AZ-700 Azure Network Engineer Associate Exam — Questions and Answers
Question 1: Which approach is most effective for problem-solving in Virtual Networks?
- Always asking someone else
- Random trial and error
- Ignoring the problem until it resolves itself
- Systematic analysis followed by evidence-based decision making (Correct answer)
Correct answer: Systematic analysis followed by evidence-based decision making
Systematic, evidence-based approaches lead to more reliable solutions than ad hoc methods.
Question 2: Which Azure security service allows administrators to set policies for access to Azure resources based on conditions such as user location or device state?
- Azure DDoS Protection
- Conditional Access in Azure Active Directory (Correct answer)
- Azure Firewall
- Azure Policy
Correct answer: Conditional Access in Azure Active Directory
Conditional Access in Azure Active Directory allows administrators to implement policies that control access to Azure resources based on specific conditions. These conditions can include user location, device compliance, application sensitivity, and sign-in risk. This enables organizations to enforce stronger security requirements, such as multi-factor authentication, only when necessary, enhancing security without hindering productivity.
Question 3: Which next hop type in a User Defined Route directs traffic to a network virtual appliance (NVA) running in Azure?
- VirtualAppliance (Correct answer)
- Internet
- VnetLocal
- VirtualNetworkGateway
Correct answer: VirtualAppliance
The 'VirtualAppliance' next hop type routes traffic to a specified private IP address, typically an NVA such as a firewall or router VM.
Question 4: What is the purpose of a private DNS zone group on a private endpoint?
- To group multiple private endpoints under a single DNS zone
- To configure BGP routing for the private endpoint
- To assign a custom domain name to the private endpoint
- To automatically create and manage DNS records in a linked private DNS zone (Correct answer)
Correct answer: To automatically create and manage DNS records in a linked private DNS zone
A private DNS zone group links a private endpoint to a private DNS zone and automatically creates/updates the DNS A record when the endpoint is created or deleted.
Question 5: How does technology impact modern practices in Virtual Networks?
- Technology is only useful for record keeping
- Technology has no impact on this field
- Technology improves efficiency, accuracy, and access to information while requiring new skills (Correct answer)
- Technology replaces all human judgment
Correct answer: Technology improves efficiency, accuracy, and access to information while requiring new skills
Technology enhances capabilities while also requiring practitioners to develop new competencies.
Question 6: What is the most important foundational concept in Network Security?
- Memorizing all rules without understanding
- Only following instructions from supervisors
- Ignoring established guidelines
- Understanding core principles and their practical application in Network Security (Correct answer)
Correct answer: Understanding core principles and their practical application in Network Security
Core principles provide the foundation for all decision-making and practice in Network Security.
Question 7: What does Azure Private Link Center provide?
- BGP route tables for Private Link traffic
- Centralized monitoring and management for private endpoints and Private Link services (Correct answer)
- A DNS configuration wizard for private endpoints
- A billing dashboard for Private Link data transfer costs
Correct answer: Centralized monitoring and management for private endpoints and Private Link services
Azure Private Link Center is a portal hub that gives you a unified view for monitoring, managing, and auditing all private endpoints and Private Link services in your subscription.
Question 8: In the Zero Trust security model, which of the following is a core concept?
- Only authenticating users from internal IP addresses
- Blocking all traffic to external networks by default
- Allowing all internal traffic by default
- Verifying each access request as though it originates from an open network (Correct answer)
Correct answer: Verifying each access request as though it originates from an open network
A core concept of the Zero Trust security model is 'never trust, always verify.' This means that every access request, whether from inside or outside the network, is treated as if it originates from an untrusted environment. It requires strict identity verification, device validation, and least privilege access for every connection, rather than assuming trust based on network location.
Question 9: How should ethical dilemmas be handled in Load Balancing and DNS?
- Ignore ethical concerns
- Follow established ethical guidelines, consult with supervisors, and prioritize stakeholder welfare (Correct answer)
- Always choose the cheapest option
- Make decisions based solely on personal preference
Correct answer: Follow established ethical guidelines, consult with supervisors, and prioritize stakeholder welfare
Ethical decision-making requires following professional guidelines and prioritizing the welfare of all stakeholders.
Question 10: How many VNets can a Standard-tier ExpressRoute circuit be linked to by default?
- 10 (Correct answer)
- 20
- Unlimited
- 4
Correct answer: 10
A Standard ExpressRoute circuit can be linked to up to 10 Azure virtual networks; upgrading to the Premium add-on increases this limit significantly.
