VNet Connectivity and Routing
This topic covers VNet peering, Virtual Network Manager, user-defined routes, forced tunneling, Route Server, NAT Gateway, and effective route troubleshooting.
How to study for AZ-700
Treat each AZ-700 item as a traffic-path problem: trace source, destination, DNS, route, next hop, load balancing, private access, and filtering before choosing.
Core concepts
Concept 1
VNet Connectivity and Routing questions test Azure networking design and troubleshooting choices rather than memorized portal paths.
Exam cue: Identify the traffic path, scope, protocol, name resolution behavior, next hop, inspection point, and security control.
Concept 2
The best answer traces traffic from source to destination through addressing, DNS, routing, security, connectivity, and delivery controls.
Exam cue: Choose the Azure networking service that fits reachability, availability, latency, scale, and security requirements.
Concept 3
Eliminate answers that ignore effective routes, name resolution, subnet constraints, private DNS, health probes, or network security boundaries.
Exam cue: Prefer least exposure, private access, validated routes, monitored health, and explicit security policy.
Risk pitfalls and guardrails
Confusing DNS resolution with routing or security filtering.
Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.
Opening public access when Private Link, VPN, ExpressRoute, or service endpoints meet the requirement.
Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.
Choosing load balancing without matching layer 4, layer 7, regional, global, or DNS-routing behavior.
Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.
Memory anchors
VNet Peering
VNet peering connects two virtual networks using the Microsoft backbone.
Global Peering
Global VNet peering connects virtual networks across supported Azure regions.
User Defined Route
A user-defined route controls custom next-hop behavior for subnet traffic.
Forced Tunneling
Forced tunneling sends internet-bound traffic through a specified inspection or on-premises path.
Route Server
Azure Route Server exchanges routes dynamically between NVAs and Azure virtual networks.
NAT Gateway
NAT Gateway provides scalable outbound internet connectivity for private subnet resources.
Virtual Network Manager
Azure Virtual Network Manager manages connectivity and security configuration across VNets.
Gateway Transit
Gateway transit lets a peered VNet use a gateway in another peered VNet where supported.
Effective Routes
Effective routes show the route table actually applied to a network interface.
Service Chaining
Service chaining steers traffic through network virtual appliances or shared services.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
VNetA and VNetB have nonoverlapping address spaces and must communicate privately over the Microsoft backbone. Which feature is the simplest fit?
A peering is configured from VNetA to VNetB, but the reverse peering was not created. What is the peering state and effect?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
