exam questions

Exam AZ-700 All Questions

View all questions & answers for the AZ-700 exam

Exam AZ-700 topic 3 question 11 discussion

Actual exam question from Microsoft's AZ-700
Question #: 11
Topic #: 3
[All AZ-700 Questions]

HOTSPOT -
You have an Azure virtual network named Vnet1 that contains two subnets named Subnet1 and Subnet2.
You have the NAT gateway shown in the NATgateway1 exhibit.

You have the virtual machine shown in the VM1 exhibit.

Subnet1 is configured as shown in the Subnet1 exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: No -
VM1 is in Zone2 whereas the NAT Gateway is in Zone1. The VM would need to be in the same zone as the NAT Gateway to be able to use it. Therefore, VM1 cannot use the NAT gateway.

Box 2: Yes -
NATgateway1 is configured in the settings for Subnet2.

Box 3: No -
The NAT gateway does not have a single public IP address, it has an IP prefix which means more than one IP address. The VMs the use the NAT Gateway can use different public IP addresses contained within the IP prefix.
Reference:
https://docs.microsoft.com/en-us/azure/virtual-network/nat-gateway/nat-gateway-resource

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AdityaGupta
Highly Voted 2 years, 7 months ago
Correct Answer: - YNN 1) NAT gateway can provide outbound connectivity for virtual machines from other availability zones different from itself. The virtual machine’s subnet needs to be configured to the NAT gateway resource to provide outbound connectivity. Additionally, multiple subnets can be configured to the same NAT gateway resource. While virtual machines in subnets from different availability zones can all be configured to a single zonal NAT gateway resource, this configuration doesn't provide the most effective method for ensuring zone-resiliency against zonal outages. 2) Subnet2 is not configured with NatGateway, refer exhibit 1, Nat Gateway is associated with only 1 subet. In exhibit 2 it shows that Subnet 1 is associated with that Nat Gateway. 3) In exhibit 1 it shows that NAT Gateway is configured with Public IP Prefix, and outbound connection can use any Public from that prefix. It is NOT neccessary to use same (one) Public IP.
upvoted 103 times
Sergovladi
3 months, 1 week ago
true if we assume there is a typo (misprint) in the exhibit: you cannot deploy NAT with public IP prefix=1, may be 31 (2 public IPs) instead
upvoted 1 times
...
rac_sp
2 years, 1 month ago
your answers are top !
upvoted 1 times
...
_cloudio_
1 year, 6 months ago
Can VM1 in Subnet1 communicate outbound when no Route Table is configured?
upvoted 1 times
...
...
jellybiscuit
Highly Voted 2 years, 6 months ago
NNN N - The nat gateway *could have been* created to support multiple zones, but it was not. A gateway supporting all zones does not show the zone in the location field. VM1 is located in a different zone and as a result, cannot use Natgateway1. N - Subnet2 is not configured to use Natgateway1. --- The screenshot of vnet1 shows that it is using Natgateway1. --- The screenshot of NATgateway1 shows a Subnet count of 1. --- If Subnet2 was configured to use the gateway, the Subnet count would be at least two. N - The gateway is using a public IP prefix (instead of a single public ip address) so communication will happen over various outbound addresses. I know we hear "tested in the lab" all the time. I actually did. I built two gateways... one in a zone, one without. I built a vnet and two subnets, one configured with the natgateway and one without.
upvoted 8 times
jellybiscuit
2 years, 6 months ago
Changing my answer to YNN - sorry https://learn.microsoft.com/en-us/azure/virtual-network/nat-gateway/nat-availability-zones#zonal I was misreading this documentation - or rather, not reading far enough down. While it says this: "When NAT gateway is deployed to a specific zone, it will provide outbound connectivity to the internet explicitly from that zone. " It also says this: "NAT gateway can provide outbound connectivity for virtual machines from other availability zones different from itself. " Seems to contradict itself.
upvoted 19 times
Bill831231
2 years, 6 months ago
seems there are two types of NAT GW deployment, zonal or regional
upvoted 1 times
...
Goofer
