PSHarriJaakkonen:~/Blog/Posts>cat ./az-700-study-guide.html

AZ-700 Study Guide: Designing and Implementing Microsoft Azure Networking Solutions

AZ-700 Study Guide: Designing and Implementing Microsoft Azure Networking Solutions

AZ-700 series. This study guide follows the official Microsoft skills measured as of April 24, 2026 and is organized as a focused path for Azure network engineers.

Overview

The AZ-700 exam targets Azure network engineers who design and implement production networking on Azure. This is not a beginner networking exam. It assumes you can reason about IP addressing, DNS resolution, routing, hybrid connectivity, load balancing, private access, and network security controls. The exam then asks you to apply those fundamentals with Azure services such as Virtual Network, VPN Gateway, ExpressRoute, Virtual WAN, Application Gateway, Azure Front Door, Private Link, Azure Firewall, and Network Watcher.

The most important study habit is to follow the packet. When a VM calls a private endpoint, which DNS answer does it receive? Which route wins? Which NSG rule applies? Does traffic hit Azure Firewall? Does the application gateway probe use the right hostname? AZ-700 rewards that kind of operational thinking.

Exam Details

AttributeDetails
ExamAZ-700
CertificationMicrosoft Certified: Azure Network Engineer Associate
LevelAssociate
RolePlan, implement, manage, monitor, secure, and troubleshoot Azure networking solutions
Passing score700 / 1000
Official skills versionApril 24, 2026
Official guideMicrosoft Learn AZ-700 study guide

Skills Measured

AZ-700 Exam Domain Weights Core networking infrastructure 25-30% Connectivity services 20-25% Application delivery 15-20% Private access to Azure services 10-15% Network security services 15-20%
Core networking and connectivity together can represent more than half of the exam.

Design and Implement Core Networking Infrastructure (25-30%)

  • Plan VNet address spaces, segmentation, service subnets, subnet delegation, and public IP addressing.
  • Design DNS with Azure DNS, Private DNS zones, VNet links, custom DNS, and DNS Private Resolver.
  • Implement VNet peering, gateway transit, Virtual Network Manager connectivity, UDRs, forced tunneling, Route Server, and NAT Gateway.
  • Monitor and troubleshoot with Network Watcher, Azure Monitor for Networks, DDoS Protection, Defender for Cloud recommendations, attack paths, and Security Explorer.

Design, Implement, and Manage Connectivity Services (20-25%)

  • Design and implement site-to-site VPN, point-to-site VPN, active-active gateways, local network gateways, and IPsec/IKE policy.
  • Configure client VPN authentication with certificates, Microsoft Entra ID, and RADIUS.
  • Design and implement ExpressRoute circuits, private peering, Microsoft peering, gateways, route advertisement, encryption, BFD, and troubleshooting.
  • Design Azure Virtual WAN architecture with virtual hubs, gateway scale units, hub routing, and third-party NVA integration.

Design and Implement Application Delivery Services (15-20%)

  • Choose and configure Azure Load Balancer, Traffic Manager, Gateway Load Balancer, inbound NAT rules, outbound rules, and health probes.
  • Configure Application Gateway with listeners, backend pools, probes, routing rules, HTTP settings, TLS, and rewrite rules.
  • Configure Azure Front Door with endpoints, origins, origin groups, routes, TLS, caching, acceleration, rules, URL rewrite, URL redirect, and Private Link origin access.

Design and Implement Private Access to Azure Services (10-15%)

  • Plan and create private endpoints, Private Link services, and private endpoint access controls.
  • Integrate Private Link and private endpoints with DNS for Azure and hybrid clients.
  • Choose when to use service endpoints, configure service endpoint policies, and compare them with private endpoints.

Design and Implement Azure Network Security Services (15-20%)

  • Implement NSGs, ASGs, inbound and outbound security rules, virtual network flow logs, IP flow verify, and Bastion-friendly remote administration.
  • Design Azure Firewall deployments, choose SKUs, configure rules, use Firewall Manager policies, and deploy secured Virtual WAN hubs.
  • Design WAF policies for Application Gateway and Azure Front Door using managed rules, custom rules, detection mode, prevention mode, and exclusions.

Azure Networking Map - What You Need to Know

Think of AZ-700 as five connected layers. The exam often gives you a scenario that crosses multiple layers, so practice joining them together rather than studying one service at a time.

