AZ-700: Designing and Implementing Microsoft Azure Networking Solutions — Questions and Answers
Question 1: Which scenario requires configuring a DNS forwarding ruleset in Azure DNS Private Resolver?
- Enabling DNSSEC for a public zone
- Resolving Azure Private DNS zones from Azure VMs
- Resolving on-premises DNS names from Azure workloads using outbound endpoint forwarding rules (Correct answer)
- Blocking external DNS queries from reaching Azure
Correct answer: Resolving on-premises DNS names from Azure workloads using outbound endpoint forwarding rules
A DNS forwarding ruleset attached to the outbound endpoint defines rules that forward Azure-originated DNS queries for specific domains to on-premises resolvers.
Question 2: Which VPN Gateway feature lets you define specific traffic selectors instead of routing all traffic through the tunnel?
- Forced tunneling
- Policy-based VPN
- Traffic selector policies on route-based VPN (Correct answer)
- Route-based VPN with BGP
Correct answer: Traffic selector policies on route-based VPN
Traffic selector policies on route-based VPN gateways allow you to specify which traffic flows are protected by the IPsec tunnel.
Question 3: What is required to enable encryption over an ExpressRoute private peering connection?
- Use ExpressRoute Premium with encryption add-on
- Run a VPN Gateway over the ExpressRoute circuit using IPsec/IKE (Correct answer)
- Configure MACsec at the Direct port layer
- Enable IPsec encryption in the circuit settings
Correct answer: Run a VPN Gateway over the ExpressRoute circuit using IPsec/IKE
To encrypt traffic over ExpressRoute private peering, you layer an IPsec/IKE VPN tunnel on top of the ExpressRoute circuit using a VPN Gateway.
Question 4: When you create a Private DNS Zone named 'internal.contoso.com' and link it to a VNet, how do VMs resolve names in that zone?
- They query 8.8.8.8 which forwards to the Private DNS Zone
- They use the Azure-provided DNS resolver (168.63.129.16) which queries the linked Private DNS Zone (Correct answer)
- They require a custom DNS server configured on the VNet
- They use the public Azure DNS resolver
Correct answer: They use the Azure-provided DNS resolver (168.63.129.16) which queries the linked Private DNS Zone
The Azure internal DNS resolver at 168.63.129.16 automatically queries Private DNS Zones linked to the VNet for name resolution.
Question 5: Which HTTP response code does Azure WAF return to clients when it blocks a request in Prevention mode?
- 400 Bad Request
- 401 Unauthorized
- 404 Not Found
- 403 Forbidden (Correct answer)
Correct answer: 403 Forbidden
When WAF blocks a request in Prevention mode, it returns HTTP 403 Forbidden to the client, indicating the request was understood but refused.
Question 6: Which IKE version does Azure VPN Gateway use by default for Route-based VPN connections?
- IKEv3
- IKEv2 (Correct answer)
- IKEv1
- Both IKEv1 and IKEv2 equally
Correct answer: IKEv2
Azure VPN Gateway defaults to IKEv2 for route-based VPN connections, though IKEv1 is supported for policy-based connections.
Question 7: In Azure Virtual Network (VNet) routing, what is the main use of a User Defined Route (UDR)?
- To create a backup route
- To override Azure's default system routes (Correct answer)
- To simplify network management
- To automatically update routing tables
Correct answer: To override Azure's default system routes
User Defined Routes (UDRs) in Azure allow administrators to create custom routing rules that override Azure's default system routes. This provides granular control over network traffic flow within and between VNets, enabling scenarios like forced tunneling to a firewall or routing traffic to a Network Virtual Appliance (NVA) for security or optimization.
Question 8: Which VNet peering type connects virtual networks in different Azure regions?
- Global VNet peering (Correct answer)
- Cross-region peering
- Remote peering
- Local VNet peering
Correct answer: Global VNet peering
Global VNet peering connects virtual networks across different Azure regions.
Question 9: What is the role of Azure Bastion in network security?
- To monitor network traffic
- To provide a secure, managed connection to virtual machines (VMs) without a public IP (Correct answer)
- To provide VPN services
- To manage network routing
Correct answer: To provide a secure, managed connection to virtual machines (VMs) without a public IP
Azure Bastion is a fully managed PaaS service that provides secure and seamless RDP/SSH connectivity to your virtual machines directly through the Azure portal over SSL. It eliminates the need for public IP addresses on your VMs, significantly enhancing security by preventing direct exposure to the internet and reducing the attack surface.
