Podcast
Questions and Answers
What should you set for session persistence to enable Sticky Sessions in Azure Load-Balancer?
What should you set for session persistence to enable Sticky Sessions in Azure Load-Balancer?
NSG1 uses only the default rules.
NSG1 uses only the default rules.
True
NSG2 has a custom incoming rule allowing TCP on port 3389.
NSG2 has a custom incoming rule allowing TCP on port 3389.
True
Before creating a load balancing rule for HTTPS traffic between VM1 and VM2, which two additional resources are needed?
Before creating a load balancing rule for HTTPS traffic between VM1 and VM2, which two additional resources are needed?
Signup and view all the answers
What type of public IP address SKU and assignment should you use for an Azure VPN gateway if it must connect to an on-premises database server?
What type of public IP address SKU and assignment should you use for an Azure VPN gateway if it must connect to an on-premises database server?
Signup and view all the answers
VM1 resolves to the IP address 131.107.3.3 in VNET1.
VM1 resolves to the IP address 131.107.3.3 in VNET1.
Signup and view all the answers
Fabrikam.com is a public DNS zone.
Fabrikam.com is a public DNS zone.
Signup and view all the answers
Which SKU should you deploy for an ExpressRoute gateway that supports up to 10 Gbps and FastPath?
Which SKU should you deploy for an ExpressRoute gateway that supports up to 10 Gbps and FastPath?
Signup and view all the answers
What should you deploy to ensure webapp1 can connect to an on-premises SMB share named Share1?
What should you deploy to ensure webapp1 can connect to an on-premises SMB share named Share1?
Signup and view all the answers
What enables a virtual machine to forward traffic with a different source IP address?
What enables a virtual machine to forward traffic with a different source IP address?
Signup and view all the answers
Azure Backup supports backup of 64-bit Windows 10 operating system.
Azure Backup supports backup of 64-bit Windows 10 operating system.
Signup and view all the answers
Azure Backup supports backup of 64-bit Ubuntu Server operating system from Ubuntu 12.04.
Azure Backup supports backup of 64-bit Ubuntu Server operating system from Ubuntu 12.04.
Signup and view all the answers
Azure Backup supports backup of VMs that are shutdown or offline.
Azure Backup supports backup of VMs that are shutdown or offline.
Signup and view all the answers
What should you create for Azure Monitor to send an email when CPU usage exceeds 80 percent for VM1?
What should you create for Azure Monitor to send an email when CPU usage exceeds 80 percent for VM1?
Signup and view all the answers
What should you do first to protect VM3 and VM4 using Recovery Services?
What should you do first to protect VM3 and VM4 using Recovery Services?
Signup and view all the answers
What is a Recovery Services vault?
What is a Recovery Services vault?
Signup and view all the answers
Does creating a metric on Network In and Network Out from Azure Monitor meet the goal of inspecting all network traffic from VM1 to VM2 for a period of three hours?
Does creating a metric on Network In and Network Out from Azure Monitor meet the goal of inspecting all network traffic from VM1 to VM2 for a period of three hours?
Signup and view all the answers
Does creating an inbound security rule that denies all traffic from the 131.107.100.50 source with a priority of 64999 ensure that connections to App1 can be established successfully?
Does creating an inbound security rule that denies all traffic from the 131.107.100.50 source with a priority of 64999 ensure that connections to App1 can be established successfully?
Signup and view all the answers
What should you do first to create the peering between VNet1 and VNet2?
What should you do first to create the peering between VNet1 and VNet2?
Signup and view all the answers
Which DNS names can you use to ping VM2 from VM1 if VNET1 is linked to a private DNS zone named contoso.com?
Which DNS names can you use to ping VM2 from VM1 if VNET1 is linked to a private DNS zone named contoso.com?
Signup and view all the answers
Does setting the Startup type for the IPSec Policy Agent service to Automatic on Computer2 allow you to establish a point-to-site VPN connection to VNet1?
