AZ-700: Designing and Implementing Microsoft Azure Networking Solutions — Questions and Answers
Question 1: In a hub-spoke VNet topology, which component typically resides in the hub VNet?
- Application workloads
- Individual department subnets
- Shared services like VPN Gateway and Azure Firewall (Correct answer)
- Storage accounts
Correct answer: Shared services like VPN Gateway and Azure Firewall
Shared services such as VPN Gateway, Azure Firewall, and DNS reside in the hub VNet in a hub-spoke topology.
Question 2: Which Azure DNS record type is used to map a domain name to an Azure resource and automatically updates when the resource's IP changes?
- CNAME record
- PTR record
- A record
- Alias record (Correct answer)
Correct answer: Alias record
Azure DNS Alias records are aware of Azure resource lifecycle and automatically reflect IP changes for resources like Public IPs, Traffic Manager, and CDN.
Question 3: Which WAF policy association scope allows different WAF configurations to be applied to individual listeners on the same Application Gateway?
- Per-URI WAF policy scoped to URL paths
- Backend pool WAF policy scoped to target servers
- Global WAF policy applied to the entire gateway
- Per-site (per-listener) WAF policy (Correct answer)
Correct answer: Per-site (per-listener) WAF policy
Per-site WAF policies allow different WAF configurations, including custom rules and exclusions, to be applied to individual listeners on the same Application Gateway instance.
Question 4: Which Azure VPN feature allows branch offices to connect to each other through a hub without individual branch-to-branch tunnels?
- Virtual WAN (Correct answer)
- VNet peering transit
- ExpressRoute FastPath
- VPN Gateway BGP
Correct answer: Virtual WAN
Azure Virtual WAN provides hub-based connectivity allowing branch-to-branch communication through Microsoft's backbone without direct tunnels.
Question 5: What DNS record type is created in a Private DNS Zone when a Private Endpoint is configured?
- MX record for service routing
- CNAME pointing to the public endpoint
- SRV record for service discovery
- A record mapping the service FQDN to the private IP (Correct answer)
Correct answer: A record mapping the service FQDN to the private IP
A Private Endpoint creates an A record in the private DNS zone mapping the service's FQDN to its assigned private IP address.
Question 6: What feature of Network Watcher allows you to monitor the latency and availability of connections between Azure regions and between your on-premises locations and Azure?
- Network Performance Monitor
- Azure Traffic Analytics
- Network Security Group (NSG) Flow Logs
- Connection Monitor (Correct answer)
Correct answer: Connection Monitor
Connection Monitor, a feature within Azure Network Watcher, provides unified, end-to-end connection monitoring for hybrid and Azure cloud deployments. It allows you to monitor network connectivity, latency, and packet loss between Azure regions, VNets, and your on-premises locations. This helps in identifying and diagnosing network performance issues proactively.
Question 7: Which Azure service provides end-to-end visibility into your network by allowing you to diagnose and monitor your network resources?
- Network Watcher (Correct answer)
- Azure Site Recovery
- Azure Traffic Manager
- Azure Firewall
Correct answer: Network Watcher
Azure Network Watcher is a suite of tools designed to monitor, diagnose, and gain insights into your Azure virtual network. It provides end-to-end visibility into network performance, security, and connectivity. This service is crucial for identifying and resolving network issues, ensuring the smooth operation of your Azure infrastructure.
Question 8: Which Azure Application Gateway SKU supports autoscaling and zone redundancy?
- WAF v1
- Basic
- Standard v1
- Standard v2 (Correct answer)
Correct answer: Standard v2
Application Gateway v2 SKUs (Standard v2 and WAF v2) support autoscaling, zone redundancy, and static virtual IP addresses.
Question 9: What feature of ExpressRoute Global Reach allows direct connectivity between on-premises sites?
- It connects ExpressRoute to Virtual WAN hubs
- It enables two ExpressRoute circuits to connect through the Microsoft backbone (Correct answer)
- It enables VNet peering across ExpressRoute
- It extends a single circuit to multiple regions
Correct answer: It enables two ExpressRoute circuits to connect through the Microsoft backbone
ExpressRoute Global Reach links two ExpressRoute circuits via the Microsoft global network, enabling direct on-premises-to-on-premises communication.
Question 10: What is the purpose of the ExpressRoute Local SKU?
- Provides the lowest-cost circuit for local/metro connectivity with unlimited egress included (Correct answer)
- Enables connectivity to all global Azure regions
- Offers the highest bandwidth up to 100 Gbps
- Connects only to Azure Government regions
Correct answer: Provides the lowest-cost circuit for local/metro connectivity with unlimited egress included
ExpressRoute Local is a lower-cost SKU for customers co-located near an Azure region that includes unlimited outbound data transfer.
Question 11: What is the primary benefit of enabling SSL offloading on Azure Application Gateway?
- Routing traffic based on SSL certificate Common Name attributes
- Encrypting traffic between the gateway and backend servers
- Generating SSL certificates automatically for backend servers
- Terminating SSL/TLS at the gateway to reduce backend server CPU overhead (Correct answer)
Correct answer: Terminating SSL/TLS at the gateway to reduce backend server CPU overhead
SSL offloading terminates the SSL/TLS connection at the Application Gateway, allowing backend servers to handle unencrypted HTTP traffic and reducing their computational load.
Question 12: In Azure, what is the main function of a VPN Gateway?
- To establish secure connections between on-premises networks and Azure VNets (Correct answer)
- To filter inbound traffic
- To manage user authentication
- To encrypt data at rest
Correct answer: To establish secure connections between on-premises networks and Azure VNets
An Azure VPN Gateway is used to create secure, encrypted connections between an on-premises network and an Azure Virtual Network (VNet) over the public internet. This enables hybrid cloud scenarios, allowing resources in Azure to communicate securely with resources in your datacenter. It's essential for extending your corporate network into Azure.
Question 13: What is the role of Azure Bastion in network security?
- To manage network routing
- To provide VPN services
- To monitor network traffic
- To provide a secure, managed connection to virtual machines (VMs) without a public IP (Correct answer)
Correct answer: To provide a secure, managed connection to virtual machines (VMs) without a public IP
Azure Bastion is a fully managed PaaS service that provides secure and seamless RDP/SSH connectivity to your virtual machines directly through the Azure portal over SSL. It eliminates the need for public IP addresses on your VMs, significantly enhancing security by preventing direct exposure to the internet and reducing the attack surface.
Question 14: What is the ASN Azure VPN Gateway uses by default for BGP if you do not specify a custom ASN?
- 64512
- 4294967295
- 65535
- 65515 (Correct answer)
Correct answer: 65515
Azure VPN Gateway uses ASN 65515 as the default BGP ASN unless a custom private ASN is configured.
Question 15: What is the purpose of a Network Security Group (NSG) in Azure?
- To create virtual networks
- To filter network traffic to and from Azure resources (Correct answer)
- To manage user access to Azure resources
- To encrypt data at rest
Correct answer: To filter network traffic to and from Azure resources
A Network Security Group (NSG) acts as a virtual firewall for Azure resources, allowing or denying inbound and outbound network traffic based on defined rules. NSGs provide a fundamental layer of security by controlling access to VMs, subnets, and other network interfaces. They help protect resources from unauthorized access and malicious traffic.
Question 16: At which OSI layer does Azure Application Gateway primarily operate?
- Layer 4 (Transport)
- Layer 3 (Network)
- Layer 7 (Application) (Correct answer)
- Layer 5 (Session)
Correct answer: Layer 7 (Application)
Application Gateway operates at Layer 7, enabling routing decisions based on HTTP/HTTPS attributes such as URLs, headers, and cookies.
Question 17: What is the maximum number of VNets you can link to a single Azure Private DNS Zone?
- 5,000 — standard limit
- 100
- Unlimited
- 1,000 (Correct answer)
Correct answer: 1,000
Each Azure Private DNS Zone supports up to 1,000 virtual network links, with auto-registration enabled on up to 100 of them.
Question 18: Which Application Gateway feature allows you to display branded HTML pages instead of default error responses for 403 and 502 status codes?
- Listener error handling policies
- Backend health monitoring
- Custom error pages (Correct answer)
- WAF custom rules
Correct answer: Custom error pages
Application Gateway supports custom error pages for HTTP 403 (WAF block) and 502 (bad gateway) responses, enabling a branded error experience.
Question 19: Which ExpressRoute peering type requires you to register route filters to control which BGP communities are received?
- Microsoft peering (Correct answer)
- Global Reach peering
- Local peering
- Private peering
Correct answer: Microsoft peering
Microsoft peering requires route filters to be configured in Azure to select which BGP service communities (e.g., specific Azure regions or M365) you receive.
Question 20: What does end-to-end SSL mean in the context of Azure Application Gateway?
- Application Gateway manages SSL certificate lifecycle for all backends
- Traffic is encrypted from the client through the gateway to the backend servers (Correct answer)
- SSL is terminated at the gateway and backends receive plain HTTP
- SSL is only applied between Application Gateway and the internet
Correct answer: Traffic is encrypted from the client through the gateway to the backend servers
End-to-end SSL maintains encrypted HTTPS communication from client to Application Gateway, and the gateway re-encrypts traffic before sending it to backend servers.
Question 21: What is the function of BGP in Azure VPN Gateway?
- Encrypts VPN tunnel traffic
- Dynamically exchanges routes between Azure and on-premises networks (Correct answer)
- Provides DDoS protection for the gateway
- Balances traffic across multiple tunnels
Correct answer: Dynamically exchanges routes between Azure and on-premises networks
BGP enables dynamic route exchange between Azure VPN Gateway and on-premises BGP-capable devices, removing the need for static route management.
Question 22: What tool within Azure Monitor is used to collect and analyze log data from various Azure resources, including network resources?
- Log Analytics (Correct answer)
- Application Insights
- Network Watcher
- Azure Policy
Correct answer: Log Analytics
Log Analytics is a powerful tool within Azure Monitor that allows you to collect, index, and analyze log data from various Azure resources, including network resources. It provides a query language and dashboards for deep insights into operational data, security events, and performance metrics. This helps in troubleshooting, auditing, and understanding resource behavior.
Question 23: Which Azure service enables you to deploy resources into a VNet subnet while keeping the service managed by Microsoft?
- VNet Injection (Correct answer)
- VNet Peering
- VNet Service Endpoints
- VNet Integration
Correct answer: VNet Injection
VNet Injection allows managed Azure services (like Azure Container Instances) to be deployed into a customer-owned subnet.
Question 24: Which routing protocol is commonly used in large enterprise networks and supports both IPv4 and IPv6?
- EIGRP
- OSPF (Correct answer)
- RIP
- BGP
Correct answer: OSPF
OSPF (Open Shortest Path First) is a widely used link-state routing protocol known for its scalability and efficiency in large enterprise networks. It supports both IPv4 and IPv6, making it a versatile choice for modern network infrastructures that require robust and fast convergence for routing decisions.
Question 25: When configuring a CNAME record in Azure DNS, which limitation applies at the zone apex (root domain)?
- CNAMEs are allowed at apex with an additional flag
- CNAMEs at apex require a wildcard certificate
- CNAMEs at apex need a higher DNS TTL
- CNAMEs cannot be used at the zone apex — use an Alias record instead (Correct answer)
Correct answer: CNAMEs cannot be used at the zone apex — use an Alias record instead
DNS standards prohibit CNAME records at the zone apex (e.g., contoso.com); Azure DNS Alias records solve this for Azure resources.
Question 26: Which Azure service provides protection against Distributed Denial of Service (DDoS) attacks?
- Azure DDoS Protection (Correct answer)
- Azure Key Vault
- Azure Security Center
- Azure Firewall
Correct answer: Azure DDoS Protection
Azure DDoS Protection is a dedicated service designed to safeguard Azure resources from Distributed Denial of Service (DDoS) attacks. It provides always-on traffic monitoring and automatic mitigation capabilities to protect applications and services from volumetric, protocol, and resource-layer attacks. This ensures the availability and performance of your Azure-hosted applications.
Question 27: Which load balancing method is used by Azure Load Balancer to distribute incoming traffic across all available VMs in a backend pool based on the number of concurrent connections?
- Least connections (Correct answer)
- Round-robin
- Source IP affinity
- Hash-based distribution
Correct answer: Least connections
The 'Least connections' load balancing method used by Azure Load Balancer directs new incoming traffic to the backend instance with the fewest active connections. This method helps to optimize resource utilization and ensure an even distribution of workload across all available virtual machines in the backend pool. By sending traffic to less busy servers, it prevents any single server from becoming overloaded.
Question 28: What is the difference between a Service Endpoint and a Private Endpoint for securing access to Azure Storage?
- Service Endpoints extend VNet identity to Storage over the backbone but Storage retains a public IP; Private Endpoints give Storage a private IP in your VNet (Correct answer)
- Service Endpoints give Storage a private IP; Private Endpoints keep traffic on the backbone only
- They are functionally identical
- Private Endpoints are cheaper but less secure
Correct answer: Service Endpoints extend VNet identity to Storage over the backbone but Storage retains a public IP; Private Endpoints give Storage a private IP in your VNet
Service Endpoints route traffic over the backbone but the service still has a public IP; Private Endpoints assign a private IP in your VNet, enabling fully private access.
Question 29: Which protocol must be used for Point-to-Site VPN when Azure AD authentication is selected?
- IKEv2
- L2TP/IPsec
- OpenVPN (Correct answer)
- SSTP
Correct answer: OpenVPN
Azure AD authentication for P2S VPN is only supported with the OpenVPN protocol.
Question 30: Which Azure feature provides a managed ExpressRoute connection without requiring a dedicated circuit from a provider?
- ExpressRoute Global Reach
- Azure Peering Service
- ExpressRoute Direct (Correct answer)
- Azure Virtual WAN with ExpressRoute gateway
Correct answer: ExpressRoute Direct
ExpressRoute Direct allows customers to connect directly into Microsoft's global network at 10G or 100G ports without an intermediary provider.
Question 31: Which Azure service lets you expose your own application (running behind an Azure Standard Load Balancer) to other VNets using Private Link?
- Azure Private Endpoint
- Azure VNet Integration
- Azure Service Endpoint
- Azure Private Link Service (Correct answer)
Correct answer: Azure Private Link Service
Azure Private Link Service allows you to publish your own application behind a Standard Load Balancer so consumers can connect via private endpoints in their VNets.
Question 32: How are WAF custom rules evaluated relative to managed ruleset rules in Azure Application Gateway?
- Custom rules are evaluated after all managed ruleset rules
- Custom rules are evaluated before managed ruleset rules and take priority (Correct answer)
- Custom rules and managed rules are evaluated in parallel simultaneously
- Custom rules only apply when managed rules are disabled
Correct answer: Custom rules are evaluated before managed ruleset rules and take priority
WAF custom rules are evaluated before managed ruleset rules, allowing you to define precise allow or deny logic that takes priority over the default ruleset.
Question 33: Which Azure service is primarily used for monitoring the performance and health of Azure resources, including virtual networks and network traffic?
- Azure Blob Storage
- Azure Active Directory
- Azure Monitor (Correct answer)
- Azure Key Vault
Correct answer: Azure Monitor
Azure Monitor is a comprehensive service that collects, analyzes, and acts on telemetry data from your Azure and on-premises environments. It provides unified monitoring capabilities for the performance and health of all your Azure resources, including virtual networks and network traffic. This allows for proactive issue resolution and performance optimization.
Question 34: What type of Azure Load Balancer provides high availability by distributing incoming network traffic across multiple virtual machines (VMs) inside a virtual network?
- Traffic Manager
- Application Gateway
- Public Load Balancer
- Internal Load Balancer (Correct answer)
Correct answer: Internal Load Balancer
An Internal Load Balancer (ILB) in Azure is used to distribute incoming network traffic among virtual machines (VMs) within a virtual network. Unlike a Public Load Balancer, an ILB is not exposed to the internet, making it suitable for internal applications and services. It ensures high availability and even traffic distribution among healthy backend instances for internal workloads.
Question 35: Which Private DNS Zone name should you use for automatic private endpoint DNS resolution of Azure Blob Storage?
- blob.privatelink.azure.com
- privatelink.storage.windows.net
- storage.private.azure.net
- privatelink.blob.core.windows.net (Correct answer)
Correct answer: privatelink.blob.core.windows.net
Azure Blob Storage private endpoints use the zone 'privatelink.blob.core.windows.net' for DNS resolution to private IPs.
Question 36: Which scenario requires configuring a DNS forwarding ruleset in Azure DNS Private Resolver?
- Enabling DNSSEC for a public zone
- Blocking external DNS queries from reaching Azure
- Resolving on-premises DNS names from Azure workloads using outbound endpoint forwarding rules (Correct answer)
- Resolving Azure Private DNS zones from Azure VMs
Correct answer: Resolving on-premises DNS names from Azure workloads using outbound endpoint forwarding rules
A DNS forwarding ruleset attached to the outbound endpoint defines rules that forward Azure-originated DNS queries for specific domains to on-premises resolvers.