LayerAzure featuresWhat to understand
FoundationVNet, subnet, public IP, public IP prefixAddress planning, service subnets, delegation, overlap avoidance, BYOIP, subnet sizing
Name resolutionAzure DNS, Private DNS, DNS Private ResolverPublic vs private zones, VNet links, forwarding rulesets, hybrid private endpoint DNS
RoutingPeering, UDRs, Route Server, NAT Gateway, Virtual Network ManagerRoute precedence, gateway transit, forced tunneling, dynamic routing, outbound SNAT
ConnectivityVPN Gateway, ExpressRoute, Virtual WANHybrid links, BGP, HA, encryption, routing, branch scale
Delivery and securityLoad Balancer, Traffic Manager, Application Gateway, Front Door, Private Link, NSG, Firewall, WAFService selection, health probes, TLS, private origin access, inspection, web protection

Exam Domain Weights

DomainWeightParts
Design and implement core networking infrastructure25-30%Parts 1-3
Design, implement, and manage connectivity services20-25%Parts 4-5
Design and implement application delivery services15-20%Parts 6-7
Design and implement private access to Azure services10-15%Part 8
Design and implement Azure network security services15-20%Parts 9-10

Fast Service Selection

RequirementThink firstWhy
Private IP access to Azure PaaSPrivate EndpointThe service appears as a private IP in your VNet.
Private publication of your own service to consumersPrivate Link serviceConsumers connect through private endpoints.
Subnet-based access to a PaaS public endpointService endpointSimpler than Private Link, but not private IP access.
Regional HTTP routingApplication GatewayLayer 7 regional routing, TLS, probes, WAF.
Global HTTP acceleration and WAFAzure Front DoorEdge-based global application delivery.
TCP/UDP balancingAzure Load BalancerLayer 4 public or internal load balancing.
DNS-based global failoverTraffic ManagerReturns DNS answers; does not proxy traffic.
Transparent NVA insertionGateway Load BalancerService chaining for appliances.
Central egress inspectionAzure FirewallNetwork, application, NAT rules, threat intelligence, premium inspection features.
Many branches and managed hub routingAzure Virtual WANManaged large-scale hub connectivity.

Study Guide Parts

PartTitleFocus
Part 1Exam Overview and Networking FoundationsExam strategy, prerequisites, design mindset
Part 2Core Networking: IP, DNS, VNetsAddressing, subnetting, public IPs, Azure DNS, Private DNS, DNS Private Resolver
Part 3Routing, NAT, Monitoring, and DDoSPeering, UDRs, Route Server, NAT Gateway, Network Watcher, Azure Monitor, DDoS
Part 4VPN ConnectivitySite-to-site VPN, point-to-site VPN, gateway SKUs, IPsec/IKE, Entra auth, RADIUS
Part 5ExpressRoute and Virtual WANPrivate peering, Microsoft peering, gateways, FastPath, Global Reach, virtual hubs
Part 6Load Balancer, Traffic Manager, Gateway Load BalancerLayer 4 balancing, DNS routing, outbound SNAT, NVA insertion
Part 7Application Gateway and Azure Front DoorLayer 7 routing, TLS, WAF, global delivery, origin protection
Part 8Private Access to Azure ServicesPrivate Endpoint, Private Link service, service endpoints, DNS integration
Part 9NSGs, ASGs, Flow Logs, and BastionTraffic filtering, admin access, flow log analysis, Virtual Network Manager
Part 10Azure Firewall, WAF, and Final ReviewFirewall SKUs, Firewall Manager, secured hubs, WAF, final cram
  1. Official AZ-700 study guide - use this as the objective checklist.
  2. Azure Virtual Network documentation - start with VNets, subnets, peering, routes, NAT Gateway, and Network Watcher.
  3. Azure DNS documentation and DNS Private Resolver - master private endpoint DNS and hybrid forwarding.
  4. VPN Gateway, ExpressRoute, and Virtual WAN - compare hybrid options and route behavior.
  5. Application Gateway, Azure Front Door, and Load Balancer - learn service selection and health probes.
  6. Azure Private Link, Azure Firewall, and WAF - finish with private access and security controls.

How AZ-700 Questions Usually Work

AZ-700 questions often combine two or three services. A question about Private Link may really be a DNS question. A question about Application Gateway may really be a probe or certificate question. A question about ExpressRoute may really be a route advertisement question. Read for the constraint that makes one answer better than the others.

Question clueWhat Microsoft is probably testing
"Name resolves to public IP"Private DNS zone link or DNS forwarding problem.
"Tunnel is connected but traffic fails"Routing, NSG, firewall, or return path problem.
"Backend is unhealthy"Probe, host header, certificate, port, or backend HTTP settings problem.
"All outbound traffic must be inspected"UDR to Azure Firewall or NVA, plus firewall rules and DNS behavior.
"Global web app with WAF and acceleration"Azure Front Door, not Traffic Manager.
"Private access from on-premises to PaaS"Private Endpoint plus VPN/ExpressRoute routing plus hybrid DNS.

Packet Walk Method

  1. Resolve the name. Is it public DNS, private DNS, custom DNS, or forwarded DNS?
  2. Find the selected route. Is it system, UDR, BGP, peering, gateway, firewall, or NAT?
  3. Check security enforcement. Which NSG, ASG, firewall rule, or WAF policy applies?
  4. Check service health. Does the probe succeed? Is the backend selected? Is the origin healthy?
  5. Check return traffic. Does the response know how to get back, and is it allowed?