AZ-700 Sample Questions & Answers
Connectivity design for VNets, including IP addressing and name resolution, carries the most weight, alongside site-to-site VPNs and ExpressRoute, private access through Private Link, firewalls and network security groups, and delivery services like Application Gateway.
Launch the full AZ-700 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Design and implement Azure network security services · Implement and manage network security groups
An organization is deploying a multi-tier application in a single VNet with three subnets: Web, App, and Data. The security policy states that the Web subnet can communicate with the App subnet, and the App subnet can communicate with the Data subnet. However, direct communication from the Web subnet to the Data subnet must be explicitly blocked. Which is the most efficient way to implement this policy using Application Security Groups (ASGs)?
Show answer & explanation
Correct answer: B
Using Application Security Groups (ASGs) is the most efficient and scalable solution. By creating an ASG for each application tier (WebASG, AppASG, DataASG) and associating the VM NICs accordingly, you can define NSG rules based on these logical groups rather than explicit IP addresses. A single NSG can be applied to all subnets with rules like: 'Allow traffic from source WebASG to destination AppASG' and 'Deny traffic from source WebASG to destination DataASG'. This simplifies management, as you don't need to update IP addresses in the NSG rules when VMs are added or removed.
- Question 2Intermediate
Design, implement, and manage connectivity services · Design, implement, and manage Azure ExpressRoute
You are designing a hybrid connectivity solution for a company with a main office in New York and a branch office in London. Both offices need to connect to Azure resources located in the East US and UK South regions, respectively. A key requirement is that the on-premises network in London must be able to communicate directly with the on-premises network in New York over the Microsoft backbone to avoid traversing the public internet. Which ExpressRoute feature is specifically designed to enable this on-premises to on-premises connectivity?
Show answer & explanation
Correct answer: D
ExpressRoute Global Reach is designed for this exact scenario. It allows you to link ExpressRoute circuits together to make a private network between your on-premises locations, using the Microsoft global network as the backbone. This enables direct connectivity between the New York and London offices without the traffic having to hairpin through a VNet in Azure or traverse the public internet. The Premium Add-on is required for global connectivity to Azure services, but Global Reach is the specific feature for on-premises to on-premises communication.
- Question 3Beginner
Design and implement core networking infrastructure · Design and implement VNet connectivity and routing
True or False: When configuring a VNet peering between two virtual networks in different Azure regions (Global VNet Peering), the data transfer costs are the same as for peering within the same region.
Show answer & explanation
Correct answer: B
This statement is false. Data transfer costs for Global VNet Peering (across regions) are different and typically higher than for VNet peering within the same region. For regional VNet peering, both ingress and egress traffic are charged. For Global VNet Peering, traffic is charged at zonal data transfer rates, which vary based on the Azure zones the data is traversing.
- Question 4IntermediateSelect 2
Design and implement core networking infrastructure · Monitor networks
An administrator is troubleshooting a connectivity issue where a virtual machine (VM1) in VNetA cannot connect to another virtual machine (VM2) in VNetB on port 3389. The VNets are peered. Using Azure Network Watcher, the administrator runs an IP Flow Verify test from VM1 to VM2. The result indicates 'Access Denied'. What are the TWO most likely causes for this result? (Select TWO)
Show answer & explanation
Correct answers: B, C
IP Flow Verify checks if a packet is allowed or denied to or from a virtual machine based on the effective security rules. An 'Access Denied' result directly points to a Network Security Group (NSG) rule blocking the traffic. The block could be on the outbound path from the source VM (VM1) or on the inbound path to the destination VM (VM2). While a disabled peering or incorrect routing would cause a failure, they would typically result in a 'Traffic is not routable' or similar error, not 'Access Denied'.
- Question 5Intermediate
Design and implement application delivery services · Design and implement Azure Load Balancer and Azure Traffic Manager
A university provides a custom application to its students, hosted on virtual machines in Azure. The application must be accessible from anywhere on the internet. To ensure high availability and optimal performance, instances of the application are deployed in two Azure regions: East US and West Europe. You need to configure a solution that directs users to the geographically closest region. If the application in the closest region becomes unavailable, users must be automatically redirected to the other healthy region. Which Azure service is the best fit for these requirements?
Show answer & explanation
Correct answer: C
Azure Traffic Manager is a DNS-based traffic load balancer that enables you to distribute traffic optimally to services across global Azure regions. The 'Performance' routing method is specifically designed to route traffic to the endpoint that has the lowest network latency from the client's perspective, effectively sending them to the 'closest' region. It also includes built-in endpoint health monitoring and automatic failover, which satisfies the requirement to redirect users if one region becomes unavailable. Azure Load Balancer and Application Gateway are regional services and cannot perform DNS-based global routing on their own.
- Question 6Intermediate
Design and implement application delivery services · Design and implement Azure Application Gateway
You are configuring an Azure Application Gateway v2. You need to ensure that incoming HTTP requests to 'http://contoso.com/images' are rewritten to be served by a backend pool that hosts content at 'http://image-server/content'. Which component of the Application Gateway should you configure to achieve this URL path rewrite?
Show answer & explanation
Correct answer: D
Application Gateway's 'Rewrite sets' feature allows you to rewrite URLs, query strings, and HTTP headers of requests and responses. To change the URL path from '/images' to '/content', you would create a rewrite rule within a rewrite set. This rule would have a condition to match the incoming path and an action to set the new path. This rewrite set is then associated with the appropriate routing rule. While a path-based routing rule directs traffic, it doesn't change the path itself. A backend path override in the HTTP settings appends a fixed string, but rewrite sets offer more powerful and conditional rewriting capabilities.
- Question 7Advanced
Design and implement private access to Azure services · Design and implement Azure Private Link service and Azure private endpoints
A company has deployed an application backend in an Azure VNet. They need to expose this application to a partner company through a secure, private connection without exposing the application to the public internet or requiring complex VPN setups. The partner company also has a VNet in their own Azure subscription. Which combination of Azure services should be used to create a private and encapsulated connection for the partner to consume the service?
Show answer & explanation
Correct answer: B
This scenario is the primary use case for Azure Private Link Service. The service provider places their application behind a Standard SKU internal Azure Load Balancer. They then create a Private Link Service that references the load balancer's frontend IP configuration. The partner (consumer) can then create a Private Endpoint in their own VNet that requests a connection to the Private Link Service. Once the provider approves the connection, the partner's VNet has a private, secure connection to the service without IP space overlap concerns, VNet peering, or internet exposure.
- Question 8Beginner
Design, implement, and manage connectivity services · Design, implement, and manage a point-to-site VPN connection
A network engineer needs to configure a Point-to-Site (P2S) VPN for remote users to connect to an Azure VNet. The company requires the use of Microsoft Entra ID for authentication to enforce Conditional Access policies, such as requiring MFA. Which VPN tunnel type must be used for the P2S configuration to support Microsoft Entra ID authentication?
Show answer & explanation
Correct answer: C
To use Microsoft Entra ID as the authentication method for a Point-to-Site VPN, you must use the OpenVPN tunnel type. The OpenVPN protocol allows for modern, token-based authentication mechanisms, which is how the integration with Microsoft Entra ID works. SSTP and IKEv2 primarily support certificate-based or RADIUS authentication and do not natively support direct Microsoft Entra ID authentication for P2S VPNs in Azure.
- Question 9Beginner
Design and implement core networking infrastructure · Design and implement VNet connectivity and routing
You are deploying a new Azure Route Server into a hub VNet. What is the primary purpose of Azure Route Server in a virtual network?
Show answer & explanation
Correct answer: C
The primary function of Azure Route Server is to simplify dynamic routing between your Network Virtual Appliances (NVAs) and your Azure virtual network. It establishes BGP peering with NVAs and injects their routes into the VNet's route table. This avoids the need for complex, manually configured User-Defined Routes (UDRs) to direct traffic to the NVA. It doesn't inspect or filter traffic itself; it only facilitates the exchange of routing information.
- Question 10Intermediate
Design and implement application delivery services · Design and implement Azure Front Door
A company is using Azure Front Door Premium for its global web application. They want to ensure that all traffic from Azure Front Door to their backend web app, which is hosted as an Azure App Service, is secure and does not traverse the public internet. Which Azure Front Door feature should be configured to achieve this?
graph TD User --> AFD[Azure Front Door Premium] AFD -- Private Connection? --> AppService[Azure App Service]Show answer & explanation
Correct answer: C
Azure Front Door Premium tier supports integrating with Private Link to secure the connection to the origin (backend). By enabling Private Link on the origin configuration in Front Door and approving the private endpoint connection on the App Service, traffic flows from Front Door to the App Service over the Azure private backbone network. This ensures the backend is not exposed to the public internet and all communication is private and secure.
Ready for the real thing?
The full AZ-700 simulator has every exam-style question, timed mode, and instant scoring.