About the exam
AZ-700 Exam structure
Microsoft Azure Network Engineer AZ-700 prep with 601 original practice questions, skills-measured weighted mocks, networking drills, flashcards, and topic recovery.
Issuer and path
Microsoft Azure Network Engineer AZ-700 Exam Prep is administered through Microsoft. Check official resources before booking, retesting, or relying on a stale requirement.
Design and Implement Core Networking Infrastructure
28 scored + 0 pretest
IP addressing, VNets, subnets, public IPs, DNS, private DNS, VNet connectivity, peering, routing, NAT Gateway, monitoring, diagnostics, and DDoS protection.
Design, Implement and Manage Connectivity Services
22 scored + 0 pretest
Site-to-site VPN, point-to-site VPN, ExpressRoute, virtual network gateways, encryption, high availability, Virtual WAN, gateway routing, and hybrid troubleshooting.
Design and Implement Application Delivery Services
18 scored + 0 pretest
Azure Load Balancer, Traffic Manager, Application Gateway, Azure Front Door, health probes, routing, TLS, WAF, caching, and origin protection.
Design and Implement Private Access to Azure Services
14 scored + 0 pretest
Private Link, private endpoints, Private Link service, private DNS integration, on-premises private access, service endpoints, and endpoint policies.
Design and Implement Azure Network Security Services
18 scored + 0 pretest
Network security groups, application security groups, flow logs, Azure Firewall, Firewall Manager, secured hub, WAF policies, and network security troubleshooting.
Before you schedule
Confirm the exam is AZ-700, review the April 24, 2026 skills measured, check ID requirements, accommodations, language availability, renewal rules, and Microsoft exam policies.
Official Outline Coverage Map
Coverage is mapped to official outline item counts so content depth can be checked without hard-coding a single exam.
| Topic | Official outline items | Your questions | Your flashcards | Confidence |
|---|---|---|---|---|
| IP Addressing, VNets and DNS | 7 | 57 | 10 | Priority |
| VNet Connectivity and Routing | 7 | 56 | 10 | Priority |
| Network Monitoring and Diagnostics | 6 | 56 | 10 | Good |
| VPN Gateway Connectivity | 6 | 66 | 10 | Priority |
| ExpressRoute and Virtual WAN | 6 | 66 | 10 | Priority |
| Load Balancer and Traffic Manager | 5 | 54 | 10 | Priority |
| Application Gateway and Azure Front Door | 5 | 54 | 10 | Priority |
| Private Link and Private Endpoints | 5 | 42 | 10 | Priority |
| Service Endpoints and Endpoint Policies | 5 | 42 | 10 | Good |
| NSGs, ASGs and Flow Logs | 5 | 54 | 10 | Priority |
| Azure Firewall, Firewall Manager and WAF | 5 | 54 | 10 | Priority |
How to use this guide
How to study for AZ-700
Treat each AZ-700 item as a traffic-path problem: trace source, destination, DNS, route, next hop, load balancing, private access, and filtering before choosing.
1. Identify source and destination
Find the client, subnet, VNet, gateway, endpoint, service, origin, or backend target.
2. Resolve the name
Check public DNS, private DNS, DNS resolver, split horizon behavior, and service-specific names.
3. Trace route and delivery
Evaluate peering, UDRs, next hop, VPN, ExpressRoute, Load Balancer, Application Gateway, Front Door, and Traffic Manager.
4. Apply security controls
Confirm NSGs, ASGs, firewall policy, WAF, private access, probes, logs, and effective rules.
IP Addressing, VNets and DNS
Core network items test address spaces, subnets, public IP prefixes, Azure DNS, private DNS, DNS resolver, subnet planning, and service-specific subnet needs.
Key rules
Rule 1
IP Addressing, VNets and DNS questions test Azure networking design and troubleshooting choices rather than memorized portal paths.
Exam cue: Identify the traffic path, scope, protocol, name resolution behavior, next hop, inspection point, and security control.
Rule 2
The best answer traces traffic from source to destination through addressing, DNS, routing, security, connectivity, and delivery controls.
Exam cue: Choose the Azure networking service that fits reachability, availability, latency, scale, and security requirements.
Rule 3
Eliminate answers that ignore effective routes, name resolution, subnet constraints, private DNS, health probes, or network security boundaries.
Exam cue: Prefer least exposure, private access, validated routes, monitored health, and explicit security policy.
Common traps
Confusing DNS resolution with routing or security filtering.
Prevention: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.
Opening public access when Private Link, VPN, ExpressRoute, or service endpoints meet the requirement.
Prevention: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.
Choosing load balancing without matching layer 4, layer 7, regional, global, or DNS-routing behavior.
Prevention: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.
Memory anchors
Virtual Network
An Azure virtual network provides an isolated network boundary for Azure resources.
Address Space
A VNet address space defines the private IP ranges available to subnets.
Subnet
A subnet segments a VNet and can host resources or delegated platform services.
Subnet Delegation
Subnet delegation grants a service permission to create service-specific resources in the subnet.
Public IP Prefix
A public IP prefix reserves a contiguous range of static public IP addresses.
Azure DNS
Azure DNS hosts public DNS zones and records for domain name resolution.
Private DNS Zone
A private DNS zone resolves private names inside linked virtual networks.
DNS Private Resolver
Azure DNS Private Resolver supports hybrid DNS resolution without custom DNS servers.
Subnet Sizing
Subnet sizing must reserve enough addresses for platform requirements and workload growth.
Name Resolution
Name resolution maps host names to addresses before routing or security rules can take effect.
Next best moves
Quick check-up
Use a short quiz to confirm the rule pattern is actually sticking.
Check-up Questions
A company will peer an Azure VNet with an on-premises network that uses 10.20.0.0/16. Which VNet address plan avoids an immediate routing conflict?
A VNet uses 10.0.0.0/24. SubnetA already uses 10.0.0.0/25. Which prefix can be assigned to SubnetB without overlap?
Answer all questions to submit.
Next step personalized recommendations
Open another topic next
Official resources
Verify the details with the official sources
Use these links for eligibility, scheduling, handbook rules, and issuer updates. Our guide helps you study; official sources tell you what the testing partner currently requires.
Microsoft AZ-700 Study Guide
Official Microsoft Learn study guide with skills measured, domain ranges, change log, and study resources.
Microsoft Azure Network Engineer Associate Certification
Microsoft certification page for Azure Network Engineer Associate exam details, renewal, scheduling, and resources.
FAQ
Common AZ-700 questions
Is this the official Microsoft AZ-700 exam?
No. These are original practice questions aligned to Microsoft's public AZ-700 study guide. They are not copied from secure exam material.
Which skills-measured version is this aligned to?
This content is aligned to the Microsoft Learn AZ-700 study guide that lists skills measured as of April 24, 2026.
What domains are covered?
The bank covers core networking infrastructure, connectivity services, application delivery, private access to Azure services, and network security services.
What should I study first?
Start with VNets, subnets, DNS, peering, routes, Network Watcher, VPN, ExpressRoute, Load Balancer, Application Gateway, Front Door, Private Link, NSGs, Azure Firewall, and WAF.
How should I use the 601 questions?
Use topic drills for traffic-path gaps, section drills for each skills group, then 100-question weighted mocks.
