AZ-700 Azure Network Engineer Associate Exam — Questions and Answers
Question 1: Which Azure service provides a dedicated private connection between on-premises networks and Azure datacenters?
- Azure ExpressRoute (Correct answer)
- Azure Application Gateway
- Azure Traffic Manager
- Azure VPN Gateway
Correct answer: Azure ExpressRoute
Azure ExpressRoute provides a dedicated, private connection between your on-premises infrastructure and Azure datacenters. Unlike VPNs, ExpressRoute connections do not go over the public internet, offering higher bandwidth, lower latency, and greater reliability. This makes it ideal for hybrid cloud scenarios requiring consistent network performance.
Question 2: What are the key regulatory requirements affecting Network Security?
- There are no regulations
- Only federal regulations apply
- Compliance with applicable laws, industry standards, and licensing requirements specific to the field (Correct answer)
- Regulations are optional guidelines
Correct answer: Compliance with applicable laws, industry standards, and licensing requirements specific to the field
Practitioners must comply with all applicable regulations, which may include federal, state, and industry-specific requirements.
Question 3: Which Azure service enables you to centrally manage routing across multiple VNets using a hub-and-spoke topology as a managed service?
- Azure Route Server
- Azure Virtual WAN (Correct answer)
- Azure VPN Gateway
- Azure Peering Service
Correct answer: Azure Virtual WAN
Azure Virtual WAN provides a managed hub-and-spoke networking service that automates branch connectivity, routing, and security across multiple VNets and sites.
Question 4: How should risk be managed in Load Balancing and DNS?
- By avoiding all risk entirely
- Through identification, assessment, mitigation strategies, and ongoing monitoring of potential risks (Correct answer)
- By ignoring potential problems
- Risk management is not necessary
Correct answer: Through identification, assessment, mitigation strategies, and ongoing monitoring of potential risks
Effective risk management involves a systematic process of identifying, evaluating, and addressing potential threats.
Question 5: Which Azure Virtual WAN component is responsible for managing route propagation and aggregation between connected branches, VNets, and hubs?
- ExpressRoute Gateway
- Azure Firewall Manager
- Virtual Hub Router (Correct answer)
- Azure Route Server
Correct answer: Virtual Hub Router
The Virtual Hub Router is the built-in routing engine within each Azure Virtual WAN hub that manages route tables, propagation, and association for all connected resources.
Question 6: What routing protocol does ExpressRoute use to exchange routes with Azure?
- OSPF
- EIGRP
- BGP (Border Gateway Protocol) (Correct answer)
- RIP
Correct answer: BGP (Border Gateway Protocol)
ExpressRoute exclusively uses BGP (Border Gateway Protocol) for dynamic route exchange between your on-premises network and Azure.
Question 7: What is the primary purpose of standardized procedures in Network Security?
- To slow down work processes
- To benefit only management
- To ensure consistency, safety, and quality across all practitioners (Correct answer)
- To create unnecessary bureaucracy
Correct answer: To ensure consistency, safety, and quality across all practitioners
Standardized procedures ensure that all practitioners deliver consistent, safe, and high-quality outcomes.
Question 8: Azure Traffic Manager is directing all users to one endpoint even though multiple healthy endpoints exist. The routing method is set to Performance. What is a likely cause?
- All endpoints have the same priority value
- The endpoint monitoring protocol does not match the application protocol
- Users are resolving the Traffic Manager DNS from a location where one endpoint has the lowest measured latency (Correct answer)
- The TTL on the Traffic Manager profile is set to 0
Correct answer: Users are resolving the Traffic Manager DNS from a location where one endpoint has the lowest measured latency
Performance routing selects the endpoint with lowest latency from the user's DNS resolver location, so users from the same region will consistently be sent to the same closest endpoint.
Question 9: You need to audit all NSG flow logs for compliance. Which service stores NSG flow logs and enables traffic analytics?
- Azure Monitor Metrics
- Azure Service Bus
- Azure Sentinel only
- Azure Network Watcher with storage account (Correct answer)
Correct answer: Azure Network Watcher with storage account
NSG flow logs are stored in an Azure Storage account via Network Watcher, and Traffic Analytics can process these logs for visualization and insights.
Question 10: What is the importance of communication skills in Virtual Networks?
- Communication skills cannot be learned
- Communication is only important for managers
- Clear communication prevents errors, builds relationships, and ensures understanding among all parties (Correct answer)
- Technical skills are sufficient without communication
Correct answer: Clear communication prevents errors, builds relationships, and ensures understanding among all parties
Effective communication is essential for coordination, error prevention, and stakeholder relationships.
