AZ-700: Designing and Implementing Microsoft Azure Networking Solutions — Questions and Answers
Question 1: Which backend member type is supported by Azure Application Gateway backend pools?
- Virtual machines and VM scale set instances (Correct answer)
- Azure Service Bus queue endpoints
- Azure Event Hub consumer groups
- Azure Blob Storage static website URLs
Correct answer: Virtual machines and VM scale set instances
Application Gateway backend pools support virtual machines, VM scale sets, App Service web apps, and on-premises servers accessible via IP or FQDN.
Question 2: What is an ExpressRoute circuit's 'service key' used for?
- Identifies the circuit to the connectivity provider for provisioning (Correct answer)
- Serves as the BGP authentication password
- Activates Premium add-ons
- Encrypts data traversing the circuit
Correct answer: Identifies the circuit to the connectivity provider for provisioning
The service key is a unique identifier for the ExpressRoute circuit that you provide to your connectivity provider to enable provisioning.
Question 3: What is the difference between a Service Endpoint and a Private Endpoint for securing access to Azure Storage?
- Private Endpoints are cheaper but less secure
- They are functionally identical
- Service Endpoints give Storage a private IP; Private Endpoints keep traffic on the backbone only
- Service Endpoints extend VNet identity to Storage over the backbone but Storage retains a public IP; Private Endpoints give Storage a private IP in your VNet (Correct answer)
Correct answer: Service Endpoints extend VNet identity to Storage over the backbone but Storage retains a public IP; Private Endpoints give Storage a private IP in your VNet
Service Endpoints route traffic over the backbone but the service still has a public IP; Private Endpoints assign a private IP in your VNet, enabling fully private access.
Question 4: What type of Azure Load Balancer provides high availability by distributing incoming network traffic across multiple virtual machines (VMs) inside a virtual network?
- Internal Load Balancer (Correct answer)
- Public Load Balancer
- Traffic Manager
- Application Gateway
Correct answer: Internal Load Balancer
An Internal Load Balancer (ILB) in Azure is used to distribute incoming network traffic among virtual machines (VMs) within a virtual network. Unlike a Public Load Balancer, an ILB is not exposed to the internet, making it suitable for internal applications and services. It ensures high availability and even traffic distribution among healthy backend instances for internal workloads.
Question 5: Which protocol does Application Gateway use for backend health probes when no custom probe is configured?
- TCP
- HTTPS
- ICMP
- HTTP (Correct answer)
Correct answer: HTTP
When no custom probe is defined, Application Gateway uses a default HTTP health probe to check backend pool member availability.
Question 6: What Azure VNet feature lets you apply consistent policies and configurations across multiple VNets at scale?
- Azure Policy with VNet effects
- Azure Blueprints
- Azure Virtual Network Manager (Correct answer)
- ARM template reuse
Correct answer: Azure Virtual Network Manager
Azure Virtual Network Manager (AVNM) provides centralized management, policy enforcement, and topology configuration across multiple VNets.
Question 7: What is the purpose of a Network Security Group (NSG) in Azure?
- To filter network traffic to and from Azure resources (Correct answer)
- To manage user access to Azure resources
- To create virtual networks
- To encrypt data at rest
Correct answer: To filter network traffic to and from Azure resources
A Network Security Group (NSG) acts as a virtual firewall for Azure resources, allowing or denying inbound and outbound network traffic based on defined rules. NSGs provide a fundamental layer of security by controlling access to VMs, subnets, and other network interfaces. They help protect resources from unauthorized access and malicious traffic.
Question 8: What is the maximum number of Site-to-Site VPN connections supported by the VpnGw2 SKU?
- 10
- 1000
- 128
- 30 (Correct answer)
Correct answer: 30
VpnGw2 supports up to 30 Site-to-Site/VNet-to-VNet tunnels.
Question 9: When configuring a CNAME record in Azure DNS, which limitation applies at the zone apex (root domain)?
- CNAMEs are allowed at apex with an additional flag
- CNAMEs at apex require a wildcard certificate
- CNAMEs cannot be used at the zone apex — use an Alias record instead (Correct answer)
- CNAMEs at apex need a higher DNS TTL
Correct answer: CNAMEs cannot be used at the zone apex — use an Alias record instead
DNS standards prohibit CNAME records at the zone apex (e.g., contoso.com); Azure DNS Alias records solve this for Azure resources.
Question 10: How does a Private Endpoint affect network security for an Azure PaaS service?
- It removes the need for NSGs on the VNet
- It allows the service to be accessed from the private IP and can be used alongside firewall rules to disable public access (Correct answer)
- It replaces role-based access control
- It automatically enables Advanced Threat Protection
Correct answer: It allows the service to be accessed from the private IP and can be used alongside firewall rules to disable public access
Private Endpoints provide a private IP path and can be combined with disabling public network access on the service to ensure all traffic is private.
Question 11: What is the purpose of the ExpressRoute Local SKU?