Does setting the Startup type for the IPSec Policy Agent service to Automatic on Computer2 allow you to establish a point-to-site VPN connection to VNet1?
Signup and view all the answers
What should you configure to ensure that visitors are serviced by the same web server for each request in your Azure load balancer setup?
What should you configure to ensure that visitors are serviced by the same web server for each request in your Azure load balancer setup?
Signup and view all the answers
Which public IP addresses can you use to create a public Azure Standard Load Balancer?
Which public IP addresses can you use to create a public Azure Standard Load Balancer?
Signup and view all the answers
What should you configure on the AKS cluster to restrict network traffic between pods?
What should you configure on the AKS cluster to restrict network traffic between pods?
Signup and view all the answers
What are the correct answers for Azure Custom Script Extension? (Select all that apply)
What are the correct answers for Azure Custom Script Extension? (Select all that apply)
Signup and view all the answers
What should you configure to ensure all traffic from VM1 to storage1 travels across the Microsoft backbone network?
What should you configure to ensure all traffic from VM1 to storage1 travels across the Microsoft backbone network?
Signup and view all the answers
Which tunneling protocol should you use for route-based Site-to-Site VPN connections?
Which tunneling protocol should you use for route-based Site-to-Site VPN connections?
Signup and view all the answers
Which subnet will the virtual machine VM1 be connected to after a test failover when VNET2 is specified?
Which subnet will the virtual machine VM1 be connected to after a test failover when VNET2 is specified?
Signup and view all the answers
What should you configure to ensure that visitors are serviced by the same web server for each request?
What should you configure to ensure that visitors are serviced by the same web server for each request?
Signup and view all the answers
What should you use to ensure that NGINX is available on all Azure virtual machines after deployment?
What should you use to ensure that NGINX is available on all Azure virtual machines after deployment?
Signup and view all the answers
Which port should you configure for inbound security rule to allow access to the virtual machines via Bastion1?
Which port should you configure for inbound security rule to allow access to the virtual machines via Bastion1?
Signup and view all the answers
To which virtual networks can you deploy an Azure firewall named AF1?
To which virtual networks can you deploy an Azure firewall named AF1?
Signup and view all the answers
What is the minimum number of connection monitors you should deploy to monitor connectivity between the virtual machines and the on-premises network?
What is the minimum number of connection monitors you should deploy to monitor connectivity between the virtual machines and the on-premises network?
Signup and view all the answers
What should you configure to manage outbound traffic from VNET1 using Firewall1?
What should you configure to manage outbound traffic from VNET1 using Firewall1?
Signup and view all the answers
Which resources can be protected by using Bastion1?
Which resources can be protected by using Bastion1?
Signup and view all the answers
What should you do to prevent VM1 from accessing VM2 on port 3389?
What should you do to prevent VM1 from accessing VM2 on port 3389?
Signup and view all the answers
What is the minimum number of Bastion hosts required for secure RDP connections to the virtual machines?
What is the minimum number of Bastion hosts required for secure RDP connections to the virtual machines?
Signup and view all the answers
What should you use to ensure that NGINX is available on all the virtual machines after they are deployed in a scale set?
What should you use to ensure that NGINX is available on all the virtual machines after they are deployed in a scale set?
Signup and view all the answers
What should you configure for an Azure container instance to set up DNS name label scope reuse?
What should you configure for an Azure container instance to set up DNS name label scope reuse?
Signup and view all the answers
Which setting should you change to ensure that an Azure container instance can use private networking when the option is unavailable?
Which setting should you change to ensure that an Azure container instance can use private networking when the option is unavailable?
Signup and view all the answers
Which virtual machines can you back up by using Azure Backup?
Which virtual machines can you back up by using Azure Backup?
Signup and view all the answers
To which virtual machines can you connect through Bastion1?
To which virtual machines can you connect through Bastion1?
