AZ-800 Cheat Sheet 2026
The 30 highest-yield AZ-800 facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
55 questions
120 min time limit
70.00% to pass
- You need to host a private DNS zone that resolves names for resources inside a virtual network without exposing it publicly. Which Azure service should you use? → Azure Private DNS Zones
- What are the two tiers of Azure DDoS Protection? → DDoS Network Protection and DDoS IP Protection
- Which Traffic Manager routing method allows you to map specific IP address ranges to specific endpoints? → Subnet routing
- Which Azure service provides the 'Effective Routes' feature to view all routes applied to a specific network interface? → Network Watcher
- A multi-national company wants to connect Azure regions across the globe using the Microsoft backbone network with VPN. Which service should they use? → Azure Virtual WAN with global transit routing
- A global e-commerce company wants Traffic Manager to send users to the endpoint with the lowest network latency. Which routing method should they configure? → Performance routing
- A packet capture on a Windows VM fails to start with 'Extension not found'. What must you do? → Install the AzureNetworkWatcherExtension VM extension
- You want Connection Monitor to test connectivity from an on-premises server to an Azure VM. What must you install on the on-premises server? → Log Analytics agent (MMA or AMA)
- NSG flow logs are stored in which Azure service? → Azure Storage Account
- An Application Gateway v2 routing rule must rewrite the response header 'Server' to remove the backend server identity. Which feature enables this? → Rewrite Rules
- An administrator deploys Azure Firewall in a Virtual WAN secured hub. What happens to the hub's routing behavior by default after Firewall deployment? → Routing remains unchanged until routing intent is configured
- You want to allow SSH access to a VM only from a corporate IP range 203.0.113.0/24. Which NSG rule configuration achieves this? → Source: 203.0.113.0/24, Destination: VM private IP, Port: 22, Action: Allow
- Traffic Analytics for NSG flow logs requires which additional Azure service to process and visualize the data? → Log Analytics Workspace
- You need to verify whether a packet from a specific source IP and port is allowed or denied by an NSG without sending real traffic. Which tool do you use? → IP Flow Verify
- A Network Watcher Connection Monitor probe is reporting 'Unreachable' between two Azure VMs. What is the FIRST diagnostic step? → Check NSG rules on both NICs and subnets
- A backend VM must receive the real client IP address through an Azure Standard Load Balancer. What must you enable? → Floating IP (Direct Server Return)
- What skills are tested in the AZ-800 exam? → Managing and implementing hybrid cloud solutions
- An organization has an ExpressRoute Standard circuit. They need to connect VNets in different geopolitical regions. What upgrade is required? → Upgrade to ExpressRoute Premium add-on
- Traffic Analytics uses KQL queries in Log Analytics. Which table contains processed NSG flow log data? → AzureNetworkAnalytics_CL
- Which exam is required to earn the Windows Server Hybrid Administrator Associate certification? → Exam Ref AZ-800 Administering Windows Server Hybrid Core Infrastructure
- Network Watcher's Next Hop feature returns 'None' for a destination IP. What does this indicate? → There is no matching route and packets will be dropped
- Which feature allows you to use Service Endpoint Policies to restrict a subnet's Service Endpoint access to only specific Azure Storage accounts? → Service Endpoint Policies for Azure Storage
- A company deploys Azure Virtual WAN and wants to monitor hub-to-hub latency and traffic metrics. Which Azure service provides this telemetry? → Azure Monitor Metrics for Virtual WAN
- When deploying a Virtual WAN hub, which resource is automatically created and managed by Microsoft within the hub virtual network? → Microsoft-managed router infrastructure and gateway resources
- An IP Flow Verify test returns 'Access Allowed' but the application still cannot connect. What should you investigate next? → The VM's OS firewall (Windows Firewall or iptables)
- Which Azure Monitor metric should you use to monitor the bandwidth utilization of a VPN gateway tunnel? → TunnelAverageBandwidth
- What is the maximum number of VNet peering connections supported per VNet by default? → 500
- What type of Azure Load Balancer rule distributes all ports and protocols with a single rule for high-availability appliances? → HA Ports rule
- A company wants centralized management of Azure Firewall Policies across multiple subscriptions. Which Azure service provides this capability? → Azure Firewall Manager
- Which routing attribute determines the preferred path when multiple ExpressRoute circuits are available for outbound traffic from Azure to on-premises? → BGP MED (Multi-Exit Discriminator)
Turn these facts into recall:
Was this helpful?