AZ-700: Designing and Implementing Microsoft Azure Networking Solutions

Associate Azure
Browse certifications
26 modules
·
~5h 26m study time
·
0 completed

Interactive Study Guide

Each module covers one exam topic with plain-English explanations, real-world scenarios, and built-in practice. Everything you need to understand and retain the material — no tab-switching required.

📖 ELI5 explanations
🔄 Flashcards
✅ Knowledge checks
📊 Compare tables
💡 Exam tips
📍 Progress tracking
Domain 1: Core Networking Infrastructure
Name Resolution: Azure DNS 14m
Loading module…
DDoS Protection and Security Posture 11m
Loading module…
IP Addressing: Public, Private & Prefixes 13m
Loading module…
Network Monitoring and Diagnostics 12m
Loading module…
Routing: UDRs, Route Server & NAT Gateway 15m
Loading module…
Virtual Networks: Your Cloud Foundation 14m
Loading module…
VNet Peering and Connectivity 13m
Loading module…
Domain 2: Connectivity Services
ExpressRoute: Advanced Features 13m
Loading module…
ExpressRoute Fundamentals 14m
Loading module…
Choosing Your Hybrid Connection 11m
Loading module…
Point-to-Site VPN: Remote Access 13m
Loading module…
Site-to-Site VPN: Connecting On-Premises 14m
Loading module…
Azure Virtual WAN 13m
Loading module…
Domain 3: Application Delivery Services
Application Gateway: Layer 7 13m
Loading module…
Azure Front Door: Global Delivery 13m
Loading module…
Azure Load Balancer: Layer 4 14m
Loading module…
Choosing the Right Load Balancer 10m
Loading module…
Traffic Manager: DNS-Based Routing 12m
Loading module…
Domain 4: Private Access to Azure Services
Private Endpoint DNS 12m
Loading module…
Private Link and Private Endpoints 13m
Loading module…
Service Endpoints: When and How 10m
Loading module…
Domain 5: Network Security Services
Azure Firewall: SKUs and Deployment 13m
Loading module…
Azure Firewall Manager and Policies 11m
Loading module…
Flow Logs, IP Flow Verify & Network Manager Security 11m
Loading module…
NSGs and Application Security Groups 13m
Loading module…
Web Application Firewall (WAF) 11m
Loading module…

Exam Resources

Official learning paths, exam details, skills measured, and community resources to supplement your study.

Exam Quick Facts

DetailValue
Exam CodeAZ-700
TitleDesigning and Implementing Microsoft Azure Networking Solutions
LevelAssociate
Pass Score700 / 1000
Duration100 minutes
Questions~40-60
Cost$165 USD (varies by region)
SchedulingPearson VUE
Skills UpdatedApril 24, 2026

Study Resources

ResourceLink
Official Exam PageMicrosoft Learn — AZ-700
Official Study GuideMicrosoft Study Guide
Free Practice AssessmentStart Practice Assessment
Exam SandboxTry the exam interface

Skills at a Glance

Skill AreaWeight
Design and implement core networking infrastructure25-30%
Design, implement, and manage connectivity services20-25%
Design and implement application delivery services15-20%
Design and implement private access to Azure services10-15%
Design and implement Azure network security services15-20%

Who is this exam for?

This is a Microsoft Azure certification exam. It tests your practical knowledge of Azure services and your ability to implement, manage, and design solutions on the Azure platform. This is an associate-level exam that expects hands-on experience. You should have practical knowledge of the technologies covered.


Skills Measured

Design and implement core networking infrastructure (25–30%)

This domain covers networking. You need to understand virtual networks, connectivity, load balancing, DNS, and network security.

Design and implement IP addressing for Azure resources

  • Plan and implement network segmentation and address spaces
  • Create a virtual network (VNet)
  • Plan and configure subnetting for services, including virtual network gateways, private endpoints, service endpoints, firewalls, application gateways, VNet-integrated platform services, and Azure Bastion
  • Plan and configure subnet delegation
  • Plan and configure shared or dedicated subnets
  • Create a prefix for public IP addresses
  • Choose when to use a public IP address prefix
  • Plan and implement a custom public IP address prefix (bring your own IP)
  • Create a public IP address
  • Associate public IP addresses to resources

Design and implement name resolution

  • Design name resolution inside a VNet
  • Configure DNS settings for a VNet
  • Design public DNS zones
  • Design private DNS zones
  • Configure public and private DNS zones
  • Link a private DNS zone to a VNet
  • Design and implement Azure DNS Private Resolver

Design and implement VNet connectivity and routing

  • Design service chaining, including gateway transit
  • Implement VNet peering
  • Implement and manage virtual network connectivity by using Azure Virtual Network Manager
  • Design and implement user-defined routes (UDRs)
  • Associate a route table with a subnet
  • Configure forced tunneling
  • Diagnose and resolve routing issues
  • Design and implement Azure Route Server
  • Identify appropriate use cases for Azure NAT Gateway
  • Implement Azure NAT Gateway

Monitor networks

  • Configure monitoring, network diagnostics, and logs in Azure Network Watcher
  • Monitor and troubleshoot network health by using Azure Network Watcher
  • Monitor and troubleshoot networks by using Azure Monitor for Networks
  • Activate and monitor distributed denial-of-service (DDoS) protection
  • Evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score
  • Evaluate network security recommendations identified by Microsoft Defender for Cloud attack oaths
  • Identify network resources by using Microsoft Defender for Cloud Security Explorer

Design, implement, and manage connectivity services (20–25%)

This domain covers the skills needed to work with the topics described below. Study each objective carefully and use the linked resources to deepen your understanding.

Design, implement, and manage a site-to-site VPN connection

  • Design a site-to-site VPN connection, including for high availability
  • Select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements
  • Implement a site-to-site VPN connection
  • Identify when to use a policy-based VPN versus a route-based VPN connection
  • Create and configure a local network gateway
  • Create and configure an IPsec/Internet Key Exchange (IKE) policy
  • Create and configure a virtual network gateway
  • Diagnose and resolve virtual network gateway connectivity issues
  • Implement Azure Extended Network

Design, implement, and manage a point-to-site VPN connection

  • Select an appropriate virtual network gateway SKU for point-to-site VPN requirements
  • Select and configure a tunnel type
  • Select an appropriate authentication method
  • Configure RADIUS authentication
  • Configure authentication by using Microsoft Entra ID
  • Implement a VPN client configuration file
  • Diagnose and resolve client-side and authentication issues
  • Specify Azure requirements for Always On VPN
  • Specify Azure requirements for Azure Network Adapter

Design, implement, and manage Azure ExpressRoute

  • Select an ExpressRoute connectivity model
  • Select an appropriate ExpressRoute SKU and tier
  • Design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery
  • Design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct
  • Choose between Azure private peering only, Microsoft peering only, or both
  • Configure Azure private peering
  • Configure Microsoft peering
  • Create and configure an ExpressRoute gateway
  • Connect a virtual network to an ExpressRoute circuit
  • Recommend a route advertisement configuration
  • Configure encryption over ExpressRoute
  • Implement Bidirectional Forwarding Detection
  • Diagnose and resolve ExpressRoute connection issues

Design and implement an Azure Virtual WAN architecture

  • Select a Virtual WAN SKU
  • Design a Virtual WAN architecture, including selecting types and services
  • Create a virtual hub in Virtual WAN
  • Choose an appropriate scale unit for each gateway type
  • Deploy a gateway into a virtual hub
  • Configure virtual hub routing
  • Integrate a virtual hub with a third-party NVA for cloud connectivity

Design and implement application delivery services (15–20%)

This domain covers the skills needed to work with the topics described below. Study each objective carefully and use the linked resources to deepen your understanding.

Design and implement Azure Load Balancer and Azure Traffic Manager

  • Map requirements to features and capabilities of Azure Load Balancer
  • Identify appropriate use cases for Azure Load Balancer
  • Choose an Azure Load Balancer SKU and tier
  • Choose between public and internal load balancers
  • Choose between regional and cross-region load balancers
  • Create and configure an Azure Load Balancer
  • Implement Azure Traffic Manager
  • Implement Gateway Load Balancer
  • Implement a load balancing rule
  • Create and configure inbound NAT rules
  • Create and configure explicit outbound rules, including source network address translation (SNAT)

Design and implement Azure Application Gateway

  • Map requirements to features and capabilities of Azure Application Gateway
  • Identify appropriate use cases for Azure Application Gateway
  • Choose between manual and autoscale
  • Create a backend pool
  • Configure health probes
  • Configure listeners
  • Configure routing rules
  • Configure HTTP settings
  • Configure Transport Layer Security (TLS)
  • Configure rewrite rule sets

Design and implement Azure Front Door

  • Map requirements to features and capabilities of Azure Front Door
  • Identify appropriate use cases for Azure Front Door
  • Choose an appropriate tier
  • Configure an Azure Front Door, including routing, origins, and endpoints
  • Configure TLS termination and end-to-end TLS encryption
  • Configure caching
  • Configure traffic acceleration
  • Implement rules, URL rewrite, and URL redirect
  • Secure an origin by using Azure Private Link in Azure Front Door

Design and implement private access to Azure services (10–15%)

This domain covers the skills needed to work with the topics described below. Study each objective carefully and use the linked resources to deepen your understanding.

  • Plan private endpoints
  • Create private endpoints
  • Configure access to private endpoints
  • Create a Private Link service
  • Integrate Private Link and Private Endpoint with DNS
  • Integrate a Private Link service with on-premises clients

Design and implement service endpoints

  • Choose when to use a service endpoint
  • Create service endpoints
  • Configure service endpoint policies
  • Configure access to service endpoints

Design and implement Azure network security services (15–20%)

This domain covers networking. You need to understand virtual networks, connectivity, load balancing, DNS, and network security.

Implement and manage network security groups

  • Create a network security group (NSG)
  • Associate a NSG to a resource
  • Create an application security group (ASG)
  • Associate an ASG to a network interface
  • Create and configure NSG inbound and outbound security rules
  • Implement virtual network flow logs
  • Interpret virtual network flow logs
  • Verify IP flow
  • Configure an NSG for remote server administration, including Azure Bastion
  • Implement and manage virtual network security by using Azure Virtual Network Manager

Design and implement Azure Firewall and Azure Firewall Manager

  • Map requirements to features and capabilities of Azure Firewall
  • Select an appropriate Azure Firewall SKU
  • Design an Azure Firewall deployment
  • Create and implement an Azure Firewall deployment
  • Configure Azure Firewall rules
  • Create and implement Azure Firewall Manager policies
  • Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub

Design and implement a Web Application Firewall (WAF) deployment

  • Map requirements to features and capabilities of WAF
  • Design a WAF deployment
  • Configure detection or prevention mode
  • Configure rule sets for WAF on Azure Front Door
  • Configure rule sets for WAF on Application Gateway
  • Implement a WAF policy
  • Associate a WAF policy

What to Study Next

Based on this exam, here are related certifications to consider:


20 Free Questions Practice Exam $9 →