AZ-700 Official Course Study Guide
AZ-700 Official Course Study Guide
AZ-700
Official
Course Study
Guide
For this exam, Microsoft suggests candidates should have subject matter expertise in planning,
implementing, and maintaining Azure networking solutions, including hybrid networking,
connectivity, routing, security, and private access to Azure services.
Candidates for this exam should also have expert Azure administration skills, in addition to extensive
experience and knowledge of networking, hybrid connections, and network security.
Books/e-books
Video training
Page | 2
To become an Azure Network Solution engineer, it’s
important to pass the Exam AZ-700 Designing and
Implementing Microsoft Azure Networking Solutions.
Before that, it is recommended to try out our updated
AZ-700 practice test questions which cover:
Microsoft Learn
Those tutorials/paths have been combined by Microsoft and published for free. They contain a
collection of text, videos, and exercises for the exam:
Page | 4
AZ-700: Design and implement network
monitoring
You will learn to design and implement network
monitoring solutions such as Azure Monitor and
Network watcher.
Page | 5
This guide is divided up into the following sections and is also part of the exam:
Feel free to join our Facebook Azure Study Group, or check out the Azure courses on Udemy. Errors
and suggestions can also be reported in the Azure Group on Facebook.
Thank you,
Page | 6
Contents
Introduction............................................................................................................................................. 1
About the exam ............................................................................................................................... 1
Books/e-books ................................................................................................................................. 1
Video training .................................................................................................................................. 2
Microsoft Learn ............................................................................................................................... 3
Design, Implement, and Manage Hybrid Networking (10–15%) ............................................................ 8
Design, implement, and manage a site-to-site VPN connection..................................................... 8
Design, implement, and manage a point-to-site VPN connection .................................................. 8
Design, implement, and manage Azure ExpressRoute.................................................................... 9
Design and Implement Core Networking Infrastructure (20–25%) ...................................................... 10
Design and implement private IP addressing for VNets................................................................ 10
Design and implement name resolution ....................................................................................... 11
Design and implement cross-VNet connectivity ........................................................................... 11
Design and implement an Azure Virtual WAN architecture.......................................................... 11
Design and Implement Routing (25–30%)............................................................................................. 12
Design, implement, and manage VNet routing ............................................................................. 12
Design and implement an Azure Load Balancer ............................................................................ 13
Design and implement Azure Application Gateway ...................................................................... 13
Implement Azure Front Door ........................................................................................................ 14
Implement an Azure Traffic Manager profile ................................................................................ 14
Design and implement an Azure Virtual Network NAT ................................................................. 15
Secure and Monitor Networks (15–20%) .............................................................................................. 15
Design, implement, and manage an Azure Firewall deployment ................................................. 15
Implement and manage network security groups (NSGs) ............................................................ 15
Implement a Web Application Firewall (WAF) deployment ......................................................... 16
Monitor networks.......................................................................................................................... 17
Design and Implement Private Access to Azure Services (10–15%) ..................................................... 17
Design and implement Azure Private Link service and Azure Private Endpoint ........................... 17
Design and implement service endpoints ..................................................................................... 18
Configure VNet integration for dedicated platform as a service (PaaS) services ......................... 18
Page | 7
Design, Implement, and Manage Hybrid Networking (10–15%)
Design, implement, and manage a site-to-site VPN connection
Design a site-to-site VPN connection for high availability
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-connect-multiple-policybased-
rm-ps#about
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpngateways#gwsku
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-connect-multiple-policybased-
rm-ps#about
https://docs.microsoft.com/en-us/azure/vpn-gateway/tutorial-site-to-site-
portal#LocalNetworkGateway
https://docs.microsoft.com/en-us/azure/vpn-gateway/ipsec-ike-policy-howto
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-ipsecikepolicy-rm-powershell
https://docs.microsoft.com/en-us/azure/vpn-gateway/tutorial-create-gateway-portal
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-troubleshoot-site-to-site-
cannot-connect
https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-diagnose-on-premises-
connectivity
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpngateways#gwsku
https://docs.microsoft.com/en-us/azure/vpn-gateway/point-to-site-how-to-radius-ps
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-howto-point-to-site-resource-
manager-portal
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-howto-openvpn
Page | 8
Plan and configure authentication by using Microsoft Azure Active Directory (Azure AD), part of
Microsoft Entra
https://docs.microsoft.com/en-us/azure/vpn-gateway/openvpn-azure-ad-tenant
https://docs.microsoft.com/en-us/azure/vpn-gateway/point-to-site-vpn-client-configuration-radius
https://docs.microsoft.com/en-us/azure/vpn-gateway/point-to-site-vpn-client-configuration-azure-
cert
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-troubleshoot-vpn-point-to-site-
connection-problems
https://docs.microsoft.com/en-us/azure/vpn-gateway/troubleshoot-ad-vpn-client
https://docs.microsoft.com/en-us/azure/expressroute/expressroute-erdirect-about#expressroute-
using-a-service-provider-and-expressroute-direct
Locations
https://docs.microsoft.com/en-us/azure/expressroute/cross-network-connectivity
https://docs.microsoft.com/en-us/azure/expressroute/expressroute-about-virtual-network-
gateways#gwsku
https://docs.microsoft.com/en-us/azure/expressroute/expressroute-global-reach
https://docs.microsoft.com/en-us/azure/expressroute/expressroute-howto-set-global-reach
https://docs.microsoft.com/en-us/azure/expressroute/about-fastpath
https://docs.microsoft.com/en-us/azure/expressroute/howto-linkvnet-cli#configure-expressroute-
fastpath
https://docs.microsoft.com/en-us/azure/expressroute/expressroute-circuit-
peerings#routingdomains
https://docs.microsoft.com/en-us/azure/expressroute/expressroute-circuit-
peerings#peeringcompare
Page | 9
Configure private peering
https://docs.microsoft.com/en-us/azure/vpn-gateway/site-to-site-vpn-private-
peering?toc=/azure/expressroute/toc.json
https://docs.microsoft.com/en-us/azure/expressroute/site-to-site-vpn-over-microsoft-peering
https://docs.microsoft.com/en-us/azure/expressroute/expressroute-about-virtual-network-
gateways
https://docs.microsoft.com/en-us/azure/expressroute/expressroute-howto-add-gateway-portal-
resource-manager
https://docs.microsoft.com/en-us/azure/expressroute/expressroute-howto-linkvnet-portal-
resource-manager
https://docs.microsoft.com/en-us/azure/expressroute/expressroute-routing#advertising-default-
routes
https://docs.microsoft.com/en-us/azure/virtual-wan/vpn-over-expressroute
https://docs.microsoft.com/en-us/azure/expressroute/expressroute-bfd
https://docs.microsoft.com/en-us/azure/expressroute/expressroute-troubleshooting-network-
performance
https://docs.microsoft.com/en-us/azure/virtual-network/quick-create-portal
Plan and configure subnetting for services, including VNet gateways, private endpoints,
https://techcommunity.microsoft.com/t5/itops-talk-blog/configuring-azure-virtual-network-subnets-
with-cidr-notation/ba-p/2047809
https://docs.microsoft.com/en-us/azure/application-gateway/configuration-infrastructure
Page | 10
Plan and configure subnet delegation
https://docs.microsoft.com/en-us/azure/virtual-network/subnet-delegation-overview
https://docs.microsoft.com/en-us/azure/virtual-network/manage-subnet-delegation
Quickstart: Create and configure Route Server using the Azure portal | Microsoft Learn
https://docs.microsoft.com/en-us/azure/architecture/hybrid/hybrid-dns-infra
https://docs.microsoft.com/en-us/azure/dns/private-dns-privatednszone
https://docs.microsoft.com/en-us/azure/virtual-network/virtual-networks-name-resolution-for-vms-
and-role-instances
https://docs.microsoft.com/en-us/azure/dns/dns-getstarted-portal
https://docs.microsoft.com/en-us/azure/dns/private-dns-getstarted-portal
https://docs.microsoft.com/en-us/azure/dns/private-dns-getstarted-portal#link-the-virtual-network
https://ravikirans.com/coursera/vnet-service-chaining
https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-peering-overview#service-
chaining
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-howto-vnet-vnet-resource-
manager-portal
https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-manage-peering
https://docs.microsoft.com/en-us/azure/virtual-wan/virtual-wan-about
https://docs.microsoft.com/en-us/azure/virtual-wan/migrate-from-hub-spoke-topology#architecture
Page | 11
Connect a VNet gateway to Azure Virtual WAN
https://docs.microsoft.com/en-us/azure/virtual-wan/connect-virtual-network-gateway-vwan
https://docs.microsoft.com/en-us/azure/virtual-wan/virtual-wan-site-to-site-portal#hub
https://docs.microsoft.com/en-us/azure/virtual-wan/about-nva-hub
https://docs.microsoft.com/en-us/azure/virtual-wan/how-to-nva-hub
https://docs.microsoft.com/en-us/azure/virtual-wan/about-virtual-hub-routing
https://docs.microsoft.com/en-us/azure/virtual-wan/how-to-virtual-hub-routing
https://docs.microsoft.com/en-us/azure/virtual-wan/pricing-concepts#connection-unit
https://docs.microsoft.com/en-us/azure/virtual-network/virtual-networks-udr-overview#user-
defined
https://docs.microsoft.com/en-us/azure/virtual-network/tutorial-create-route-table-portal
https://docs.microsoft.com/en-us/azure/virtual-network/manage-route-table#associate-a-route-
table-to-a-subnet
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-forced-tunneling-rm
https://docs.microsoft.com/en-us/azure/network-watcher/diagnose-vm-network-routing-problem-
powershell
https://docs.microsoft.com/en-us/azure/virtual-network/diagnose-network-routing-problem
Quickstart: Create and configure Route Server using the Azure portal | Microsoft Learn
Page | 12
Design and implement an Azure Load Balancer
Choose an Azure Load Balancer SKU (Basic versus Standard)
https://docs.microsoft.com/en-us/azure/load-balancer/skus
https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-overview
https://docs.microsoft.com/en-us/azure/load-balancer/quickstart-load-balancer-standard-public-
portal?tabs=option-1-create-load-balancer-standard
https://docs.microsoft.com/en-us/azure/load-balancer/tutorial-cross-region-portal
https://docs.microsoft.com/en-us/azure/virtual-machines/windows/tutorial-load-balancer#create-a-
load-balancer-rule
https://docs.microsoft.com/en-us/azure/load-balancer/tutorial-load-balancer-port-forwarding-
portal#create-an-inbound-nat-port-forwarding-rule
https://docs.microsoft.com/en-us/azure/load-balancer/outbound-rules
https://docs.microsoft.com/en-us/azure/load-balancer/quickstart-load-balancer-standard-public-
portal?tabs=option-1-create-load-balancer-standard#create-outbound-rule-configuration
https://docs.microsoft.com/en-us/azure/application-gateway/quick-create-portal
https://docs.microsoft.com/en-us/azure/application-gateway/application-gateway-autoscaling-zone-
redundant#scaling-application-gateway-and-waf-v2
https://docs.microsoft.com/en-us/azure/application-gateway/quick-create-portal#backends-tab
https://docs.microsoft.com/en-us/azure/application-gateway/application-gateway-create-probe-
portal#create-probe-for-application-gateway-v2-sku
Configure listeners
https://docs.microsoft.com/en-us/azure/application-gateway/configuration-listeners
https://docs.microsoft.com/en-us/azure/application-gateway/configuration-request-routing-rules
Page | 13
Configure HTTP settings
https://docs.microsoft.com/en-us/azure/application-gateway/configuration-http-settings
https://docs.microsoft.com/en-us/azure/application-gateway/application-gateway-end-to-end-ssl-
powershell
https://docs.microsoft.com/en-us/azure/application-gateway/rewrite-url-portal
https://docs.microsoft.com/en-us/azure/frontdoor/standard-premium/tier-comparison
https://docs.microsoft.com/en-us/azure/////frontdoor/front-door-health-probes
https://docs.microsoft.com/en-us/azure/frontdoor/standard-premium/how-to-configure-https-
custom-domain
https://docs.microsoft.com/en-us/azure/application-gateway/multiple-site-overview
https://docs.microsoft.com/en-us/azure/frontdoor/front-door-backend-pool
https://docs.microsoft.com/en-us/azure/frontdoor/front-door-route-matching
https://docs.microsoft.com/en-us/azure/frontdoor/front-door-how-to-redirect-https
https://docs.microsoft.com/en-us/azure/traffic-manager/traffic-manager-routing-methods
https://docs.microsoft.com/en-us/azure/traffic-manager/traffic-manager-configure-priority-routing-
method
Configure endpoints
https://docs.microsoft.com/en-us/azure/traffic-manager/quickstart-create-traffic-manager-
profile#add-traffic-manager-endpoints
https://docs.microsoft.com/en-us/azure/traffic-manager/traffic-manager-monitoring#configure-
endpoint-monitoring
Page | 14
Design and implement an Azure Virtual Network NAT
Choose when to use a Virtual Network NAT
https://docs.microsoft.com/en-us/azure/virtual-network/nat-overview
https://docs.microsoft.com/en-us/azure/virtual-network/nat-gateway-resource
https://docs.microsoft.com/en-us/azure/virtual-network/nat-overview
https://docs.microsoft.com/en-us/azure/firewall/tutorial-firewall-deploy-portal
https://docs.microsoft.com/en-us/azure/firewall/tutorial-firewall-deploy-portal-policy
https://docs.microsoft.com/en-us/azure/firewall/rule-processing
https://docs.microsoft.com/en-us/azure/firewall-manager/policy-overview
Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub
https://docs.microsoft.com/en-us/azure/virtual-wan/howto-firewall
https://docs.microsoft.com/en-us/azure/firewall-manager/secure-cloud-network
https://docs.microsoft.com/en-us/azure/virtual-wan/about-nva-hub
https://docs.microsoft.com/en-us/azure/virtual-wan/scenario-route-through-nva
https://docs.microsoft.com/en-us/azure/virtual-network/manage-network-security-group#create-a-
network-security-group
https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-network-
interface#associate-or-dissociate-a-network-security-group
https://docs.microsoft.com/en-us/azure/virtual-network/tutorial-filter-network-traffic#associate-
network-security-group-to-subnet
https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-network-
interface#associate-or-dissociate-a-network-security-group
https://docs.microsoft.com/en-us/azure/virtual-network/manage-network-security-group#create-a-
security-rule
https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-read-nsg-flow-logs
https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-nsg-flow-logging-
overview
Verify IP flow
https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-ip-flow-verify-overview
https://channel9.msdn.com/Blogs/Azure-Help/Troubleshoot-NSG-configuration-using-IP-Flow-Verify
https://docs.microsoft.com/en-us/azure/web-application-firewall/ag/ag-overview#waf-modes
https://docs.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-create-
portal#change-mode
Configure rule sets for Azure Front Door, including Microsoft managed and user defined
https://docs.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-create-
portal#default-rule-set-drs
https://docs.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-
drs?tabs=drs20
https://docs.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-custom-rules
Configure rule sets for Application Gateway, including Microsoft managed and user Defined
https://docs.microsoft.com/en-us/azure/web-application-firewall/ag/application-gateway-crs-
rulegroups-rules?tabs=owasp31
https://docs.microsoft.com/en-us/azure/web-application-firewall/ag/custom-waf-rules-overview
https://github.com/MicrosoftDocs/azure-docs/blob/master/articles/web-application-
firewall/ag/create-custom-waf-rules.md
Page | 16
Implement a WAF policy
https://docs.microsoft.com/en-us/azure/web-application-firewall/ag/create-waf-policy-ag
https://docs.microsoft.com/en-us/azure/web-application-firewall/ag/associate-waf-policy-existing-
gateway
Monitor networks
Configure network health alerts and logging by using Azure Monitor
https://docs.microsoft.com/en-us/azure/azure-monitor/insights/network-insights-
overview#networkhealth
https://docs.microsoft.com/en-us/azure/network-watcher/connection-monitor-create-using-portal
https://docs.microsoft.com/en-us/azure/network-watcher/traffic-analytics
https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-nsg-flow-logging-azure-
resource-manager
https://docs.microsoft.com/en-us/azure/azure-monitor/essentials/diagnostic-settings?tabs=CMD
https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-create
https://docs.microsoft.com/en-us/azure/private-link/create-private-link-service-portal
https://docs.microsoft.com/en-us/azure/private-link/private-endpoint-overview
https://docs.microsoft.com/en-us/azure/private-link/create-private-endpoint-portal
https://docs.microsoft.com/en-us/azure/storage/common/storage-private-endpoints
https://docs.microsoft.com/en-us/azure/cloud-adoption-framework/ready/azure-best-
practices/private-link-and-dns-integration-at-scale
Page | 17
Integrate a Private Link service with on-premises clients
https://docs.microsoft.com/en-us/azure/private-link/tutorial-private-endpoint-sql-portal
https://docs.microsoft.com/en-us/azure/virtual-network/tutorial-restrict-network-access-to-
resources
https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-service-endpoint-policies-
portal
https://docs.microsoft.com/en-us/azure/virtual-network/service-tags-overview
https://docs.microsoft.com/en-us/azure/service-bus-messaging/service-bus-service-endpoints
https://docs.microsoft.com/en-us/azure/app-service/web-sites-integrate-with-vnet
https://docs.microsoft.com/en-us/azure/aks/private-clusters
https://docs.microsoft.com/en-us/azure/app-service/environment/using-an-ase#app-access
Page | 18