Question 11: What makes a professional competent in Load Balancing and DNS?
- A combination of education, practical experience, ongoing learning, and adherence to professional standards (Correct answer)
- Only experience matters
- Only formal education matters
- Only certifications matter
Correct answer: A combination of education, practical experience, ongoing learning, and adherence to professional standards
Competence requires the integration of knowledge, skills, experience, and professional conduct.
Question 12: How many VNets can a Standard-tier ExpressRoute circuit be linked to by default?
- 20
- Unlimited
- 10 (Correct answer)
- 4
Correct answer: 10
A Standard ExpressRoute circuit can be linked to up to 10 Azure virtual networks; upgrading to the Premium add-on increases this limit significantly.
Question 13: An application deployed behind Azure Application Gateway WAF is returning 403 errors only for requests containing special characters in query strings. What is the most likely cause?
- Application Gateway SKU does not support query strings
- NSG blocking traffic to Application Gateway
- The backend pool health probe is failing
- A WAF rule matching the special characters as a SQL injection or XSS pattern (Correct answer)
Correct answer: A WAF rule matching the special characters as a SQL injection or XSS pattern
WAF OWASP rules detect patterns like SQL injection and XSS, which can match special characters in query strings and generate 403 block responses.
Question 14: Which type of Azure Private Endpoint connection approval is required when the Private Endpoint and the target resource are in different Azure AD tenants?
- Automatic approval
- Manual approval (Correct answer)
- Resource provider approval
- Cross-tenant policy approval
Correct answer: Manual approval
When a Private Endpoint and target resource are in different Azure AD tenants, the resource owner must manually approve the connection request.
Question 15: What is the purpose of a private DNS zone group on a private endpoint?
- To group multiple private endpoints under a single DNS zone
- To automatically create and manage DNS records in a linked private DNS zone (Correct answer)
- To assign a custom domain name to the private endpoint
- To configure BGP routing for the private endpoint
Correct answer: To automatically create and manage DNS records in a linked private DNS zone
A private DNS zone group links a private endpoint to a private DNS zone and automatically creates/updates the DNS A record when the endpoint is created or deleted.
Question 16: How should risk be managed in Virtual Networks?
- Through identification, assessment, mitigation strategies, and ongoing monitoring of potential risks (Correct answer)
- By avoiding all risk entirely
- Risk management is not necessary
- By ignoring potential problems
Correct answer: Through identification, assessment, mitigation strategies, and ongoing monitoring of potential risks
Effective risk management involves a systematic process of identifying, evaluating, and addressing potential threats.
Question 17: Which tool in the Azure portal allows you to trace the next hop for traffic from a specific VM to a destination IP address for routing troubleshooting?
- Azure Advisor
- Azure Monitor – Network Insights
- Traffic Analytics
- Network Watcher – Next Hop (Correct answer)
Correct answer: Network Watcher – Next Hop
Network Watcher's 'Next Hop' feature evaluates the effective routing for a VM's NIC and returns the next hop type and IP for a specified destination, directly reflecting the VM's effective route table.
Question 18: How should risk be managed in Connectivity Solutions?
- Risk management is not necessary
- Through identification, assessment, mitigation strategies, and ongoing monitoring of potential risks (Correct answer)
- By avoiding all risk entirely
- By ignoring potential problems
Correct answer: Through identification, assessment, mitigation strategies, and ongoing monitoring of potential risks
Effective risk management involves a systematic process of identifying, evaluating, and addressing potential threats.
Question 19: Which Azure VPN Gateway SKU does NOT support BGP?
- VpnGw2
- VpnGw1
- VpnGw1AZ
- Basic (Correct answer)
Correct answer: Basic
The Basic SKU does not support BGP; all VpnGw1 and higher SKUs (including AZ variants) support BGP for dynamic routing.
Question 20: Which Azure service is used to protect applications from Distributed Denial of Service (DDoS) attacks?
- Azure Security Center
- Azure DDoS Protection (Correct answer)
- Azure Traffic Manager
- Azure Firewall
Correct answer: Azure DDoS Protection
Azure DDoS Protection is a service specifically designed to safeguard Azure applications and resources from Distributed Denial of Service (DDoS) attacks. It provides always-on traffic monitoring and automatic mitigation capabilities to detect and block malicious traffic before it can impact the availability of your services. This ensures business continuity even under attack.