Question 11: Which Azure resource is automatically created when you configure a private endpoint?
- A network interface with a private IP (Correct answer)
- A NAT gateway
- A load balancer rule
- A VPN gateway
Correct answer: A network interface with a private IP
Configuring a private endpoint automatically creates a network interface (NIC) with a private IP address in the designated subnet.
Question 12: Which Azure Firewall rule collection type should be used to allow an on-premises server to initiate RDP sessions to Azure VMs?
- Application rule collection
- DNAT rule collection
- Network rule collection (Correct answer)
- NAT rule collection with SNAT
Correct answer: Network rule collection
Network rule collections handle Layer 4 traffic (TCP/UDP/ICMP) based on source/destination IP and port, which is appropriate for allowing RDP on port 3389.
Question 13: What is the purpose of a Local Network Gateway resource in Azure?
- It represents the Azure VPN Gateway endpoint
- It configures BGP peering for ExpressRoute private peering
- It defines the on-premises VPN device's public IP and address space for a site-to-site connection (Correct answer)
- It stores the shared key for point-to-site VPN connections
Correct answer: It defines the on-premises VPN device's public IP and address space for a site-to-site connection
A Local Network Gateway is an Azure object that represents your on-premises VPN device, specifying its public IP address and the on-premises address prefixes that Azure needs to route to it.
Question 14: What role does continuing education play in Connectivity Solutions?
- Only beneficial for management
- Only required for new practitioners
- Keeping practitioners current with evolving best practices and new developments (Correct answer)
- It is optional and rarely helpful
Correct answer: Keeping practitioners current with evolving best practices and new developments
Continuing education ensures practitioners stay current with advances in their field.
Question 15: When configuring VNet peering between two virtual networks in different Azure regions, what is this configuration called?
- Local VNet peering
- ExpressRoute peering
- Global VNet peering (Correct answer)
- Cross-region VPN
Correct answer: Global VNet peering
VNet peering between virtual networks in different Azure regions is called global VNet peering, and it uses the Microsoft backbone network.
Question 16: How many private endpoints can reference the same Private Link resource?
- Up to 10
- Multiple private endpoints can connect to the same resource (Correct answer)
- Only one
- Up to 100, with a support request
Correct answer: Multiple private endpoints can connect to the same resource
Multiple private endpoints in different VNets or subscriptions can all connect to the same Private Link resource simultaneously.
Question 17: Which Azure Virtual WAN component is responsible for managing route propagation and aggregation between connected branches, VNets, and hubs?
- Azure Route Server
- Virtual Hub Router (Correct answer)
- Azure Firewall Manager
- ExpressRoute Gateway
Correct answer: Virtual Hub Router
The Virtual Hub Router is the built-in routing engine within each Azure Virtual WAN hub that manages route tables, propagation, and association for all connected resources.
Question 18: Which IP address range is NOT a valid private IP address range per RFC 1918?
- 10.0.0.0/8
- 192.168.0.0/16
- 172.16.0.0/12
- 198.51.100.0/24 (Correct answer)
Correct answer: 198.51.100.0/24
198.51.100.0/24 (TEST-NET-2) is reserved for documentation purposes, not private use; the RFC 1918 ranges are 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16.
Question 19: How does technology impact modern practices in Load Balancing and DNS?
- Technology improves efficiency, accuracy, and access to information while requiring new skills (Correct answer)
- Technology replaces all human judgment
- Technology is only useful for record keeping
- Technology has no impact on this field
Correct answer: Technology improves efficiency, accuracy, and access to information while requiring new skills
Technology enhances capabilities while also requiring practitioners to develop new competencies.
Question 20: What is the primary purpose of Azure Private Link?
- To access Azure PaaS services over a private IP address within your VNet (Correct answer)
- To connect Azure VNets using peering
- To expose internal services to the public internet
- To configure DNS resolution for Azure services
Correct answer: To access Azure PaaS services over a private IP address within your VNet
Azure Private Link enables you to access Azure PaaS services (like Azure Storage and SQL) through a private endpoint using a private IP in your virtual network.
Question 21: What is the primary purpose of standardized procedures in Load Balancing and DNS?
- To benefit only management
- To ensure consistency, safety, and quality across all practitioners (Correct answer)
- To create unnecessary bureaucracy
- To slow down work processes
Correct answer: To ensure consistency, safety, and quality across all practitioners
Standardized procedures ensure that all practitioners deliver consistent, safe, and high-quality outcomes.
