Microsoft Azure Network Engineer [AZ-700] Exam Guide (2026)
![Microsoft Azure Network Engineer [AZ-700] Exam Guide (2026)](/_next/image?url=https%3A%2F%2Fcdn.sanity.io%2Fimages%2F2oo9oqu3%2Fproduction%2F06d7fdf8a89bb95b4bdb7199dd0e232db9a10a78-1600x789.png%3Frect%3D99%2C0%2C1403%2C789%26w%3D1200%26h%3D675&w=3840&q=75)
If you can say whether a branch should ride a site-to-site VPN, an ExpressRoute circuit, or a Virtual WAN hub, why Azure Load Balancer does not stop a SQL injection, and whether a storage account needs a service endpoint or a private endpoint, you are reading the right outline.
AZ-700 is the exam behind Microsoft Certified: Azure Network Engineer Associate. The credential page marks it intermediate, Azure, network engineer role, technical infrastructure, with a last updated date of 29 July 2026. The study guide publishes the matching skills outline under the heading Skills measured as of July 27, 2026. That outline is the whole scope of the current sitting.
The sitting is live. The credential page publishes 100 minutes, a Pearson VUE schedule path, and a free practice assessment. Associate certifications expire annually and renew on a free, unproctored Microsoft Learn assessment. This guide is for people scheduling that July 2026 blueprint, who already hold the title and need the current task list, or who are moving from Azure administration into the network-engineer role.
Who this exam is for
Take it as a map of the Azure network-engineer job Microsoft scores under this code. The audience profile asks for subject matter expertise planning, implementing, and managing Azure networking solutions. The five named areas are core network infrastructure, hybrid connectivity, application delivery services, private access to Azure services, and network security.
The responsibility list is concrete. Optimize performance, resiliency, scale, and security of Azure networking solutions. Monitor network environments to find issues and reduce risk. Identify and resolve connectivity problems. Microsoft is explicit that the role sits with solution architects, cloud administrators, security engineers, application developers, and DevOps engineers. The network engineer is the person who designs the path, picks the SKU, and owns the packet when it fails.
The prerequisite list is a gap check. Experience creating and managing compute, storage, and networking resources in Azure. A working grasp of name resolution, network protocols, and network address management. If those three fundamentals are things you have only read about, the sitting will feel like a product catalog rather than a job test.
Skip it if the goal is the language of the cloud rather than the design of it. Service definitions, pricing models, and shared responsibility belong to AZ-900. Skip it if the work you actually want is running someone else's subscription day to day without owning the hybrid path, the delivery service, or the private access design, because that job is AZ-104. Skip it if the work you actually want is hardening identity, compute, and posture without owning ExpressRoute SKUs, Front Door origins, or Virtual WAN hubs, because that job is AZ-500. Networking appears on both of those outlines. It is scored here as the whole job.
The current associate networking credential Microsoft publishes is this one. Use this page for the AZ-700 task list. Use the AZ-104 exam guide when the stem is an administrator control that happens to sit on a virtual network. Use the AZ-500 exam guide when the stem is a security control that happens to sit on a packet.
Exam shape and how the score works
The July 2026 outline has five functional groups, and Microsoft publishes weight ranges rather than fixed percentages.
| Skill area | Weight | What gets tested |
|---|---|---|
| Design and implement core networking infrastructure | 25 to 30% | Address space and subnetting for gateways, private endpoints, firewalls, Application Gateway, and Bastion, public IP prefixes, custom IP prefixes, public and private DNS, DNS Private Resolver, peering, Virtual Network Manager, user-defined routes, forced tunneling, Route Server, NAT Gateway, Network Watcher, DDoS Protection, Defender for Cloud network recommendations |
| Design, implement, and manage connectivity services | 20 to 25% | Site-to-site and point-to-site VPN, gateway SKUs, policy-based against route-based, IPsec and IKE, ExpressRoute models and SKUs, Global Reach, FastPath, ExpressRoute Direct, private peering against Microsoft peering, encryption over ExpressRoute, Bidirectional Forwarding Detection, Virtual WAN hubs, scale units, hub routing, NVAs |
| Design and implement application delivery services | 15 to 20% | Azure Load Balancer SKU and tier, public against internal, regional against cross-region, Gateway Load Balancer, inbound NAT, SNAT outbound rules, Traffic Manager, Application Gateway listeners and routing and TLS and rewrite, Front Door origins and caching and acceleration and Private Link to an origin |
| Design and implement private access to Azure services | 10 to 15% | Private endpoints, Private Link service, DNS for Private Link, on-premises clients to a Private Link service, service endpoints, service endpoint policies |
| Design and implement Azure network security services | 15 to 20% | NSGs and ASGs, virtual network flow logs, IP flow verify, Bastion administration, Virtual Network Manager security, Azure Firewall SKUs, Firewall Manager policies, secure Virtual WAN hubs, WAF detection against prevention, WAF on Front Door and on Application Gateway |
Do the arithmetic on those ranges before building a plan. The lower bounds total 85%. The upper bounds total 110%. The midpoints total 97.5%. No exact split exists to memorize, and the bands are the only ordering Microsoft gives you. Core networking infrastructure sits alone at the top. Connectivity services sit alone in the upper middle. Application delivery ties with network security in the lower middle. Private access sits alone at the bottom. Any study plan that gives five equal weeks overweights private endpoints and underweights address space, DNS, routing, and Network Watcher.
The logistics come off the credential page and the duration table. The sitting is proctored, scheduled through Pearson VUE, and the page warns that the exam may have interactive components. Price depends on the country or region where the exam is proctored, so no single global figure is published. Languages are English, German, Spanish, French, Italian, Japanese, Korean, Portuguese (Brazil), Chinese (Simplified), and Chinese (Traditional). A failed attempt can be retaken 24 hours later, and the wait varies for later retakes. Microsoft tells candidates to register with a personal MSA account, because an organizational account loses the exam record if the person leaves that organization.
The credential page publishes 100 minutes for the assessment. That figure matches Microsoft's row for associate and expert role-based exams without labs, which lists 100 minutes of exam time and 120 minutes of seat time. Associate exams that may contain labs are listed at 120 minutes with 140 minutes of seat time. Microsoft states plainly that it does not publish a list of exams with labs, because labs can be pulled at any time for an outage or a bandwidth problem, and that the real exam time is confirmed at registration and on the launch screens. Plan for interactive components. Do not plan for a lab timer that Microsoft did not give you.
Scoring is the part most candidates get wrong. Technical exam scores are reported on a scale of 1 to 1,000 and 700 or greater passes. Microsoft says outright that the scaled score is not 70 percent of the points, because the passing standard reflects question difficulty. Multi-part questions usually award one point per correctly answered component, so all, some, or none of the points on a question are possible. There is no penalty for guessing. Some questions are unscored and used to collect data, and candidates are never told which, so every question deserves an answer.
The score report gives one overall number, a pass or fail status, and a bar chart per skill area. It does not give a numeric score per section, and Microsoft warns that the bars cannot be added up to reconstruct the result. A short bar in a small area can mean a handful of questions went wrong, and scoring zero in an area that carries only a few questions is documented as normal. Private access at 10 to 15% is the area where a short bar is easiest to misread as a catastrophe.
Two more details change how the sitting is taken. Microsoft Learn is available in a split screen during role-based exams, covering everything on learn.microsoft.com except Q&A, practice assessments, and your profile, with no extra time added and no navigation outside the domain. Five minutes of break time are built into the clock, questions were removed to make room for it, and any question you have already seen is gone once the break starts.
The credential itself follows the associate renewal rule. Associate certifications expire annually. Renewal is free, unproctored, open book, and shorter than the original exam, inside a six month window before expiry. Passing extends the certification one year from the expiration date. The credential page states the renewal frequency as 12 months.
What changed on 27 July 2026
The study guide publishes a change log comparing the previous outline with the current one. The full table is short.
| Skill area prior to 27 July 2026 | Skill area as of 27 July 2026 | Change |
|---|---|---|
| Audience profile | Audience profile | No change |
| Design and implement core networking infrastructure | Design and implement core networking infrastructure | No change |
| Design and implement IP addressing for Azure resources | Design and implement IP addressing for Azure resources | Minor |
| Monitor networks | Monitor networks | Minor |
| Design and implement Azure network security services | Design and implement Azure network security services | No change |
| Implement and manage network security groups | Implement and manage network security groups | Minor |
Three things are true of that table, and each one changes what you should do with older study material.
Every functional group listed is marked No change. Nothing on the table is marked Major. The exam code did not move, the five areas did not move, and the published weight ranges are the ones above. AZ-700 material written against the previous outline is still structurally correct.