Question 21: What is the default BGP Autonomous System Number (ASN) used by Azure VPN Gateways?
- 65000
- 64512
- 12076
- 65515 (Correct answer)
Correct answer: 65515
Azure VPN Gateways use BGP ASN 65515 by default; note that Microsoft's ExpressRoute edge routers use the separate ASN 12076.
Question 22: What makes a professional competent in Virtual Networks?
- Only formal education matters
- Only certifications matter
- A combination of education, practical experience, ongoing learning, and adherence to professional standards (Correct answer)
- Only experience matters
Correct answer: A combination of education, practical experience, ongoing learning, and adherence to professional standards
Competence requires the integration of knowledge, skills, experience, and professional conduct.
Question 23: An NSG is applied to both a subnet and a NIC. Traffic arrives at the subnet. In what order are the NSG rules evaluated for inbound traffic?
- Subnet NSG first, then NIC NSG (Correct answer)
- Both NSGs evaluated simultaneously with most permissive winning
- NIC NSG first, then subnet NSG
- Only the subnet NSG is evaluated
Correct answer: Subnet NSG first, then NIC NSG
For inbound traffic, the subnet NSG is evaluated first, and if traffic passes, the NIC NSG is evaluated second.
Question 24: What are the key regulatory requirements affecting Virtual Networks?
- Regulations are optional guidelines
- Only federal regulations apply
- Compliance with applicable laws, industry standards, and licensing requirements specific to the field (Correct answer)
- There are no regulations
Correct answer: Compliance with applicable laws, industry standards, and licensing requirements specific to the field
Practitioners must comply with all applicable regulations, which may include federal, state, and industry-specific requirements.
Question 25: ExpressRoute Direct provides dedicated port speeds of which options?
- 1 Gbps and 5 Gbps
- 5 Gbps and 50 Gbps
- 10 Gbps and 100 Gbps (Correct answer)
- 100 Gbps only
Correct answer: 10 Gbps and 100 Gbps
ExpressRoute Direct allows organizations to connect directly into Microsoft's global network at port speeds of 10 Gbps or 100 Gbps, without going through a connectivity provider.
Question 26: What is the significance of documentation in Load Balancing and DNS?
- Only management needs to document
- Only required during audits
- Documentation is unnecessary busy work
- It provides a record for accountability, quality assurance, and legal compliance (Correct answer)
Correct answer: It provides a record for accountability, quality assurance, and legal compliance
Proper documentation supports accountability, enables quality review, and satisfies legal requirements.
Question 27: Which approach is most effective for problem-solving in Load Balancing and DNS?
- Random trial and error
- Systematic analysis followed by evidence-based decision making (Correct answer)
- Ignoring the problem until it resolves itself
- Always asking someone else
Correct answer: Systematic analysis followed by evidence-based decision making
Systematic, evidence-based approaches lead to more reliable solutions than ad hoc methods.
Question 28: What do service endpoint policies allow you to do?
- Block all outbound traffic from a subnet
- Restrict VNet service endpoint access to specific Azure Storage accounts (Correct answer)
- Enable private DNS resolution for service endpoints
- Apply NSG rules to service endpoint traffic
Correct answer: Restrict VNet service endpoint access to specific Azure Storage accounts
Service endpoint policies let you filter outbound VNet traffic to Azure Storage, allowing access only to specific storage accounts rather than all accounts.
Question 29: What makes a professional competent in Connectivity Solutions?
- Only certifications matter
- Only experience matters
- Only formal education matters
- A combination of education, practical experience, ongoing learning, and adherence to professional standards (Correct answer)
Correct answer: A combination of education, practical experience, ongoing learning, and adherence to professional standards
Competence requires the integration of knowledge, skills, experience, and professional conduct.
Question 30: Which type of load balancer is required to create an Azure Private Link service exposing your own application?
- Basic Internal Load Balancer
- Application Gateway
- Standard Internal Load Balancer (Correct answer)
- Basic Public Load Balancer
Correct answer: Standard Internal Load Balancer
Azure Private Link service requires a Standard tier internal load balancer as the frontend to expose your service privately to consumers.
Question 31: What are the key regulatory requirements affecting Load Balancing and DNS?
- Compliance with applicable laws, industry standards, and licensing requirements specific to the field (Correct answer)
- Regulations are optional guidelines
- There are no regulations
- Only federal regulations apply
Correct answer: Compliance with applicable laws, industry standards, and licensing requirements specific to the field
Practitioners must comply with all applicable regulations, which may include federal, state, and industry-specific requirements.
Question 32: A security audit requires that all Azure resources have no public IP addresses. Which Azure Policy effect enforces this during resource deployment?
- Deny (Correct answer)
- Audit
- AuditIfNotExists
- Modify
Correct answer: Deny
The Deny effect prevents deployment of resources that violate the policy condition, such as having a public IP address assigned.
Question 33: What does Azure Private Link Center provide?
- A DNS configuration wizard for private endpoints
- BGP route tables for Private Link traffic
- A billing dashboard for Private Link data transfer costs
- Centralized monitoring and management for private endpoints and Private Link services (Correct answer)
Correct answer: Centralized monitoring and management for private endpoints and Private Link services
Azure Private Link Center is a portal hub that gives you a unified view for monitoring, managing, and auditing all private endpoints and Private Link services in your subscription.
Question 34: What is the importance of communication skills in Load Balancing and DNS?
- Communication skills cannot be learned
- Technical skills are sufficient without communication
- Communication is only important for managers
- Clear communication prevents errors, builds relationships, and ensures understanding among all parties (Correct answer)
Correct answer: Clear communication prevents errors, builds relationships, and ensures understanding among all parties
Effective communication is essential for coordination, error prevention, and stakeholder relationships.
Question 35: How many private endpoints can reference the same Private Link resource?
- Only one
- Multiple private endpoints can connect to the same resource (Correct answer)
- Up to 10
- Up to 100, with a support request
Correct answer: Multiple private endpoints can connect to the same resource
Multiple private endpoints in different VNets or subscriptions can all connect to the same Private Link resource simultaneously.
Question 36: What quality metrics are most important in Virtual Networks?
- Measurable outcomes, process compliance, and stakeholder satisfaction (Correct answer)
- No metrics are needed
- Only financial metrics
- Only speed of completion
Correct answer: Measurable outcomes, process compliance, and stakeholder satisfaction
Quality in Virtual Networks is measured through multiple dimensions including outcomes, processes, and satisfaction.
Question 37: Which Azure Policy built-in initiative helps enforce network security compliance for PCI DSS workloads?
- Microsoft cloud security benchmark
- NIST SP 800-53 initiative
- CIS Microsoft Azure Foundations Benchmark
- PCI DSS built-in initiative (Correct answer)
Correct answer: PCI DSS built-in initiative
Azure Policy includes a built-in PCI DSS initiative that maps controls to Azure configurations, helping enforce network and security compliance for cardholder data environments.
Question 38: When configuring BGP on an Azure VPN Gateway, what must the on-premises VPN device use as the BGP neighbor IP address?
- Any IP address within the on-premises network range
- The Azure VNet's first usable IP address
- The Azure gateway's public IP address
- The Azure gateway's BGP IP address assigned within the GatewaySubnet (Correct answer)
Correct answer: The Azure gateway's BGP IP address assigned within the GatewaySubnet
BGP sessions are established using the gateway's BGP IP address (from GatewaySubnet address space), not its public IP, because BGP runs over the tunnel after it is established.
Question 39: Which statement about application security groups (ASGs) and private endpoints is correct?
- ASGs can be applied to private endpoint NICs to simplify NSG rules (Correct answer)
- ASGs cannot be used with private endpoints
- ASGs replace private DNS zones for private endpoints
- ASGs are required for all private endpoint deployments
Correct answer: ASGs can be applied to private endpoint NICs to simplify NSG rules
Once network policies are enabled on a subnet, ASGs can be associated with private endpoint NICs, allowing you to reference them in NSG rules instead of individual IPs.
Question 40: How should ethical dilemmas be handled in Connectivity Solutions?
- Follow established ethical guidelines, consult with supervisors, and prioritize stakeholder welfare (Correct answer)
- Make decisions based solely on personal preference
- Ignore ethical concerns
- Always choose the cheapest option
Correct answer: Follow established ethical guidelines, consult with supervisors, and prioritize stakeholder welfare
Ethical decision-making requires following professional guidelines and prioritizing the welfare of all stakeholders.
AZ-700 Azure Network Engineer Associate Exam
The Microsoft AZ-700 exam certifies skills in designing, implementing, and managing Azure networking solutions including virtual networks, ExpressRoute, VPN gateways, load balancing, DNS, Private Link, network security, and hybrid connectivity.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds