Topic module

VNet Connectivity and Routing

This topic covers VNet peering, Virtual Network Manager, user-defined routes, forced tunneling, Route Server, NAT Gateway, and effective route troubleshooting.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for AZ-700

Treat each AZ-700 item as a traffic-path problem: trace source, destination, DNS, route, next hop, load balancing, private access, and filtering before choosing.

Core concepts

Concept 1

VNet Connectivity and Routing questions test Azure networking design and troubleshooting choices rather than memorized portal paths.

Exam cue: Identify the traffic path, scope, protocol, name resolution behavior, next hop, inspection point, and security control.

Concept 2

The best answer traces traffic from source to destination through addressing, DNS, routing, security, connectivity, and delivery controls.

Exam cue: Choose the Azure networking service that fits reachability, availability, latency, scale, and security requirements.

Concept 3

Eliminate answers that ignore effective routes, name resolution, subnet constraints, private DNS, health probes, or network security boundaries.

Exam cue: Prefer least exposure, private access, validated routes, monitored health, and explicit security policy.

Risk pitfalls and guardrails

Confusing DNS resolution with routing or security filtering.

Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.

Opening public access when Private Link, VPN, ExpressRoute, or service endpoints meet the requirement.

Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.

Choosing load balancing without matching layer 4, layer 7, regional, global, or DNS-routing behavior.

Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.

Memory anchors

VNet Peering

VNet peering connects two virtual networks using the Microsoft backbone.

Global Peering

Global VNet peering connects virtual networks across supported Azure regions.

User Defined Route

A user-defined route controls custom next-hop behavior for subnet traffic.

Forced Tunneling

Forced tunneling sends internet-bound traffic through a specified inspection or on-premises path.

Route Server

Azure Route Server exchanges routes dynamically between NVAs and Azure virtual networks.

NAT Gateway

NAT Gateway provides scalable outbound internet connectivity for private subnet resources.

Virtual Network Manager

Azure Virtual Network Manager manages connectivity and security configuration across VNets.

Gateway Transit

Gateway transit lets a peered VNet use a gateway in another peered VNet where supported.

Effective Routes

Effective routes show the route table actually applied to a network interface.

Service Chaining

Service chaining steers traffic through network virtual appliances or shared services.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

VNetA and VNetB have nonoverlapping address spaces and must communicate privately over the Microsoft backbone. Which feature is the simplest fit?

A peering is configured from VNetA to VNetB, but the reverse peering was not created. What is the peering state and effect?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.