Free 2023 Microsoft Certified: Azure Support Engineer for Connectivity Specialty AZ-720 dumps are available by ActualTestsQuiz [Q55-Q76]

Share

Free 2023 Microsoft Certified: Azure Support Engineer for Connectivity Specialty AZ-720 dumps are available on Google Drive shared by ActualTestsQuiz

Welcome to download the newest ActualTestsQuiz AZ-720 PDF dumps: https://www.actualtestsquiz.com/AZ-720-test-torrent.html ( 121 Q&As)


Microsoft AZ-720 exam is a challenging certification exam that requires you to have excellent problem-solving skills. You must be able to identify the root cause of a connectivity issue and develop a plan to resolve it. AZ-720 exam also tests your ability to communicate effectively with stakeholders and provide them with regular updates on the status of the issue.

 

NEW QUESTION # 55
You need to resolve the Azure virtual machine (VM) deployment issues.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 56
A company deploys Azure Bastion to connect to their virtual machine (VM) infrastructure.
An engineer attempts to connect to a Windows VM by using Remote Desktop Protocol (RDP). The connection fails.
You need to troubleshoot the issue.
Which two actions should you perform?

  • A. Apply a network security group on the same subnet as Azure Bastion.
  • B. Run the Network Watcher Connection troubleshoot service.
  • C. Monitor traffic with the following PowerShell cmdlet Test-AzNetworkWatcherConnectivity.
  • D. Configure Azure Bastion with static assignment.
  • E. Monitor traffic with the following PowerShell cmdlet New-AzNetworkWatcherFlowLog.

Answer: D,E


NEW QUESTION # 57
A company deploys the Azure Application Gateway Web Application Firewall (WAF) to protect their web applications.
Users in a remote office location report the following issues:
Unable to access part of a web application.
Part of the web application is failing to load.
Parts of the web application has activities that are not performing as expected.
You need to troubleshoot the issue.
Which diagnostic log should you review?

  • A. Azure Activity
  • B. Access
  • C. Performance
  • D. Firewall

Answer: D

Explanation:
To troubleshoot the issue, you should review the Firewall diagnostic log. According to 2, Azure Application Gateway Web Application Firewall (WAF) logs requests that are logged through either detection or prevention mode of an application gateway that is configured with WAF. You can use this log to view and analyze blocked requests and identify false positives or false negatives.


NEW QUESTION # 58
A company uses an Azure VPN gateway with an IP address of 203.0.113.20.
Users report that the VPN connection frequently drops.
You need to determine when each connection failure occurred.
How should you complete the Azure Monitor query?

Answer:

Explanation:


NEW QUESTION # 59
A company manages a solution that uses Azure Functions.
A function returns the following error: Azure Function Runtime is unreachable.
You need to troubleshoot the issue.
What are two possible causes of the issue?

  • A. The storage account application settings were deleted.
  • B. The storage account for the function was deleted.
  • C. The company did not configure a timer trigger.
  • D. The execution quota is full.
  • E. The function key was deleted.

Answer: A,B

Explanation:
Two possible causes of the issue where a function returns the error "Azure Function Runtime is unreachable" are: C. The storage account application settings were deleted. E. The storage account for the function was deleted.
According to Microsoft, this issue occurs when the Functions runtime can't start. The most common reason for this is that the function app has lost access to its storage account. If that account is deleted or if the storage account application settings were deleted, your functions won't work
https://learn.microsoft.com/en-us/azure/azure-functions/functions-recover-storage-account


NEW QUESTION # 60
A company has users in Azure Active Directory (Azure AD). The company enables the users to use Azure AD multi-factor authentication (MFA).
A user named User1 reports they receive the following error while setting up additional security verification settings for MFA:
Sorry! We can't process your request. Your session is invalid or expired. There was an error processing your request because your session is invalid or expired. Please try again.
You need to help the user complete the MFA setup.
What should you do?

  • A. From the Azure AD portal, reset the user's password.
  • B. Instruct the user to enter the correct verification code.
  • C. From the Microsoft 365 Admin portal, clear the Block this user from signing in option for the user.
  • D. Instruct the user to clear their web browser cache.
  • E. Instruct the user to complete the setup process within 10 minutes.

Answer: D

Explanation:
this error can occur when there are issues with cookies or cached data in the web browser. To resolve this issue, you can instruct the user to clear their web browser cache and try again.


NEW QUESTION # 61
A company enables just-in-time (JIT) virtual machine (VM) access in Azure.
An administrator observes a list of VMs on the Unsupported tab of the JIT VM access page in the Microsoft Defender for Cloud portal.
You need to determine why some VMs are not supported for JIT VM access.
What should you conclude?

  • A. The VMs were provisioned by using a classic deployment.
  • B. The administrator does not have permissions to request JIT access to the VMs.
  • C. The administrator is using the Microsoft Defender for Cloud free tier.
  • D. The administrator does not have the SecurityReader role.

Answer: A

Explanation:
JIT VM access is only supported for VMs that are deployed using the Azure Resource Manager (ARM) deployment model. VMs that are provisioned using the classic deployment model are not compatible with JIT VM access and will be displayed under the Unsupported tab of the JIT VM access page in the Microsoft Defender for Cloud portal.


NEW QUESTION # 62
A company uses Azure Site Recovery (ASR) for a VMware environment that includes the following virtual machines (VMs):

The company reports that they are unable to configure all of the servers for replication.
You need to evaluate the servers and server roles to determine which servers can be protected.
Which server can you protect by using ASR?

  • A. VM4
  • B. VM3
  • C. VM1
  • D. VM2

Answer: B


NEW QUESTION # 63
You need to troubleshoot the issues reported by Agent1.
What should you review? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 64
A company uses Azure AD Connect. The company plans to implement self-service password reset (SSPR).
An administrator receives an error that password writeback cloud not be enabled during the Azure AD Connect configuration. The administrator observes the following event log error:
Error getting auth token
You need to resolve the issue.
Solution: Restart the Azure AD Connect service.
Does the solution meet the goal?

  • A. Yes
  • B. No

Answer: B


NEW QUESTION # 65
A company uses an Azure blob container.
The IT department has a service-level agreement (SLA) that requests on average cannot exceed 20 milliseconds.
You need to implement a log analytics query to generate the SLA report.
How should you complete the query?

Answer:

Explanation:


NEW QUESTION # 66
A customer creates an Azure resource group named RG1 in the East US region. RG1 contains the following resources:

The customer performs the following tasks:
Create a private endpoint for sqlsrv1 in subnet2 with the private IP address of 192.168.2.100.
Create a private DNS zone named privatelink.database.windows.net by using a single A record named sqlsvr1 and the IP address 192.168.2.100.
Disable public access by using the public endpoint for sqlsvr1.
The customer reports that connections from VM1 to DB1 are failing. The solution must allow connections from VM1 to DB1 without making platform-level changes.
You need to troubleshoot and resolve the issue.
What should you do?

Answer:

Explanation:


NEW QUESTION # 67
A company uses public Azure DNS zones.
The company reports DNS record creation and name resolution issues.
You need to troubleshoot the issues.
What are the causes of the issues?

Answer:

Explanation:


NEW QUESTION # 68
You need to troubleshoot the CosmosDB1 issues from the on-premises environment. What should you use?

  • A. nslookup command
  • B. route command
  • C. Network Watcher next hop diagnostic tool
  • D. Network Watcher Connection troubleshoot diagnostic tool

Answer: D

Explanation:
This tool helps you troubleshoot network connectivity issues from a virtual machine to a given endpoint. It tests for reachability from the virtual machine to the endpoint and provides information about why a connection fails1. In this case, you can use this tool to troubleshoot the connectivity issues from the on-premises environment to CosmosDB1.


NEW QUESTION # 69
A company creates an Azure resource group named RG1. RG1 has an Azure SQL Database logical server named sqlsvr1 that hosts the following resources:

An administrator grants a user named User1 the Reader RBAC role in RG1. The administrator grants User2 the Contributor role in sqlsvr1.
User1 reports that they can connect to SQLDB1 from the IP address 155.127.95.212. User1 cannot connect to SQLDB2. User2 can connect to both SQLDB1 and SQLDB2 from the IP address 121.19.27.18. Both users can successfully connect to SQLDB1 and SQLDB2 from VM1.
You are helping the administrator troubleshoot the issue. You run the following PowerShell command:
Get-AzSqlServerFirewallRule -ResourceGroupName 'RG1' -ServerName 'sqlsvr1' The following output displays:

You need to identify the cause for the reported issue and resolve User1's issues. The solution must satisfy the principle of least privilege.
What should you do?

Answer:

Explanation:


NEW QUESTION # 70
A company has an Azure point-to-site virtual private network (VPN) that uses certificate-based authentication.
A user reports that the following error message when they try to connect to the VPN by using a VPN client on
a Windows 11 machine:
A certificate could not be found
You need to resolve the issue.
Which three actions should you perform?

  • A. Install a root certificate on the user's device.
  • B. Generate a root certificate.
  • C. Install a client certificate on the VPN gateway.
  • D. Generate a client certificate.
  • E. Install a client certificate on the user's device.
  • F. Enable Azure AD authentication on the gateway
  • G. Configure an Azure Active Directory (Azure AD) tenant.

Answer: B,F,G


NEW QUESTION # 71
A company deploys an ExpressRoute circuit.
You need to verify accepted peering routes from the ExpressRoute circuit.
Which PowerShell cmdlet should you run?

  • A. Get-AzExpressRouteCircuitStats
  • B. Get-AzExpressRouteCircuitPeeringConfig
  • C. Get-AzExpressRouteCircuit
  • D. Get-AzExpressRouteCrossConnectionPeering
  • E. Get-AzExpressRouteCircuitRouteTable

Answer: E

Explanation:
To verify accepted peering routes from the ExpressRoute circuit, you should run the PowerShell cmdlet Get-AzExpressRouteCircuitRouteTable. According to 1, this cmdlet returns a list of routes advertised by an ExpressRoute circuit peering. You can specify which peering type (AzurePrivatePeering, AzurePublicPeering, or MicrosoftPeering) and which route table (AdvertisedPublicPrefixes or AdvertisedPublicPrefixesState) you want to view.


NEW QUESTION # 72
A company migrates an on-premises Windows virtual machine (VM) to Azure. An administrator enables backups for the VM by using the Azure portal.
The company reports that the Azure VM backup job is failing.
You need to troubleshoot the issue.
What should you do?

  • A. Enable replication and create a recovery plan for the backup vault.
  • B. Run chkdsk on the VM.
  • C. Configure the retention range of the current backup policy for the VM.
  • D. Create a new manual backup in Backup center.
  • E. Install the VM guest agent with administrative permissions.

Answer: E

Explanation:
According to Microsoft Azure's troubleshooting documentation, one of the steps to troubleshoot backup failures on Azure virtual machines is to check the Azure VM Guest Agent service health. You should ensure that the Azure VM Guest Agent service is started and up-to-date 1. On a Windows VM, you can navigate to services.msc and ensure that the Windows Azure VM Guest Agent service is up and running. Also, ensure that the latest version is installed 2


NEW QUESTION # 73
A company has users in Azure Active Directory (Azure AD). The company enables the users to use Azure AD
multi-factor authentication (MFA).
A user named User1 reports they receive the following error while setting up additional security verification
settings for MFA:
Sorry! We can't process your request. Your session is invalid or expired. There was an error processing your
request because your session is invalid or expired. Please try again.
You need to help the user complete the MFA setup.
What should you do?

  • A. Instruct the user to enter the correct verification code.
  • B. From the Microsoft 365 Admin portal, clear the Block this user from signing in option for the user.
  • C. Instruct the user to clear their web browser cache.
  • D. Instruct the user to complete the setup process within 10 minutes.
  • E. From the Azure AD portal, reset the user's password.

Answer: E


NEW QUESTION # 74
A company uses Azure Site Recovery (ASR) to replicate and recover Azure virtual machines (VM) between Azure regions.
An administrator receives the following warning from ASR about a VM that uses P10 disks: Data change rate beyond supported limits You add OS Disk Write Bytes/Sec and Data Disk Write Bytes/Sec to the list of metrics for monitoring. You discover that the VM consistently has a data churn of greater than 8 MB/s but less than 10 MB/s.
You need to resolve the issue.
What should you do?