Every sub-area listed is marked Minor. The touched sub-areas are IP addressing for Azure resources, Monitor networks, and network security groups. Those are the places Azure has been adding public IP prefixes, custom IP prefixes, flow logs, and Defender for Cloud network recommendations. Treat them as refresh work rather than relearning. Microsoft adds that most questions cover features that are generally available, and that preview features can appear when they are commonly used.
The table carries no row at all for connectivity services, application delivery services, or private access to Azure services. Core infrastructure and network security each appear. The three areas that decide VPN against ExpressRoute, Load Balancer against Front Door, and private endpoint against service endpoint are the ones the change log leaves out entirely. Those controls behave on the current exam the way they behaved on the previous one, which makes those areas the cheapest place to bank points and the least excusable place to lose them.
The credential page last-updated date is 29 July 2026, two days after the study guide skills-measured date. Use the study guide date for the outline. Use the credential page date when a stem asks when the certification record moved.
How a hybrid path gets picked
Connectivity services are 20 to 25%, the change log skipped them, and the same discriminator shows up in routing stems, DNS stems, and Virtual WAN stems as often as in VPN ones.

Microsoft files VPN Gateway, ExpressRoute, and Virtual WAN in the same Hybrid Connectivity category, and each one has its own job. Read the failure the stem describes before reading the options.
Azure VPN Gateway sends encrypted traffic between an Azure virtual network and on-premises locations over the public internet, and between Azure virtual networks over the Microsoft network. Site-to-site is a cross-premises IPsec and IKE tunnel to an on-premises VPN device. Point-to-site is OpenVPN, IKEv2, or SSTP for a remote user. A site-to-site VPN can sit next to ExpressRoute as a secure failover path, and the two connections can coexist. Microsoft's planning table puts typical site-to-site bandwidth under 10 Gbps aggregate and names the usual use case as development, test, lab, and small to medium production. Point-to-site routing is route-based. Site-to-site supports policy-based static routing and route-based dynamic routing. A stem that wants a static policy map on an older on-premises device is a policy-based stem. A stem that wants BGP and multiple prefixes is a route-based stem. If the stem needs more than 100 site-to-site tunnels, Microsoft says to use Virtual WAN instead of a standalone VPN gateway. New deployments should use the zone-redundant AZ SKUs. VpnGw1 through VpnGw5 are slated for migration and are the wrong answer for a new gateway.
ExpressRoute extends an on-premises network into the Microsoft cloud over a private connection through a connectivity provider. The connection does not go over the public internet. Microsoft states that this path offers more reliability, faster speeds, consistent latencies, and higher security than a typical internet connection. The connectivity models are any-to-any IP VPN, point-to-point Ethernet, and a virtual cross-connection at a colocation facility. Routing is Layer 3 with BGP. Each circuit has two connections to two Microsoft Enterprise edge routers. Provider circuits come in 50 Mbps through 10 Gbps. ExpressRoute Direct is the dual 10-Gbps, 100-Gbps, or 400-Gbps on-ramp when the stem wants massive ingestion or physical isolation. Local SKU keeps data near one Azure region and includes data transfer in the port charge. Premium raises private-peering route limits from 4,000 to 10,000, opens global connectivity across geopolitical regions, and raises the number of virtual network links. Global Reach joins two on-premises sites through their ExpressRoute circuits so that traffic uses the Microsoft network instead of the customer's WAN. FastPath and encryption over ExpressRoute are on the outline as named options, not as default behavior.
The peering type is its own question. Azure private peering is a trusted extension of the core network into Azure and reaches virtual machines and cloud services on private IP addresses. Microsoft peering reaches Microsoft online services, including Microsoft 365 and Azure PaaS, over public IP addresses owned by the customer or the provider. A circuit can run one peering or both. Microsoft's recommended layout puts private peering on the core network and Microsoft peering on the DMZ. Microsoft 365 was built to be reached on the internet, and ExpressRoute for Microsoft 365 is a specific-scenario answer, not the default. Private peering defaults to 4,000 IPv4 prefixes and 10,000 with Premium. Microsoft peering caps IPv4 prefixes at 200. A stem that dumps Microsoft prefixes into private peering is testing that limit.
Azure Virtual WAN is the hub that collapses those paths onto one operational interface. The architecture is hub and spoke. Hubs in a Standard Virtual WAN are connected in full mesh, so a branch, a user, or a virtual network on one hub can reach a spoke on another hub over the Microsoft backbone. A Basic Virtual WAN and a Basic hub do site-to-site VPN only. A Standard Virtual WAN and a Standard hub add ExpressRoute, point-to-site user VPN, inter-hub and VNet-to-VNet transit, Azure Firewall, and a third-party NVA. You can upgrade Basic to Standard. You cannot revert. A hub gateway is not the virtual network gateway used on a standalone ExpressRoute or VPN design. Traffic always goes through the hub. Spoke virtual networks do not need their own gateway. Transit between VPN-connected sites and ExpressRoute-connected sites works when the Branch-to-branch flag is on and BGP is supported. Virtual WAN can also encrypt ExpressRoute traffic with IPsec without putting that traffic on the public internet.
Routing around the hybrid path is scored in the heavier core-infrastructure band, and the two areas share stems. Virtual network peering joins networks so they behave as one for connectivity, locally or globally, with traffic on the Microsoft backbone. Gateway transit lets a peered spoke use the hub's VPN or ExpressRoute gateway. A spoke that uses a remote gateway cannot have a gateway of its own. Service chaining is the user-defined route that sends spoke traffic through an appliance or a gateway in the hub. Forced tunneling is the user-defined route that sends internet-bound traffic back on-premises. Azure Route Server is how a network virtual appliance exchanges routes with the virtual network using BGP instead of a pile of static routes. Azure Virtual Network Manager is how those connectivity configurations land across many virtual networks at once.
Outbound internet from a private subnet is a NAT Gateway question more often than a load-balancer question. NAT Gateway lets every instance in a subnet reach the internet while staying private, and it refuses unsolicited inbound connections. Microsoft recommends it for outbound connectivity. As of 31 March 2026, new virtual networks default to private subnets and no longer get default outbound access. A Standard NAT gateway is zonal and processes up to 50 Gbps. StandardV2 is zone redundant, processes up to 100 Gbps, and adds IPv6 and flow logs. NAT Gateway takes precedence over load balancer outbound rules, instance-level public IPs, and Azure Firewall for new connections. A user-defined route that sends 0.0.0.0/0 to a virtual appliance or a virtual network gateway overrides it. You cannot attach two NAT gateways to one subnet, and you cannot drop one in a gateway subnet.
Name resolution is the other core skill the hybrid path depends on. Public DNS zones answer the internet. Private DNS zones answer inside linked virtual networks. Azure DNS Private Resolver is the managed way to resolve those private zones from on-premises, and to forward Azure queries to on-premises DNS, without standing up a custom DNS virtual machine. Hybrid resolution requires ExpressRoute or a VPN. An inbound endpoint receives queries that enter Azure. An outbound endpoint sends queries out through a forwarding ruleset. Each endpoint needs a dedicated subnet delegated only to Microsoft.Network/dnsResolvers, no smaller than /28 and no larger than /24. A resolver can reference only one virtual network, and that virtual network must be in the same region. The resolver does not support ExpressRoute FastPath.
Read the constraint the stem is buying. A small lab that can tolerate the public internet is a site-to-site VPN. A production path that cannot ride the public internet is ExpressRoute. Many branches, users, and circuits that need transit through one hub are Virtual WAN. A stem that wants Microsoft 365 over ExpressRoute is asking for Microsoft peering, and it is asking you to remember that this is a specific scenario, not the default.
How an application delivery service gets picked
Application delivery is 15 to 20%, the change log skipped it, and most of its questions reduce to one skill. Name whether the stem is about Layer 4 inside a region, Layer 7 inside a region, Layer 7 across the globe, or DNS that never sees the packet.

Microsoft's load-balancing guide sorts the services on two axes, global against regional, and HTTP(S) against everything else.
| Service | Reach | Traffic it is built for | What it does not do |
|---|---|---|---|
| Azure Load Balancer | Regional or cross-region | TCP and UDP at Layer 4 | Path-based routing, TLS offload, WAF |
| Azure Application Gateway | Regional | HTTP(S), and TCP or TLS as a terminating proxy | A single global control plane |
| Azure Front Door | Global | HTTP(S) at Layer 7, with caching and acceleration | Owning a regional private subnet by itself |
| Azure Traffic Manager | Global | Any traffic, by DNS only | Seeing the packet or failing over as fast as Front Door |
Azure Load Balancer is the Layer 4 service. It handles inbound and outbound TCP and UDP, is built for high performance and ultra-low latency, and is zone redundant. It supports a regional topology and a cross-region topology. The outline asks you to pick a SKU and a tier, to pick public against internal, to write a load-balancing rule, to write an inbound NAT rule, and to write an explicit outbound SNAT rule. Gateway Load Balancer is the bump-in-the-path appliance insert, and it is a named task, not a synonym for Application Gateway. Traffic Manager sits on the same task statement because both can spread any protocol. Traffic Manager does not handle the traffic. It returns a DNS answer. Microsoft says outright that it cannot fail over as quickly as Azure Front Door, because resolvers cache answers and some clients ignore TTL. A stem about millions of TCP connections inside one virtual network is a Load Balancer stem. A stem about failing a web app over by changing a DNS record is a Traffic Manager stem.
Azure Application Gateway is the regional application delivery controller. It is a proxy. It terminates the client connection, then opens a new connection to the backend. Microsoft names Layer 7 routing, TLS offload, and a web application firewall as the reason to pick it, and adds that it can also load-balance TCP and TLS at Layer 4 as a terminating proxy. The job Microsoft writes down is moving traffic from public network space to web servers in private network space inside one region. The outline then asks for the pieces you actually click: backend pool, health probe, listener, routing rule, HTTP setting, TLS, rewrite rule set, and manual scale against autoscale. A stem about one region, a path-based listener, and a WAF policy on that listener is Application Gateway. Using Application Gateway as the global router for backends in other regions is the trap. Microsoft warns that a regional resource used that way becomes a regional single point of failure and adds a hop through that region.
Azure Front Door is the global application delivery network. It load-balances HTTP(S) across regions and accelerates the site. Microsoft names SSL offload, path-based routing, fast failover, and caching. The outline asks for tier, routing, origins, endpoints, TLS termination against end-to-end TLS, caching, traffic acceleration, rules, URL rewrite, URL redirect, and securing an origin with Azure Private Link. A stem about anycast, a global failover, and a WAF at the edge is Front Door. A stem about keeping the origin off the public internet while Front Door is the only public entry is Front Door with Private Link to the origin.
API Management appears on Microsoft's load-balancing page and does not appear on the AZ-700 application-delivery task list. It is an API gateway that can spread HTTP(S) API traffic. It is not the general-purpose answer when the stem says load balancer.
The official decision order is short. If the application is not HTTP(S), start with Load Balancer. If it is HTTP(S) and lives in one region, start with Application Gateway. If it is HTTP(S) and lives in several regions and needs acceleration, start with Front Door. If the only requirement is a DNS policy across endpoints, start with Traffic Manager. Many production designs stack two of these. Front Door in front of Application Gateway is a documented pattern. That stack is two answers, not a reason to treat the services as interchangeable.
How a private path to a PaaS service gets picked
Private access is 10 to 15%, the lightest band, the change log skipped it, and the question still shows up in storage stems, SQL stems, and Front Door origin stems.

A private endpoint is a network interface that takes a private IP from your virtual network and brings one instance of a service into that network over Azure Private Link. Clients initiate the connection. The service does not dial back into the virtual network. The endpoint must live in the same region and subscription as the virtual network. The target resource can sit in another region. Only an endpoint in an Approved state passes traffic. Automatic approval needs the approval action on the target. A caller without that permission opens a Pending request for the resource owner. On Azure Storage each subresource needs its own endpoint, so blob and file are two endpoints rather than one, and the storage account has to be general purpose v2. DNS has to resolve the service host name to that private IP. The public IP of the target can stay in place while the service firewall blocks it. Network policies can apply NSGs, user-defined routes, and application security groups to the endpoint when they are enabled.
A service endpoint solves a narrower problem. It extends the virtual network to the service over the Azure backbone while the service keeps its public endpoint. Private addresses in the virtual network reach the service without an outbound public IP, and the service sees a private source address, which is what lets a service firewall allow one specific subnet. DNS entries stay as they are and keep resolving to public addresses. The source IP on existing connections flips from public to private when the endpoint is enabled, so open TCP sessions drop and any firewall rule that still names a public VM address stops working. Service endpoint routes override BGP and user-defined routes for that service prefix, which is why forced tunneling does not drag Azure Storage back on-premises once the endpoint is on. Service endpoints do not carry on-premises traffic. To let a datacenter in, you add the public NAT addresses of that datacenter to the service firewall. Service endpoint policies then narrow the endpoint so the subnet can reach only the storage accounts or SQL servers you list, not every instance of the service.
Microsoft's comparison table is the whole question. A service endpoint applies to all instances of the target service. A private endpoint targets one instance. A service endpoint has no built-in data-exfiltration protection and no private path from on-premises. A private endpoint has both, can disable the public IP on the target, and needs a DNS change. Microsoft recommends Azure Private Link. A stem about stopping data from being written to some other tenant's storage account is a private endpoint stem. A stem about keeping DNS alone and locking a subnet to a service tag is a service endpoint stem.
Private Link service is the provider-side half that AZ-104 does not score. It is how your own application, sitting behind a Standard Load Balancer, becomes a Private Link target so another tenant can attach a private endpoint to it. Basic Load Balancer is not supported. The backend pool must be built from network interfaces, not from IP addresses. Azure mints a globally unique alias of the form Prefix.{GUID}.region.azure.privatelinkservice. Visibility can be role-based access control only, a list of subscriptions, or anyone who has the alias. Auto-approval can pre-approve a subset of those subscriptions. The service must live in the same region as its virtual network and its load balancer. Traffic is IPv4 only, TCP or UDP. On the provider side the packets arrive from a NAT IP in the provider's subnet, so the application does not see the consumer's real source address unless TCP Proxy v2 is on. A stem about publishing your own service to another virtual network is a Private Link service stem. A stem about reaching Microsoft SQL or Microsoft Storage is a private endpoint stem. They are not the same resource.
On-premises clients reach a private endpoint the same way they reach any private IP, through the VPN or ExpressRoute path you already built, and through DNS that resolves the service name to that private IP. That is the inbound endpoint on DNS Private Resolver, or a conditional forwarder aimed at it. A service endpoint cannot do this. Microsoft's table says private access from on-premises is not available on service endpoints.
The private path is the same discriminator the AZ-104 exam guide teaches for administrators and the AZ-500 exam guide teaches for security engineers. AZ-700 scores the provider side, the DNS integration, the on-premises client, and the Front Door origin that uses Private Link. The instance-against-service test does not change.
How to study the July 2026 blueprint
Order the weeks by the weight bands, not by the order the areas are printed in.
Week 1. Core networking infrastructure, the 25 to 30% area. Build one hub and two spokes with non-overlapping address space. Carve dedicated subnets for a VPN gateway, Azure Firewall, Application Gateway, Azure Bastion, a private endpoint, and DNS Private Resolver, and write down which of those subnets cannot be shared. Create a public IP prefix and attach addresses from it. Peer the spokes to the hub with gateway transit on and confirm a spoke cannot have its own gateway. Write a user-defined route that forces spoke egress through the hub firewall, then write another that forces tunneling to on-premises, and read the effective routes on a network interface after each change. Deploy NAT Gateway on a private subnet and confirm a virtual machine with no public IP can still reach the internet. Stand up a private DNS zone, link it to both spokes, then deploy DNS Private Resolver with an inbound endpoint and an outbound forwarding ruleset. Finish the week in Network Watcher. Run IP flow verify, read a virtual network flow log, and open one Defender for Cloud network recommendation and one attack path that names a network resource.
Week 2. Connectivity services, the 20 to 25% area the change log skipped. Create a route-based VPN gateway on an AZ SKU and a policy-based connection next to it so the difference is visible. Build a site-to-site connection with a local network gateway and a custom IPsec and IKE policy. Build a point-to-site profile twice, once with Microsoft Entra ID authentication and once with RADIUS, and generate the client configuration file. If you have a provider relationship, create an ExpressRoute circuit and configure private peering, then Microsoft peering, and write down which prefixes each one will accept. If you do not have a circuit, walk the portal through Local, Standard, and Premium, Global Reach, FastPath, and ExpressRoute Direct until you can name the constraint each SKU removes. Create a Standard Virtual WAN, a hub, a site-to-site gateway in that hub, and a virtual network connection, then turn on Branch-to-branch and read the hub route table. Upgrade a Basic virtual WAN to Standard in a test subscription and confirm the reverse action is absent.
Week 3. Application delivery and private access, 15 to 20% stacked with 10 to 15%. Create an internal Standard Load Balancer and a public one. Add a load-balancing rule, an inbound NAT rule, and an outbound SNAT rule. Create a Traffic Manager profile and watch it return a DNS answer rather than a proxy hop. Deploy Application Gateway with a path-based routing rule, a rewrite set, and a WAF policy. Deploy Front Door with two origins, caching on, and Private Link to one origin. Then reach one storage account through a service endpoint and one through a private endpoint, and watch what each does to DNS and to the service firewall. Apply a service endpoint policy that allows only the first account. Publish a small service behind a Standard Load Balancer as a Private Link service, share the alias, and approve a private endpoint from a second subscription. Resolve that endpoint from a peered spoke and from the inbound resolver endpoint.
Week 4. Network security, the other 15 to 20% area, and a full review. Attach an NSG to a subnet and to a NIC. Create an application security group and write a rule that uses it. Enable virtual network flow logs and interpret one denied flow. Deploy Azure Firewall Basic, Standard, and Premium in turn in a test hub, or walk the SKU comparison until you can name threat-intelligence alert-only on Basic, threat-intelligence block on Standard, and IDPS signatures on Premium. Write a Firewall Manager policy and attach it to a firewall in a virtual network and to a firewall in a Virtual WAN secure hub. Put a WAF in detection mode on Application Gateway and in prevention mode on Front Door, and be able to say which one logs and which one blocks. Spend the rest of the week rereading the study guide task statements and naming, for each bullet, the portal blade and the CLI command that does it.
Take the free practice assessment linked from the credential page and run the exam sandbox at least once before using this outline against a clock. The sandbox exists so the question formats cost you nothing on the timer.
Traps that look like easy elimination
Associate items rarely give one plausible answer and three absurd ones. They give two controls that both sound correct and one detail that picks between them.
- A site-to-site VPN rides the public internet. ExpressRoute does not. Picking VPN because the stem says encrypted is how that question is lost.
- Policy-based VPN is static. Route-based VPN is dynamic. Point-to-site is route-based.
- More than 100 site-to-site tunnels is Virtual WAN, not a larger standalone VPN gateway SKU.
- VpnGw1 through VpnGw5 are slated for migration. A new gateway uses an AZ SKU.
- ExpressRoute private peering reaches private IPs in virtual networks. Microsoft peering reaches Microsoft public services. They are two BGP domains on one circuit.
- ExpressRoute for Microsoft 365 is a specific scenario. Microsoft 365 was built to be reached on the internet.
- Premium raises private-peering prefixes from 4,000 to 10,000 and opens global reach across geopolitical regions. Local keeps you near one region.
- A Basic Virtual WAN does site-to-site VPN only. Standard adds ExpressRoute, user VPN, hub transit, Azure Firewall, and NVAs. The upgrade is one way.
- A Virtual WAN hub gateway is not a virtual network gateway. Spoke virtual networks do not get their own gateway.
- Gateway transit lets a spoke use the hub gateway. That spoke cannot also have a gateway.
- Azure Load Balancer is Layer 4. It does not read an HTTP path and it does not run a WAF.
- Application Gateway is regional Layer 7. Front Door is global Layer 7. Traffic Manager is DNS and does not see the packet.
- Traffic Manager failover is slower than Front Door failover because of DNS caches and ignored TTLs.
- API Management is an API gateway. It is not the AZ-700 answer for a general load-balancing stem.
- A service endpoint covers every instance of a service and keeps public DNS. A private endpoint covers one instance and needs a private DNS record.
- Service endpoints do not reach on-premises clients. Private endpoints do, over VPN or ExpressRoute, once DNS is right.
- Private Link service publishes your own application behind a Standard Load Balancer. A private endpoint consumes a Private Link resource. They are opposite sides of the same connection.
- Private Link service does not run on Basic Load Balancer and does not run on a backend pool built from IP addresses.
- Microsoft recommends Azure Private Link over service endpoints when the stem wants data-exfiltration protection or a disabled public IP.
- NAT Gateway is the outbound answer for a private subnet. It does not accept inbound connections. A user-defined default route to a gateway or an appliance overrides it.
- As of 31 March 2026, new virtual networks default to private subnets. Default outbound access is no longer the free answer.
- DNS Private Resolver inbound and outbound endpoints each need their own delegated subnet. The resolver does not support ExpressRoute FastPath.
- An NSG is a five-tuple filter. It does not stop SQL injection. That is a WAF.
- Azure Firewall is the hub control for east-west and north-south traffic. A WAF is the HTTP control. DDoS Protection is the volumetric control on a public IP.
- Firewall Basic alerts on threat intelligence. Standard can block on it. Premium adds IDPS signatures.
- WAF detection mode logs. Prevention mode blocks. The outline asks you to configure both.
- A Secure Score network recommendation is a posture finding. A Network Watcher IP-flow failure is a live path finding. They are not the same blade.
If deleting the scenario still lets you pick the answer from the service name, the question is easier than the live exam.
How this maps to CloudFluently
Start with the official material. The Microsoft Certified: Azure Network Engineer Associate credential page carries the 100 minute timer, the audience profile, the practice assessment, and the exam sandbox. The study guide for Exam AZ-700 carries the task statements, the weight ranges, and the change log quoted above. Exam duration and exam experience explains the associate timer, the built-in break, and the Microsoft Learn split screen. Exam scoring and score reports explains the 700 scaled pass mark and why the bar chart cannot be added up. Microsoft Certification renewal explains the annual free assessment.
AZ-700 sits on top of Azure fundamentals and Azure administration, and that ground is already live here. Name resolution, address ranges, and shared responsibility are the AZ-900 Azure Fundamentals study notes and the AZ-900 Azure Fundamentals practice exam sets. The Azure Fundamentals roadmap sequences that ground, and the AZ-900 exam guide is the first companion page. Virtual networks, NSGs, Bastion, peering, user-defined routes, and the administrator form of service endpoints against private endpoints are the AZ-104 exam guide. NSG against Firewall against WAF, private endpoint against service endpoint, and the security-engineer reading of those same controls are the AZ-500 exam guide.
Work those until the platform, the administrator controls, and the security controls are automatic, then use this page and the official study guide for the network-engineer-only skills: VPN against ExpressRoute against Virtual WAN, Load Balancer against Application Gateway against Front Door against Traffic Manager, private endpoint against service endpoint against Private Link service, and NAT Gateway against a load-balancer outbound rule.
Frequently Asked Questions
What is the passing score for AZ-700? 700 or greater on a scale of 1 to 1,000. Microsoft states that this is a scaled score and is not the same as 70 percent of the points, because the standard reflects the difficulty of the questions asked.
How long is the exam and how many questions are there? The credential page publishes 100 minutes. Microsoft does not publish a question count for any individual exam, and says most certification exams typically contain between 40 and 60 questions.
Does AZ-700 have labs? Microsoft does not publish a list of exams with labs, because labs can be removed at any time for outages or bandwidth issues. The exam page says the exam may have interactive components. The published 100 minute duration matches Microsoft's row for associate role-based exams without labs, while exams that may contain labs are listed at 120 minutes. The exam time is confirmed at registration and on the launch screens.
What changed on 27 July 2026? Every functional group on the change log is marked No change, and every listed sub-area is marked Minor. The touched sub-areas are IP addressing for Azure resources, Monitor networks, and network security groups. The change log carries no row for connectivity services, application delivery, or private access.
Which skill area is heaviest? Design and implement core networking infrastructure is the top band at 25 to 30%. Design, implement, and manage connectivity services sits at 20 to 25%. Application delivery and Azure network security services share 15 to 20%. Private access to Azure services is lowest at 10 to 15%.
Why do the percentages not add up to 100? Because Microsoft publishes ranges. The lower bounds total 85% and the upper bounds total 110%. Use the bands to order study time and stop looking for an exact split.
Can I use Microsoft Learn during the exam? Yes, on role-based exams. The split screen covers learn.microsoft.com, minus Q&A, practice assessments, and your profile. No extra time is added, the clock keeps running, and navigation to other domains is blocked.
How long does the certification last? Associate certifications expire annually. Renewal is free, online, unproctored, and open book, with a six month window before expiry. Passing extends the certification one year from the expiration date.
Can I retake it if I fail? A failed attempt can be retaken 24 hours after the first attempt. Waiting periods for later retakes vary.
How does AZ-700 relate to AZ-104 and AZ-500? AZ-104 scores the administrator controls that sit on a virtual network. AZ-500 scores the security controls that sit on a packet. AZ-700 scores the network-engineer design: the hybrid path, the delivery service, the private access pattern, and the SKU that makes that design hold. The official outline is the study guide for Exam AZ-700. Use Microsoft for the task statements and the weight ranges. Use this page for what changed, what the discriminators are, and how to sequence the July 2026 blueprint.
