- AZ-700 Domain Overview: How the Exam Blueprint Breaks Down
- Domain 1: Core Networking Infrastructure (25-30%)
- Domain 2: Connectivity Services (20-25%)
- Domain 3: Application Delivery Services (15-20%)
- Domain 4: Private Access to Azure Services (10-15%)
- Domain 5: Azure Network Security Services (15-20%)
- What AZ-700 Questions Actually Look Like
- Mapping Domains to a Study Timeline
- Who Hires for This Domain Knowledge
- FAQ
- Core networking infrastructure is the largest domain at 25-30% - master it first.
- Connectivity services (20-25%) covers VPN, ExpressRoute, and Virtual WAN design decisions.
- Application delivery and network security domains each carry 15-20% weight.
- Private access to Azure services is the smallest domain at 10-15%, but still tested.
AZ-700 Domain Overview: How the Exam Blueprint Breaks Down
The Microsoft Certified: Azure Network Engineer Associate credential is earned by passing exam AZ-700: Designing and Implementing Microsoft Azure Networking Solutions, delivered through Pearson VUE. Microsoft organizes the exam into five weighted content areas, and understanding exactly what falls inside each one is the single most useful thing you can do before you start studying. This guide breaks down every domain in the current outline, effective July 27, 2026, so you know precisely what to prioritize.
Unlike a flat list of "networking topics," Microsoft's blueprint assigns specific percentage ranges to each domain. That weighting is not decorative - it reflects how many scenario-based questions you're likely to encounter on test day. If you're still deciding whether this certification fits your career plans, our ROI analysis and salary guide are worth reading alongside this domain breakdown.
Domain 1: Design and Implement Core Networking Infrastructure (25-30%)
This is the largest domain on the AZ-700 outline, and it forms the foundation everything else builds on. If you get virtual network design wrong, the connectivity, application delivery, and security domains all become harder to reason about correctly.
Core Networking Infrastructure
Candidates must understand how to design and implement the fundamental building blocks of an Azure network topology.
- Virtual network (VNet) design, address space planning, and subnetting
- VNet peering and hub-and-spoke topology decisions
- Custom routing with route tables and user-defined routes (UDRs)
- IP addressing strategies, including public and private IP assignment
- Network diagnostics and troubleshooting tools within Azure
Because this domain touches so many downstream decisions, many candidates spend an entire study week here before moving on. Our study guide walks through a sequencing approach that treats this domain as the anchor for everything else.
Domain 2: Design, Implement, and Manage Connectivity Services (20-25%)
The second-largest domain covers how Azure networks connect to on-premises environments, other Azure regions, and hybrid infrastructure. This is where hybrid connectivity design decisions live.
Connectivity Services
Candidates must be able to design and manage hybrid and inter-region connectivity, not just describe the services.
- Site-to-site, point-to-site, and multi-site VPN gateway design
- ExpressRoute circuit planning, peering configurations, and failover
- Virtual WAN architecture and hub design
- VNet-to-VNet connectivity across regions and subscriptions
- Routing and performance considerations for hybrid connectivity
Expect scenario questions that ask you to choose between VPN and ExpressRoute, or to identify why a specific hybrid connectivity design fails to meet a stated requirement (bandwidth, redundancy, or latency). This domain rewards hands-on lab time more than memorization.
Key Takeaway
Treat Domains 1 and 2 as a combined 45-55% block. If your practice-test scores lag in either one, pause and rebuild the underlying VNet or connectivity lab before advancing further in your study plan.
Domain 3: Design and Implement Application Delivery Services (15-20%)
This domain shifts focus from "how traffic moves" to "how traffic is distributed and delivered" at the application layer.
Application Delivery Services
Candidates must know how to select and configure the right load-balancing and delivery service for a given scenario.
- Azure Load Balancer configuration and health probes
- Application Gateway and Web Application Firewall (WAF) policies
- Azure Front Door for global HTTP/HTTPS delivery
- Traffic Manager routing methods and failover scenarios
- Choosing between Layer 4 and Layer 7 delivery services
A recurring exam pattern in this domain is presenting a business requirement - global reach, SSL offload, path-based routing - and asking which service satisfies it. Knowing the decision criteria between these four services matters more than memorizing every configuration option.
Domain 4: Design and Implement Private Access to Azure Services (10-15%)
The smallest domain by weight, but it's frequently underestimated because private access concepts (Private Link, Private Endpoints, service endpoints) are conceptually dense despite the lower percentage.
Private Access to Azure Services
Candidates must understand how to keep traffic to PaaS services off the public internet.
- Azure Private Link and Private Endpoint configuration
- Service endpoints versus Private Endpoints - when to use each
- DNS integration for private endpoint resolution
- Network policies for private access scenarios
Because this domain carries the lowest weight, don't let it consume disproportionate study time - but don't skip it either, since it still represents a real slice of scored questions.
Domain 5: Design and Implement Azure Network Security Services (15-20%)
The final domain covers protecting the network perimeter and internal traffic flows - a natural counterpart to the connectivity and application delivery domains covered earlier.
Network Security Services
Candidates must design layered security controls across the network stack.
- Network Security Groups (NSGs) and Application Security Groups (ASGs)
- Azure Firewall design, rules, and policies
- DDoS Protection configuration and standard tier features
- Bastion and secure remote access patterns
- Defense-in-depth strategies combining multiple security layers
Security questions often overlap with earlier domains - for example, a question might combine a VNet design decision (Domain 1) with an NSG rule requirement (Domain 5) in a single scenario. Studying domains in isolation can leave gaps at these intersections.
| Domain | Weight | Primary Focus |
|---|---|---|
| 1. Core Networking Infrastructure | 25-30% | VNets, peering, routing, IP addressing |
| 2. Connectivity Services | 20-25% | VPN, ExpressRoute, Virtual WAN |
| 3. Application Delivery Services | 15-20% | Load Balancer, App Gateway, Front Door, Traffic Manager |
| 4. Private Access to Azure Services | 10-15% | Private Link, Private Endpoints, service endpoints |
| 5. Network Security Services | 15-20% | NSGs, Azure Firewall, DDoS Protection, Bastion |
What AZ-700 Questions Actually Look Like
The AZ-700 exam is a proctored, computer-based test delivered through Pearson VUE, with a standard appointment length of 120 minutes and an actual exam time of 100 minutes. Microsoft has not disclosed the exact scored/unscored question count or the precise mix of case studies versus interactive labs, so treat any specific number you see elsewhere with caution. What's consistent across Microsoft's Associate-level networking exams is a heavy reliance on scenario framing: you're given a business or technical requirement and asked to select, configure, or troubleshoot a solution rather than recall a definition.
You may also encounter restricted, in-exam access to Microsoft Learn documentation for certain question types, which rewards candidates who know where to look rather than those who've memorized every setting. Passing requires a scaled score of 700 out of 1000 - this is not the same as answering 70% of questions correctly, since scaled scoring weights questions differently. Our dedicated passing score breakdown explains this scoring mechanic in more depth.
Mapping Domains to a Study Timeline
Rather than studying domains in the order Microsoft lists them, sequence your prep around weight and dependency. Core networking infrastructure underpins everything else, so it comes first regardless of study method.
Domain 1: Core Networking Infrastructure
- Build VNets, subnets, and peering in a sandbox subscription
- Configure UDRs and trace effective routes
Domain 2: Connectivity Services
- Stand up a site-to-site VPN gateway
- Compare ExpressRoute and Virtual WAN design tradeoffs
Domains 3 and 5
- Configure Application Gateway with WAF policies
- Layer NSGs and Azure Firewall on the same topology
Domain 4 and Full Review
- Practice Private Link and Private Endpoint scenarios
- Run full-length practice tests on the practice test platform
This sequencing avoids the common mistake of spending equal time on all five domains - a strategy that ignores the fact that Domains 1 and 2 alone can account for roughly half the exam. For a broader look at pacing and technique across the full prep cycle, see our complete AZ-700 study guide.
Who Hires for This Domain Knowledge
The five domains above map directly onto real job responsibilities rather than abstract exam trivia. Organizations running hybrid Azure environments - connecting on-premises data centers to Azure via ExpressRoute or VPN, securing PaaS traffic with Private Link, and load-balancing global applications through Front Door - need engineers who can make the same design tradeoffs the exam tests. If you're evaluating how this credential translates into job titles and hiring demand, browse our AZ-700 jobs overview for a sense of where this skill set is applied.
Because there's no formal prerequisite certification or documented experience requirement for AZ-700, candidates arrive with varying backgrounds - some from network engineering roles, others from cloud administration or infrastructure teams. Microsoft does expect familiarity with Azure compute, storage, and networking fundamentals, along with general networking concepts, before you attempt the exam. Our requirements guide covers this expected baseline in detail, and if you want a sense of how the overall exam difficulty compares to other Azure certifications, check how hard the AZ-700 exam really is.
Key Takeaway
Study each domain as a job function, not a trivia category. Ask "what would I actually configure in this scenario at work?" - it mirrors how Microsoft writes the scenario-based questions.
Keeping the Domains Current After You Pass
Once earned, the AZ-700 credential is valid for 12 months. Microsoft offers a free, open-book, unproctored renewal assessment available during the six months before expiry, which extends validity another year if passed. Because the domain weightings and topic emphasis can shift between outline versions - as they did with the update effective July 27, 2026 - it's worth revisiting the current domain list each renewal cycle rather than assuming nothing changed. Bookmark the official exam dates and scheduling guide so you're not caught off guard by outline transitions near your renewal window.
Frequently Asked Questions
Start with Domain 1 (Core Networking Infrastructure) since it carries the highest weight at 25-30% and underpins the connectivity, application delivery, and security domains that follow.
No. Weights range from 10-15% for the smallest domain (private access to Azure services) up to 25-30% for the largest (core networking infrastructure), so study time should be allocated proportionally.
No. Microsoft publishes percentage ranges for each domain but does not disclose exact scored or unscored question counts, so treat any specific count you see elsewhere as unofficial.
Yes, Microsoft periodically updates exam outlines. The current English outline takes effect July 27, 2026, so always check the official domain breakdown before finalizing your study plan.
No. The overall passing score is 700 out of 1000 on a scaled score, which is not the same as answering 70% of questions correctly across domains - see our passing score guide for details.