AZ-700 Cheat Sheet 2026

The 30 highest-yield AZ-700 facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

55 questions
100 min time limit
70.00% to pass
  1. What is the function of BGP in Azure VPN Gateway? → Dynamically exchanges routes between Azure and on-premises networks
  2. Which DNS record type is used in Azure DNS to provide reverse DNS lookups (IP address to hostname)? → PTR record
  3. What does end-to-end SSL mean in the context of Azure Application Gateway? → Traffic is encrypted from the client through the gateway to the backend servers
  4. Which Azure service resolves Private DNS Zone names from on-premises networks connected via ExpressRoute or VPN? → Azure DNS Private Resolver with inbound/outbound endpoints
  5. Which VNet peering type connects virtual networks in different Azure regions? → Global VNet peering
  6. What is the impact of setting autoRegistration to true on multiple VNet links to the same Private DNS Zone? → Each VNet's VMs register in the shared zone, enabling cross-VNet hostname resolution
  7. Which Azure DNS record type is used to map a domain name to an Azure resource and automatically updates when the resource's IP changes? → Alias record
  8. Which policy must be enabled on a subnet to apply NSG rules and UDRs to Private Endpoint traffic? → PrivateEndpointNetworkPolicies = Enabled
  9. What is the primary benefit of enabling SSL offloading on Azure Application Gateway? → Terminating SSL/TLS at the gateway to reduce backend server CPU overhead
  10. Which Azure service enables you to deploy resources into a VNet subnet while keeping the service managed by Microsoft? → VNet Injection
  11. Which Azure tool can you use to audit all Private Endpoint connections and their approval status across your subscription? → The Private Link Center in the Azure portal
  12. In Azure, which private IP allocation method guarantees the same IP address is assigned to a VM each time it starts? → Static
  13. Which type of ExpressRoute connectivity model uses a Layer 2 connection provided by a carrier to extend your network to Azure? → Point-to-point Ethernet connection
  14. What is the purpose of a Local Network Gateway in Azure? → Represents the on-premises VPN device and its address space in Azure
  15. Which statement is TRUE about network traffic flowing through a Private Endpoint? → Traffic stays entirely within the Microsoft backbone and never crosses the public internet
  16. What is the recommended GatewaySubnet CIDR size for a production VPN Gateway deployment to support future scaling? → /27 or larger
  17. What is the maximum number of virtual networks you can peer with a single Azure VNet by default? → 500
  18. Which Azure service lets you expose your own application (running behind an Azure Standard Load Balancer) to other VNets using Private Link? → Azure Private Link Service
  19. What does enabling 'Service Endpoints' on a subnet accomplish? → Extends the VNet identity to Azure services over the Azure backbone
  20. When a Private Endpoint is created, what network policy must be disabled on the subnet to allow the private IP assignment? → Private endpoint network policies (PrivateEndpointNetworkPolicies)
  21. In Azure, what is the main function of a VPN Gateway? → To establish secure connections between on-premises networks and Azure VNets
  22. Which Azure resource must be deployed in your VNet to connect it to an ExpressRoute circuit? → ExpressRoute Gateway (Virtual Network Gateway with type ExpressRoute)
  23. What is the smallest subnet size you can create in an Azure VNet? → /29
  24. Which protocol does Application Gateway use for backend health probes when no custom probe is configured? → HTTP
  25. Which IKE version does Azure VPN Gateway use by default for Route-based VPN connections? → IKEv2
  26. When peering two VNets, what happens to existing connections if peering is deleted? → Traffic routing between the VNets is immediately lost
  27. Which VNet feature allows you to add additional, non-contiguous address spaces to an existing VNet without downtime? → Address space expansion
  28. Which Application Gateway component is responsible for accepting incoming client connections on a specified protocol and port? → Listener
  29. When configuring a CNAME record in Azure DNS, which limitation applies at the zone apex (root domain)? → CNAMEs cannot be used at the zone apex — use an Alias record instead
  30. Which Azure service provides protection against Distributed Denial of Service (DDoS) attacks? → Azure DDoS Protection
Was this helpful?