The Up To The Immediate Present Guide To AZ-720 Simulations

we provide Virtual Microsoft AZ-720 free draindumps which are the best for clearing AZ-720 test, and to get certified by Microsoft Troubleshooting Microsoft Azure Connectivity. The AZ-720 Questions & Answers covers all the knowledge points of the real AZ-720 exam. Crack your Microsoft AZ-720 Exam with latest dumps, guaranteed!

Check AZ-720 free dumps before getting the full version:

NEW QUESTION 1
A company deploys a new application and places the application behind an Azure Application Gateway Web Application Firewall (WAF).
A user with client IP 203.0.113.26 reports that they cannot access the application. You need to troubleshoot the issue.
How should you complete the query?
AZ-720 dumps exhibit


Solution:
AZ-720 dumps exhibit

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 2
A company enables just-in-time (JIT) virtual machine (VM) access in Azure.
An administrator observes a list of VMs on the Unsupported tab of the JIT VM access page in the Microsoft
Defender for Cloud portal.
You need to determine why some VMs are not supported for JIT VM access. What should you conclude?

  • A. The administrator is using the Microsoft Defender for Cloud free tier.
  • B. The VMs were provisioned by using a classic deployment.
  • C. The VMs were recently provisioned by using an Azure Resource Manager deployment.
  • D. The administrator does not have the SecurityReader role.

Answer: B

NEW QUESTION 3
A company has an Azure Virtual Network gateway named VNetGW1. The company enables point-to-site connectivity on VNetGW1. An administrator configures VNetGW1 for the following:
AZ-720 dumps exhibit OpenVPN for the tunnel type.
AZ-720 dumps exhibit Azure certificate for the authentication type.
Users receive a certificate mismatch error when connecting by using a VPN client. You need to resolve the certificate mismatch error.
What should you do?

  • A. Install an IKEv2 VPN client on the user's computers.
  • B. Reissue the client certificate with client authentication enabled.
  • C. Create a profile manually, add the server FQDN and reissue the client certificate.
  • D. Configure the tunnel type for IKEv2 and OpenVPN on VNetGW1.

Answer: D

NEW QUESTION 4
A company has an Azure tenant. The company deploys an Azure firewall named FW1 to control access from an on-premises datacenter to an Azure virtual machine named VM1.
The company troubleshoots ICMP connectivity from the on-premises datacenter to VM1. You are unable to ping VM1 from an on-premises server.
You need to determine if ICMP connectivity to VM1 is allow on FW1. What should you do?

  • A. Use the ping command targeting the IP address of VM1 and review the Infrastructure rules log of FW1.
  • B. Use the ping command targeting the IP address of VM1 and review the command's response.
  • C. Use the ping command targeting the IP address of VM1 and review the Network rules log of FW1.
  • D. Use the ping command targeting the fully qualified domain name of VM1 and review the command's response.

Answer: B

NEW QUESTION 5
A company connects their on-premises network by using Azure VPN Gateway. The on-premises environment includes three VPN devices that separately tunnel to the gateway by using Border Gateway Protocol (BGP).
A new subnet should be unreachable from the on-premises network. You need to implement a solution.
Solution: Disable peering on the virtual network. Does the solution meet the goal?

  • A. Yes
  • B. No

Answer: B

NEW QUESTION 6
A company uses an Azure Virtual Network (VNet) gateway named VNetGW1. VNetGW1 connects to a partner site by using a site-to-site VPN connection with dynamic routing.
The company observes that the VPN disconnects from time to time. You need to troubleshoot the cause for the disconnections.
What should you verify?

  • A. The partner's VPN device and VNetGW1 are configured using the same shared key.
  • B. VNetGW1 has exceeded the subnet Security Association pairs.
  • C. The partner's VPN device and VNetGW1 are configured with the same virtual network address space.
  • D. The public IP address of the partner's VPN device is configured in the local network gateway address space on VNetGW1.

Answer: A

NEW QUESTION 7
A company uses public Azure DNS zones.
The company reports DNS record creation and name resolution issues. You need to troubleshoot the issues.
What are the causes of the issues?
AZ-720 dumps exhibit


Solution:
AZ-720 dumps exhibit

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 8
A customer creates an Azure resource group named RG1 in the East US region. RG1 contains the following resources:
AZ-720 dumps exhibit
The customer performs the following tasks:
AZ-720 dumps exhibit Create a private endpoint for sqlsrv1 in subnet2 with the private IP address of 192.168.2.100.
AZ-720 dumps exhibit Create a private DNS zone named privatelink.database.windows.net by using a single A record named sqlsvr1 and the IP address 192.168.2.100.
AZ-720 dumps exhibit Disable public access by using the public endpoint for sqlsvr1.
The customer reports that connections from VM1 to DB1 are failing. The solution must allow connections from VM1 to DB1 without making platform-level changes.
You need to troubleshoot and resolve the issue.
AZ-720 dumps exhibit


Solution:
AZ-720 dumps exhibit

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 9
A company uses Azure AD Connect. The company plans to implement self-service password reset (SSPR). An administrator receives an error that password writeback cloud not be enabled during the Azure AD Connect configuration. The administrator observes the following event log error:
Error getting auth token
You need to resolve the issue.
Solution: Use a global administrator account that is not federated to configure Azure AD Connect. Does the solution meet the goal?

  • A. Yes
  • B. No

Answer: A

NEW QUESTION 10
A company implements self-service password reset (SSPR).
After a firewall upgrade at the company's datacenter, SSPR stops working. You need to resolve the issue.
Which two URLs must be present on the firewalls to allow SSPR to connect?

  • A. *.update.microsoft.com
  • B. *.servicebus.windows.net
  • C. *.passwordreset.onmicrosoft.com
  • D. *.svc.ms
  • E. *.adl.windows.com

Answer: AE

NEW QUESTION 11
A company uses Azure Site Recovery (ASR) to replicate and recover Azure virtual machines (VM) between Azure regions.
An administrator receives the following warning from ASR about a VM that uses P10 disks: Data change rate beyond supported limits
You add OS Disk Write Bytes/Sec and Data Disk Write Bytes/Sec to the list of metrics for monitoring. You discover that the VM consistently has a data churn of greater than 8 MB/s but less than 10 MB/s.
You need to resolve the issue. What should you do?

  • A. Uninstall the Volume Shadow Copy Service (VSS) Provider service.
  • B. Use AzCopy to upload data to a cache storage account.
  • C. Create a network service endpoint in a virtual network.
  • D. Upgrade the target storage disk.

Answer: D

NEW QUESTION 12
A company has users in Azure Active Directory (Azure AD). The company enables the users to use Azure AD multi-factor authentication (MFA).
A user named User1 reports they receive the following error while setting up additional security verification settings for MFA:
Sorry! We can't process your request. Your session is invalid or expired. There was an error processing your request because your session is invalid or expired. Please try again.
You need to help the user complete the MFA setup. What should you do?

  • A. From the Microsoft 365 Admin portal, clear the Block this user from signing in option for the user.
  • B. Instruct the user to complete the setup process within 10 minutes.
  • C. Instruct the user to enter the correct verification code.
  • D. Instruct the user to clear their web browser cache.
  • E. From the Azure AD portal, reset the user's password.

Answer: E

NEW QUESTION 13
A company has an Azure virtual network (VNet). An administrator creates a subet in the VNet named AzureSastionSubnet. The administrator deploys Azure Bastion to AzureBastionSubnet.
The administrator creates a default network security group named nsg-Bastion. The following error message display when the administrator attempts to assign nsg-Bastion to AzureBastionSubnet:
Network security group nsg-Bastion does not have necessary rules for Azure Bastion Subnet AzureBastionSubnet
You need to resolve the issues with the inbound security rules. Which port or set of ports should you configure?
AZ-720 dumps exhibit


Solution:
AZ-720 dumps exhibit

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 14
A company uses an Azure Virtual Network (VNet) gateway named VNetGW1. VNetGW1 connects to a partner site by using a site-to-site VPN connection with dynamic routing.
The company observes that the VPN disconnects from time to time.
You need to troubleshoot the cause for the disconnections. What should you verify?

  • A. The partner's VPN device and VNetGW1 are configured using the same shared key.
  • B. The IP address of the local network gateway matches the partner's VPN device.
  • C. The partner's VPN device is enabled for Perfect forward secrecy.
  • D. The partner's VPN device and VNetGW1 are configured with the same virtual network address space.

Answer: D

NEW QUESTION 15
A company deploys the Azure Application Gateway Web Application Firewall (WAF) to protect their web applications.
Users in a remote office location report the following issues:
AZ-720 dumps exhibit Unable to access part of a web application.
AZ-720 dumps exhibit Part of the web application is failing to load.
AZ-720 dumps exhibit Parts of the web application has activities that are not performing as expected.
You need to troubleshoot the issue. Which diagnostic log should you review?

  • A. Performance
  • B. Firewall
  • C. Access
  • D. Azure Activity

Answer: D

NEW QUESTION 16
A company uses Azure virtual machines (VMs) in multiple regions. The VMs have the following configuration:
AZ-720 dumps exhibit
The backend pool of an internal Azure Load Balancer (ILB) named ILB1 contains VM1 and VM2. The ILB uses the Basic SKU and is in a resource group RG2.
Virtual network peering has been configured between VNet1 and VNet2.
Users report that they are unable to connect to resources on VM1 and VM2 by using ILB1 from VM3. You need to resolve the connectivity issues.
What should you do?

  • A. Redeploy VM1 and VM2 into availability zones.
  • B. Move ILB1 to RG1.
  • C. Redeploy the ILB using the Standard SKU.
  • D. Move VM1 and VM2 into RG3.

Answer: A

NEW QUESTION 17
A company creates an Azure resource group named RG1. RG1 has an Azure SQL Database logical server named sqlsvr1 that hosts the following resources:
AZ-720 dumps exhibit
An administrator grants a user named User1 the Reader RBAC role in RG1. The administrator grants User2 the Contributor role in sqlsvr1.
User1 reports that they can connect to SQLDB1 from the IP address 155.127.95.212. User1 cannot connect to SQLDB2. User2 can connect to both SQLDB1 and SQLDB2 from the IP address 121.19.27.18. Both users can successfully connect to SQLDB1 and SQLDB2 from VM1.
You are helping the administrator troubleshoot the issue. You run the following PowerShell command: Get-AzSqlServerFirewallRule -ResourceGroupName 'RG1' -ServerName 'sqlsvr1'
The following output displays:
AZ-720 dumps exhibit
You need to identify the cause for the reported issue and resolve User1's issues. The solution must satisfy the principle of least privilege.
What should you do?
AZ-720 dumps exhibit


Solution:
AZ-720 dumps exhibit

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 18
A company hosts a network virtual appliance (VNA) and Azure Route Server in different virtual networks (VNets). Border Gateway Protocol (BGP) peering is enabled between the NVA loses internet connectivity after it advertises the default route to the route server.
You need to resolve the problem with the NVA. What should you do?

  • A. Configure a user-defined route on the NVA subnet.
  • B. Move the route server to the same VNet as the NVA.
  • C. Configure a unique autonomous system number (ASN) on the NVA.
  • D. Configure a public IP address on the route server.

Answer: C

NEW QUESTION 19
......

Recommend!! Get the Full AZ-720 dumps in VCE and PDF From Surepassexam, Welcome to Download: https://www.surepassexam.com/AZ-720-exam-dumps.html (New 81 Q&As Version)