Microsoft · AZ-700 · Associate
Designing and Implementing Microsoft Azure Networking Solutions (AZ-700) — Practice Questions and Mock Exam
Practice real AZ-700 questions, never dumps. Alex explains every answer, and your readiness score tells you when you're ready to pass.
Checked against Microsoft · July 2026Current exam version
Overview
About the exam
The AZ-700 certification validates expertise in designing, implementing, and maintaining Azure networking solutions. It covers virtual networks, hybrid networking, routing, load balancing, application delivery, private access to Azure services, and network security. Candidates must demonstrate proficiency with VNet peering, VPN gateways, ExpressRoute, Azure Front Door, Azure Firewall, and DNS configuration.
This certification is designed for network engineers who specialize in Azure networking infrastructure. Candidates should have significant experience with on-premises networking concepts and hands-on Azure networking skills, including configuring and troubleshooting complex hybrid connectivity and network security architectures.
Exam Domains
What's on the exam
The exam consists of 40–60 questions to be completed in approximately 100 minutes (100 minutes if labs are included). Question types include multiple-choice, multiple-select, drag-and-drop, hot area, and case study formats. Questions heavily test network topology design, routing tables, load balancer configurations, and VPN/ExpressRoute troubleshooting. Expect detailed scenarios requiring you to select correct IP addressing and connectivity solutions.
Design and implement IP addressing (network segmentation, VNets, subnets, subnet delegation, public IP prefixes), name resolution (DNS settings, public/private DNS zones, Azure DNS Private Resolver), VNet connectivity and routing (service chaining, VNet peering, UDRs, forced tunneling, Route Server, NAT Gateway), and monitor networks (Network Watcher, Azure Monitor, DDoS protection, Defender for Cloud)
Design and manage site-to-site VPN connections (high availability, gateway SKUs, IPsec/IKE policies, local network gateways), point-to-site VPN (tunnel types, authentication including RADIUS and Entra ID, Always On VPN), Azure ExpressRoute (connectivity models, SKUs, Global Reach, FastPath, Direct, peering), and Azure Virtual WAN architecture (hub routing, NVA integration)
Design and implement Azure Load Balancer and Traffic Manager (SKU selection, regional/cross-region, Gateway Load Balancer, NAT rules, outbound rules), Azure Application Gateway (autoscale, backend pools, health probes, listeners, routing rules, TLS, rewrite rules), and Azure Front Door (routing, origins, endpoints, TLS, caching, traffic acceleration, URL rewrite/redirect, Private Link)
Design and implement Azure Private Link service and private endpoints (planning, configuration, DNS integration, on-premises client integration) and design and implement service endpoints (endpoint policies, access configuration)
Implement and manage NSGs (ASGs, security rules, VNet flow logs, IP flow verification, Azure Bastion, Virtual Network Manager), design and implement Azure Firewall and Firewall Manager (SKU selection, deployment, rules, policies, secured hubs), and design and implement WAF (detection/prevention mode, rule sets for Front Door and Application Gateway)
SourceMicrosoft study guide
Format
What to expect
Watch out
Where candidates struggle
This exam goes deep into Azure networking specifics. Candidates with general cloud experience but limited Azure networking hands-on practice often struggle with the detailed routing and connectivity questions.
- 01Routing Precedence — Not understanding Azure route evaluation order including system routes, UDRs, and BGP routes and their precedence.
- 02Load Balancer SKUs — Confusing Standard vs Basic Load Balancer capabilities and when to use Azure Load Balancer vs Application Gateway vs Front Door.
- 03ExpressRoute Circuits — Struggling with ExpressRoute peering types (Private, Microsoft), circuit redundancy, and Global Reach configurations.
- 04DNS Resolution — Overlooking Azure Private DNS zone configurations, DNS forwarding, and hybrid DNS resolution for private endpoints.
- 05Network Segmentation — Not designing proper subnet segmentation with NSGs, ASGs, and Azure Firewall for defense-in-depth network security.
Details
Exam logistics
Delivered via Pearson VUE online or at testing centers. Available in English, Japanese, Chinese, Korean, French, German, and Spanish. The certification is valid for 1 year with a free renewal assessment on Microsoft Learn.
SourceMicrosoft exam page
Before you book the exam
Would you pass AZ-700 today?
Take the free readiness check. Answer real AZ-700 questions and get your readiness score across every domain.
Take the free readiness check20 questions · freeReach 80% readiness by exam day. Pass, or your money back.