Skip to content

AZ-700 Practice Questions

Prepare for AZ-700 with more than an answer.

258 questions in the full set20 sample questionsUpdated Aug 21, 2026

Unlock the full exam and previous versions

  • v1Version 1 258 questions Current
  • 98-366Legacy Networking Fundamentals 50 questions Locked
Exam fee
$165 USD
Level
Associate
Valid for
1 year
Domains covered on the exam 5
  1. Design and implement core networking infrastructure27.5%
  2. Design, implement, and manage connectivity services22.5%
  3. Design and implement application delivery services17.5%
  4. Design and implement private access to Azure services12.5%
  5. Design and implement Azure network security services17.5%
  1. 1

    You are deploying a new Azure Route Server into a hub VNet. What is the primary purpose of Azure Route Server in a virtual network?

    Show answer details

    Correct answer: C

    The primary function of Azure Route Server is to simplify dynamic routing between your Network Virtual Appliances (NVAs) and your Azure virtual network. It establishes BGP peering with NVAs and injects their routes into the VNet's route table. This avoids the need for complex, manually configured User-Defined Routes (UDRs) to direct traffic to the NVA. It doesn't inspect or filter traffic itself; it only facilitates the exchange of routing information.

  2. 2

    A company is using Azure Front Door Premium for its global web application. They want to ensure that all traffic from Azure Front Door to their backend web app, which is hosted as an Azure App Service, is secure and does not traverse the public internet. Which Azure Front Door feature should be configured to achieve this?

    graph TD User --> AFD[Azure Front Door Premium] AFD -- Private Connection? --> AppService[Azure App Service]

    Show answer details

    Correct answer: C

    Azure Front Door Premium tier supports integrating with Private Link to secure the connection to the origin (backend). By enabling Private Link on the origin configuration in Front Door and approving the private endpoint connection on the App Service, traffic flows from Front Door to the App Service over the Azure private backbone network. This ensures the backend is not exposed to the public internet and all communication is private and secure.

  3. 3

    A company wants to connect its on-premises network to Azure using a Site-to-Site VPN. The on-premises VPN device is a policy-based (static routing) VPN. The Azure VPN Gateway is, by default, a route-based gateway. What must be configured on the Azure side to successfully establish a connection with the on-premises policy-based VPN device?

    Show answer details

    Correct answer: B

    Azure's route-based VPN gateways can connect to on-premises policy-based VPN devices by configuring a specific option on the connection. You must enable 'UsePolicyBasedTrafficSelectors' in a custom IPsec/IKE policy. This setting makes the Azure gateway behave like a policy-based gateway by using traffic selector prefixes to negotiate the IPsec tunnel, matching the behavior of the on-premises device. Azure no longer offers a dedicated 'policy-based' gateway SKU; instead, this compatibility is handled through connection settings.

  4. 4

    You are designing a solution for a global company that requires a unified, hub-spoke network architecture. The solution must provide connectivity for numerous branch offices via Site-to-Site VPNs, remote users via Point-to-Site VPNs, and private connectivity to a data center via ExpressRoute. All traffic must be centrally managed and secured. Which Azure networking service is best suited to act as the central hub for all these connection types?

    Show answer details

    Correct answer: B

    Azure Virtual WAN is a managed networking service that brings together networking, security, and routing functionalities into a single operational interface. It is specifically designed to be the central hub in a global hub-spoke architecture, providing scalable, any-to-any connectivity for branches (S2S VPN), users (P2S VPN), and private connections (ExpressRoute). It simplifies large-scale network deployments compared to a manually configured hub VNet.

  5. 5

    A new junior administrator is trying to create a private DNS zone named 'corp.local' and link it to an existing virtual network, VNet1. However, they discover that another team has already created a private DNS zone with the same name and linked it to a different virtual network, VNet2, in the same subscription. Can the new administrator proceed with linking 'corp.local' to VNet1?

    Show answer details

    Correct answer: D

    A single private DNS zone can be linked to multiple virtual networks. The administrator does not need to create a new zone. They can simply navigate to the existing 'corp.local' private DNS zone and add a new virtual network link pointing to VNet1. Once linked, VMs in VNet1 will be able to resolve records in that zone. It's important to note that a virtual network can only have one private DNS zone linked for automatic registration, but it can be linked to multiple zones for resolution purposes.

  6. 6

    You are configuring a Standard SKU public Azure Load Balancer. You need to ensure that the virtual machines in the backend pool can initiate outbound connections to the internet through the load balancer's public IP address. What must be configured to enable this outbound connectivity explicitly?

    Show answer details

    Correct answer: C

    Standard SKU Load Balancers are 'secure by default' and do not provide automatic outbound NAT like the Basic SKU. To enable outbound internet access for backend pool members, you must explicitly define it. This can be done by either creating an outbound rule on the load balancer, which configures Source Network Address Translation (SNAT) using the load balancer's public IP, or by associating the subnet containing the VMs with a NAT Gateway.

  7. 7

    Case Study: Contoso Pharmaceuticals

    Company Background:
    Contoso Pharmaceuticals is a global research company with its main on-premises data center in Frankfurt and a large research facility in Singapore. They have an extensive Azure presence with a hub-and-spoke topology in the West Europe region to serve their Frankfurt operations and another hub-and-spoke topology in Southeast Asia for the Singapore facility. Both on-premises locations are connected to their respective regional Azure hubs via dual 10 Gbps ExpressRoute circuits for redundancy.

    Current Situation:
    Researchers in Singapore frequently need to access large datasets and applications hosted in the West Europe Azure environment. Currently, this traffic is routed from the Singapore on-premises network, over the public internet, to the Frankfurt data center, and then up the ExpressRoute circuit to Azure West Europe. This path introduces significant latency and unpredictable performance, hindering research collaboration.

    Requirements:

    1. Enable low-latency, private connectivity between the VNet spokes in Southeast Asia and the VNet spokes in West Europe.
    2. Enable low-latency, private connectivity from the Singapore on-premises research facility directly to the Azure VNet spokes in West Europe.
    3. The solution must use the Microsoft global backbone and avoid traversing the public internet.
    4. The solution must be highly available and scalable.

    Which solution should Contoso Pharmaceuticals implement to meet all stated requirements?

    Show answer details

    Correct answer: B

    Azure Virtual WAN is the ideal solution for this scenario. By creating a Virtual WAN and deploying hubs in both regions, Contoso can connect their ExpressRoute circuits directly to the hubs. The Virtual WAN's global transit architecture automatically enables full mesh connectivity, allowing spokes in Southeast Asia to communicate with spokes in West Europe over the Microsoft backbone (Requirement 1). Furthermore, because the Singapore ExpressRoute circuit is connected to the WAN, it gains transitive routing to the West Europe hub and its connected spokes, allowing the Singapore on-premises network to reach West Europe Azure resources privately and with low latency (Requirements 2 & 3). This managed service is inherently scalable and highly available (Requirement 4).

  8. 8

    A financial services company is designing a network architecture in Azure to host a new algorithmic trading platform. A key requirement is to ensure that traffic from the application servers in one subnet (AppSubnet) is always inspected by a Network Virtual Appliance (NVA) before reaching the database servers in another subnet (DataSubnet) within the same VNet. Which of the following is the most effective way to enforce this traffic flow without altering the VNet's address space?

    Show answer details

    Correct answer: C

    The correct method to force traffic between subnets through a Network Virtual Appliance (NVA) is called service chaining, which is implemented using User-Defined Routes (UDRs). By creating a route table and associating it with the source subnet (AppSubnet), you can define a custom route for traffic destined for the target subnet (DataSubnet). Setting the next hop type to 'VirtualAppliance' and specifying the NVA's private IP address ensures that all traffic matching the route is sent to the NVA for inspection first. NSGs control access but do not redirect traffic flow. VNet peering is for connecting separate VNets, not subnets within the same VNet.

  9. 9

    A retail company is expanding its e-commerce platform, which is hosted entirely in Azure. They have multiple VNets across several Azure regions (East US, West Europe, Southeast Asia). The security team requires a centralized method to manage and apply consistent firewall rules and security policies across all VNets, including those in a hub-and-spoke topology. Which Azure service is specifically designed to meet this requirement for centralized policy management and deployment of secured virtual hubs?

    Show answer details

    Correct answer: B

    Azure Firewall Manager is the correct service for this scenario. It provides a centralized security policy and route management for cloud-based security perimeters. It is specifically designed to manage Azure Firewall policies across multiple secured virtual hubs (in a Virtual WAN context) or hub virtual networks. This allows for consistent security policy enforcement globally. While Azure Policy can enforce deployment standards and Network Watcher provides monitoring, neither offers the centralized firewall rule management that Firewall Manager does.

  10. 10

    A media company uses Azure Application Gateway v2 to protect its web applications. To enhance security, a Web Application Firewall (WAF) policy has been implemented in Prevention mode. During a recent feature launch, legitimate users reported that their search queries containing special characters (e.g., 'O'Malley') are being blocked. A review of the WAF logs confirms that rule 942100 (SQL Injection Attack) from the OWASP 3.1 ruleset is being triggered. What is the most precise and secure method to resolve this issue while minimizing the attack surface?

    Show answer details

    Correct answer: D

    The best practice for handling a false positive in WAF is to be as specific as possible to avoid weakening security. Creating a per-rule exclusion is the most precise method. By specifying the rule ID (942100) and limiting the exclusion to the specific request argument name (e.g., 'search_query'), you are telling the WAF to ignore this specific SQL injection check only for that parameter, while keeping the rule active for all other parts of the request. Disabling the rule entirely or switching to Detection mode would significantly increase the security risk. A custom allow rule for apostrophes is too broad and could be exploited.

Create an account to continue.