Signup and view all the answers
You have five Azure virtual machines that run Windows Server 2016. What should you configure to ensure that visitors are serviced by the same web server for each request?
You have five Azure virtual machines that run Windows Server 2016. What should you configure to ensure that visitors are serviced by the same web server for each request?
Signup and view all the answers
What should you do first to ensure Bastion1 can support 100 concurrent SSH users minimizing administrative effort?
What should you do first to ensure Bastion1 can support 100 concurrent SSH users minimizing administrative effort?
Signup and view all the answers
What should you configure to ensure that visitors are serviced by the same web server for each request?
What should you configure to ensure that visitors are serviced by the same web server for each request?
Signup and view all the answers
Which IP addresses can you use when deploying an Azure Bastion Basic SKU host named Bastion1?
Which IP addresses can you use when deploying an Azure Bastion Basic SKU host named Bastion1?
Signup and view all the answers
What should you configure to support the same web server for different requests on Azure load balancer LB1?
What should you configure to support the same web server for different requests on Azure load balancer LB1?
Signup and view all the answers
To enable multi-user authorization (MAU) for a Recovery Services vault named Vault1, which resource should you create first?
To enable multi-user authorization (MAU) for a Recovery Services vault named Vault1, which resource should you create first?
Signup and view all the answers
What should you configure to ensure that all traffic from VM1 to storage1 travels across the Microsoft backbone network?
What should you configure to ensure that all traffic from VM1 to storage1 travels across the Microsoft backbone network?
Signup and view all the answers
What should you use to ensure that NGINX is available on all the virtual machines after deployment in a scale set?
What should you use to ensure that NGINX is available on all the virtual machines after deployment in a scale set?
Signup and view all the answers
What should you use to ensure that NGINX is available on all the virtual machines after deployment with an Azure Resource Manager template?
What should you use to ensure that NGINX is available on all the virtual machines after deployment with an Azure Resource Manager template?
Signup and view all the answers
Does creating an inbound security rule allowing any traffic from AzureLoadBalancer source and has a priority of 150 meet the goal for establishing connections to App1 from a specific IP?
Does creating an inbound security rule allowing any traffic from AzureLoadBalancer source and has a priority of 150 meet the goal for establishing connections to App1 from a specific IP?
Signup and view all the answers
What should you do first to enable Desired State Configuration for VM1?
What should you do first to enable Desired State Configuration for VM1?
Signup and view all the answers
Which resources can be protected by Bastion1 in the provided Azure subscription scenario?
Which resources can be protected by Bastion1 in the provided Azure subscription scenario?
Signup and view all the answers
What configuration should be set on the Azure load balancer to ensure that web server visitors are serviced by the same instance for each request?
What configuration should be set on the Azure load balancer to ensure that web server visitors are serviced by the same instance for each request?
Signup and view all the answers
What additional configuration is needed on Azure load balancer LB1 to maintain the same web server servicing for various client requests?
What additional configuration is needed on Azure load balancer LB1 to maintain the same web server servicing for various client requests?
Signup and view all the answers
Which IP address assignment is appropriate for creating a public Azure Standard Load Balancer?
Which IP address assignment is appropriate for creating a public Azure Standard Load Balancer?
Signup and view all the answers
What initial step should be taken to ensure Bastion1 can support a high number of concurrent SSH users?
What initial step should be taken to ensure Bastion1 can support a high number of concurrent SSH users?
Signup and view all the answers
What setting should you use on an Azure load balancer to maintain session persistence based on the client's IP address?
What setting should you use on an Azure load balancer to maintain session persistence based on the client's IP address?
Signup and view all the answers
If you want to ensure NGINX is deployed on multiple Azure virtual machines in a scale set, which command should you use?
If you want to ensure NGINX is deployed on multiple Azure virtual machines in a scale set, which command should you use?
Signup and view all the answers
What are the SKUs available for ExpressRoute virtual network gateways?
What are the SKUs available for ExpressRoute virtual network gateways?
Signup and view all the answers
What should you avoid configuring if you want to ensure an Azure load balancer does not failover to another server?
What should you avoid configuring if you want to ensure an Azure load balancer does not failover to another server?
Signup and view all the answers
In the context of NSG rules, what does a higher priority for a rule imply?
In the context of NSG rules, what does a higher priority for a rule imply?
Signup and view all the answers
Which type of Azure load balancer configuration would you use if you aim to establish a distinct server return for each request without persistence?
Which type of Azure load balancer configuration would you use if you aim to establish a distinct server return for each request without persistence?
Signup and view all the answers
How does the default rule for NSGs impact communication if no explicit block exists?
How does the default rule for NSGs impact communication if no explicit block exists?
Signup and view all the answers
What is the primary purpose of the Azure load balancer when configuring web servers?
What is the primary purpose of the Azure load balancer when configuring web servers?
Signup and view all the answers
To ensure the effective deployment of software across Azure VMs, what infrastructure should be utilized?
To ensure the effective deployment of software across Azure VMs, what infrastructure should be utilized?
Signup and view all the answers
What is the significance of the CIDR notation 10.10.2.0/24 in the context of inbound security rules?
What is the significance of the CIDR notation 10.10.2.0/24 in the context of inbound security rules?
Signup and view all the answers
In what scenario would you enable UDP protocol in Azure load balancer settings?
In what scenario would you enable UDP protocol in Azure load balancer settings?
Signup and view all the answers
What happens if an inbound rule in an NSG is designed to block certain VM communications?
What happens if an inbound rule in an NSG is designed to block certain VM communications?
Signup and view all the answers
What deployment strategy ensures that Azure virtual machines automatically install specific software like NGINX post-launch?
What deployment strategy ensures that Azure virtual machines automatically install specific software like NGINX post-launch?
Signup and view all the answers
What role do security groups (NSGs) play in managing traffic in Azure virtual networks?
What role do security groups (NSGs) play in managing traffic in Azure virtual networks?
Signup and view all the answers
Can ExpressRoute gateways improve site-to-site VPN performance?
Can ExpressRoute gateways improve site-to-site VPN performance?
Signup and view all the answers
What is the importance of understanding network traffic routing for Azure virtual machines?
What is the importance of understanding network traffic routing for Azure virtual machines?
Signup and view all the answers
What does enabling IP forwarding on a network interface allow the virtual machine to do?
What does enabling IP forwarding on a network interface allow the virtual machine to do?
Signup and view all the answers
How does routing need to be configured on a virtual machine for it to use multiple network interfaces effectively?
How does routing need to be configured on a virtual machine for it to use multiple network interfaces effectively?
Signup and view all the answers
What must be applied to Subnet1 and Subnet2 for RT1 to be effective?
What must be applied to Subnet1 and Subnet2 for RT1 to be effective?
Signup and view all the answers
In Azure, what happens if no rules explicitly block communication between two virtual machines on the same subnet?
In Azure, what happens if no rules explicitly block communication between two virtual machines on the same subnet?
Signup and view all the answers
What happens when IP forwarding is not enabled on a network interface?
What happens when IP forwarding is not enabled on a network interface?
Signup and view all the answers
What is the significance of enabling IP forwarding for every network interface attached to a virtual machine?
What is the significance of enabling IP forwarding for every network interface attached to a virtual machine?
Signup and view all the answers
Why is it important to configure routing on VM3 when it has IP forwarding enabled?
Why is it important to configure routing on VM3 when it has IP forwarding enabled?
Signup and view all the answers
What do default network security rules in Azure generally allow regarding communication between virtual machines?
What do default network security rules in Azure generally allow regarding communication between virtual machines?
Signup and view all the answers
What must you configure in Azure to ensure that VNet1 and VNet2 traffic uses the Microsoft backbone network?
What must you configure in Azure to ensure that VNet1 and VNet2 traffic uses the Microsoft backbone network?
Signup and view all the answers
Which configuration allows Azure Bastion to support file uploads and downloads while minimizing address usage?
Which configuration allows Azure Bastion to support file uploads and downloads while minimizing address usage?
Signup and view all the answers
What is required to allow secure remote access to virtual machines in VNet1 through Azure Bastion?
What is required to allow secure remote access to virtual machines in VNet1 through Azure Bastion?
Signup and view all the answers
What is the benefit of using VNet peering among virtual networks in Azure?
What is the benefit of using VNet peering among virtual networks in Azure?
Signup and view all the answers
For connecting various Azure VNets with efficient data flow, which service should you consider aside from VNet peering?
For connecting various Azure VNets with efficient data flow, which service should you consider aside from VNet peering?
Signup and view all the answers
Match the ExpressRoute virtual network gateway SKUs with their supported capabilities:
Match the ExpressRoute virtual network gateway SKUs with their supported capabilities:
Signup and view all the answers
Match the inbound security rule configurations with their effects:
Match the inbound security rule configurations with their effects:
Signup and view all the answers
Match the components of a virtual network with their descriptions:
Match the components of a virtual network with their descriptions:
Signup and view all the answers
Match the following Azure services with their functions:
Match the following Azure services with their functions:
Signup and view all the answers
Match the Azure resources with their primary usages:
Match the Azure resources with their primary usages:
Signup and view all the answers
Match the Azure network configurations with their traffic flow characteristics:
Match the Azure network configurations with their traffic flow characteristics:
Signup and view all the answers
Match the following Azure load balancer configurations with their purposes:
Match the following Azure load balancer configurations with their purposes:
Signup and view all the answers
Match the following components of an Azure virtual network with their descriptions:
Match the following components of an Azure virtual network with their descriptions:
Signup and view all the answers
Match the types of Azure virtual machines with their specifications:
Match the types of Azure virtual machines with their specifications:
Signup and view all the answers
Match the following Azure resources with their main functionality:
Match the following Azure resources with their main functionality:
Signup and view all the answers
Match the Azure monitoring tools with their respective features:
Match the Azure monitoring tools with their respective features:
Signup and view all the answers
Match the following Azure security features with their uses:
Match the following Azure security features with their uses:
Signup and view all the answers
Match the following types of IP addresses used in Azure with their characteristics:
Match the following types of IP addresses used in Azure with their characteristics:
Signup and view all the answers
Match the following Azure concepts with their definitions:
Match the following Azure concepts with their definitions:
Signup and view all the answers
Match the following Azure connectivity options with their descriptions:
Match the following Azure connectivity options with their descriptions:
Signup and view all the answers
Match the following Azure backup types with their characteristics:
Match the following Azure backup types with their characteristics:
Signup and view all the answers
Match the Azure service with its primary functionality:
Match the Azure service with its primary functionality:
Signup and view all the answers
Match the Azure networking concept with its description:
Match the Azure networking concept with its description:
Signup and view all the answers
Match the Azure product with its deployment scenario:
Match the Azure product with its deployment scenario:
Signup and view all the answers
Match the Azure resource with its required settings:
Match the Azure resource with its required settings:
Signup and view all the answers
Match the route configuration with its purpose:
Match the route configuration with its purpose:
Signup and view all the answers
Match the Azure monitoring feature with its functionality:
Match the Azure monitoring feature with its functionality:
Signup and view all the answers
Match the Azure compliance concept with its definition:
Match the Azure compliance concept with its definition:
Signup and view all the answers
Match the Azure solution with its scenario:
Match the Azure solution with its scenario:
Signup and view all the answers
Match the Azure components with their respective functionalities:
