FDNY Z51 EXAM 3 STUDY GUIDE 2026 ACTUAL
PRACTICE QUESTIONS WITH SOLUTIONS AND
FIRE CODE REVIEW COMPLETE SET
◉ What is a virtual network gateway.
Answer: It allows you to create connections from your virtual
network to other networks
◉ What is the minimum size for a gateway subnet.
Answer: CIDR /29
◉ Steps to Create a VPN Gateway using the Azure portal.
Answer: 1. Add a Subnet
2. Assign an address space using a /27 CIDR
◉ ExpressRoute.
Answer: A secure and reliable private connection between your on-
premises network and the Microsoft cloud.
◉ Difference between ExpressRoute connections and Site-to-Site
VPN.
,Answer: Site-to-Site VPN connections only provide connectivity to
your Azure VNet, whereas ExpressRoute provides connectivity to all
Microsoft cloud services
◉ Azure Private Peering.
Answer: Provides connectivity over the Intranet address space into
your Azure virtual network. This peering is considered a trusted
extension of your core network into Azure.
◉ Microsoft Peering.
Answer: Provides connectivity over the Internet address space into
Microsoft services such as Office 365, Dynamics 365, and Internet-
facing endpoints of Azure platform (PaaS) services.
◉ ExpressRoute gateway.
Answer: a virtual network gateway, created with the ExpressRoute
option (rather than the VPN option, used to create VPN gateways).
Just as with VPN gateways, the ExpressRoute gateway must be
created in the gateway subnet of the virtual network.
◉ Azure Virtual WAN.
Answer: Creates a unified wide area network (WAN) that connects
local and remote sites.
,◉ Basic vs Standard WAN.
Answer: With Basic WAN, you can only create Basic Hubs. Basic
Hubs are only capable of creating site-to-site connections. For any
other connectivity, it is recommended to use Standard WAN.
◉ Performance Monitor.
Answer: Performance Monitor enables you to monitor packet loss
and latency between your endpoints, both in Azure and on-
premises. A VM or server running the Log Analytics agent is
required at both ends of each monitored connection.
◉ Service Connectivity Monitor.
Answer: Monitors outbound connectivity from nodes on your
network to any external service with an open TCP port, such as web
sites, applications, or databases.
◉ ExpressRoute Monitor.
Answer: Allows you to monitor end-to-end network connectivity
and performance between on-premises and Azure endpoints over
ExpressRoute connections. It can auto-detect ExpressRoute circuits
and your network topology, and track bandwidth utilization, packet
loss and network latency.
◉ Azure Network Watcher.
, Answer: Provides a central hub for a wide range of network
monitoring and diagnostic tools.
◉ IP Flow Verify.
Answer: The IP Flow Verify tool provides a quick and easy way to
test whether a given network flow will be allowed into or out of an
Azure virtual machine. It will report whether the requested traffic is
allowed or blocked, and in the latter case, which NSG rule is blocking
the flow. It is a useful tool for verifying that NSGs are correctly
configured.
◉ Next Hop.
Answer: The Next Hop tool provides a useful way to understand how
a VM's outbound traffic is being directed. For a given outbound flow,
it shows the next hop IP address and type and the route table ID of
any user-defined route in effect
◉ Packet Captures.
Answer: The Packet Capture tool allows you to capture network
packets entering or leaving your virtual machines. It is a powerful
tool for deep network diagnostics. Use WireShark or Microsoft
Message Analyzer to read the file
◉ Network Topology.
PRACTICE QUESTIONS WITH SOLUTIONS AND
FIRE CODE REVIEW COMPLETE SET
◉ What is a virtual network gateway.
Answer: It allows you to create connections from your virtual
network to other networks
◉ What is the minimum size for a gateway subnet.
Answer: CIDR /29
◉ Steps to Create a VPN Gateway using the Azure portal.
Answer: 1. Add a Subnet
2. Assign an address space using a /27 CIDR
◉ ExpressRoute.
Answer: A secure and reliable private connection between your on-
premises network and the Microsoft cloud.
◉ Difference between ExpressRoute connections and Site-to-Site
VPN.
,Answer: Site-to-Site VPN connections only provide connectivity to
your Azure VNet, whereas ExpressRoute provides connectivity to all
Microsoft cloud services
◉ Azure Private Peering.
Answer: Provides connectivity over the Intranet address space into
your Azure virtual network. This peering is considered a trusted
extension of your core network into Azure.
◉ Microsoft Peering.
Answer: Provides connectivity over the Internet address space into
Microsoft services such as Office 365, Dynamics 365, and Internet-
facing endpoints of Azure platform (PaaS) services.
◉ ExpressRoute gateway.
Answer: a virtual network gateway, created with the ExpressRoute
option (rather than the VPN option, used to create VPN gateways).
Just as with VPN gateways, the ExpressRoute gateway must be
created in the gateway subnet of the virtual network.
◉ Azure Virtual WAN.
Answer: Creates a unified wide area network (WAN) that connects
local and remote sites.
,◉ Basic vs Standard WAN.
Answer: With Basic WAN, you can only create Basic Hubs. Basic
Hubs are only capable of creating site-to-site connections. For any
other connectivity, it is recommended to use Standard WAN.
◉ Performance Monitor.
Answer: Performance Monitor enables you to monitor packet loss
and latency between your endpoints, both in Azure and on-
premises. A VM or server running the Log Analytics agent is
required at both ends of each monitored connection.
◉ Service Connectivity Monitor.
Answer: Monitors outbound connectivity from nodes on your
network to any external service with an open TCP port, such as web
sites, applications, or databases.
◉ ExpressRoute Monitor.
Answer: Allows you to monitor end-to-end network connectivity
and performance between on-premises and Azure endpoints over
ExpressRoute connections. It can auto-detect ExpressRoute circuits
and your network topology, and track bandwidth utilization, packet
loss and network latency.
◉ Azure Network Watcher.
, Answer: Provides a central hub for a wide range of network
monitoring and diagnostic tools.
◉ IP Flow Verify.
Answer: The IP Flow Verify tool provides a quick and easy way to
test whether a given network flow will be allowed into or out of an
Azure virtual machine. It will report whether the requested traffic is
allowed or blocked, and in the latter case, which NSG rule is blocking
the flow. It is a useful tool for verifying that NSGs are correctly
configured.
◉ Next Hop.
Answer: The Next Hop tool provides a useful way to understand how
a VM's outbound traffic is being directed. For a given outbound flow,
it shows the next hop IP address and type and the route table ID of
any user-defined route in effect
◉ Packet Captures.
Answer: The Packet Capture tool allows you to capture network
packets entering or leaving your virtual machines. It is a powerful
tool for deep network diagnostics. Use WireShark or Microsoft
Message Analyzer to read the file
◉ Network Topology.