Topic module

IP Addressing, VNets and DNS

Core network items test address spaces, subnets, public IP prefixes, Azure DNS, private DNS, DNS resolver, subnet planning, and service-specific subnet needs.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for AZ-700

Treat each AZ-700 item as a traffic-path problem: trace source, destination, DNS, route, next hop, load balancing, private access, and filtering before choosing.

Core concepts

Concept 1

IP Addressing, VNets and DNS questions test Azure networking design and troubleshooting choices rather than memorized portal paths.

Exam cue: Identify the traffic path, scope, protocol, name resolution behavior, next hop, inspection point, and security control.

Concept 2

The best answer traces traffic from source to destination through addressing, DNS, routing, security, connectivity, and delivery controls.

Exam cue: Choose the Azure networking service that fits reachability, availability, latency, scale, and security requirements.

Concept 3

Eliminate answers that ignore effective routes, name resolution, subnet constraints, private DNS, health probes, or network security boundaries.

Exam cue: Prefer least exposure, private access, validated routes, monitored health, and explicit security policy.

Risk pitfalls and guardrails

Confusing DNS resolution with routing or security filtering.

Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.

Opening public access when Private Link, VPN, ExpressRoute, or service endpoints meet the requirement.

Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.

Choosing load balancing without matching layer 4, layer 7, regional, global, or DNS-routing behavior.

Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.

Memory anchors

Virtual Network

An Azure virtual network provides an isolated network boundary for Azure resources.

Address Space

A VNet address space defines the private IP ranges available to subnets.

Subnet

A subnet segments a VNet and can host resources or delegated platform services.

Subnet Delegation

Subnet delegation grants a service permission to create service-specific resources in the subnet.

Public IP Prefix

A public IP prefix reserves a contiguous range of static public IP addresses.

Azure DNS

Azure DNS hosts public DNS zones and records for domain name resolution.

Private DNS Zone

A private DNS zone resolves private names inside linked virtual networks.

DNS Private Resolver

Azure DNS Private Resolver supports hybrid DNS resolution without custom DNS servers.

Subnet Sizing

Subnet sizing must reserve enough addresses for platform requirements and workload growth.

Name Resolution

Name resolution maps host names to addresses before routing or security rules can take effect.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

A company will peer an Azure VNet with an on-premises network that uses 10.20.0.0/16. Which VNet address plan avoids an immediate routing conflict?

A VNet uses 10.0.0.0/24. SubnetA already uses 10.0.0.0/25. Which prefix can be assigned to SubnetB without overlap?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.