2 years, 3 months ago
https://learn.microsoft.com/en-us/azure/virtual-network/nat-gateway/nat-availability-zones#single-zonal-nat-gateway-resource-for-zone-spanning-resources
upvoted 2 times
...
sapien45
2 years, 6 months ago
No contradiction here. YNN It says that a ZONAL NAT gateway provides internect connectivity FROM a single zone. It does not say TO a single zone. VMs in others zones can use that ZONAL nat gateway. https://azurecomcdn.azureedge.net/mediahandler/acomblog/media/Default/blog/809936d8-a658-465b-9085-f4bbae9b7e33.png YNN
upvoted 5 times
...
...
...
Saba53
Most Recent 2 months, 1 week ago
YNN is correct
upvoted 1 times
...
Murad01
1 year, 4 months ago
Appeared on Exam November - 2023
upvoted 2 times
...
Lazylinux
1 year, 9 months ago
YNN 1- Y - Based on this From MS Zonal: You can place your NAT gateway resource in a specific zone for a region. When NAT gateway is deployed to a specific zone, it will provide outbound connectivity to the internet explicitly from that zone. The public IP address or prefix configured to NAT gateway must match the same zone. NAT gateway resources with public IP addresses from a different zone, zone-redundancy or with no zone aren't allowed. NAT gateway can provide outbound connectivity for virtual machines from other availability zones different from itself. The virtual machine’s subnet needs to be configured to the NAT gateway resource to provide outbound connectivity. Additionally, multiple subnets can be configured to the same NAT gateway resource. see next post run out of buffer!!
upvoted 1 times
Lazylinux
1 year, 9 months ago
continued 2- N - Subnet 2 is not associated with NATgateway1 3- N - Considering that Public IP prefixes are of CIDR /28-31 and from the question Prefix 1 /28 = 16 IPs /29 = 8 IPs /30 = 4 IPs and smallest /31 = 2 IPs Implies CIDR /31 has 2 IP addresses avilable and hence outbound connection can be from any of them
upvoted 1 times
...
...
MightyMonarch74
2 years ago
YNN - Confirmed via lab
upvoted 2 times
...
sapien45
2 years, 7 months ago
YNN If not Zonal NAT would have been deployed, multiple subnets can be configured to the same NAT gateway resource. https://learn.microsoft.com/en-us/azure/virtual-network/nat-gateway/nat-gateway-resource
upvoted 3 times
sapien45
2 years, 6 months ago
NNN then as VM1 is not in the same zone as the zonal NATGTWAY
upvoted 1 times
Feliphus
5 months ago
When the NAT gateway is zonal, it says a zone, you can not set the specific AZ/zone when you are creating it. When is non-zonal you don't see any zone reference in the Overview.
upvoted 1 times
...
...
...
BlackZeros
2 years, 7 months ago
Answer should be YNY. Minimum number of PIP you need for Nat Gateway is 1 and maximum is 16. It will work just like your home router where multiple devices are using same IP to go out. it is not one to one ratio. If Subnet1 has 50 VMs and you can only have 16 IP addresses in Nat gateway then there will be a problem (ip exhaustion) which is not the case here. Nat Gateways can be assigned to multiple Subnets https://learn.microsoft.com/en-us/azure/virtual-network/nat-gateway/faq#can-virtual-network-nat-gateway-be-attached-to-multiple-subnets
upvoted 3 times
...
MrHabanero
2 years, 7 months ago
YNN NAT GW is attached only to subnet1
upvoted 3 times
...
charlesr1700
2 years, 7 months ago
YNN Agree with Tonys link, under the Zonal header it clearly states 'NAT gateway can provide outbound connectivity for virtual machines from other availability zones different from itself'
upvoted 1 times
...
TonyOmar
2 years, 7 months ago
YNN for part 1 you can use NATgateway1 while your VM in different zone check: https://learn.microsoft.com/en-us/azure/virtual-network/nat-gateway/nat-availability-zones
upvoted 2 times
...
[Removed]
2 years, 7 months ago
NNN Only Subnet1 is connected to NATgateway1.
upvoted 2 times
[Removed]
2 years, 7 months ago
YNN tested) VM in zone3 can use a NATGW in zone2. It does support outbound connectivity, while it does not guarantee availability from zone-failure.
upvoted 6 times
...
...
Cristoicach91
2 years, 7 months ago
NNN. VM and NAT gate are in different zones. Subnet 2 is not using NAT gateway. NAT gateway uses a public prefix.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago