to VM1. You are unable to
ping VM1 from an on-premises server.
You need to determine if ICMP connectivity to VM1 is allow on FW1.
What should you do?

  • A. Use the ping command targeting the IP address of VM1 and review the Network rules log of FW1.
  • B. Use the ping command targeting the IP address of VM1 and review the command's response.
  • C. Use the ping command targeting the IP address of VM1 and review the Infrastructure rules log of FW1.
  • D. Use the ping command targeting the fully qualified domain name of VM1 and review the command's response.

Answer: B


NEW QUESTION # 64
A company uses Azure AD Connect. The company plans to implement self-service password reset (SSPR).
An administrator receives an error that password writeback cloud not be enabled during the Azure AD Connect configuration. The administrator observes the following event log error:
Error getting auth token
You need to resolve the issue.
Solution: Use a global administrator account that is not federated to configure Azure AD Connect.
Does the solution meet the goal?

  • A. No
  • B. Yes

Answer: B


NEW QUESTION # 65
A company deploys ExpressRoute.
The company reports that there is an autonomous system (AS) number mismatch.
You need to identify the AS number of the circuit.
Which PowerShell cmdlet should you run?

  • A. Get-AzExpressRouteCircuitStats
  • B. Get-AzExpressRouteCircuit
  • C. Get-AzExpressRouteCircuitRouteTable
  • D. Get-AzExpressRouteCircuitPeeringConfig

Answer: A


NEW QUESTION # 66
You need to troubleshoot the sales department issues.
How should you configure the system? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 67
A company migrates an on-premises Windows virtual machine (VM) to Azure. An administrator enables backups for the VM by using the Azure portal.
The company reports that the Azure VM backup job is failing.
You need to troubleshoot the issue.
Solution: Configure the retention range for the current VM backup policy.
Does the solution meet the goal?

  • A. No
  • B. Yes

Answer: A

Explanation:
It is unlikely that configuring the retention range for the current VM backup policy would resolve the issue of the Azure VM backup job failing after enabling backups for the VM through the Azure portal. To troubleshoot the issue, the administrator should first check the Azure VM backup job logs and identify the specific error message or code provided. This can help identify the underlying issue and the appropriate solution.
Therefore, the solution mentioned in the question is incorrect and the answer is B. No.
Reference:
Troubleshoot Azure VM backup failures (Microsoft documentation)


NEW QUESTION # 68
You create an Azure Traffic Manager profile with five endpoints Each endpoint is a web app running in an Azure virtual machine (VM).
You observe that one of the endpoints has a degraded status. You plan to verify whether the endpoint is responding to the Traffic Manager health probe with a valid status code.
You need to identify the PowerShell comdlet to use and the status code that the cmdlet should return.
Which value should you use for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 69
A company uses Azure Firewall. The firewall uses the following rules:

The company requires the following:
* Block outbound connections to Contoso.com on ports 80 and 443. You configure the NetRC2 firewall rule to block the connections. Users report that they can still access Contoso.com on port 80
* Allow outbound connections to Adatuin.com on ports 80 and 443. You configure the AppRC2 firewall rule to allow the connections. Users report that they can access the Adaturn com website by using the IP address but not by using the fully qualified domain name (FQDN).
You need to troubleshoot the rules that are causing the issues.
Which rules should you review? To answer, select the appropriate options in the answer area.

Answer:

Explanation:


NEW QUESTION # 70
A customer creates an Azure resource group named RG1 in the East US region. RG1 contains the following
resources:

The customer performs the following tasks:
* Create a private endpoint for sqlsrv1 in subnet2 with the private IP address of 192.168.2.100.
* Create a private DNS zone named privatelink.database.windows.net by using a single A record named
sqlsvr1 and the IP address 192.168.2.100.
* Disable public access by using the public endpoint for sqlsvr1.
The customer reports that connections from VM1 to DB1 are failing. The solution must allow connections
from VM1 to DB1 without making platform-level changes.
You need to troubleshoot and resolve the issue.
What should you do?

Answer:

Explanation:


NEW QUESTION # 71
You need to resolve the connectivity issue with the on-premises database named CosmosDB1.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 72
A company connects their on-premises network by using Azure VPN Gateway. The on-premises environment includes three VPN devices that separately tunnel to the gateway by using Border Gateway Protocol (BGP).
A new subnet should be unreachable from the on-premises network.
You need to implement a solution.
Solution: Disable peering on the virtual network.
Does the solution meet the goal?

  • A. No
  • B. Yes

Answer: A


NEW QUESTION # 73
A company uses Azure Active Directory (Azure AD) for authentication. The company synchronizes Azure AD with an on-premises Active Directory domain.
The company reports that an Azure AD object fails to sync.
You need to determine which objects are not syncing.
Which troubleshooting steps should you use to diagnose the failure?

