AZ-700 sample questions with answers

10 free practice questions for the Microsoft Certified: Azure Network Engineer Associate exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Design and implement core networking infrastructure

Northwind has an ExpressRoute circuit to a hub virtual network. On-premises servers must resolve privatelink.blob.core.windows.net records that are held in an Azure private DNS zone, and the design must avoid running and patching DNS forwarder virtual machines. You need to enable the resolution. What should you deploy in the hub virtual network?

  1. A.

    A public Azure DNS zone named blob.core.windows.net that contains the private endpoint A records

  2. B.

    Configure a conditional forwarder for blob.core.windows.net on the on-premises DNS servers that targets 168.63.129.16, and advertise 168.63.129.16/32 to on-premises over the ExpressRoute circuit

  3. C.

    An Azure DNS Private Resolver with an inbound endpoint, then point an on-premises conditional forwarder for blob.core.windows.net at the inbound endpoint IP address

  4. D.

    An Azure DNS Private Resolver with an outbound endpoint and a DNS forwarding ruleset for blob.core.windows.net

Show answer

Answer: C

An inbound endpoint on Azure DNS Private Resolver gives on-premises resolvers a private IP address in the VNet to forward Azure private zone queries to.

  • A. A public DNS zone cannot hold private endpoint resolution for the Microsoft-owned blob namespace and would not be authoritative for on-premises clients anyway.
  • B. 168.63.129.16 is only reachable from inside a virtual network, so an on-premises forwarder aimed at it cannot receive answers.
  • C. The inbound endpoint provides a VNet private IP that on-premises resolvers can forward to, and it answers from every private DNS zone linked to that virtual network.
  • D. Outbound endpoints and forwarding rulesets send queries from Azure toward on-premises DNS, which is the reverse of the required direction.
Question 2Design and implement core networking infrastructure

Litware must continuously measure round-trip latency and packet loss between on-premises servers, Azure virtual machines in two regions, and an external HTTPS endpoint. The team wants historical trends, a topology view of each hop, and alerts when loss exceeds a threshold. You need to recommend a solution. What should you recommend?

  1. A.

    Virtual network flow logs with Traffic Analytics enabled on every subnet

  2. B.

    Azure Monitor Network Insights topology, with diagnostic settings enabled on the virtual network gateways and on every network security group in both regions

  3. C.

    Connection troubleshoot in Azure Network Watcher, scheduled hourly by an Azure Automation runbook

  4. D.

    Connection monitor in Azure Network Watcher, with the Network Watcher agent extension on the endpoints and results sent to a Log Analytics workspace

Show answer

Answer: D

Connection monitor is the continuous, multi-endpoint reachability test that records latency, loss and per-hop topology and can raise metric alerts.

  • A. Flow logs and Traffic Analytics report allowed and denied flows and volumes; they contain no latency or packet loss measurements.
  • B. Network Insights visualises existing resource metrics and topology but cannot probe arbitrary endpoints for loss and latency.
  • C. Connection troubleshoot is a one-time diagnostic; scheduling it gives no trend store, no unified topology history and no built-in alerting.
  • D. Connection monitor performs scheduled synthetic tests across hybrid and external endpoints, with the Network Watcher agent extension on each source, storing latency, loss and hop topology in Log Analytics for alerting.
Question 3Design and implement core networking infrastructure

Contoso Freight owns the internet-routable range 198.51.100.0/24, which hundreds of partner firewalls already allow-list. Contoso is migrating its edge services to Azure and must keep the same source addresses after the migration, with the range advertised from an Azure region. You need to make the range usable for Azure public IP addresses. What should you do first?

  1. A.

    Advertise 198.51.100.0/24 to Azure over ExpressRoute Microsoft peering and create Standard public IP addresses from it

  2. B.

    Create a Standard public IP address prefix of size /24 in the target region and ask Azure support to assign Contoso the 198.51.100.0/24 range from the Microsoft pool

  3. C.

    Create a Route Origin Authorization for AS8075 at the internet registry, then onboard the range as a custom IP address prefix

  4. D.

    Create a public IP address prefix and add 198.51.100.0/24 to the address space of the virtual network

Show answer

Answer: C

Bringing your own addresses to Azure means onboarding a custom IP address prefix, which requires a Route Origin Authorization naming Microsoft's AS8075 plus a signed ownership message.

  • A. Microsoft peering advertises on-premises public prefixes toward Microsoft services; it never makes those addresses assignable to Azure resources.
  • B. A public IP address prefix hands out Microsoft-owned addresses from the region's pool; you cannot choose the actual range, so partner allow-lists would break.
  • C. Custom IP address prefix is the bring-your-own-IP feature, and the ROA authorising AS8075 plus the signed ownership message are its documented prerequisites.
  • D. A virtual network address space holds the private addressing used inside the VNet; public ranges are represented by public IP resources, not VNet prefixes.
Question 4Design and implement core networking infrastructure

You must produce reports that show the top talkers, denied flows, and malicious IP addresses across a virtual network named VNet-Ops, and the reports must refresh roughly every ten minutes. You plan to use virtual network flow logs with Traffic Analytics. Which two components must you configure? (Choose TWO.)

Choose 2.

  1. A.

    A private endpoint for the storage account so that flow records never traverse the internet

  2. B.

    A storage account in the same region as the flow log to receive the raw flow records

  3. C.

    An Azure Event Hubs namespace to buffer flow records before ingestion

  4. D.

    A route table on each subnet that sends flow records to the storage account

  5. E.

    The Network Watcher agent virtual machine extension on every virtual machine in VNet-Ops

  6. F.

    A Log Analytics workspace to receive the processed Traffic Analytics data, with the processing interval set to 10 minutes

Show answer

Answer: B, F

Flow logging writes raw records to a storage account, and Traffic Analytics processes them into a Log Analytics workspace at a 10 or 60 minute interval.

  • A. A private endpoint is an optional hardening step and is not a prerequisite for flow logging or Traffic Analytics.
  • B. A flow log resource cannot be created without a storage account destination for the raw JSON flow records.
  • C. Event Hubs is a streaming destination for other diagnostic data; flow logs are written directly to the storage account.
  • D. Flow records are emitted out of band by the platform, so no route table entry carries them to storage.
  • E. Virtual network flow logs are captured by the platform; no Network Watcher agent extension is needed inside the virtual machines.
  • F. Traffic Analytics requires a Log Analytics workspace, and the 10 minute processing interval gives the near real time refresh the reports need.
Question 5Design and implement core networking infrastructure

Snet-Reports has a route table with a 0.0.0.0/0 route whose next hop is an Azure Firewall private address, and the firewall is expected to inspect and log every outbound flow. An audit finds that traffic from Snet-Reports to Azure Storage never appears in the firewall logs, although all other outbound traffic does. The Microsoft.Storage service endpoint is enabled on Snet-Reports. What should you do?

  1. A.

    Disable virtual network gateway route propagation on the route table associated with Snet-Reports

  2. B.

    Move the 0.0.0.0/0 route to a route table associated with the AzureFirewallSubnet instead

  3. C.

    Disable the Microsoft.Storage service endpoint on Snet-Reports

  4. D.

    Add a route for the Storage service tag with the next hop set to the Azure Firewall private address

Show answer

Answer: C

Enabling a service endpoint adds a VirtualNetworkServiceEndpoint route that is more specific than 0.0.0.0/0 and cannot be overridden by any user-defined route, so the endpoint must be removed to force storage traffic through the firewall.

