AZ-700: Designing and Implementing Microsoft Azure Networking Solutions — Questions and Answers
Question 1: Which Azure service provides load balancing at the application layer (Layer 7) and includes features like SSL termination, URL-based routing, and Web Application Firewall (WAF)?
- Azure Front Door
- Azure Application Gateway (Correct answer)
- Azure Traffic Manager
- Azure Load Balancer
Correct answer: Azure Application Gateway
Azure Application Gateway operates at Layer 7 (the application layer) and provides advanced load balancing capabilities specifically for web traffic. It includes features like SSL termination, URL-based routing, session affinity, and an integrated Web Application Firewall (WAF). This makes it ideal for securing, managing, and optimizing traffic to your web applications.
Question 2: Which Azure resource must be deployed in your VNet to connect it to an ExpressRoute circuit?
- ExpressRoute Gateway (Virtual Network Gateway with type ExpressRoute) (Correct answer)
- Azure Firewall
- VPN Gateway
- Application Gateway
Correct answer: ExpressRoute Gateway (Virtual Network Gateway with type ExpressRoute)
An ExpressRoute Virtual Network Gateway is required in each VNet you want to connect to the ExpressRoute circuit.
Question 3: Which backend member type is supported by Azure Application Gateway backend pools?
- Azure Event Hub consumer groups
- Azure Service Bus queue endpoints
- Azure Blob Storage static website URLs
- Virtual machines and VM scale set instances (Correct answer)
Correct answer: Virtual machines and VM scale set instances
Application Gateway backend pools support virtual machines, VM scale sets, App Service web apps, and on-premises servers accessible via IP or FQDN.
Question 4: Which Azure DNS feature allows you to create a record that responds differently based on the client's geographic location?
- Azure DNS latency-based routing
- Azure DNS does not support geo-routing — use Traffic Manager instead (Correct answer)
- Azure DNS geo-routing records
- Azure DNS weighted records with geographic tags
Correct answer: Azure DNS does not support geo-routing — use Traffic Manager instead
Azure DNS does not natively support geo-routing; use Azure Traffic Manager or Azure Front Door with DNS for geographic traffic distribution.
Question 5: What is the role of Azure Bastion in network security?
- To manage network routing
- To monitor network traffic
- To provide VPN services
- To provide a secure, managed connection to virtual machines (VMs) without a public IP (Correct answer)
Correct answer: To provide a secure, managed connection to virtual machines (VMs) without a public IP
Azure Bastion is a fully managed PaaS service that provides secure and seamless RDP/SSH connectivity to your virtual machines directly through the Azure portal over SSL. It eliminates the need for public IP addresses on your VMs, significantly enhancing security by preventing direct exposure to the internet and reducing the attack surface.
Question 6: Which Azure service is primarily used for monitoring the performance and health of Azure resources, including virtual networks and network traffic?
- Azure Active Directory
- Azure Monitor (Correct answer)
- Azure Key Vault
- Azure Blob Storage
Correct answer: Azure Monitor
Azure Monitor is a comprehensive service that collects, analyzes, and acts on telemetry data from your Azure and on-premises environments. It provides unified monitoring capabilities for the performance and health of all your Azure resources, including virtual networks and network traffic. This allows for proactive issue resolution and performance optimization.
Question 7: Which Private DNS Zone name should you use for automatic private endpoint DNS resolution of Azure Blob Storage?
- storage.private.azure.net
- privatelink.blob.core.windows.net (Correct answer)
- privatelink.storage.windows.net
- blob.privatelink.azure.com
Correct answer: privatelink.blob.core.windows.net
Azure Blob Storage private endpoints use the zone 'privatelink.blob.core.windows.net' for DNS resolution to private IPs.
Question 8: Which Azure service enables you to deploy resources into a VNet subnet while keeping the service managed by Microsoft?
- VNet Service Endpoints
- VNet Peering
- VNet Integration
- VNet Injection (Correct answer)
Correct answer: VNet Injection
VNet Injection allows managed Azure services (like Azure Container Instances) to be deployed into a customer-owned subnet.
Question 9: Which Azure tool can you use to audit all Private Endpoint connections and their approval status across your subscription?
- The Private Link Center in the Azure portal (Correct answer)
- Azure Security Center
- Azure Monitor Logs
- Azure Policy compliance dashboard
Correct answer: The Private Link Center in the Azure portal
The Azure Private Link Center provides a centralized view of all Private Endpoints and Private Link Services, including connection approval status.
Question 10: What is an Azure Private Endpoint?
- A network interface with a private IP that connects to an Azure service via Private Link (Correct answer)
- A public IP address assigned to an Azure PaaS service
- A VNet peering connection to a PaaS service
- A DNS alias for an Azure service
Correct answer: A network interface with a private IP that connects to an Azure service via Private Link
A Private Endpoint is a NIC with a private IP from your VNet subnet, connected to an Azure service through the Private Link service.