  • A. Uninstall the Volume Shadow Copy Service (VSS) Provider service.
  • B. Create a network service endpoint in a virtual network.
  • C. Upgrade the target storage disk.
  • D. Use AzCopy to upload data to a cache storage account.

Answer: C

Explanation:
Azure Site Recovery has limits on data change rates depending on the type of disk used for replication. If a VM has a data change rate higher than the supported limit for its disk type, it can cause replication issues or errors. To resolve this issue, you can upgrade the target storage disk to a higher tier that supports higher data change rates.


NEW QUESTION # 75
You need to resolve the VM2 routing issue.
What should you do?

  • A. Add a network interface to VM2.
  • B. Modify the IP configuration setting of the Azure network interface resource of VM2.
  • C. Modify the IP configuration setting of the Azure network interface resource of VM1.
  • D. Add a network interface to VM1.

Answer: B

Explanation:
To resolve the VM2 routing issue, you should modify the IP configuration setting of the Azure network interface resource of VM2. This will ensure that VM2 can communicate with other resources in the virtual network.
Troubleshooting connectivity problems between Azure VMs involves several steps such as checking whether NIC is misconfigured, whether network traffic is blocked by NSG or UDR, whether network traffic is blocked by VM firewall, whether VM app or service is listening on the port and whether the problem is caused by SNAT1.
Fabrikam Inc. runs an online reservation service that allows agents to manage online registrations for various hotels, vacation rentals, and customers.
The company has on-premises infrastructure and services that are hosted in Azure. The on-premises infrastructure includes servers that run Active Directory Domain Services (AD DS). Azure services include virtual machines (VMs) that are in one subscription and the following environments: development, testing, and production. Each environment is located in a different virtual network (VNet).
The company has a perimeter network that supports connections to the internet. The perimeter network is also hosted in a separate VNet All of the VNets are connected by using virtual network peering.

The company's subscription contains the following Azure virtual machines (VMs):

The Web Server (IIS) role is installed on VM4 The operating system firewall for each VM allows inbound ping requests.
The company's subscription includes the following network security groups (NSGs):

NSG1, NSG2. NSG3, and NSG5 use the default inbound security rules. NSG4. NSG5. and NSG10 use the default outbound security rules. NSG4 has the following inbound security rule:

NSG10 has the following inbound security rules:

Network Policy Server (NPS) is installed on an on-premises server named SRV2. The NPS extension for Azure AD multi-factor authentication (MFA) is configured on the server as well.
The virtual network peering connections are in the following table.

You provision a virtual network gateway named VNetGW in the perimeter network. The virtual network gateway uses SKU VpnGw1 and the public IP address 16.4.4.4 The virtual network gateway will provide:
* Network routing to customer data centers using site-to-site VPN connections.
* Network routing to Azure for the scheduling agents and sales employees using a point-to-site VPN connection.
The company's site-to-site VPN connections with customers are shown in the following table.

The point-to-site VPN is configured as shown in the following table;

The company's user and group memberships are shown in the following table:

The scheduling agents, warehouse, and sales groups are members of the self-service password reset (SSPR) group named SSPR-group.
Azure AD Connect is installed on an on-premises server named SRV1. In addition;
* The server uses a pass-through authentication agent.
* The SSPR feature is enabled
* The SSPR feature is applied only to a group named SSPR-group
* The scheduling agents' internet connectivity must be blocked when connected to the point-to-site VPN.
* Sales employees must use the default VPN client on MacOS computers to connect to Azure.
* Azure AD Connect must synchronize all user accounts from AD DS to Azure AD.
* Pass-through authentication is required for all users.
* Azure AD multi-factor authentication (MFA) is requited for all users.
* All admin user accounts must be in an organizational unit (OU) named Admins.


NEW QUESTION # 76
......

Tested Material Used To AZ-720: https://www.actualtestsquiz.com/AZ-720-test-torrent.html

Following are some new AZ-720 Real Exam Questions!: https://drive.google.com/open?id=1w8hutNrlWSHcHoVZozT8B7KVFSDnecBJ