  • A. Route propagation controls whether BGP routes from a virtual network gateway are added to the subnet. It has nothing to do with service endpoint routes.
  • B. A default route on AzureFirewallSubnet governs the firewall's own egress. It would not change how Snet-Reports routes storage traffic, and it risks breaking the firewall.
  • C. The service endpoint installs a more specific, non-overridable route for the service's addresses. Removing the endpoint is the only way to make storage traffic follow the 0.0.0.0/0 route to the firewall.
  • D. A service tag route is still a user-defined route, and a VirtualNetworkServiceEndpoint route cannot be overridden by one, so storage traffic would continue to bypass the firewall.
Question 6Design and implement core networking infrastructure

A small business unit runs three public IP addresses on one virtual network in its own subscription. It needs the same always-on monitoring, adaptive tuning, metrics and alerting that the rest of the organisation has, but it does not need DDoS Rapid Response support or cost protection and must avoid committing to a protection plan. What should you recommend?

  1. A.

    Rely on the default infrastructure-level DDoS protection that Azure provides

  2. B.

    Enable Azure DDoS IP Protection on each of the three public IP address resources

  3. C.

    Associate the business unit's virtual network with an existing DDoS Network Protection plan in another subscription

  4. D.

    Create a DDoS Network Protection plan and associate it with the virtual network

Show answer

Answer: B

DDoS IP Protection is the pay-per-protected-address tier with the same core mitigation engine, and it is the right choice when neither Rapid Response nor cost protection is required and no plan is wanted.

  • A. Default infrastructure protection defends the platform against common network-layer attacks and provides no adaptive tuning, per-address metrics or alerting.
  • B. IP Protection is enabled per public IP address, needs no plan, and carries the same always-on monitoring, adaptive tuning, metrics and alerting as Network Protection.
  • C. Sharing another subscription's plan is supported within a tenant, but it still means depending on a plan and on another team's resource, which the requirement excludes.
  • D. Creating a plan is exactly the commitment the requirement rules out, and it buys value-added services the business unit has said it does not need.
Question 7Design and implement core networking infrastructure

You remediate the network security group recommendation on eleven of the twenty-six resources in the Restrict unauthorized network access security control. The secure score rises by a small fraction of the control's maximum score, and your manager asks why it did not rise by the full amount. What is the reason?

  1. A.

    The control's current score is the score per resource multiplied by the number of healthy resources, so the full points are earned only when every resource in the control complies

  2. B.

    Recommendations remediated manually do not count towards the secure score unless the Fix action is used

  3. C.

    The secure score is recalculated only once every thirty days, so the remaining points will appear at the next cycle

  4. D.

    Network recommendations are weighted lower than identity recommendations, so they contribute a reduced number of points

Show answer

Answer: A

A security control awards points in proportion to healthy resources, and the full maximum is reached only when every resource complies with every recommendation in the control.

  • A. The control score is proportional to healthy resources, and the maximum is awarded only when every resource complies with every recommendation in the control.
  • B. The score reflects resource health, not the method of remediation. Manual fixes, the Fix action and policy enforcement all count identically.
  • C. Defender for Cloud recalculates each control every eight hours per subscription or connector, so the delay is hours rather than a month.
  • D. Controls are not discounted by category. Each control has its own published maximum score, which is a different thing from a per-category weighting.
Question 8Design and implement core networking infrastructure

You create a new virtual network and deploy virtual machines that have no public IP address and sit behind a Standard internal load balancer. The virtual machines must download operating system updates from the internet, and no inbound connection from the internet may be possible. Which two actions would each meet the requirements? Each correct answer presents a complete solution. (Choose TWO.)

Choose 2.

  1. A.

    Add a public frontend IP configuration and an inbound NAT rule to the existing Standard internal load balancer

  2. B.

    Associate a NAT gateway that has a Standard public IP address with the subnet that contains the virtual machines

  3. C.

    Rely on default outbound access, which Azure provides automatically to virtual machines without an explicit method

  4. D.

    Assign an instance-level Standard public IP address to each virtual machine and keep the internal load balancer

  5. E.

    Add the virtual machines to the backend pool of a Standard public load balancer that has only an outbound rule

Show answer

Answer: B, E

Both a NAT gateway on the subnet and an outbound-only public load balancer give the virtual machines explicit outbound connectivity without allowing unsolicited inbound connections.

  • A. An internal load balancer cannot take a public frontend, and an inbound NAT rule would open an inbound path.
  • B. A NAT gateway provides subnet-wide outbound SNAT and admits only return traffic for flows the virtual machines started.
  • C. New virtual networks default to private subnets, so no default outbound access exists for these virtual machines.
  • D. An instance-level public address makes each virtual machine reachable from the internet, which the requirement rules out.
  • E. The documented egress-only pattern adds the virtual machines to a public load balancer used purely for outbound rules.
Question 9Design and implement core networking infrastructure

VNet-Spoke-A is peered with VNet-Hub. A third-party firewall appliance runs on a virtual machine in VNet-Hub with the private address 10.60.250.4. All traffic leaving the subnet Snet-Web in VNet-Spoke-A must pass through the appliance for inspection. You need to implement service chaining. Which two configurations should you apply in Azure? Each correct answer presents part of the solution. (Choose TWO.)

Choose 2.

  1. A.

    Associate a route table with Snet-Web that contains a 0.0.0.0/0 route whose next hop type is Virtual appliance at 10.60.250.4

  2. B.

    Associate a network security group with Snet-Web that permits outbound traffic only to the address 10.60.250.4

  3. C.

    Turn on the Enable IP forwarding setting of the network interface that the firewall appliance uses at 10.60.250.4

  4. D.

    Enable Allow gateway transit on the hub-to-spoke peering and Use remote gateways on the spoke-to-hub peering

  5. E.

    Associate a route table with Snet-Web that contains a 0.0.0.0/0 route whose next hop type is Virtual network gateway

Show answer

Answer: A, C

Service chaining across a peering needs a user-defined route in the spoke that names the appliance as a virtual appliance next hop, and the Azure Enable IP forwarding setting on the appliance network interface so that Azure delivers packets not addressed to it.

  • A. The user-defined route overrides the default route and sends every packet leaving Snet-Web to the appliance address across the peering.
  • B. A network security group only allows or denies flows; it cannot redirect traffic to another next hop for inspection.
  • C. Azure only delivers traffic addressed to other hosts to a network interface that has Enable IP forwarding turned on.
  • D. Gateway transit lets a spoke use the hub gateway; it does not steer any traffic through the firewall appliance.
  • E. This next hop sends traffic to a VPN gateway rather than to the appliance, and the scenario has no gateway to use.
Question 10Design and implement core networking infrastructure

Every subnet in VNet-Falkirk must send internet-bound traffic to the on-premises datacentre for inspection through the site-to-site VPN connection. The set of on-premises prefixes changes regularly, the gateway already uses BGP, and the network team wants the default route to be withdrawn automatically if the on-premises edge stops advertising it. What should you do?

  1. A.

    Advertise 0.0.0.0/0 to the virtual network gateway over BGP from the on-premises router

  2. B.

    Enable Allow gateway transit on the peerings of VNet-Falkirk

  3. C.

    Associate a route table containing a 0.0.0.0/0 route with the next hop type Virtual network gateway with every subnet, including GatewaySubnet

  4. D.

    Add 0.0.0.0/0 to the address prefixes of the local network gateway that represents the on-premises datacentre

Show answer

Answer: A

Advertising 0.0.0.0/0 over BGP delivers the default route dynamically to every subnet and withdraws it automatically when on-premises stops advertising it.

  • A. A BGP-advertised default route reaches every subnet automatically and is withdrawn as soon as on-premises stops advertising it, which is exactly the behaviour required.
  • B. Gateway transit lets peered virtual networks use this gateway. It installs no default route and does not force any traffic on-premises.
  • C. A route table containing 0.0.0.0/0 must never be associated with GatewaySubnet, because it breaks the virtual network gateway. The route would also be static rather than withdrawable.
  • D. Address prefixes on a local network gateway are the static alternative to BGP for describing the on-premises network, and mixing them with a BGP-enabled connection is not the dynamic behaviour asked for.

Keep going with 519 more AZ-700 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

AZ-700 sample questions with answers (10 free) · CertifyCloudx