Question 11: Which Application Gateway component is responsible for accepting incoming client connections on a specified protocol and port?
- Backend pool
- Listener (Correct answer)
- Routing rule
- Health probe
Correct answer: Listener
A listener checks for incoming connection requests based on protocol, port, host name, and IP address combination.
Question 12: Which WAF policy association scope allows different WAF configurations to be applied to individual listeners on the same Application Gateway?
- Global WAF policy applied to the entire gateway
- Backend pool WAF policy scoped to target servers
- Per-site (per-listener) WAF policy (Correct answer)
- Per-URI WAF policy scoped to URL paths
Correct answer: Per-site (per-listener) WAF policy
Per-site WAF policies allow different WAF configurations, including custom rules and exclusions, to be applied to individual listeners on the same Application Gateway instance.
Question 13: How are WAF custom rules evaluated relative to managed ruleset rules in Azure Application Gateway?
- Custom rules only apply when managed rules are disabled
- Custom rules are evaluated after all managed ruleset rules
- Custom rules are evaluated before managed ruleset rules and take priority (Correct answer)
- Custom rules and managed rules are evaluated in parallel simultaneously
Correct answer: Custom rules are evaluated before managed ruleset rules and take priority
WAF custom rules are evaluated before managed ruleset rules, allowing you to define precise allow or deny logic that takes priority over the default ruleset.
Question 14: Which Azure service provides end-to-end visibility into your network by allowing you to diagnose and monitor your network resources?
- Azure Traffic Manager
- Network Watcher (Correct answer)
- Azure Firewall
- Azure Site Recovery
Correct answer: Network Watcher
Azure Network Watcher is a suite of tools designed to monitor, diagnose, and gain insights into your Azure virtual network. It provides end-to-end visibility into network performance, security, and connectivity. This service is crucial for identifying and resolving network issues, ensuring the smooth operation of your Azure infrastructure.
Question 15: What is the purpose of WAF exclusion lists in Azure Application Gateway?
- Blocking specific IP address ranges from accessing the application
- Disabling WAF inspection for specific backend pool members
- Creating custom WAF rules for unique application traffic patterns
- Excluding specific request attributes from WAF rule evaluation to prevent false positives (Correct answer)
Correct answer: Excluding specific request attributes from WAF rule evaluation to prevent false positives
WAF exclusion lists allow you to omit specific request attributes such as headers, cookies, or query strings from WAF rule evaluation to eliminate false positive blocks.
Question 16: Which Azure feature provides a managed ExpressRoute connection without requiring a dedicated circuit from a provider?
- ExpressRoute Global Reach
- Azure Peering Service
- ExpressRoute Direct (Correct answer)
- Azure Virtual WAN with ExpressRoute gateway
Correct answer: ExpressRoute Direct
ExpressRoute Direct allows customers to connect directly into Microsoft's global network at 10G or 100G ports without an intermediary provider.
Question 17: Which protocol does Application Gateway use for backend health probes when no custom probe is configured?
- ICMP
- HTTPS
- TCP
- HTTP (Correct answer)
Correct answer: HTTP
When no custom probe is defined, Application Gateway uses a default HTTP health probe to check backend pool member availability.
Question 18: What is the ASN Azure VPN Gateway uses by default for BGP if you do not specify a custom ASN?
- 4294967295
- 65535
- 64512
- 65515 (Correct answer)
Correct answer: 65515
Azure VPN Gateway uses ASN 65515 as the default BGP ASN unless a custom private ASN is configured.
Question 19: In an active-active VPN Gateway configuration, what is created to ensure high availability?
- Two gateway instances each with their own public IP and BGP peer (Correct answer)
- One active and one standby instance sharing a single IP
- Two Local Network Gateways
- Two separate VPN gateways in different regions
Correct answer: Two gateway instances each with their own public IP and BGP peer
Active-active mode deploys two gateway instances, each with its own public IP, establishing dual tunnels for redundancy.
Question 20: Which command can be used to view the routing table on a Windows server?
- tracert
- ipconfig
- route print (Correct answer)
- netstat -r
Correct answer: route print
The `route print` command is the standard utility on Windows operating systems for displaying the local IP routing table. It provides detailed information about network destinations, gateways, interfaces, and metrics. This command is crucial for network troubleshooting, verifying connectivity, and understanding how a Windows server routes traffic.
Question 21: Which load balancing method is used by Azure Load Balancer to distribute incoming traffic across all available VMs in a backend pool based on the number of concurrent connections?
- Source IP affinity
- Least connections (Correct answer)
- Round-robin
- Hash-based distribution
Correct answer: Least connections
The 'Least connections' load balancing method used by Azure Load Balancer directs new incoming traffic to the backend instance with the fewest active connections. This method helps to optimize resource utilization and ensure an even distribution of workload across all available virtual machines in the backend pool. By sending traffic to less busy servers, it prevents any single server from becoming overloaded.