Question 37: Which subnet is reserved for Azure-managed services and cannot be used by user resources within a VNet?
- GatewaySubnet (Correct answer)
- AzureFirewallSubnet
- DefaultSubnet
- AzureBastionSubnet
Correct answer: GatewaySubnet
GatewaySubnet is a reserved subnet specifically required by Azure VPN and ExpressRoute gateways.
Question 38: Which Azure networking feature allows you to restrict which specific resources (not just subnets) can access an Azure Storage account via Service Endpoints?
- Azure Firewall FQDN rules
- Network Security Groups
- Private Link Service filters
- Service Endpoint Policies (Correct answer)
Correct answer: Service Endpoint Policies
Service Endpoint Policies let you specify exact Azure Storage accounts (or other resources) that a subnet can reach via Service Endpoints, providing resource-level granularity.
Question 39: In Azure, which private IP allocation method guarantees the same IP address is assigned to a VM each time it starts?
- Reserved
- Pinned
- Static (Correct answer)
- Dynamic
Correct answer: Static
Setting the private IP allocation method to 'Static' ensures the VM always receives the same IP address from the subnet.
Question 40: Which HTTP response code does Azure WAF return to clients when it blocks a request in Prevention mode?
- 401 Unauthorized
- 400 Bad Request
- 404 Not Found
- 403 Forbidden (Correct answer)
Correct answer: 403 Forbidden
When WAF blocks a request in Prevention mode, it returns HTTP 403 Forbidden to the client, indicating the request was understood but refused.
Question 41: Which Application Gateway feature ensures that requests from the same client session are always directed to the same backend server?
- URL rewrite rules
- Connection draining
- Custom health probes
- Cookie-based session affinity (Correct answer)
Correct answer: Cookie-based session affinity
Cookie-based session affinity uses a gateway-managed cookie to route requests from the same client session to the same backend server.
Question 42: What Azure resource must be provisioned in the GatewaySubnet before deploying a VPN Gateway?
- A route table with default routes
- A public IP address resource (Correct answer)
- Nothing — the gateway deploys directly into GatewaySubnet
- A Network Security Group
Correct answer: A public IP address resource
A Public IP address resource must be created and associated with the VPN Gateway before deployment.
Question 43: Which category of attacks does Azure WAF on Application Gateway primarily protect against?
- BGP route hijacking and DNS amplification attacks
- Network-level port scanning and IP spoofing
- SQL injection, cross-site scripting, and OWASP Top 10 vulnerabilities (Correct answer)
- DDoS volumetric and bandwidth exhaustion attacks
Correct answer: SQL injection, cross-site scripting, and OWASP Top 10 vulnerabilities
Azure WAF protects against common web application attacks including SQL injection, XSS, and other OWASP Top 10 threats using managed rule sets.
Question 44: In Azure DNS, what is the minimum TTL (Time to Live) value allowed for a DNS record?
- 60 seconds
- 0 (Correct answer)
- 300 seconds
- 1 second
Correct answer: 0
Azure DNS allows a TTL of 0, though values this low are impractical and Microsoft recommends a minimum TTL of 300 seconds.
Question 45: Which VNet feature allows you to add additional, non-contiguous address spaces to an existing VNet without downtime?
- Address space expansion (Correct answer)
- Subnet delegation
- VNet resize
- CIDR extension
Correct answer: Address space expansion
Azure allows you to add additional address spaces to an existing VNet at any time without downtime.
Question 46: What is the recommended GatewaySubnet CIDR size for a production VPN Gateway deployment to support future scaling?
- /24
- /32
- /30
- /27 or larger (Correct answer)
Correct answer: /27 or larger
Microsoft recommends using /27 or larger for GatewaySubnet to accommodate additional gateway resources and future ExpressRoute coexistence.
Question 47: Which Azure Monitor feature provides metrics and logs for your virtual networks, including data about traffic, throughput, and network latency?
- Activity Log
- Application Insights
- Network Performance Monitor (Correct answer)
- Metrics Explorer
Correct answer: Network Performance Monitor
Network Performance Monitor (NPM) is a feature within Azure Monitor specifically designed to provide comprehensive visibility into network health and performance. It collects metrics and logs related to network connectivity, latency, and packet loss across your Azure virtual networks and hybrid connections. This makes NPM the ideal tool for diagnosing and troubleshooting network-related issues within your Azure infrastructure.
Question 48: Which Azure service can you use to manage DNS-based load balancing across multiple regions or endpoints for high availability and resilience?
- Azure Front Door
- Azure Traffic Manager (Correct answer)
- Azure Application Gateway
- Azure Load Balancer
Correct answer: Azure Traffic Manager
Azure Traffic Manager is a DNS-based traffic load balancer that enables you to distribute user traffic to service endpoints across global Azure regions. It uses various routing methods to ensure high availability and responsiveness by directing users to the best performing or closest available endpoint. This service is crucial for multi-region deployments requiring global traffic management.
Question 49: Which VPN type should you use when you need to support multiple VNet-to-VNet and cross-premises connections with dynamic routing?
- Policy-based VPN
- BGP-only VPN
- Static VPN
- Route-based VPN (Correct answer)
Correct answer: Route-based VPN
Route-based VPNs use dynamic routing and support multiple connections, VNet-to-VNet, and BGP — required for most modern scenarios.
Question 50: What is the impact of setting autoRegistration to true on multiple VNet links to the same Private DNS Zone?
- Each VNet's VMs register in the shared zone, enabling cross-VNet hostname resolution (Correct answer)
- Only the first VNet's VMs are registered
- It enables zone transfer between VNets
- It causes DNS conflicts and must be avoided
Correct answer: Each VNet's VMs register in the shared zone, enabling cross-VNet hostname resolution
Multiple VNets can auto-register into the same Private DNS Zone (up to 100), allowing VMs across all linked VNets to resolve each other by hostname.
Question 51: When a Private Endpoint is created, what network policy must be disabled on the subnet to allow the private IP assignment?
- Network Security Group policies
- Private endpoint network policies (PrivateEndpointNetworkPolicies) (Correct answer)
- Service endpoint policies
- Route table policies
Correct answer: Private endpoint network policies (PrivateEndpointNetworkPolicies)
The subnet property 'PrivateEndpointNetworkPolicies' must be set to Disabled to allow private endpoints to be deployed in that subnet.
Question 52: What is the billing model for ExpressRoute data transfer by default on the Standard and Premium SKUs?
- Metered — both inbound and outbound charged
- Metered — inbound free, outbound charged per GB (Correct answer)
- Unlimited inbound and outbound included
- Flat monthly rate regardless of usage
Correct answer: Metered — inbound free, outbound charged per GB
Standard and Premium ExpressRoute circuits use a metered billing model where inbound data is free but outbound data is charged per GB.
Question 53: Can a Private Endpoint be accessed from an on-premises network connected via ExpressRoute or VPN?
- Yes — on-premises clients can reach Private Endpoints via ExpressRoute or VPN with proper DNS forwarding (Correct answer)
- No — Private Endpoints are restricted to Azure VNets only
- Only if the on-premises network uses Azure AD-joined devices
- Yes — but only with ExpressRoute Premium
Correct answer: Yes — on-premises clients can reach Private Endpoints via ExpressRoute or VPN with proper DNS forwarding
On-premises clients can access Private Endpoints over ExpressRoute or VPN; DNS must be configured to resolve the privatelink FQDN to the private IP.
Question 54: Which VPN Gateway feature lets you define specific traffic selectors instead of routing all traffic through the tunnel?
- Policy-based VPN
- Traffic selector policies on route-based VPN (Correct answer)
- Forced tunneling
- Route-based VPN with BGP
Correct answer: Traffic selector policies on route-based VPN
Traffic selector policies on route-based VPN gateways allow you to specify which traffic flows are protected by the IPsec tunnel.
Question 55: Which command can be used to view the routing table on a Windows server?
- route print (Correct answer)
- tracert
- netstat -r
- ipconfig
Correct answer: route print
The `route print` command is the standard utility on Windows operating systems for displaying the local IP routing table. It provides detailed information about network destinations, gateways, interfaces, and metrics. This command is crucial for network troubleshooting, verifying connectivity, and understanding how a Windows server routes traffic.
AZ-700: Designing and Implementing Microsoft Azure Networking Solutions
AZ-700 validates skills in designing and implementing core Azure networking infrastructure, hybrid connectivity, application delivery, and network security. It leads to the Microsoft Certified: Azure Network Engineer Associate certification.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds