certslothcertsloth
← AZ-700 overview

Azure Network Engineer Associate / STUDY TOOLS

AZ-700 quick review

Memory hook: DNS → route → filter → translation → listener.

Reviewed 10 October 2026. Read this once, then answer the last-pass checks without looking.

Must remember by domain

Domain Rapid revision
Core networking Plan nonoverlapping VNet/subnet ranges with room for delegated/gateway services. Azure reserves five addresses in each IPv4 subnet. Peering is nontransitive. Longest-prefix routes win; equal-prefix preference is normally UDR, BGP, system, subject to service-specific rules. NVA routing needs NIC/OS forwarding and a valid return path.
DNS and diagnostics Public DNS is authoritative hosting, not registration. Private-zone links supply resolution; autoregistration is separate. Private Resolver inbound endpoints accept queries into Azure; outbound endpoints/rulesets forward selected namespaces out. Test client-side DNS before route changes. Connection Monitor trends paths; Network Watcher verifies rules/routes and supported captures.
Hybrid connectivity S2S VPN connects networks with IPsec; P2S connects clients. Route-based gateways/BGP support appropriate redundant designs. ExpressRoute is private provider connectivity, not automatically end-to-end encryption; circuit, provider/location and gateway redundancy are separate. Virtual WAN centralizes managed hubs with route-table association/propagation and routing intent.
Application delivery Load Balancer handles regional L4 flows; Application Gateway handles regional HTTP routing/TLS/WAF; Front Door handles global HTTP origins/edge delivery; Traffic Manager steers DNS. Health probes, host headers, certificate names/SNI and backend ports must agree. Restrict origin bypass paths.
Private access Service endpoint keeps the service public endpoint but adds supported VNet identity/rules. Private endpoint assigns a private IP to a selected resource/subresource. Private Link service publishes supported provider workloads. DNS, approval, public access settings and data authorization are independent.
Network security NSGs are stateful subnet/NIC filters; ASGs group supported VM interfaces. Azure Firewall centralizes network/application rules; Premium adds supported TLS inspection/IDPS. WAF inspects HTTP threats; DDoS protection addresses network floods. Network Manager centrally deploys supported connectivity/security policy.

Diagnosis and common traps

Resolve from the failing client → verify intended destination IP → inspect effective routes/BGP → check both-direction stateful firewall path → inspect NSGs/probe allowance → test actual listener and TLS. For intermittent egress, inspect SNAT ports and connection churn. Large-packet-only failure suggests MTU/MSS/path-MTU issues. Private DNS is not inherited merely because networks are peered. VNet flow logs record metadata, not a full application payload; prefer their current deployment guidance over retired NSG-flow-log assumptions.

Last-pass self-check

1. How many usable IPv4 addresses in an Azure /27 subnet?

32 total minus 5 reserved = 27.

2. A specific BGP route versus a less-specific UDR: which wins?

The more-specific matching route normally wins; source preference compares equal prefixes.

3. Does ExpressRoute guarantee encryption?

No. Design encryption separately where required.

4. Why can an internal private endpoint resolve publicly?

Missing zone links, wrong DNS servers or incomplete hybrid forwarding.

5. Why does a working probe not prove the app works?

It may test a different path/port or omit the failed dependency.

Sources

Every topic at a glance

Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.

01 · Virtual Networks, Routes and Secure Access

Memory hook: Check the effective route and the effective rule in both directions.

Must remember

  • VNets contain address spaces and subnets. Plan non-overlapping ranges and future growth; supported peering requires compatible addresses. Peering connects VNets but is not automatically transitive through a third VNet.
  • Azure selects routes using prefix specificity and route-source precedence for equal prefixes; inspect effective routes when system, BGP and user-defined routes interact. A UDR can direct traffic to a virtual appliance, but the appliance must forward it and the return path must work.
  • For ordinary equal-prefix comparisons, remember UDR → BGP → system; first compare the destination prefix length. A matching /24 normally beats a /16 regardless of that general source order. Service-specific routes have exceptions: service-endpoint routes cannot simply be overridden by a UDR. Inspect the effective route rather than treating the mnemonic as universal.
  • Azure reserves the first four and last IPv4 addresses of each subnet. A /27 contains 32 addresses, leaving 27 usable; service-specific subnet sizing can require more than the generic minimum. Subnet capacity planning must include service reservations and scale-out needs.
  • NSGs are stateful network filtering with priority-ordered allow/deny rules. They can apply at subnet and NIC scopes; evaluate the effective combination. Application security groups group supported VM interfaces for rule targeting; they are not application-layer WAFs.
  • Public IP addresses have SKU/allocation/zone properties. NAT Gateway supports explicit outbound SNAT for associated subnets; consider port use and destination patterns. Do not assume new workloads receive default outbound internet access.
  • Bastion provides managed administration through supported private VM access without exposing a public management port on each VM. It still needs the required deployment/network configuration and authorised users.
  • Service endpoints extend supported service access from a VNet using its public service endpoint and service-side rules. Private endpoints use a private IP for a specific resource/subresource; DNS must resolve appropriately. Endpoint creation and resource approval are separate checks.
  • Diagnose with Network Watcher tools, Connection Monitor, effective security rules/routes, name resolution and application listener checks. Existing stateful flows may not behave like brand-new test connections after a rule change.

Choose under exam pressure

Requirement Choice and reason
One private PaaS resource endpoint Private Link/private endpoint with private DNS.
Traffic must traverse a network appliance UDR plus forwarding and a symmetric return path.
VM administration without a VM public IP Bastion where appropriate.

Traps

  • Peering is not automatically transitive.
  • A service endpoint does not put the service itself inside your subnet.
  • An NSG allow does not create a route.

Practise this topic

02 · DNS and Load Balancing

Memory hook: DNS answers names; Layer 4 forwards connections; Layer 7 routes application requests.

Must remember

  • Azure DNS hosts authoritative public zones; domain registration is a separate function. Delegate with the correct name servers. Private DNS zones require links to the VNets that need resolution; autoregistration is a specific feature, not universal record creation.
  • Azure DNS Private Resolver supports hybrid resolution through inbound/outbound endpoints and forwarding rulesets. Avoid loops and test from the real client network. DNS TTL and negative caching can make a corrected record appear stale.
  • Azure Load Balancer operates at Layer 4 for supported TCP/UDP traffic, with public or internal frontends, backend pools, probes and rules. Probe success depends on the actual response and permitted probe path. An inbound NAT rule is not the same as balancing to a pool.
  • Application Gateway provides regional HTTP/S routing and WAF integration. Front Door provides global HTTP/S application delivery and edge features. Traffic Manager uses DNS routing and is not a reverse proxy for every request.
  • TLS can terminate at an application gateway/edge, with a separate encrypted connection to the origin where configured. Host headers, certificate names, SNI and backend settings must align. A valid frontend certificate does not prove origin TLS works.
  • Troubleshoot the client DNS answer, frontend connectivity, rule, backend health and application listener in order. A health probe can be too shallow: test a path that reflects usable service without making every shared dependency trigger an unnecessary fleet-wide outage.

Choose under exam pressure

Requirement Choice and reason
Regional path-based HTTP routing Application Gateway.
Global HTTP application delivery Front Door.
TCP/UDP load distribution Azure Load Balancer.

Traps

  • Traffic Manager decisions can remain cached.
  • A healthy probe is only as useful as its tested condition.
  • Private-zone association is not inherited through every network connection.

Practise this topic

03 · VPN, ExpressRoute and Virtual WAN

Memory hook: A hybrid path needs non-overlapping addresses, compatible routing and tested redundancy.

Must remember

  • Plan address space, subnet growth, gateway subnets and route limits. Use system routes, UDRs and BGP deliberately; longest-prefix matching precedes equal-prefix route-source preference. Network virtual appliances need IP forwarding and a valid return path.
  • Site-to-site VPN connects networks over IPsec; point-to-site connects individual clients. Select gateway SKU, route-based/policy compatibility, authentication and protocols according to the scenario. Active-active designs and BGP can improve availability, but client/on-premises equipment must support the topology.
  • ExpressRoute uses provider connectivity and peering to reach supported Microsoft services; private peering serves Azure private networking. It is not inherently end-to-end encrypted. ExpressRoute gateways, circuit bandwidth, provider paths and regional/global reach features have separate constraints.
  • Design redundant circuits/locations where the availability requirement demands it. A single provider path can remain a common failure point. VPN backup needs suitable routes, capacity and failover testing; equal physical capacity does not guarantee equal application throughput.
  • Virtual WAN supplies managed hub connectivity and routing capabilities. Hub route tables, associations, propagation and routing intent affect which traffic reaches firewalls or other networks. VNet peering gateway transit and use-remote-gateway settings solve a different topology and have compatibility constraints.
  • Hybrid DNS uses Private Resolver inbound/outbound endpoints and forwarding rulesets or another supported resolver design. Link the correct private zones, prevent loops and permit required UDP/TCP traffic. Network connectivity alone does not share DNS resolution.