Question 22: When configuring a CNAME record in Azure DNS, which limitation applies at the zone apex (root domain)?
- CNAMEs at apex require a wildcard certificate
- CNAMEs cannot be used at the zone apex — use an Alias record instead (Correct answer)
- CNAMEs are allowed at apex with an additional flag
- CNAMEs at apex need a higher DNS TTL
Correct answer: CNAMEs cannot be used at the zone apex — use an Alias record instead
DNS standards prohibit CNAME records at the zone apex (e.g., contoso.com); Azure DNS Alias records solve this for Azure resources.
Question 23: When configuring a Public Load Balancer in Azure, which component is used to define how incoming traffic is distributed to the backend pool instances?
- Network security groups
- Backend pool
- Health probes
- Load balancing rules (Correct answer)
Correct answer: Load balancing rules
When configuring an Azure Public Load Balancer, load balancing rules are the component used to define how incoming traffic is distributed to the backend pool instances. These rules specify the frontend IP address and port, the protocol, and the backend pool to which the traffic should be directed. They also determine the desired load balancing distribution method for the traffic.
Question 24: What is the billing model for ExpressRoute data transfer by default on the Standard and Premium SKUs?
- Unlimited inbound and outbound included
- Flat monthly rate regardless of usage
- Metered — both inbound and outbound charged
- Metered — inbound free, outbound charged per GB (Correct answer)
Correct answer: Metered — inbound free, outbound charged per GB
Standard and Premium ExpressRoute circuits use a metered billing model where inbound data is free but outbound data is charged per GB.
Question 25: Which ExpressRoute peering type provides private connectivity to Azure PaaS services like Azure Storage and Azure SQL without traversing the public internet?
- Service peering
- Public peering
- Microsoft peering (Correct answer)
- Private peering
Correct answer: Microsoft peering
Microsoft peering connects to Azure PaaS and Microsoft 365 services over the ExpressRoute circuit via Microsoft's edge routers.
Question 26: Which Azure service can you use to manage DNS-based load balancing across multiple regions or endpoints for high availability and resilience?
- Azure Load Balancer
- Azure Traffic Manager (Correct answer)
- Azure Front Door
- Azure Application Gateway
Correct answer: Azure Traffic Manager
Azure Traffic Manager is a DNS-based traffic load balancer that enables you to distribute user traffic to service endpoints across global Azure regions. It uses various routing methods to ensure high availability and responsiveness by directing users to the best performing or closest available endpoint. This service is crucial for multi-region deployments requiring global traffic management.
Question 27: What does enabling 'Service Endpoints' on a subnet accomplish?
- Creates a private IP for the Azure service
- Extends the VNet identity to Azure services over the Azure backbone (Correct answer)
- Configures a firewall rule on the service
- Enables DNS resolution for the service
Correct answer: Extends the VNet identity to Azure services over the Azure backbone
Service Endpoints extend the VNet's identity to supported Azure services over the Microsoft backbone, restricting access to that VNet.
Question 28: When configuring VNet peering, which setting must be enabled to allow traffic from a peered network to use the local VNet's gateway?
- Allow forwarded traffic
- Use remote gateways
- Allow gateway transit (Correct answer)
- Allow virtual network access
Correct answer: Allow gateway transit
'Allow gateway transit' must be enabled on the hub VNet so spoke VNets can use its gateway.
Question 29: Which policy must be enabled on a subnet to apply NSG rules and UDRs to Private Endpoint traffic?
- EndpointFirewallPolicy = Active
- ServiceEndpointPolicies = Enabled
- PrivateEndpointNetworkPolicies = Enabled (Correct answer)
- NetworkPolicyEnabled = True
Correct answer: PrivateEndpointNetworkPolicies = Enabled
Setting PrivateEndpointNetworkPolicies to 'Enabled' on a subnet allows NSGs and UDRs to be applied to traffic destined for private endpoints in that subnet.
Question 30: What happens when you deploy a VNet in Azure without specifying a custom DNS server?
- DNS resolution fails until a custom server is added
- Azure-provided DNS (168.63.129.16) is used by default (Correct answer)
- The VNet uses the public internet DNS root servers
- Resources must use their own local resolver
Correct answer: Azure-provided DNS (168.63.129.16) is used by default
By default, Azure uses its internal recursive resolver at 168.63.129.16 for DNS within a VNet.
Question 31: Which protocol must be used for Point-to-Site VPN when Azure AD authentication is selected?
- IKEv2
- L2TP/IPsec
- SSTP
- OpenVPN (Correct answer)
Correct answer: OpenVPN
Azure AD authentication for P2S VPN is only supported with the OpenVPN protocol.
AZ-700: Designing and Implementing Microsoft Azure Networking Solutions
AZ-700 validates skills in designing and implementing core Azure networking infrastructure, hybrid connectivity, application delivery, and network security. It leads to the Microsoft Certified: Azure Network Engineer Associate certification.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds