Module 1: Domain 1: Core Networking Infrastructure
1
1.1 Virtual Networks and Address Spaces 2
1.2 Subnet Design for Azure Services 3
1.3 Public IP Addresses and Prefixes 4
1.4 Name Resolution Inside a VNet 5
1.5 Public and Private DNS Zones 6
1.6 Azure DNS Private Resolver 7
1.7 VNet Peering, Gateway Transit, and Virtual Network Manager 8
1.8 User-Defined Routes and Forced Tunneling 9
1.9 Azure Route Server and NAT Gateway 10
1.10 Network Watcher, DDoS, and Defender for Cloud Module 2: Domain 2: Connectivity Services
1
2.1 VPN Gateway SKUs and Creating the Gateway 2
2.2 Site-to-Site VPN and Local Network Gateway 3
2.3 IPsec IKE Policies and Azure Extended Network 4
2.4 Point-to-Site Tunnel Types and SKU Scale 5
2.5 Point-to-Site Authentication, Always On, and Network Adapter 6
2.6 ExpressRoute Connectivity Models, SKUs, and Direct 7
2.7 ExpressRoute Private Peering, Microsoft Peering, and BFD 8
2.8 ExpressRoute Global Reach, FastPath, and Encryption 9
2.9 Virtual WAN SKUs, Hubs, and Scale Units 10
2.10 Virtual WAN Hub Routing and NVAs Module 3: Domain 3: Application Delivery Services
1
3.1 Load Balancer SKUs Tiers and Public vs Internal 2
3.2 Regional and Cross-Region Load Balancer 3
3.3 Load-Balancing Rules and Inbound NAT 4
3.4 Outbound Rules and SNAT 5
3.5 Gateway Load Balancer 6
3.6 Azure Traffic Manager 7
3.7 Application Gateway Scale, Pools, Probes, and Listeners 8
3.8 Application Gateway Routing, HTTP Settings, TLS, and Rewrite 9
3.9 Azure Front Door Tiers, Routes, Origins, and TLS 10
3.10 Front Door Cache, Acceleration, Rules, and Private Link Module 4: Domain 4: Private Access to Azure Services
1
4.1 Plan Private Endpoints 2
4.2 Create Private Endpoints 3
4.3 Configure Access to Private Endpoints 4
4.4 Create a Private Link Service 5
4.5 Integrate Private Link and Private Endpoint with DNS 6
4.6 Integrate a Private Link Service with On-Premises Clients 7
4.7 Choose When to Use a Service Endpoint 8
4.8 Create Service Endpoints 9
4.9 Configure Service Endpoint Policies 10
4.10 Configure Access to Service Endpoints Module 5: Domain 5: Azure Network Security Services
1
5.1 Create and Associate Network Security Groups 2
5.2 Create and Associate Application Security Groups 3
5.3 Create and Configure NSG Inbound and Outbound Rules 4
5.4 Implement Virtual Network Flow Logs 5
5.5 Interpret Flow Logs and Verify IP Flow 6
5.6 Configure NSG for Remote Administration including Azure Bastion 7
5.7 Implement Virtual Network Security with Azure Virtual Network Manager 8
5.8 Map Azure Firewall Features and Select a SKU 9
5.9 Configure Firewall Rules, Firewall Manager, and Secure Hubs 10
5.10 Design and Implement a Web Application Firewall Deployment