Question 22: What is the significance of documentation in Load Balancing and DNS?
- It provides a record for accountability, quality assurance, and legal compliance (Correct answer)
- Only management needs to document
- Documentation is unnecessary busy work
- Only required during audits
Correct answer: It provides a record for accountability, quality assurance, and legal compliance
Proper documentation supports accountability, enables quality review, and satisfies legal requirements.
Question 23: What is the significance of documentation in Virtual Networks?
- Only management needs to document
- It provides a record for accountability, quality assurance, and legal compliance (Correct answer)
- Documentation is unnecessary busy work
- Only required during audits
Correct answer: It provides a record for accountability, quality assurance, and legal compliance
Proper documentation supports accountability, enables quality review, and satisfies legal requirements.
Question 24: What quality metrics are most important in Virtual Networks?
- Measurable outcomes, process compliance, and stakeholder satisfaction (Correct answer)
- Only financial metrics
- No metrics are needed
- Only speed of completion
Correct answer: Measurable outcomes, process compliance, and stakeholder satisfaction
Quality in Virtual Networks is measured through multiple dimensions including outcomes, processes, and satisfaction.
Question 25: Why are private DNS zones important when using private endpoints?
- To restrict traffic to specific subnets
- To resolve the service's public FQDN to its private IP address (Correct answer)
- To assign static IPs to private endpoints
- To enable BGP routing for private endpoints
Correct answer: To resolve the service's public FQDN to its private IP address
Private DNS zones are used so that the service's FQDN (e.g., mystorageaccount.blob.core.windows.net) resolves to the private endpoint's private IP instead of the public IP.
Question 26: What routing protocol does ExpressRoute use to exchange routes with Azure?
- OSPF
- RIP
- BGP (Border Gateway Protocol) (Correct answer)
- EIGRP
Correct answer: BGP (Border Gateway Protocol)
ExpressRoute exclusively uses BGP (Border Gateway Protocol) for dynamic route exchange between your on-premises network and Azure.
Question 27: Which VPN Gateway SKU naming convention indicates availability zone redundancy?
- The SKU name starts with 'Zone-'
- The SKU name ends in 'AZ' (e.g., VpnGw1AZ) (Correct answer)
- The SKU name ends in 'ZR'
- The SKU name includes 'HA'
Correct answer: The SKU name ends in 'AZ' (e.g., VpnGw1AZ)
Zone-redundant VPN Gateway SKUs are identified by the 'AZ' suffix (e.g., VpnGw1AZ, VpnGw2AZ), deploying gateway instances across availability zones for higher resilience.
Question 28: What is the primary purpose of standardized procedures in Network Security?
- To create unnecessary bureaucracy
- To slow down work processes
- To ensure consistency, safety, and quality across all practitioners (Correct answer)
- To benefit only management
Correct answer: To ensure consistency, safety, and quality across all practitioners
Standardized procedures ensure that all practitioners deliver consistent, safe, and high-quality outcomes.
Question 29: What does a 'black hole' route mean in the context of Azure networking?
- A route used for diagnostic packet capture purposes
- A route with next hop type 'None' that silently drops matching traffic (Correct answer)
- A route that loops traffic back to the originating VM
- A route that sends traffic to the nearest Microsoft backbone node
Correct answer: A route with next hop type 'None' that silently drops matching traffic
A black hole route uses the 'None' next hop type, causing Azure to silently discard all traffic matching that destination prefix without sending an ICMP unreachable message.
Question 30: How should risk be managed in Virtual Networks?
- By ignoring potential problems
- Through identification, assessment, mitigation strategies, and ongoing monitoring of potential risks (Correct answer)
- Risk management is not necessary
- By avoiding all risk entirely
Correct answer: Through identification, assessment, mitigation strategies, and ongoing monitoring of potential risks
Effective risk management involves a systematic process of identifying, evaluating, and addressing potential threats.
Question 31: What role does continuing education play in Load Balancing and DNS?
- Keeping practitioners current with evolving best practices and new developments (Correct answer)
- Only required for new practitioners
- It is optional and rarely helpful
- Only beneficial for management
Correct answer: Keeping practitioners current with evolving best practices and new developments
Continuing education ensures practitioners stay current with advances in their field.
Question 32: What is Azure Route Server primarily designed to accomplish?