Question 10: Which ExpressRoute peering type requires you to register route filters to control which BGP communities are received?
- Microsoft peering (Correct answer)
- Local peering
- Private peering
- Global Reach peering
Correct answer: Microsoft peering
Microsoft peering requires route filters to be configured in Azure to select which BGP service communities (e.g., specific Azure regions or M365) you receive.
Question 11: What is the purpose of a Network Security Group (NSG) in Azure?
- To manage user access to Azure resources
- To encrypt data at rest
- To filter network traffic to and from Azure resources (Correct answer)
- To create virtual networks
Correct answer: To filter network traffic to and from Azure resources
A Network Security Group (NSG) acts as a virtual firewall for Azure resources, allowing or denying inbound and outbound network traffic based on defined rules. NSGs provide a fundamental layer of security by controlling access to VMs, subnets, and other network interfaces. They help protect resources from unauthorized access and malicious traffic.
Question 12: Which Application Gateway feature allows you to display branded HTML pages instead of default error responses for 403 and 502 status codes?
- Listener error handling policies
- WAF custom rules
- Backend health monitoring
- Custom error pages (Correct answer)
Correct answer: Custom error pages
Application Gateway supports custom error pages for HTTP 403 (WAF block) and 502 (bad gateway) responses, enabling a branded error experience.
Question 13: Which backend member type is supported by Azure Application Gateway backend pools?
- Azure Blob Storage static website URLs
- Azure Service Bus queue endpoints
- Azure Event Hub consumer groups
- Virtual machines and VM scale set instances (Correct answer)
Correct answer: Virtual machines and VM scale set instances
Application Gateway backend pools support virtual machines, VM scale sets, App Service web apps, and on-premises servers accessible via IP or FQDN.
Question 14: Which Application Gateway feature ensures that requests from the same client session are always directed to the same backend server?
- Custom health probes
- Cookie-based session affinity (Correct answer)
- Connection draining
- URL rewrite rules
Correct answer: Cookie-based session affinity
Cookie-based session affinity uses a gateway-managed cookie to route requests from the same client session to the same backend server.
Question 15: When configuring a Point-to-Site VPN, which authentication method uses certificates stored in Azure AD?
- Certificate authentication
- Azure AD authentication (Correct answer)
- IKEv2 PSK
- RADIUS authentication
Correct answer: Azure AD authentication
Azure AD authentication for P2S VPN allows users to authenticate using their Azure AD credentials via the OpenVPN protocol.
Question 16: When you configure a URL redirect rule in Application Gateway, what does the gateway send to the client?
- A proxy response transparently fetching content from the redirect target
- An HTTP redirect response instructing the browser to navigate to a different URL (Correct answer)
- It rewrites the URL path in the forwarded backend request silently
- A TCP reset to force the client to reconnect to a different endpoint
Correct answer: An HTTP redirect response instructing the browser to navigate to a different URL
URL redirect sends an HTTP 301 or 302 redirect response to the client, instructing the browser to request a different URL.
Question 17: Which Application Gateway feature allows you to add, remove, or modify HTTP request and response headers as traffic passes through?
- Backend HTTP settings
- Rewrite rules (Correct answer)
- Custom health probes
- URL path routing
Correct answer: Rewrite rules
Rewrite rules allow modification of HTTP request and response headers, as well as URL paths, as traffic flows through Application Gateway.
Question 18: When a Private Endpoint is created, what network policy must be disabled on the subnet to allow the private IP assignment?
- Network Security Group policies
- Service endpoint policies
- Private endpoint network policies (PrivateEndpointNetworkPolicies) (Correct answer)
- Route table policies
Correct answer: Private endpoint network policies (PrivateEndpointNetworkPolicies)
The subnet property 'PrivateEndpointNetworkPolicies' must be set to Disabled to allow private endpoints to be deployed in that subnet.
Question 19: In Azure, which private IP allocation method guarantees the same IP address is assigned to a VM each time it starts?
- Pinned
- Reserved
- Dynamic
- Static (Correct answer)
Correct answer: Static
Setting the private IP allocation method to 'Static' ensures the VM always receives the same IP address from the subnet.