Answer:

Explanation:


NEW QUESTION # 74
A company deploys the Azure Application Gateway Web Application Firewall (WAF) to protect their web applications.
Users in a remote office location report the following issues:
Unable to access part of a web application.
Part of the web application is failing to load.
Parts of the web application has activities that are not performing as expected.
You need to troubleshoot the issue.
Which diagnostic log should you review?

  • A. Firewall
  • B. Azure Activity
  • C. Performance
  • D. Access

Answer: B


NEW QUESTION # 75
A customer has an Azure Virtual Network named VNet1 that contains an internal standard SKU load balancer named LB1. The backend pool for LB1 includes the following virtual machines: VM1, VM2.
The customer configures a rule named Rul1 to load balance incoming HTTPS requests for VM1 and VM2. Rule1 is associated with an HTTPS health probe. The path for the probe is set to /.
The network adapters of VM1 and VM2 are associated with a network security named NSG1 that contains the following rules:

You connect to https://VM1 and https://VM2 from VNet1. Attempts to connect using the front-end IP address of LB1 are failing.
You need to resolve the issue.
What should you do?

  • A. Change the health probe associated with Rule1 to use TCP.
  • B. Add an NSG1 rule with the source set to VirtualNetwork.
  • C. Add an NSG1 rule with the source set to AzureLoadBalancer.
  • D. Change the health probe associated with Rule1 to use HTTP.

Answer: D


NEW QUESTION # 76
A company uses Azure Backup Server to back up re deployed in an availability group.
The company reports that a backup operation for a database fails. The following error message displays:
Unable to configure protection.
You need to ensure that the backup operation runs successfully.
What should you do?

  • A. Add the Sysadmin role to the system account on the SQL Server instance.
  • B. Add a partitioned drive to the storage pool on the backup server.
  • C. Configure the availability group replicas to allow read and write operations on the SQL Server instance.
  • D. Run the following command on the backup server: net stop OBEngine

Answer: A

Explanation:
To ensure that the backup operation for a database in an availability group using Azure Backup Server runs successfully, you should add the Sysadmin role to the system account on the SQL Server instance. The system account on the SQL Server instance must have the Sysadmin role to perform backup operations. So the correct answer is B. Add the Sysadmin role to the system account on the SQL Server instance.
You can find more information about Azure Backup Server and its requirements in the official Microsoft documentation.


NEW QUESTION # 77
A company has an Azure Active Directory (Azure AD) tenant. You are assigned the Owner role-based access control (RBAC) role of an Azure resource group named RG1.
An administrator grants a user named User1 the Contributor RBAC role for RG1. User1 receives an authorization error when attempting to create a Cosmos DB account in RG1.
The administrator verifies that they can create a Cosmos DB account in RG1.
You need to troubleshoot the issue.
What should you do?

Answer:

Explanation:


NEW QUESTION # 78
A company develops an Azure Cosmos DB solution.
The solution has the following components:
A virtual network named VNet1 in a resource group named RG1.
A subnet named Subnet1 in VNet1.
A Private Link service.
The company is unable to configure a source IP address for the Private Link service from Subnet1.
You need to resolve the issue for Subnet1.
How should you complete the PowerShell commands?

Answer:

Explanation:


NEW QUESTION # 79
A company deploys a new application and places the application behind an Azure Application Gateway Web Application Firewall (WAF).
A user with client IP 203.0.113.26 reports that they cannot access the application.
You need to troubleshoot the issue.
How should you complete the query?

Answer:

Explanation:


NEW QUESTION # 80
You need to resolve the issue with VM10.
What should you do?

  • A. In the NSG10 inbound security rule that has a priority of 100, change the destination to ASG10
  • B. Add an outbound security rule to NSG1 that allows outbound traffic from ASG1 to ASG10. Configure the rule to use a priority of 100.
  • C. In NSG10, remove the inbound security rule that has a priority of 100.
  • D. In the NSG10 inbound security rule that has a priority of 100, change the protocol to Any

Answer: C

Explanation:
To resolve the issue with VM10, you need to remove the inbound security rule that has a priority of 100 in NSG10, which is blocking ICMP traffic from ASG1 to ASG10. The rule has a source of Any, a destination of VirtualNetwork, a protocol of ICMP, and an action of Deny. This means that any ICMP traffic from outside the VNet4 address space will be denied by NSG10, which is attached to subnet4. This prevents VM1 from pinging VM10 by using ICMP, as VM1 is in VNet1 and not in VNet4. By removing this rule, you can allow ICMP traffic from ASG1 to ASG10, as there is no other rule in NSG10 that explicitly denies it. Alternatively, you could also modify the rule to change the source to VirtualNetwork or the action to Allow, but removing the rule is simpler and more effective.


NEW QUESTION # 81
......

Positive Aspects of Valid Dumps AZ-720 Exam Dumps! : https://examkiller.itexamreview.com/AZ-720-valid-exam-braindumps.html