ExpressRoute and Virtual WAN
This topic covers ExpressRoute models, peering, gateways, Global Reach, FastPath, encryption, BFD, Virtual WAN hubs, gateways, routing, and third-party NVAs.
How to study for AZ-700
Treat each AZ-700 item as a traffic-path problem: trace source, destination, DNS, route, next hop, load balancing, private access, and filtering before choosing.
Core concepts
Concept 1
ExpressRoute and Virtual WAN questions test Azure networking design and troubleshooting choices rather than memorized portal paths.
Exam cue: Identify the traffic path, scope, protocol, name resolution behavior, next hop, inspection point, and security control.
Concept 2
The best answer traces traffic from source to destination through addressing, DNS, routing, security, connectivity, and delivery controls.
Exam cue: Choose the Azure networking service that fits reachability, availability, latency, scale, and security requirements.
Concept 3
Eliminate answers that ignore effective routes, name resolution, subnet constraints, private DNS, health probes, or network security boundaries.
Exam cue: Prefer least exposure, private access, validated routes, monitored health, and explicit security policy.
Risk pitfalls and guardrails
Confusing DNS resolution with routing or security filtering.
Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.
Opening public access when Private Link, VPN, ExpressRoute, or service endpoints meet the requirement.
Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.
Choosing load balancing without matching layer 4, layer 7, regional, global, or DNS-routing behavior.
Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.
Memory anchors
ExpressRoute
ExpressRoute provides private connectivity between on-premises networks and Microsoft cloud services.
Private Peering
Azure private peering connects on-premises networks to Azure virtual networks through ExpressRoute.
Microsoft Peering
Microsoft peering connects to Microsoft public services through ExpressRoute where configured.
ExpressRoute Gateway
An ExpressRoute gateway connects a virtual network to an ExpressRoute circuit.
Global Reach
ExpressRoute Global Reach connects on-premises networks through the Microsoft backbone.
FastPath
FastPath sends data traffic directly to virtual machines while bypassing the gateway data path where supported.
BFD
Bidirectional Forwarding Detection improves route failure detection speed.
Virtual WAN
Azure Virtual WAN provides managed hub-and-spoke connectivity across branches, users, and VNets.
Virtual Hub
A virtual hub is a Microsoft-managed network hub within Azure Virtual WAN.
Hub Routing
Hub routing controls traffic flow between VPN, ExpressRoute, VNets, and security appliances.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A company needs private connectivity from its colocation facility to Azure without traversing the public internet. Which service should it use?
A company connects through an exchange provider at a shared facility. Which ExpressRoute connectivity model is this?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