Question 20: Which Azure feature provides a managed ExpressRoute connection without requiring a dedicated circuit from a provider?
- Azure Peering Service
- ExpressRoute Direct (Correct answer)
- ExpressRoute Global Reach
- Azure Virtual WAN with ExpressRoute gateway
Correct answer: ExpressRoute Direct
ExpressRoute Direct allows customers to connect directly into Microsoft's global network at 10G or 100G ports without an intermediary provider.
Question 21: Which Azure Monitor feature provides metrics and logs for your virtual networks, including data about traffic, throughput, and network latency?
- Application Insights
- Activity Log
- Network Performance Monitor (Correct answer)
- Metrics Explorer
Correct answer: Network Performance Monitor
Network Performance Monitor (NPM) is a feature within Azure Monitor specifically designed to provide comprehensive visibility into network health and performance. It collects metrics and logs related to network connectivity, latency, and packet loss across your Azure virtual networks and hybrid connections. This makes NPM the ideal tool for diagnosing and troubleshooting network-related issues within your Azure infrastructure.
Question 22: What feature of Network Watcher allows you to monitor the latency and availability of connections between Azure regions and between your on-premises locations and Azure?
- Connection Monitor (Correct answer)
- Azure Traffic Analytics
- Network Security Group (NSG) Flow Logs
- Network Performance Monitor
Correct answer: Connection Monitor
Connection Monitor, a feature within Azure Network Watcher, provides unified, end-to-end connection monitoring for hybrid and Azure cloud deployments. It allows you to monitor network connectivity, latency, and packet loss between Azure regions, VNets, and your on-premises locations. This helps in identifying and diagnosing network performance issues proactively.
Question 23: Which load balancing method is used by Azure Load Balancer to distribute incoming traffic across all available VMs in a backend pool based on the number of concurrent connections?
- Source IP affinity
- Round-robin
- Hash-based distribution
- Least connections (Correct answer)
Correct answer: Least connections
The 'Least connections' load balancing method used by Azure Load Balancer directs new incoming traffic to the backend instance with the fewest active connections. This method helps to optimize resource utilization and ensure an even distribution of workload across all available virtual machines in the backend pool. By sending traffic to less busy servers, it prevents any single server from becoming overloaded.
Question 24: Which WAF policy association scope allows different WAF configurations to be applied to individual listeners on the same Application Gateway?
- Backend pool WAF policy scoped to target servers
- Per-site (per-listener) WAF policy (Correct answer)
- Per-URI WAF policy scoped to URL paths
- Global WAF policy applied to the entire gateway
Correct answer: Per-site (per-listener) WAF policy
Per-site WAF policies allow different WAF configurations, including custom rules and exclusions, to be applied to individual listeners on the same Application Gateway instance.
Question 25: What does end-to-end SSL mean in the context of Azure Application Gateway?
- SSL is only applied between Application Gateway and the internet
- Application Gateway manages SSL certificate lifecycle for all backends
- Traffic is encrypted from the client through the gateway to the backend servers (Correct answer)
- SSL is terminated at the gateway and backends receive plain HTTP
Correct answer: Traffic is encrypted from the client through the gateway to the backend servers
End-to-end SSL maintains encrypted HTTPS communication from client to Application Gateway, and the gateway re-encrypts traffic before sending it to backend servers.
Question 26: What type of Azure Load Balancer provides high availability by distributing incoming network traffic across multiple virtual machines (VMs) inside a virtual network?
- Public Load Balancer
- Application Gateway
- Internal Load Balancer (Correct answer)
- Traffic Manager
Correct answer: Internal Load Balancer
An Internal Load Balancer (ILB) in Azure is used to distribute incoming network traffic among virtual machines (VMs) within a virtual network. Unlike a Public Load Balancer, an ILB is not exposed to the internet, making it suitable for internal applications and services. It ensures high availability and even traffic distribution among healthy backend instances for internal workloads.
Question 27: In Azure, what is the main function of a VPN Gateway?
- To encrypt data at rest
- To manage user authentication
- To filter inbound traffic
- To establish secure connections between on-premises networks and Azure VNets (Correct answer)
Correct answer: To establish secure connections between on-premises networks and Azure VNets
An Azure VPN Gateway is used to create secure, encrypted connections between an on-premises network and an Azure Virtual Network (VNet) over the public internet. This enables hybrid cloud scenarios, allowing resources in Azure to communicate securely with resources in your datacenter. It's essential for extending your corporate network into Azure.
Question 28: Which Azure service provides end-to-end visibility into your network by allowing you to diagnose and monitor your network resources?
- Azure Traffic Manager
- Azure Site Recovery
- Network Watcher (Correct answer)
- Azure Firewall
Correct answer: Network Watcher
Azure Network Watcher is a suite of tools designed to monitor, diagnose, and gain insights into your Azure virtual network. It provides end-to-end visibility into network performance, security, and connectivity. This service is crucial for identifying and resolving network issues, ensuring the smooth operation of your Azure infrastructure.
Question 29: How many BGP sessions does a standard ExpressRoute private peering configuration use?
- Dynamic — scales based on route count
- 4 — two per peering location
- 1 — a single BGP session to Microsoft
- 2 — one primary and one secondary for redundancy (Correct answer)
Correct answer: 2 — one primary and one secondary for redundancy
ExpressRoute private peering requires two BGP sessions (primary and secondary) for built-in redundancy across the two physical links.
Question 30: Which statement is TRUE about network traffic flowing through a Private Endpoint?
- Traffic is routed through Azure Firewall by default
- Traffic traverses the public internet with encryption
- Traffic uses BGP routing over ExpressRoute
- Traffic stays entirely within the Microsoft backbone and never crosses the public internet (Correct answer)
Correct answer: Traffic stays entirely within the Microsoft backbone and never crosses the public internet
Private Endpoint traffic remains on the Microsoft global network, never crossing the public internet, providing a private and secure path to Azure services.
Question 31: Which Azure service can you use to manage DNS-based load balancing across multiple regions or endpoints for high availability and resilience?
- Azure Load Balancer
- Azure Traffic Manager (Correct answer)
- Azure Front Door
- Azure Application Gateway
Correct answer: Azure Traffic Manager
Azure Traffic Manager is a DNS-based traffic load balancer that enables you to distribute user traffic to service endpoints across global Azure regions. It uses various routing methods to ensure high availability and responsiveness by directing users to the best performing or closest available endpoint. This service is crucial for multi-region deployments requiring global traffic management.
Question 32: What is the smallest subnet size you can create in an Azure VNet?
- /28
- /30
- /29 (Correct answer)
- /32
Correct answer: /29
Azure supports subnets as small as /29, which provides 3 usable IP addresses after reserving 5 Azure addresses.
Question 33: What address space overlap rule applies to Azure VNet peering?
- Overlapping address spaces are allowed with NAT
- Address spaces must not overlap (Correct answer)
- Overlap is allowed for global peering only
- Only the first /24 must be unique
Correct answer: Address spaces must not overlap
VNet peering requires that the address spaces of the peered VNets do not overlap.
Question 34: What is an Azure Private Link Service alias used for?
- Maps to a DNS CNAME for the service
- Is a globally unique name used by consumers to request a connection to your Private Link Service (Correct answer)
- Identifies the load balancer frontend configuration
- Provides a shorter name for the Private Endpoint IP
Correct answer: Is a globally unique name used by consumers to request a connection to your Private Link Service
The Private Link Service alias is a globally unique string that consumers use to identify and request a connection to your service without needing full resource IDs.
Question 35: Which Azure resource must be deployed in your VNet to connect it to an ExpressRoute circuit?
- ExpressRoute Gateway (Virtual Network Gateway with type ExpressRoute) (Correct answer)
- VPN Gateway
- Application Gateway
- Azure Firewall
Correct answer: ExpressRoute Gateway (Virtual Network Gateway with type ExpressRoute)
An ExpressRoute Virtual Network Gateway is required in each VNet you want to connect to the ExpressRoute circuit.
Question 36: What is the impact of setting autoRegistration to true on multiple VNet links to the same Private DNS Zone?
- It causes DNS conflicts and must be avoided
- Each VNet's VMs register in the shared zone, enabling cross-VNet hostname resolution (Correct answer)
- It enables zone transfer between VNets
- Only the first VNet's VMs are registered
Correct answer: Each VNet's VMs register in the shared zone, enabling cross-VNet hostname resolution
Multiple VNets can auto-register into the same Private DNS Zone (up to 100), allowing VMs across all linked VNets to resolve each other by hostname.
Question 37: Which Azure service provides load balancing at the application layer (Layer 7) and includes features like SSL termination, URL-based routing, and Web Application Firewall (WAF)?
- Azure Front Door
- Azure Traffic Manager
- Azure Application Gateway (Correct answer)
- Azure Load Balancer
Correct answer: Azure Application Gateway
Azure Application Gateway operates at Layer 7 (the application layer) and provides advanced load balancing capabilities specifically for web traffic. It includes features like SSL termination, URL-based routing, session affinity, and an integrated Web Application Firewall (WAF). This makes it ideal for securing, managing, and optimizing traffic to your web applications.
Question 38: How many private IPs does a single Private Endpoint consume from the subnet's address space?
- One private IP per Private Endpoint (Correct answer)
- It depends on the service tier
- It shares the subnet's Azure-reserved IPs
- One per sub-resource (group ID)
Correct answer: One private IP per Private Endpoint
Each Private Endpoint consumes exactly one private IP address from the subnet, regardless of the number of ports or protocols the service uses.
Question 39: Which tool can you use to validate effective routes on a VM's NIC in Azure?
- Azure Advisor
- Traffic Analytics
- Network Watcher — Effective Routes (Correct answer)
- Route Analyzer in Azure Monitor
Correct answer: Network Watcher — Effective Routes
Azure Network Watcher's 'Effective Routes' feature shows the combined routing table applied to a specific NIC.
Question 40: What is an Azure Private Endpoint?
- A DNS alias for an Azure service
- A VNet peering connection to a PaaS service
- A public IP address assigned to an Azure PaaS service
- A network interface with a private IP that connects to an Azure service via Private Link (Correct answer)
Correct answer: A network interface with a private IP that connects to an Azure service via Private Link
A Private Endpoint is a NIC with a private IP from your VNet subnet, connected to an Azure service through the Private Link service.
Question 41: Which Azure networking feature allows you to restrict which specific resources (not just subnets) can access an Azure Storage account via Service Endpoints?
- Network Security Groups
- Service Endpoint Policies (Correct answer)
- Private Link Service filters
- Azure Firewall FQDN rules
Correct answer: Service Endpoint Policies
Service Endpoint Policies let you specify exact Azure Storage accounts (or other resources) that a subnet can reach via Service Endpoints, providing resource-level granularity.
Question 42: Which Azure VPN Gateway SKU is NOT supported for production workloads and should only be used for dev/test?
- VpnGw3
- Basic (Correct answer)
- VpnGw1
- VpnGw2AZ
Correct answer: Basic
The Basic SKU is a legacy gateway intended for dev/test scenarios and does not support many production features like BGP or active-active.
Question 43: In Azure DNS, what is the minimum TTL (Time to Live) value allowed for a DNS record?
- 0 (Correct answer)
- 300 seconds
- 60 seconds
- 1 second
Correct answer: 0
Azure DNS allows a TTL of 0, though values this low are impractical and Microsoft recommends a minimum TTL of 300 seconds.
Question 44: Which Azure service is primarily used for monitoring the performance and health of Azure resources, including virtual networks and network traffic?
- Azure Blob Storage
- Azure Active Directory
- Azure Key Vault
- Azure Monitor (Correct answer)
Correct answer: Azure Monitor
Azure Monitor is a comprehensive service that collects, analyzes, and acts on telemetry data from your Azure and on-premises environments. It provides unified monitoring capabilities for the performance and health of all your Azure resources, including virtual networks and network traffic. This allows for proactive issue resolution and performance optimization.
Question 45: Which Azure VPN feature allows branch offices to connect to each other through a hub without individual branch-to-branch tunnels?
- VNet peering transit
- ExpressRoute FastPath
- VPN Gateway BGP
- Virtual WAN (Correct answer)
Correct answer: Virtual WAN
Azure Virtual WAN provides hub-based connectivity allowing branch-to-branch communication through Microsoft's backbone without direct tunnels.
Question 46: Which command can be used to view the routing table on a Windows server?
- route print (Correct answer)
- tracert
- netstat -r
- ipconfig
Correct answer: route print
The `route print` command is the standard utility on Windows operating systems for displaying the local IP routing table. It provides detailed information about network destinations, gateways, interfaces, and metrics. This command is crucial for network troubleshooting, verifying connectivity, and understanding how a Windows server routes traffic.
Question 47: What are the two operating modes available for Azure WAF on Application Gateway?