Choose under exam pressure

Requirement Choice and reason
Remote users need individual VPN access Point-to-site VPN.
Managed hub connectivity across branches/VNets Virtual WAN when its routing/operating model fits.
Dedicated provider connectivity ExpressRoute, with separate encryption and resilience decisions.

Traps

  • A second logical connection may share the same physical failure domain.
  • BGP advertisements do not create all subnet/return routes automatically.
  • Peering and Virtual WAN do not erase overlapping-address constraints.

Practise this topic

04 · Application Delivery and Network Security

Memory hook: Choose the traffic layer, then preserve origin access, TLS and inspection symmetry.

Must remember

  • Load Balancer handles Layer 4 flows; Application Gateway handles regional HTTP/S routing; Front Door handles global HTTP/S delivery. Configure backend pools/origin groups, probes, rules and failover priorities according to the selected product.
  • Host/path routing needs correct host headers and backend TLS/SNI. Front Door origins should reject unwanted bypass paths using supported origin-access controls. Caching requires deliberate keys, TTL and invalidation; never cache personalised responses as shared public content.
  • WAF managed/custom/rate-limit rules inspect web requests; choose detection/prevention and exclusions based on observed false positives. Azure Firewall supports network/application rules and SKU-specific capabilities; policy hierarchy and rule processing order matter. NSGs filter connections at subnet/NIC scopes.
  • DDoS protection addresses volumetric/network attacks under the selected plan; it does not replace WAF or secure application logic. Network Manager can centrally manage supported connectivity/security configurations; staged rollout avoids widespread incorrect routing.
  • Private Link service exposes supported provider services through consumer private endpoints. Approvals, endpoint subresources, DNS and backend configuration all matter. Service endpoints are a different mechanism and still use service public endpoints with network identity/rules.
  • Centralised inspection must handle symmetric stateful flows and zone failures. TLS inspection requires a supported SKU/configuration, certificate trust and a reasoned exception policy. Do not assume encrypting traffic means a firewall can inspect its application payload.

Choose under exam pressure

Requirement Choice and reason
Block malicious HTTP payload patterns WAF on a supported application delivery service.
Inspect outbound destination domains Appropriate Firewall application rules and DNS design.
Expose a specific service privately to consumers Private Link service/endpoints where supported.

Traps

  • TLS termination and end-to-end TLS are different designs.
  • A health probe can succeed while the requested host/path fails.
  • A firewall can be bypassed by an unintended alternate route.

Practise this topic

05 · Network Monitoring and Failure Isolation

Memory hook: Test name resolution, route, permission, listener and response as separate hypotheses.

Must remember

  • Use Network Watcher connection troubleshooting, IP flow verification, effective routes/security rules and packet capture for supported scenarios. Connection Monitor measures paths over time. A configuration-analysis result is not the same as a successful business request.
  • VNet flow logs provide supported traffic metadata; legacy NSG flow-log availability/retirement differs, so use current guidance when deploying new telemetry. Flow data does not contain every application payload; packet capture has additional permissions, privacy and volume implications.
  • Check DNS from the affected client context, including private-zone links and forwarding. Compare actual destination IP with the intended endpoint. A successful public lookup can hide a missing private DNS configuration.
  • Diagnose intermittent outbound failures using SNAT utilisation, connection churn, timeouts and destination distribution. Long-lived connection reuse and an explicit scalable egress design can help; opening every inbound port does not repair SNAT exhaustion.
  • Large-packet failures suggest MTU/MSS or path-MTU discovery issues. Asymmetric routing can produce failures that look like random firewall drops. BGP changes and DNS caches can cause different clients to observe different transition times.
  • Monitor probes, backend health, gateway/circuit metrics, firewall/WAF events and route changes. Use narrow diagnostic time ranges and known test flows. Automate changes through reviewed IaC with rollback and evaluate cross-zone, gateway, firewall and transfer charges against expected traffic.

Choose under exam pressure

Requirement Choice and reason
Only some new outbound connections fail Inspect SNAT capacity and connection patterns.
One subnet cannot reach an endpoint Compare its effective routes, NSGs and DNS context.
Need historical path availability Connection Monitor with suitable test targets.

Traps

  • No traffic logs may indicate missing collection rather than no traffic.
  • An allow rule cannot repair a missing return path.
  • Averages hide intermittent failure and tail latency.

Practise this topic

Search across every published topic.