- Offers the highest bandwidth up to 100 Gbps
- Provides the lowest-cost circuit for local/metro connectivity with unlimited egress included (Correct answer)
- Enables connectivity to all global Azure regions
- Connects only to Azure Government regions
Correct answer: Provides the lowest-cost circuit for local/metro connectivity with unlimited egress included
ExpressRoute Local is a lower-cost SKU for customers co-located near an Azure region that includes unlimited outbound data transfer.
Question 12: What feature of Network Watcher allows you to monitor the latency and availability of connections between Azure regions and between your on-premises locations and Azure?
- Network Security Group (NSG) Flow Logs
- Network Performance Monitor
- Azure Traffic Analytics
- Connection Monitor (Correct answer)
Correct answer: Connection Monitor
Connection Monitor, a feature within Azure Network Watcher, provides unified, end-to-end connection monitoring for hybrid and Azure cloud deployments. It allows you to monitor network connectivity, latency, and packet loss between Azure regions, VNets, and your on-premises locations. This helps in identifying and diagnosing network performance issues proactively.
Question 13: When configuring VNet peering, which setting must be enabled to allow traffic from a peered network to use the local VNet's gateway?
- Allow virtual network access
- Allow gateway transit (Correct answer)
- Allow forwarded traffic
- Use remote gateways
Correct answer: Allow gateway transit
'Allow gateway transit' must be enabled on the hub VNet so spoke VNets can use its gateway.
Question 14: Which Azure feature allows you to use a VNet in one subscription peered to a VNet in a different subscription?
- VNet-to-VNet VPN
- Azure Relay
- Cross-subscription VNet peering (Correct answer)
- Azure Private Link
Correct answer: Cross-subscription VNet peering
Cross-subscription VNet peering allows peering VNets across different Azure subscriptions using resource IDs.
Question 15: When configuring BGP (Border Gateway Protocol) on Azure, what is the purpose of specifying AS (Autonomous System) numbers?
- To identify individual routers within a network
- To assign unique IP addresses to devices
- To identify and differentiate routing domains (Correct answer)
- To control access to the network
Correct answer: To identify and differentiate routing domains
In BGP (Border Gateway Protocol), Autonomous System (AS) numbers are unique identifiers assigned to routing domains. They are crucial for BGP to establish peering relationships and exchange routing information between different administrative entities. This differentiation allows for scalable and controlled inter-domain routing on the internet and in cloud environments like Azure.
Question 16: Which Application Gateway feature ensures that requests from the same client session are always directed to the same backend server?
- Connection draining
- Cookie-based session affinity (Correct answer)
- URL rewrite rules
- Custom health probes
Correct answer: Cookie-based session affinity
Cookie-based session affinity uses a gateway-managed cookie to route requests from the same client session to the same backend server.
Question 17: Which VPN Gateway feature lets you define specific traffic selectors instead of routing all traffic through the tunnel?
- Forced tunneling
- Traffic selector policies on route-based VPN (Correct answer)
- Policy-based VPN
- Route-based VPN with BGP
Correct answer: Traffic selector policies on route-based VPN
Traffic selector policies on route-based VPN gateways allow you to specify which traffic flows are protected by the IPsec tunnel.
Question 18: What is the maximum number of route prefixes that can be advertised to Azure over ExpressRoute private peering with a Standard SKU?
- 10,000
- 4,000 (Correct answer)
- 100
- 1,000
Correct answer: 4,000
ExpressRoute Standard allows advertising up to 4,000 prefixes to Azure over private peering; Premium raises this to 10,000.
Question 19: Which Azure Application Gateway SKU supports autoscaling and zone redundancy?
- WAF v1
- Standard v1
- Basic
- Standard v2 (Correct answer)
Correct answer: Standard v2
Application Gateway v2 SKUs (Standard v2 and WAF v2) support autoscaling, zone redundancy, and static virtual IP addresses.
Question 20: Which Azure Monitor feature provides metrics and logs for your virtual networks, including data about traffic, throughput, and network latency?
- Metrics Explorer
- Activity Log
- Application Insights
- Network Performance Monitor (Correct answer)
Correct answer: Network Performance Monitor
Network Performance Monitor (NPM) is a feature within Azure Monitor specifically designed to provide comprehensive visibility into network health and performance. It collects metrics and logs related to network connectivity, latency, and packet loss across your Azure virtual networks and hybrid connections. This makes NPM the ideal tool for diagnosing and troubleshooting network-related issues within your Azure infrastructure.
Question 21: What is a managed ruleset in Azure WAF?
- Rules imported from third-party security marketplace solutions
- A pre-configured set of rules maintained by Microsoft protecting against known web vulnerabilities (Correct answer)
- A set of rules created and fully managed by the application owner
- Automatically generated rules based on machine learning traffic analysis
Correct answer: A pre-configured set of rules maintained by Microsoft protecting against known web vulnerabilities
Managed rulesets are pre-configured security rules maintained and updated by Microsoft to protect against common web vulnerabilities without requiring manual rule authoring.
Question 22: What is the ASN Azure VPN Gateway uses by default for BGP if you do not specify a custom ASN?
- 4294967295
- 65515 (Correct answer)
- 65535
- 64512
Correct answer: 65515
Azure VPN Gateway uses ASN 65515 as the default BGP ASN unless a custom private ASN is configured.
Question 23: What is the primary purpose of using a default route in a routing table?
- To handle all local traffic
- To prioritize certain types of traffic
- To forward packets to a specific subnet
- To route traffic to destinations not explicitly listed in the routing table (Correct answer)
Correct answer: To route traffic to destinations not explicitly listed in the routing table
A default route acts as a "gateway of last resort" in a routing table. Its primary purpose is to forward packets to any destination that does not have a more specific route explicitly defined. This ensures that traffic can reach external networks, such as the internet, even if the exact destination is unknown to the local router.
Question 24: Which VNet feature allows you to add additional, non-contiguous address spaces to an existing VNet without downtime?
- Address space expansion (Correct answer)
- Subnet delegation
- VNet resize
- CIDR extension
Correct answer: Address space expansion
Azure allows you to add additional address spaces to an existing VNet at any time without downtime.
Question 25: What is the purpose of WAF exclusion lists in Azure Application Gateway?
- Blocking specific IP address ranges from accessing the application
- Disabling WAF inspection for specific backend pool members
- Excluding specific request attributes from WAF rule evaluation to prevent false positives (Correct answer)
- Creating custom WAF rules for unique application traffic patterns
Correct answer: Excluding specific request attributes from WAF rule evaluation to prevent false positives
WAF exclusion lists allow you to omit specific request attributes such as headers, cookies, or query strings from WAF rule evaluation to eliminate false positive blocks.
Question 26: Which protocol must be used for Point-to-Site VPN when Azure AD authentication is selected?
- L2TP/IPsec
- OpenVPN (Correct answer)
- IKEv2
- SSTP
Correct answer: OpenVPN
Azure AD authentication for P2S VPN is only supported with the OpenVPN protocol.
Question 27: Which statement is TRUE about network traffic flowing through a Private Endpoint?
- Traffic stays entirely within the Microsoft backbone and never crosses the public internet (Correct answer)
- Traffic uses BGP routing over ExpressRoute
- Traffic traverses the public internet with encryption
- Traffic is routed through Azure Firewall by default
Correct answer: Traffic stays entirely within the Microsoft backbone and never crosses the public internet
Private Endpoint traffic remains on the Microsoft global network, never crossing the public internet, providing a private and secure path to Azure services.
Question 28: Which Azure service can you use to manage DNS-based load balancing across multiple regions or endpoints for high availability and resilience?
- Azure Traffic Manager (Correct answer)
- Azure Front Door
- Azure Application Gateway
- Azure Load Balancer
Correct answer: Azure Traffic Manager
Azure Traffic Manager is a DNS-based traffic load balancer that enables you to distribute user traffic to service endpoints across global Azure regions. It uses various routing methods to ensure high availability and responsiveness by directing users to the best performing or closest available endpoint. This service is crucial for multi-region deployments requiring global traffic management.
Question 29: What tool within Azure Monitor is used to collect and analyze log data from various Azure resources, including network resources?
- Network Watcher
- Application Insights
- Log Analytics (Correct answer)
- Azure Policy
Correct answer: Log Analytics
Log Analytics is a powerful tool within Azure Monitor that allows you to collect, index, and analyze log data from various Azure resources, including network resources. It provides a query language and dashboards for deep insights into operational data, security events, and performance metrics. This helps in troubleshooting, auditing, and understanding resource behavior.
Question 30: What is the purpose of subnet delegation in Azure Virtual Networks?
- Delegates administrative rights to another user
- Assigns a static IP block to a service
- Grants a specific Azure service permission to create service-specific resources in that subnet (Correct answer)
- Allows cross-tenant subnet sharing
Correct answer: Grants a specific Azure service permission to create service-specific resources in that subnet
Subnet delegation grants a named Azure service the ability to create and manage service-specific resources (e.g., NICs) within that subnet.
Question 31: Which Azure service is primarily used for monitoring the performance and health of Azure resources, including virtual networks and network traffic?
- Azure Blob Storage
- Azure Monitor (Correct answer)
- Azure Active Directory
- Azure Key Vault
Correct answer: Azure Monitor
Azure Monitor is a comprehensive service that collects, analyzes, and acts on telemetry data from your Azure and on-premises environments. It provides unified monitoring capabilities for the performance and health of all your Azure resources, including virtual networks and network traffic. This allows for proactive issue resolution and performance optimization.
AZ-700: Designing and Implementing Microsoft Azure Networking Solutions
AZ-700 validates skills in designing and implementing core Azure networking infrastructure, hybrid connectivity, application delivery, and network security. It leads to the Microsoft Certified: Azure Network Engineer Associate certification.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds