Microsoft Certified: Azure Network Engineer Associate Exam Prep
Free practice questions

Free AZ-700 Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

These 10 free AZ-700 questions are organized by exam domain, so you can see how each part of the Microsoft Certified: Azure Network Engineer Associate blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Design and implement core networking infrastructure (25-30%)

Question 1

A deployment normally runs 54 Azure VMs, each requiring one private IPv4 address. During replacement, all 54 remain running while eight additional VMs start in the same subnet. No other resources consume addresses in that subnet. The address plan must accommodate this peak without allocating a larger subnet than necessary. Select the correct prefix and Azure-assignable address count.

Show answer & explanation

Correct answer: D - /25, with 123 assignable IPv4 addresses.

Question 2

A workload subnet has these relevant effective routes: 0.0.0.0/0: user-defined route to firewall 10.0.0.4. 172.22.0.0/16: BGP route through the VPN gateway. 172.22.40.0/24: BGP route through the VPN gateway. Traffic to the on-premises server 172.22.40.18 bypasses the firewall. The firewall has the necessary forwarding rules and a valid return path. Only traffic to 172.22.40.0/24 must be redirected; other on-premises ranges must keep their existing routes. Which amendment meets that requirement?

Show answer & explanation

Correct answer: C - Add a 172.22.40.0/24 user-defined route to 10.0.0.4.

Question 3

Azure VMs resolve ledger.database.windows.net to an approved private endpoint and can connect successfully. On-premises clients use a corporate DNS server and still resolve the name to a public address. ExpressRoute private routing to the endpoint subnet works. Azure DNS Private Resolver is deployed in a reachable hub, and privatelink.database.windows.net is linked to that hub with the correct A record. The corporate DNS server needs a conditional forwarder for database.windows.net. Where should it send those queries?

Show answer & explanation

Correct answer: B - To the private IP of the resolver's inbound endpoint.

Domain 2: Design, implement, and manage connectivity services (20-25%)

Question 4

Remote engineers use Windows 11 laptops. Their point-to-site VPN must apply Microsoft Entra Conditional Access and multifactor authentication. Some engineers connect from networks that permit outbound TCP 443 but block UDP 500 and 4500. A supported route-based Azure VPN gateway is already available. Which client and authentication design satisfies both the identity and transport requirements?

Show answer & explanation

Correct answer: D - Azure VPN Client, OpenVPN, and Microsoft Entra ID authentication.

Question 5

A site-to-site VPN design has two on-premises devices, A and B, and an active-active Azure VPN gateway with instances X and Y. The proposed tunnels are A-X and B-Y. Both devices support BGP and equal-cost multipath routing. Operations requires an already-established path to remain available when either on-premises device is taken out of service while either Azure instance is also unavailable. What is missing from the design?

Show answer & explanation

Correct answer: B - The A-Y and B-X tunnels, completing all four device-to-instance paths.

Domain 3: Design and implement application delivery services (15-20%)

Question 6

An Application Gateway WAF_v2 deployment returns 502 responses after a backend migration. The backend settings send HTTPS requests with Host: api.contoso.example. Its custom probe instead uses Host: portal.contoso.example and path /ready. Backend health shows that the probe completes TLS negotiation but receives HTTP 404. A test using the same backend address, port, and path returns HTTP 200 when both the Host header and TLS server name are api.contoso.example. What change corrects the health check without concealing a backend failure?

Show answer & explanation

Correct answer: B - Set the custom probe hostname to api.contoso.example.

Question 7

A company will publish an Azure App Service web application to internet users through Azure Front Door. It needs global HTTP acceleration, caching, and managed WAF rules. Public network access on the App Service must remain disabled. The application is in a region supported for Front Door Private Link. Choose the design that meets the origin-access requirement as well as the edge-delivery requirements.

Show answer & explanation

Correct answer: A - Use Front Door Premium, enable Private Link on the origin, and approve its managed private endpoint connection.

Domain 4: Design and implement private access to Azure services (10-15%)

Question 8

A batch-processing subnet uses a Microsoft.Storage service endpoint. Its applications must retain access to the company's storage account, but must not upload data to other Azure Storage accounts even if someone supplies valid credentials for those accounts. The approved account already permits this subnet. The design must retain service endpoints and public service addresses. What should enforce the destination restriction?

Show answer & explanation

Correct answer: C - A subnet service endpoint policy allowing the approved storage account's resource ID.

Domain 5: Design and implement Azure network security services (15-20%)

Question 9

A production form is protected by an Application Gateway WAF policy in Prevention mode. Testing confirms that legitimate values in the form field customerNote trigger one managed SQL-injection rule. Other fields still need that rule, and the application team has verified that these customerNote submissions are handled safely. The ruleset supports per-rule exclusions. Which adjustment restores the form while retaining the remaining inspection?

Show answer & explanation

Correct answer: A - Exclude the customerNote value from that specific managed rule.

Question 10

A contractor's authorized access window to a production Linux VM has ended. An engineer adds an inbound deny to the subnet NSG for TCP 22 from that contractor's source address. IP flow verify reports the deny, and fresh SSH connections from that address fail. The contractor's original SSH connection remains active. Other administrators and unrelated processing jobs must stay connected and running. How should the engineer end the contractor's access immediately?

Show answer & explanation

Correct answer: D - Terminate that SSH connection on the VM and retain the NSG deny.

That's 10 of 1,030

The full bank has 1,020 more AZ-700 questions with explanations.

Continue in the free practice test →

View plans