AZ-700STUDY GUIDEFree
Guides

AZ-700 Study Guide

A curated learning path for the AZ-700 exam: the best documentation, videos, blog posts and tutorials for every exam objective.

Microsoft Certified: Azure Network Engineer Associate


Exam at a Glance

AZ-700 measures whether you can do the day-to-day work of an Azure network engineer: planning address spaces and name resolution, connecting sites over VPN and ExpressRoute, delivering applications through load balancers, Application Gateway and Front Door, giving platform services private access, and securing and monitoring all of it.

AZ-700Designing and Implementing Microsoft Azure Networking Solutions
CertificationMicrosoft Certified: Azure Network Engineer Associate
LevelIntermediate (associate role-based exam)
PrerequisiteNo prerequisite certification is listed; Microsoft Certified: Azure Administrator Associate (exam AZ-104) is an optional starting point
Exam length100 minutes
QuestionsTypically 40 to 60; the number and format mix can vary
Passing score700 out of 1000
Question formatsMultiple choice, multiple select, drag and drop, build list, hot area, case studies
Microsoft Learn accessAvailable within the exam; browsing is restricted and the timer continues
Skills measured versionJuly 27, 2026
RenewalCertification expires annually; renew with a free online assessment on Microsoft Learn
CostDepends on your country or region; shown when you schedule

 

What the Exam Covers

The exam has five domains. Core networking infrastructure carries the most weight and connectivity services comes next. Private access is the smallest domain, but its topics, private endpoints and their DNS, reappear inside scenarios from every other domain, so do not skip it.

 

Design and implement core networking infrastructure — 25-30%

Address spaces, subnet sizing for gateways, private endpoints, firewalls, application gateways and Azure Bastion, subnet delegation, public IP addresses and prefixes, and custom IP prefixes. Name resolution with VNet DNS settings, public and private DNS zones and Azure DNS Private Resolver. Peering and gateway transit, Azure Virtual Network Manager, user-defined routes, forced tunneling, Azure Route Server and NAT Gateway. Monitoring with Network Watcher, Azure Monitor for Networks, DDoS protection and the network recommendations in Microsoft Defender for Cloud.

 

Design, implement, and manage connectivity services — 20-25%

Site-to-site VPN design including high availability, gateway SKUs, policy-based versus route-based connections, local network gateways, IPsec/IKE policies and Azure Extended Network. Point-to-site VPN SKUs, tunnel types, RADIUS and Microsoft Entra ID authentication, client configuration files, Always On VPN and Azure Network Adapter. ExpressRoute connectivity models, SKUs and tiers, redundancy, Global Reach, FastPath and ExpressRoute Direct, private and Microsoft peering, route advertisement and encryption. Virtual WAN SKUs, virtual hubs, gateway scale units, hub routing and third-party NVA integration.

 

Design and implement application delivery services — 15-20%

Azure Load Balancer SKUs and tiers, public versus internal, regional versus cross-region, load balancing rules, inbound NAT rules, outbound rules and SNAT, Gateway Load Balancer, and Azure Traffic Manager. Application Gateway use cases, scaling, backend pools, health probes, listeners, routing rules, HTTP settings, TLS and rewrite rule sets. Azure Front Door tiers, routing, origins and endpoints, TLS, caching, rules, URL rewrite and redirect, and Private Link origins.

 

Design and implement private access to Azure services — 10-15%

Planning and creating private endpoints, configuring access to them, creating a Private Link service, integrating both with DNS, and reaching a Private Link service from on-premises clients. Choosing when a service endpoint is enough, creating service endpoints, and service endpoint policies and access.

 

Design and implement Azure network security services — 15-20%

Network security groups and application security groups, their rules, virtual network flow logs, IP flow verify, rules for remote administration including Azure Bastion, and security administration with Azure Virtual Network Manager. Azure Firewall SKUs, design and rules, Azure Firewall Manager policies and secured virtual hubs. Web Application Firewall design, detection versus prevention mode, rule sets on Azure Front Door and Application Gateway, and WAF policies.

 

The full bullet-level list lives in the official study guide. Treat it as your checklist:

The Official AZ-700 Study Guide

 

How This Maps to CertiAce Practice Modules

The CertiAce question bank is organized by the eight modules of the official AZ-700 learning path on Microsoft Learn, so you can drill each area in isolation. Modules and domains are not one-to-one: two modules cover core infrastructure, two split connectivity services, two cover application delivery, and the security module also carries DDoS Protection, which the outline files under core infrastructure:

CertiAce practice moduleWhat you will drill there
Introduction to Azure Virtual NetworksAddress spaces and subnets, public IP prefixes, DNS zones and Private Resolver, peering, user-defined routes, Route Server, NAT Gateway
Design and implement hybrid networkingSite-to-site and point-to-site VPN gateways, SKUs, IPsec/IKE policies, authentication, Virtual WAN hubs and routing
Design and implement Azure ExpressRouteConnectivity models, SKUs and tiers, peerings, Global Reach, FastPath, ExpressRoute Direct, redundancy, troubleshooting
Load balance non-HTTP(S) traffic in AzureLoad Balancer SKUs, rules, probes, inbound NAT and outbound rules, Gateway Load Balancer, Traffic Manager
Load balance HTTP(S) traffic in AzureApplication Gateway listeners, probes, routing and rewrite rules, TLS; Front Door tiers, routing, caching, Private Link origins
Design and implement network securityNSGs and ASGs, service tags, Azure Bastion rules, Virtual Network Manager security admin rules, Azure Firewall and Firewall Manager, WAF policies, DDoS Protection
Design and implement private access to Azure ServicesPrivate endpoints, Private Link service, DNS integration, service endpoints and policies
Design and implement network monitoringNetwork Watcher diagnostics, virtual network flow logs and traffic analytics, Azure Monitor for Networks, Defender for Cloud network recommendations

 

Where AZ-700 Fits

CertificationWhat it validatesWhen to take it
Microsoft Certified: Azure Fundamentals (AZ-900)Cloud concepts, core Azure services and the vocabulary of governance and pricingOptional first step if you are new to Azure
Microsoft Certified: Azure Administrator Associate (AZ-104)Managing identities, governance, storage, compute and virtual networking in AzureOptional before AZ-700; it builds the resource-management experience the AZ-700 audience profile expects
Microsoft Certified: Azure Network Engineer Associate (AZ-700, this exam)Designing, implementing and managing Azure networking: core infrastructure, hybrid connectivity, application delivery, private access and securityYou are here
Microsoft Certified: Azure Solutions Architect Expert (AZ-305)Designing identity, governance, storage, business continuity and infrastructure solutionsA later step if you move into architecture; its prerequisite is Azure Administrator Associate (AZ-104), not AZ-700

AZ-700 has no listed prerequisite certification, but Microsoft expects experience creating and managing compute, storage and networking resources in Azure, so if you have not administered Azure before, Microsoft Certified: Azure Administrator Associate (exam AZ-104) is a sensible first step. The certification is a specialization rather than a gateway: no expert certification lists Azure Network Engineer Associate as a prerequisite, and Microsoft Certified: Azure Solutions Architect Expert (exam AZ-305) requires Azure Administrator Associate (AZ-104) instead.

 

Before You Start

The exam assumes real networking experience and hands-on time in Azure, not just reading. Check yourself against this table. Anything unfamiliar is where your preparation should start:

AreaYou should be comfortable with
Networking fundamentalsIP addressing and CIDR subnetting, DNS, routing and BGP basics, TCP/IP, common protocols and ports
Hybrid connectivityHow site-to-site VPNs, IPsec and WAN links work, on-premises firewalls and virtualization
Azure resource managementCreating and managing compute, storage and networking resources in the portal, with everyday Azure PowerShell or Azure CLI commands
Identity and security basicsMicrosoft Entra ID authentication, role-based access control, least privilege, certificates and TLS
Resilience and recoveryAvailability zones and regions, high availability, disaster recovery and what a failover involves

 


Step-by-Step Study Plan

How long you need depends on where you start. Treat these estimates as planning guidance and adjust them to your starting knowledge and weekly study hours:

Your starting pointSuggested prep time
You work with Azure networking weekly3 to 5 weeks
Experienced network engineer, newer to Azure5 to 8 weeks
Azure administrator with limited networking depth6 to 10 weeks

 

Step 1: Read the Official Study Guide

Skim the full skills-measured list once, and mark every bullet you could not explain to a colleague. That marked-up list is your personal syllabus: everything else in this plan exists to clear it. The current list is the July 27, 2026 version; its change log records only minor changes, so material built for the previous outline is still broadly aligned.

The Official Study Guide

 

Step 2: Schedule Your Exam

Choose a realistic target date after reviewing the skills list and your available study time. A date on the calendar turns studying into a countdown, so pick one using the prep-time table above and plan backwards from it.

The exam is offered in English, German, Spanish, French, Italian, Japanese, Korean, Portuguese (Brazil), Chinese (Simplified) and Chinese (Traditional). If the exam is not available in your native language, check the English as a Second Language accommodation and arrange any approved extra time before booking.

Exam accommodations

Certification and Exam Details Page

 

Step 3: Work Through the Official Learning Path

Complete the AZ-700 learning path on Microsoft Learn: a single path of eight modules that the CertiAce practice modules follow one-to-one, so you can benchmark each module as soon as you finish it. Take notes on concepts you cannot explain in simple terms, and flag anything that needs hands-on practice. For every service, record the SKU or tier choices and the subnet it needs; the exam leans on those details.

Official AZ-700 Learning Path

 

Step 4: Watch a Full Video Course

Microsoft Learn's own AZ-700 course series on YouTube covers the whole syllabus in eleven videos, just under four hours, with one episode per learning-path module. Watch it as a second pass after the learning path, pausing to replicate the key configurations in your own subscription, and rewatch the episodes behind your weakest practice modules. It predates the July 27, 2026 skills update, whose changes are minor.

AZ-700: Designing and Implementing Microsoft Azure Networking Solutions (Microsoft Learn on YouTube)

 

Step 5: Get Hands-On Practice

AZ-700 is a hands-on engineer exam: many questions describe a topology or a symptom and ask which component, setting or sequence fixes it. Create a free Azure account and work through the official lab exercises for the course, seventeen exercises organized by the same eight modules. Make sure you personally touch:

  • An address plan with dedicated subnets for a VPN gateway, Azure Bastion, Azure Firewall and private endpoints
  • Public and private DNS zones, a private zone linked to a virtual network, and resolving a private endpoint name from a VM
  • Virtual network peering, user-defined routes, and a network interface's effective routes
  • A VPN gateway for site-to-site or point-to-site access, and a Virtual WAN hub
  • A Standard load balancer with health probes, inbound NAT and outbound rules, then an Application Gateway and a Front Door profile with a WAF policy
  • NSGs and application security groups checked with IP flow verify, Azure Firewall with a firewall policy, and virtual network flow logs

The free account's credit supports many of the core exercises, but VPN gateways, ExpressRoute circuits, Azure Firewall, Application Gateway and Front Door are chargeable: delete each lab's resource group when you finish, and learn from the documentation what you cannot deploy, such as a provider-connected ExpressRoute circuit. Repeat the key tasks in PowerShell and the Azure CLI, not only the portal.

Official AZ-700 Lab Instructions

Azure free account

 

Step 6: Benchmark Your Knowledge

Use CertiAce to benchmark your readiness module by module. The practice modules map to the exam domains as shown above, so use the module mapping and the topics behind your missed questions to identify the skills-measured areas to revisit. Microsoft also offers a free official practice assessment on the certification page. Aim for consistent performance across every module, not one lucky high score; if a topic is unstable, go back to learning plus hands-on practice. Watch for questions that separate similar services: service endpoints versus private endpoints, and Load Balancer versus Application Gateway versus Front Door.

CertiAce AZ-700 Exam Practice

Official AZ-700 Practice Assessment

 

Step 7: Take the Exam

The day before, review only your weak topics and the numbers you find hard to remember, such as minimum subnet sizes and gateway SKU limits. No brand-new material. On exam day, read each question for what it is truly asking, eliminate wrong options first, and find the constraint that decides the answer: no public exposure, lowest latency, minimal cost, or the fewest changes.

Worth knowing before you sit down:

  • Microsoft Learn is available during the exam in a split screen. Use it to check details you genuinely need: the timer keeps running, and the exam is deliberately too long to look up every answer. Browsing is limited to Microsoft Learn itself (no Q&A, practice assessments, or profile), and personal notes and other websites are unavailable.
  • You can take unscheduled breaks, but the clock keeps running and you cannot return to questions you already saw.
  • Case studies lock when you leave them: finish each one before moving on, because you cannot revisit its questions afterwards.
  • Try the exam sandbox beforehand so the question formats and interface hold no surprises: Exam Sandbox

 


Additional Learning Resources

ResourceTypeWhy it is useful
AZ-700: Designing and Implementing Microsoft Azure Networking SolutionsYouTube playlistMicrosoft Learn's official eleven-video course series, one episode per learning-path module
Preparing for AZ-700 - Design and implement core networking infrastructure (1 of 5)Video seriesFive Exam Readiness Zone episodes, one per skill area; they show an older outline, so use the current study guide for weights
Official AZ-700 Lab InstructionsHands-on labsThe seventeen exercises behind the official course, organized by module
Hub-spoke network topology in AzureArchitectureThe reference design most AZ-700 scenarios are built on: hub, spokes, shared services and inspection
Azure Virtual Network documentationDocsAddress spaces, subnets, peering, routing, NAT Gateway and service endpoints
VPN Gateway documentationDocsSite-to-site and point-to-site design, SKUs, IPsec/IKE policies and troubleshooting
ExpressRoute documentationDocsConnectivity models, peerings, Global Reach, FastPath, ExpressRoute Direct and resiliency designs
READY TO TEST YOURSELF?
Practice what you just studied

Realistic AZ-700 exam-style questions with instant feedback and detailed explanations.

Practice AZ-700 now
AZ-700 Study Guide — Azure Network Engineer | CertiAce