-A diagram of the resource in the East US Azure region is shown in the Azure Network Diagram exhibit.There is bidirectional peering between Vnet1 and Vnet2. There is bidirectional peering between Vnet1 and Vnet3. Currently, Vnet2 and Vnet3 cannot communicate directly.Azure Network Diagram -
Requirements -
Business Requirements -
Litware wants to minimize costs whenever possible, as long as all other requirements are met.
Virtual Networking Requirements -
Litware identifies the following virtual networking requirements:
Direct the default route of 0.0.0.0/0 on Vnet2 and Vnet3 to the Boston datacenter over an ExpressRoute circuit.
Ensure that the records in the cloud.litwareinc.com can be resolved from the on-premises locations.
Automatically register the DNS names of Azure virtual machines to the cloud.litwareinc.com zone.
Minimize the size of the subnets allocated to platform-managed services.
Allow traffic from VMScaleSet1 to VMScaleSet2 on the TCP port 443 only.
Hybrid Networking Requirements -
Litware identifies the following hybrid networking requirements:
Users must be able to connect to Vnet1 by using a Point-to-Site (P2S) VPN when working remotely. Connections must be authenticated by Azure AD.
Latency of the traffic between the Boston datacenter and all the virtual networks must be minimized.
The Boston datacenter must connect to the Azure virtual networks by using an ExpressRoute FastPath connection.
Traffic between Vnet2 and Vnet3 must be routed through Vnet1.
PaaS Networking Requirements -
Litware identifies the following networking requirements for platform as a service (PaaS):
The storage1 account must be accessible from all on-premises locations without exposing the public endpoint of storage1.
The storage2 account must be accessible from Vnet2 and Vnet3 without exposing the public endpoint of storage2.
Question
You need to provide access to storage1. The solution must meet the PaaS networking requirements and the business requirements.
What should you include in the solution?相关试题
单选题 You have the Azure environment shown in the exhibit. VM1 is a virtual machine that has an instance-level public IP address (ILPIP). Basic Load Balancer uses a public IP address. VM1 and VM2 are in the backend pool. NAT Gateway uses a public IP address named IP3 that is associated to SubnetA. VNet1 has a virtual network gateway that has a public IP address named IP4. When initiating outbound traffic to the internet from VM1, which public address is used? •
单选题 You have an Azure application gateway for a web app named App1. The application gateway allows end-to-end encryption. You configure the listener for HTTPS by uploading an enterprise-signed certificate. You need to ensure that the application gateway can provide end-to-end encryption for App1. What should you do?
单选题 You have an Azure subscription that contains the resources shown in the following table. You plan to deploy an Azure Virtual Network NAT gateway named Gateway1. The solution must meet the following requirements: • VM1 will access the internet by using its public IP address. • VM2 will access the internet by using its public IP address. • Administrative effort must be minimized. You need to ensure that you can deploy Gateway1 to Vnet1. What is the minimum number of subnets required on Vnet1?
单选题 You have an Azure subscription that contains an ExpressRoute Standard gateway named GW1. You need to upgrade GW1 to support ExpressRoute FastPath. The solution must minimize downtime. Which SKU should you use?
单选题 You have an Azure subscription that contains the following resources: • A virtual network named Vnet1 • Two subnets named subnet1 and AzureFirewallSubnet • A public Azure Firewall named FW1 • A route table named RT1 that is associated to Subnet1 • A rule routing of 0.0.0.0/0 to FW1 in RT1 After deploying 10 servers that run Windows Server to Subnet1, you discover that none of the virtual machines were activated. You need to ensure that the virtual machines can be activated. What should you do?
单选题 You have an Azure application gateway named AppGW1 that balances requests to a Web app named App1. You need to modify the server variables in the response header of App1. What should you configure on AppGW1? •
单选题 Your company has 40 branch offi ces that are linked by using a Software-Defi ned Wide Area Network (SD-WAN). The SD-WAN uses BGP. You have an Azure subscription that contains 20 virtual networks confi gured as a hub and spoke topology. The topology contains a hub virtual Network named Vnet1. The virtual networks connect to the SD-WAN by using a network virtual appliance (NVA) in Vnet1. You need to ensure that BGP route advertisements will propagate between the virtual networks and the SD-WAN. The solution must minimize Administrative effort. What should you implement? 贵公司有40个分支机构,它们通过软件定义的广域网(SD-WAN)进行连接。SD-WAN使用BGP。 您有一个Azure订阅,其中包含20个已配置为轮辐拓扑的虚拟网络。拓扑包含一个集线器虚拟 名为Vnet1的网络。 虚拟网络通过使用Vnet1中的网络虚拟设备(NVA)连接到SD-WAN。 您需要确保BGP路由播发将在虚拟网络和SD-WAN之间传播。解决方案必须最小化行政努力。 您应该执行什么?
单选题 You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains a subnet named Subnet1. You deploy an instance of Azure Application Gateway v2 named AppGw1 to Subnet1. You create a network security group (NSG) named NSG1 and Link NSG1 to Subnet1. You need to ensure that AppGw1 will only load balance traffic that originates from VNet1. The solution must minimize the impact on the Functionality of AppGw1. What should you add to NSG1?