Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingHard
A company is designing its network infrastructure in Azure. They have multiple virtual machines (VMs) that need to communicate with each other securely within a private network segment. Additionally, these VMs need to be able to resolve DNS names for both internal resources and external public websites. Which two Azure networking services are fundamental for achieving this connectivity and name resolution?
- AAzure VPN Gateway and Azure Firewall
- BAzure Application Gateway and Azure DNS
- CAzure Virtual Network and Azure DNS
- DAzure ExpressRoute and Azure Network Security Groups
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Virtual Network and Azure DNS
Azure Virtual Network (VNet) provides the fundamental network isolation and connectivity for Azure resources, allowing VMs to communicate securely within a private network. Azure DNS is essential for name resolution, enabling VMs to locate resources by name, both within Azure and on the internet.
Why the other options are wrong
- A. VPN Gateway is for hybrid connectivity and Firewall is for traffic filtering; neither provides the fundamental private network or DNS resolution for VMs.
- B. Application Gateway is for Layer 7 load balancing; while Azure DNS is correct, the gateway is not fundamental for basic VM communication.
- D. ExpressRoute is for hybrid connectivity and NSGs are for traffic filtering; neither provides the fundamental private network or DNS resolution for VMs.
Azure Virtual Network & Azure DNS
Azure Virtual Network (VNet) provides private network connectivity for Azure resources, while Azure DNS provides name resolution for resources inside and outside Azure.
- VNet isolates and connects Azure resources privately.
- Azure DNS integrates with VNets for internal name resolution.
- Azure DNS can host public DNS zones for external resolution.
Memory trick: VNet is the 'house' for your 'VMs', and DNS is the 'address book'.