Match the Azure components with their respective functionalities:
Signup and view all the answers
Match the Azure virtual machine features with their purposes:
Match the Azure virtual machine features with their purposes:
Signup and view all the answers
Match the Azure DNS records with their types:
Match the Azure DNS records with their types:
Signup and view all the answers
Match the Azure VPN types with their characteristics:
Match the Azure VPN types with their characteristics:
Signup and view all the answers
Match the Azure backup types with their purposes:
Match the Azure backup types with their purposes:
Signup and view all the answers
Match the Azure security features with their functions:
Match the Azure security features with their functions:
Signup and view all the answers
Match the Azure services with their primary use cases:
Match the Azure services with their primary use cases:
Signup and view all the answers
Match the Azure storage types with their attributes:
Match the Azure storage types with their attributes:
Signup and view all the answers
Match the Azure components with their primary function:
Match the Azure components with their primary function:
Signup and view all the answers
Match the Azure services with their appropriate operational tasks:
Match the Azure services with their appropriate operational tasks:
Signup and view all the answers
Match the email notification settings with their functionalities:
Match the email notification settings with their functionalities:
Signup and view all the answers
Match these Azure VM settings with their descriptions:
Match these Azure VM settings with their descriptions:
Signup and view all the answers
Match the Azure infrastructure components with their specific roles:
Match the Azure infrastructure components with their specific roles:
Signup and view all the answers
Match the backup policies with their appropriate functionalities:
Match the backup policies with their appropriate functionalities:
Signup and view all the answers
Match the Azure monitoring strategies with their purposes:
Match the Azure monitoring strategies with their purposes:
Signup and view all the answers
Match the Azure features with their key benefits:
Match the Azure features with their key benefits:
Signup and view all the answers
Study Notes
Azure Load Balancer and Network Configuration
- Load balancing of HTTPS connections requires defining appropriate load balancer rules and configuring backend pools.
- Effective monitoring of network traffic in Azure utilizes Azure Monitor, but merely creating metrics on Network In and Out is insufficient for full inspection.
- For connections to an app running on Azure VMs, ensure security configurations allow traffic through. Denial rules must align with desired access, otherwise, connections will fail.
Azure Virtual WAN and Connectivity
- Establishing connectivity between on-premises sites via Azure Virtual WAN necessitates a series of specific configuration steps in the correct order.
- Peering of virtual networks requires non-overlapping IP address spaces; ensure modifications are made to avoid conflicts.
Azure DNS and Name Resolution
- Private DNS zones enable seamless name resolution for VMs; specific DNS names must be validated based on linked records to successfully ping target VMs.
- When resolving hosts in a private DNS zone, ensure all relevant records are correctly configured to allow communication.
Network Security and Access Control
- Network Security Groups (NSGs) control inbound and outbound traffic. When configuring NSGs, least privilege principles should be applied to allow only necessary traffic.
- Point-to-Site VPN connections necessitate client certificates for successful authentication. Install client certificates to maintain secure connections.
Session Persistence and Sticky Sessions
- Azure Load Balancer can maintain session persistence to ensure that clients are routed to the same server during a session, typically done through Client IP and protocol settings.
- For a consistent user experience, particularly for web applications, utilize session persistence configurations.
Public IP and Standard Load Balancer Compatibility
- Matching SKUs between public IP addresses and Standard Load Balancers is crucial; mixing Basic and Standard SKUs is not permitted in configurations.
Kubernetes Network Policies
- Restricting network traffic between pods in Azure Kubernetes Service (AKS) can be achieved through Calico network policies to enforce desired traffic controls.
Routing and Traffic Management
- Traffic routing through specific appliances or virtual machines in Azure is configurable via defined routing tables, ensuring that inbound traffic is correctly directed.
Remote Connectivity Configurations
- Ensure that Remote Desktop connections to Azure VMs are properly configured with necessary NSGs that permit inbound traffic on relevant ports.### NSG Rules and Virtual Machines
- NSG2 has a custom incoming rule allowing TCP traffic on port 3389 from any source to any destination.
- NSG1 is linked to Subnet1 and NSG2 is associated with VM2's network interface.
Load Balancing in Azure
- A load balancing rule for HTTPS traffic between VM1 and VM2 requires two additional resources:
- A frontend IP address
- A backend pool
- Inbound NAT rules, virtual networks, or health probes are not essential for this specific setup.
VPN Gateway Configuration
- When connecting an Azure VPN gateway for site-to-site VPN, use:
- Basic SKU with dynamic IP assignment is supported for gateways.
- Essential for enabling virtual machines to connect to on-premises resources like a database server.
DNS and Virtual Networks
- Azure virtual networks can leverage Azure Private DNS zones with automatic record creation for linked VMs.
- Cross-VNET communication relies on accurate DNS configurations and peering.
- Custom DNS servers can restrict DNS lookup capabilities if misconfigured.
ExpressRoute Gateway Deployment
- To support up to 10 Gbps traffic with availability zones and FastPath, deploy the ErGw3Az SKU.
- Ensure that the chosen SKU aligns with organizational needs for performance and cost.
Route Tables and IP Forwarding
- IP forwarding allows VMs to receive traffic not destined for their IP addresses, enhancing routing flexibility.
- Route tables can facilitate or restrict connectivity between virtual machines based on defined routes.
Secure SMB Share Access
- To connect an Azure web app to an on-premises SMB share, deploy an Azure Virtual Network Gateway for a Site-to-Site VPN connection.
Automating Application Deployment
- For deploying NGINX across multiple Windows Server VMs in a scale set, utilize the Azure Custom Script Extension.
- Custom scripts facilitate the installation and configuration of applications post-deployment.
Ensuring Traffic across Microsoft Backbone
- Configure a network security group (NSG) for controlling traffic routes between VMs and Azure storage.
VPN Tunneling Protocol
- For route-based Site-to-Site VPN connections, IKEv2 is the recommended protocol, offering enhanced security and connection capabilities.
Azure Site Recovery and Subnet Connections
- In the event of a test failover of a VM, it will link to the specified subnet in the target virtual network, ensuring continuity and network segmentation.### Load Balancing with Azure
- To ensure consistent service from the same web server for each visitor request, configure session persistence to Client IP.
- Configuring a health probe is also necessary to monitor the availability and performance of the web servers behind the load balancer.
Azure Virtual Machine Scale Sets
- Deploy NGINX across virtual machines consistently by utilizing a Desired State Configuration (DSC) extension via Azure Resource Manager templates.
Azure Bastion Configuration
- For Azure Bastion access to virtual machines, configure network security group (NSG) inbound rules allowing port 443 for secure communications.
- Azure Bastion Basic SKU can support users via public IP addresses that fall under specific criteria.
Connection Monitoring
- Minimum connection monitors needed to track connectivity between multiple Azure virtual machines and an on-premises network is two.
DNS Resolution in Azure
- When migrating an on-premises Active Directory to Azure, ensure the domain controller (DC) can resolve AD DS DNS names for member servers.
Strengthening Network Security
- To prevent specific virtual machines from accessing others through remote desktop protocol (RDP), implement an NSG rule denying outbound traffic on port 3389.
Azure Network Management
- For managing outbound traffic from virtual networks using an Azure Firewall, creating a route table is a fundamental first step.
- Azure Bastion can protect specific resources within the same virtual network to facilitate secure access.
Scaling Azure Bastion
- Upgrade to Standard SKU if the goal is to support up to 100 concurrent SSH users with minimal administrative work.
Correct Configuration for Persistent Sessions
- Session persistence can also be achieved by setting it to Client IP alongside ensuring the load balancer protocol aligns with application requirements.
Key Practice Questions
- Understand the function of protocol types such as UDP in the context of Azure load balancers for specific scenarios.
- Familiarize with the rights and responsibilities of Azure subscription resources, including which virtual networks can support specific deployments, like firewalls.
Using Azure Tools
- For establishing Remote Desktop connections, specific sequences must be followed using Azure PowerShell and the Azure Command-Line Interface (CLI) to ensure connections are correctly authorized and secured.
ExpressRoute Virtual Network Gateways
- Several SKUs are available for ExpressRoute virtual network gateways: Standard, HighPerformance, UltraPerformance, ErGw1Az, ErGw2Az, ErGw3Az.
Network Security Groups (NSG)
- NSG1 allows TCP port 1433 from Subnet2 (10.10.2.0/24) to Subnet1 (10.10.1.0/24).
- NSG2 blocks TCP port 1433 from VM2 (10.10.2.5) to VM1 (10.10.1.5).
- NSG1 has a higher priority than NSG2, allowing communication from VM2 to VM1.
- Default rules permit communication unless explicitly blocked by rules in the NSGs.
Virtual Network Configuration
- Subscription1 contains a virtual network named VNet1, including two subnets.
- VM3 has multiple network adapters, with IP forwarding and routing enabled.
- Route table RT1 is applied to Subnet1 and Subnet2, facilitating controlled traffic routing.
Azure Load Balancer
- For consistent visitor servicing by the same web server, configure session persistence to Client IP.
- UDP protocol is not suitable for session persistence requirements.
NGINX Deployment in VM Scale Sets
- Use Azure Resource Manager templates for deploying Windows Server 2019 VMs in a scale set to ensure NGINX is available on all instances.
Azure Bastion Host
- Azure Bastion can protect specific resources, including virtual machines within the same virtual network.
- VMs can utilize Bastion for secure connections without needing public IP addresses.
Peering and Traffic Configuration
- Ensure all traffic between VNets traverses Microsoft’s backbone network by configuring ExpressRoute.
- VNet1 can potentially peer with other virtual networks based on connectivity configurations.
Key Community Insights
- Community voting indicates a strong preference for certain configurations, such as 93% support for a specific answer about VM routing.
Understanding Network Interfaces
- IP forwarding allows a VM network interface to receive traffic not aimed at its assigned IP addresses.
- Each interface needing to forward traffic must have IP forwarding separately enabled for proper functionality.
Azure Networking and Security
-
Network Security Group (NSG): Controls inbound and outbound traffic to Azure resources. Essential for applying the principle of least privilege.
-
Pinging Between VMs: To enable VM1 to ping VM2, appropriate NSG rules must be configured, highlighting the need for tailored network security settings.
-
Routing Tables: Created to manage traffic flow in Azure. Routing in Azure can direct inbound traffic through specific virtual appliances like routers.
-
Load Balancer Configuration: To ensure user requests are consistently served by the same web server, use features like session persistence.
Azure Virtual Machines and Subnets
-
Virtual Network (VNet): A fundamental building block in Azure that allows for the creation of isolated network environments within the Azure cloud.
-
IP Forwarding: Enables a virtual machine to receive and send traffic not meant for its assigned IP addresses. Must be enabled for each network interface that forwards traffic.
-
Virtual Appliances: These can act as routers, affecting routing tables. Proper configuration is crucial for efficient traffic management.
Azure Backup and Monitoring
-
Recovery Services Vault: A cloud storage solution for backing up and managing data across Azure services. Essential for data protection and recovery strategies.
-
Monitor Azure Storage Accounts: Requires configuring alert rules and action groups to effectively track and respond to storage conditions or changes.
General Exam Strategy
-
Focus on understanding Azure concepts and configurations related to virtual networking, security groups, load balancers, and monitoring tools.
-
Practice scenario-based questions to familiarize with predictably configuring Azure resources while adhering to best practices.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.
Description
Prepare for the AZ-104 exam with this quiz focused on load balancing HTTPS connections in Azure. Test your knowledge on configuring resources like virtual machines and load balancers. Enhance your understanding of Azure subscription management and resource distribution.