- Learning mode and Enforcement mode
- Active mode and Passive mode
- Detection mode and Prevention mode (Correct answer)
- Monitor mode and Block mode
Correct answer: Detection mode and Prevention mode
WAF operates in Detection mode (logs threats without blocking) or Prevention mode (logs and actively blocks malicious requests).
Question 48: Which Azure feature allows you to delegate a subdomain to Azure DNS while keeping the parent zone with another registrar?
- Zone transfer
- DNS forwarding
- DNS alias chaining
- NS record delegation (Correct answer)
Correct answer: NS record delegation
By creating NS records for the subdomain at the parent registrar pointing to Azure DNS name servers, you delegate that subdomain to Azure DNS.
Question 49: What does ExpressRoute FastPath do?
- Increases circuit bandwidth beyond the provisioned tier
- Accelerates BGP route convergence
- Enables sub-50ms SLA for ExpressRoute
- Bypasses the ExpressRoute Gateway to send data plane traffic directly to VNet VMs (Correct answer)
Correct answer: Bypasses the ExpressRoute Gateway to send data plane traffic directly to VNet VMs
FastPath bypasses the ExpressRoute Virtual Network Gateway for data plane traffic, sending packets directly to VMs to reduce latency and increase throughput.
Question 50: What is the purpose of an Azure Private DNS Zone?
- Enables DNSSEC for VNets
- Hosts public DNS records for custom domains
- Provides name resolution for resources within Azure VNets without public DNS exposure (Correct answer)
- Replaces Azure DNS public zones
Correct answer: Provides name resolution for resources within Azure VNets without public DNS exposure
Azure Private DNS Zones provide DNS name resolution scoped to linked VNets, keeping records private and not resolvable from the internet.
Question 51: At which OSI layer does Azure Application Gateway primarily operate?
- Layer 7 (Application) (Correct answer)
- Layer 3 (Network)
- Layer 5 (Session)
- Layer 4 (Transport)
Correct answer: Layer 7 (Application)
Application Gateway operates at Layer 7, enabling routing decisions based on HTTP/HTTPS attributes such as URLs, headers, and cookies.
Question 52: When an ExpressRoute circuit and a VPN Gateway coexist in the same VNet, which connection type takes precedence for on-premises traffic by default?
- Both are used simultaneously via ECMP
- VPN Gateway always takes precedence
- ExpressRoute takes precedence (Correct answer)
- The connection with the lower latency wins
Correct answer: ExpressRoute takes precedence
In coexistence scenarios, ExpressRoute connections are preferred over VPN by default due to their higher AS path weight in BGP.
Question 53: What tool within Azure Monitor is used to collect and analyze log data from various Azure resources, including network resources?
- Azure Policy
- Application Insights
- Network Watcher
- Log Analytics (Correct answer)
Correct answer: Log Analytics
Log Analytics is a powerful tool within Azure Monitor that allows you to collect, index, and analyze log data from various Azure resources, including network resources. It provides a query language and dashboards for deep insights into operational data, security events, and performance metrics. This helps in troubleshooting, auditing, and understanding resource behavior.
Question 54: What is an ExpressRoute circuit's 'service key' used for?
- Encrypts data traversing the circuit
- Identifies the circuit to the connectivity provider for provisioning (Correct answer)
- Serves as the BGP authentication password
- Activates Premium add-ons
Correct answer: Identifies the circuit to the connectivity provider for provisioning
The service key is a unique identifier for the ExpressRoute circuit that you provide to your connectivity provider to enable provisioning.
Question 55: What is a managed ruleset in Azure WAF?
- Automatically generated rules based on machine learning traffic analysis
- A pre-configured set of rules maintained by Microsoft protecting against known web vulnerabilities (Correct answer)
- A set of rules created and fully managed by the application owner
- Rules imported from third-party security marketplace solutions
Correct answer: A pre-configured set of rules maintained by Microsoft protecting against known web vulnerabilities
Managed rulesets are pre-configured security rules maintained and updated by Microsoft to protect against common web vulnerabilities without requiring manual rule authoring.
AZ-700: Designing and Implementing Microsoft Azure Networking Solutions
AZ-700 validates skills in designing and implementing core Azure networking infrastructure, hybrid connectivity, application delivery, and network security. It leads to the Microsoft Certified: Azure Network Engineer Associate certification.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds