Black Friday Special Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

Note! Following AZ-720 Exam is Retired now. Please select the alternative replacement for your Exam Certification.

AZ-720 Exam Dumps - Troubleshooting Microsoft Azure Connectivity

Question # 4

A company implements Azure Firewall and deploys an Azure Firewall policy.

The policy incudes multiple application and network rules for the company's infrastructure. After deployment, an application is not accessible from on-premises computers.

You need to enable diagnostic logging for the following settings:

  • AzureFirewallApplicationRule
  • AzureFirewallNetworkRule
  • AzureFirewallDnsProxy

How should you complete the PowerShell cmdlet?

Full Access
Question # 5

A company migrates an on-premises Windows virtual machine (VM) to Azure. An administrator enables backups for the VM by using the Azure portal.

The company reports that the Azure VM backup job is failing.

You need to troubleshoot the issue.

What should you do?

A.

Create a new manual backup in Backup center.

B.

Run chkdsk on the VM.

C.

Configure the retention range of the current backup policy for the VM.

D.

Install the VM guest agent with administrative permissions.

E.

Enable replication and create a recovery plan for the backup vault.

Full Access
Question # 6

A company has on-premises application server that runs in System Center Virtual Machine Manager (SCVMM). The company configures Azure Site Recovery.

An administrator at the company reports that they receive an error message. The error message indicates that there are replication issues.

You need to troubleshoot the issue.

Which log should you review?

A.

Network Security Group flow log

B.

Azure Monitor log

C.

Network Watcher diagnostic log

D.

SCVMM debug log

Full Access
Question # 7

A company uses Azure AD Connect. The company plans to implement self-service password reset (SSPR).

An administrator receives an error that password writeback cloud not be enabled during the Azure AD Connect configuration. The administrator observes the following event log error:

Error getting auth token

You need to resolve the issue.

Solution: Restart the Azure AD Connect service.

Does the solution meet the goal?

A.

Yes

B.

No

Full Access
Question # 8

You need to troubleshoot the issue reported by Blue Yonder Airlines.

Which diagnostic log should you review?

A.

RouteDiagnosticLog

B.

GatewayDiagnosticLog

C.

TunnelDiagnosticLog

D.

IKEDiagnosticLog

Full Access
Question # 9

You need to resolve the issue with Admin1.

What should you do?

A.

Configure Azure AD Connect filtering to include the Admins organizational unit.

B.

Reset the Azure AD Connect service account password in AD DS.

C.

Enable security inheritance in Active Directory Domain Services (AD DS).

D.

Start a full import in Azure AD Connect.

Full Access
Question # 10

You need to resolve the issue repotted by Admin2.

What should you do?

A.

Add a rule to N5G2 that allows outbound traffic to the internet over port 80.

B.

Disassociate NSG2 from Subnet12.

C.

Configure a second network interface on VM4.

D.

Disassociate NSG5 from NIC4.

Full Access
Question # 11

A company has an Azure point-to-site virtual private network (VPN) that uses certificate-based authentication.

A user reports that the following error message when they try to connect to the VPN by using a VPN client on a Windows 11 machine:

A certificate could not be found

You need to resolve the issue.

Which three actions should you perform?

A.

Configure an Azure Active Directory (Azure AD) tenant.

B.

Install a root certificate on the user's device.

C.

Generate a root certificate.

D.

Install a client certificate on the VPN gateway.

E.

Enable Azure AD authentication on the gateway

F.

Generate a client certificate.

G.

Install a client certificate on the user's device.

Full Access
Question # 12

You need to resolve the issue with VM10.

What should you do?

A.

In the NSG10 inbound security rule that has a priority of 100, change the destination to ASG10

B.

In NSG10, remove the inbound security rule that has a priority of 100.

C.

In the NSG10 inbound security rule that has a priority of 100, change the protocol to Any

D.

Add an outbound security rule to NSG1 that allows outbound traffic from ASG1 to ASG10. Configure the rule to use a priority of 100.

Full Access
Question # 13

A company enables just-in-time (JIT) virtual machine (VM) access in Azure.

An administrator observes a list of VMs on the Unsupported tab of the JIT VM access page in the Microsoft Defender for Cloud portal.

You need to determine why some VMs are not supported for JIT VM access.

What should you conclude?

A.

The administrator is using the Microsoft Defender for Cloud free tier.

B.

The VMs were provisioned by using a classic deployment.

C.

The administrator does not have the SecurityReader role.

D.

The administrator does not have permissions to request JIT access to the VMs.

Full Access
Question # 14

You need to resolve the issue with internet traffic from VM1 being routed directly to the internet.

What should you do?

A.

Modify IP address prefix of RT12

B.

Associate RT12 with Subnet1a.

C.

Associate RT12 with Subnet2a.

D.

Modify the next hop type of RT12.

Full Access
Question # 15

A company uses a service principal to assign RBAC roles for an application hosted in Azure.

The company attempts to create a rule assignment. The following error displays:Insufficient privileges to complete the operation.

You need to resolve the issue.

How should you complete the CLI command? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 16

A company uses Azure virtual machines (VMs) in multiple regions. The VMs have the following configuration:

The backend pool of an internal Azure Load Balancer (ILB) named ILB1 contains VM1 and VM2. The ILB uses the Basic SKU and is in a resource group RG2.

Virtual network peering has been configured between VNet1 and VNet2.

Users report that they are unable to connect to resources on VM1 and VM2 by using ILB1 from VM3.

You need to resolve the connectivity issues.

What should you do?

A.

Redeploy VM1 and VM2 into availability zones.

B.

Move ILB1 to RG1.

C.

Redeploy the ILB using the Standard SKU.

D.

Move VM1 and VM2 into RG3.

Full Access
Question # 17

A company migrates an on-premises Windows virtual machine (VM) to Azure. An administrator enables backups for the VM by using the Azure portal.

The company reports that the Azure VM backup job is failing.

You need to troubleshoot the issue.

Solution: Enable replication and create a recovery plan for the backup vault.

Does the solution meet the goal?

A.

Yes

B.

No

Full Access
Question # 18

A company uses an Azure Virtual Network (VNet) gateway named VNetGW1. VNetGW1 connects to a partner site by using a site-to-site VPN connection with dynamic routing.

The company observes that the VPN disconnects from time to time.

You need to troubleshoot the cause for the disconnections.

What should you verify?

A.

The partner's VPN device and VNetGW1 are configured using the same shared key.

B.

VNetGW1 has exceeded the subnet Security Association pairs.

C.

The partner's VPN device and VNetGW1 are configured with the same virtual network address space.

D.

The public IP address of the partner's VPN device is configured in the local network gateway address space on VNetGW1.

Full Access
Question # 19

A company has an Azure Active Directory (Azure AD) tenant. The company deploys Azure AD Connect to synchronize users from an Active Directory Domain Services (AD DS).

The synchronization of a user object is failing.

You need to troubleshoot the failing synchronization by using a built-in Azure AD Connect troubleshooting task.

Which two pieces of information should you collect before you start troubleshooting?

A.

Object common name

B.

AD connector name

C.

Object globally unique identifier

D.

Azure AD connector name

E.

Object distinguished name

Full Access
Question # 20

You need to troubleshoot the issues reported by User1.

Which commands should you use? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 21

You need to troubleshoot the issues reported by Agent1.

What should you review? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 22

You need to troubleshoot the issues related to VM3.

How should you complete the web link? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 23

You need to troubleshoot the issue with SRV2.

Which PowerShell cmdlet should you run?

A.

Confirm-MsolDomain

B.

Get-MsolDomamFederationSettings

C.

Get-MsolDomamVerificationDns

D.

Get-MsolServicePrincipalCredential

E.

Get-Mousers

Full Access
Question # 24

You need to resolve the problem reported by User2.

What should you do?

A.

Enable all users for the self-service password reset feature.

B.

Enable the warehouse group for the self-service password reset feature.

C.

Assign an Azure AD Premium Pi license to User2

D.

Identify and resolve the misconfigured directory information for User2.

E.

Instruct User2 to wait 24 hours and try again.

Full Access