- Aggregate and summarize routes advertised from on-premises networks
- Provide DNS-based traffic routing across Azure regions
- Replace Azure Load Balancer for north-south traffic distribution
- Enable dynamic BGP route exchange between network virtual appliances and Azure virtual network gateways (Correct answer)
Correct answer: Enable dynamic BGP route exchange between network virtual appliances and Azure virtual network gateways
Azure Route Server acts as a BGP route reflector that enables NVAs to dynamically exchange routes with Azure's VPN and ExpressRoute gateways without requiring manual UDRs.
Question 33: What are the key regulatory requirements affecting Connectivity Solutions?
- Only federal regulations apply
- Compliance with applicable laws, industry standards, and licensing requirements specific to the field (Correct answer)
- There are no regulations
- Regulations are optional guidelines
Correct answer: Compliance with applicable laws, industry standards, and licensing requirements specific to the field
Practitioners must comply with all applicable regulations, which may include federal, state, and industry-specific requirements.
Question 34: You are designing a zero-trust network for Azure. Which combination of services best enforces micro-segmentation between application tiers?
- VNet Peering with route tables
- Single VNet with one large NSG
- ExpressRoute with private peering
- NSGs on each subnet combined with Azure Firewall for inter-tier inspection (Correct answer)
Correct answer: NSGs on each subnet combined with Azure Firewall for inter-tier inspection
NSGs on each subnet enforce micro-segmentation at the subnet level, while Azure Firewall provides stateful deep inspection for traffic crossing tier boundaries.
Question 35: How does technology impact modern practices in Connectivity Solutions?
- Technology is only useful for record keeping
- Technology improves efficiency, accuracy, and access to information while requiring new skills (Correct answer)
- Technology has no impact on this field
- Technology replaces all human judgment
Correct answer: Technology improves efficiency, accuracy, and access to information while requiring new skills
Technology enhances capabilities while also requiring practitioners to develop new competencies.
Question 36: What is the importance of communication skills in Load Balancing and DNS?
- Clear communication prevents errors, builds relationships, and ensures understanding among all parties (Correct answer)
- Technical skills are sufficient without communication
- Communication skills cannot be learned
- Communication is only important for managers
Correct answer: Clear communication prevents errors, builds relationships, and ensures understanding among all parties
Effective communication is essential for coordination, error prevention, and stakeholder relationships.
Question 37: What is the default Azure-provided DNS server IP address that VMs use when no custom DNS is configured?
- 192.168.1.1
- 8.8.8.8
- 168.63.129.16 (Correct answer)
- 10.0.0.1
Correct answer: 168.63.129.16
Azure's recursive DNS resolver is available at the virtual IP address 168.63.129.16, which is the default DNS for Azure VMs.
Question 38: An organization must ensure all inter-VNet traffic is inspected by Azure Firewall. What hub-and-spoke component achieves this?
- User-Defined Routes forcing traffic to the Firewall as next hop (Correct answer)
- Network Security Group on each spoke
- Azure Front Door with routing rules
- VNet Peering with UseRemoteGateways
Correct answer: User-Defined Routes forcing traffic to the Firewall as next hop
User-Defined Routes (UDRs) with the Azure Firewall private IP as the next hop force spoke VNet traffic through the firewall for inspection.
Question 39: Which Azure networking feature allows you to assign multiple IP configurations to a single network interface, enabling scenarios like hosting multiple SSL websites on one VM?
- NIC teaming
- Secondary VNet attachment
- Multiple IP configurations on a NIC (Correct answer)
- IP forwarding
Correct answer: Multiple IP configurations on a NIC
Azure NICs support multiple IP configurations, each with its own private IP and optional public IP, allowing a VM to host multiple SSL sites with different IPs.
Question 40: A company needs to prevent data exfiltration from Azure PaaS services by ensuring traffic stays on the Microsoft backbone. Which feature should be implemented?
- Service Endpoints with Service Endpoint Policies (Correct answer)
- Azure Bastion
- Public IP with NSG
- VNet Peering
Correct answer: Service Endpoints with Service Endpoint Policies
Service Endpoint Policies allow you to filter traffic to specific Azure resources, preventing data exfiltration to unauthorized storage accounts or services.
AZ-700 Azure Network Engineer Associate Exam
The Microsoft AZ-700 exam certifies skills in designing, implementing, and managing Azure networking solutions including virtual networks, ExpressRoute, VPN gateways, load balancing, DNS, Private Link, network security, and hybrid connectivity.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds