AZ-700 Study Guide
A curated learning path for the AZ-700 exam: the best documentation, videos, blog posts and tutorials for every exam objective.A curated learning path for the AZ-700 exam: the best documentation, videos, blog posts and tutorials for every exam objective, in the order worth studying them.
Microsoft Certified: Azure Network Engineer Associate
Exam at a Glance
AZ-700 measures whether you can do the day-to-day work of an Azure network engineer: planning address spaces and name resolution, connecting sites over VPN and ExpressRoute, delivering applications through load balancers, Application Gateway and Front Door, giving platform services private access, and securing and monitoring all of it.
| AZ-700 | Designing and Implementing Microsoft Azure Networking Solutions |
|---|---|
| Certification | Microsoft Certified: Azure Network Engineer Associate |
| Level | Intermediate (associate role-based exam) |
| Prerequisite | No prerequisite certification is listed; Microsoft Certified: Azure Administrator Associate (exam AZ-104) is an optional starting point |
| Exam length | 100 minutes |
| Questions | Typically 40 to 60; the number and format mix can vary |
| Passing score | 700 out of 1000 |
| Question formats | Multiple choice, multiple select, drag and drop, build list, hot area, case studies |
| Microsoft Learn access | Available within the exam; browsing is restricted and the timer continues |
| Skills measured version | July 27, 2026 |
| Renewal | Certification expires annually; renew with a free online assessment on Microsoft Learn |
| Cost | Depends on your country or region; shown when you schedule |
What the Exam Covers
The exam has five domains. Core networking infrastructure carries the most weight and connectivity services comes next. Private access is the smallest domain, but its topics, private endpoints and their DNS, reappear inside scenarios from every other domain, so do not skip it.
Design and implement core networking infrastructure — 25-30%
Address spaces, subnet sizing for gateways, private endpoints, firewalls, application gateways and Azure Bastion, subnet delegation, public IP addresses and prefixes, and custom IP prefixes. Name resolution with VNet DNS settings, public and private DNS zones and Azure DNS Private Resolver. Peering and gateway transit, Azure Virtual Network Manager, user-defined routes, forced tunneling, Azure Route Server and NAT Gateway. Monitoring with Network Watcher, Azure Monitor for Networks, DDoS protection and the network recommendations in Microsoft Defender for Cloud.
Design, implement, and manage connectivity services — 20-25%
Site-to-site VPN design including high availability, gateway SKUs, policy-based versus route-based connections, local network gateways, IPsec/IKE policies and Azure Extended Network. Point-to-site VPN SKUs, tunnel types, RADIUS and Microsoft Entra ID authentication, client configuration files, Always On VPN and Azure Network Adapter. ExpressRoute connectivity models, SKUs and tiers, redundancy, Global Reach, FastPath and ExpressRoute Direct, private and Microsoft peering, route advertisement and encryption. Virtual WAN SKUs, virtual hubs, gateway scale units, hub routing and third-party NVA integration.
Design and implement application delivery services — 15-20%
Azure Load Balancer SKUs and tiers, public versus internal, regional versus cross-region, load balancing rules, inbound NAT rules, outbound rules and SNAT, Gateway Load Balancer, and Azure Traffic Manager. Application Gateway use cases, scaling, backend pools, health probes, listeners, routing rules, HTTP settings, TLS and rewrite rule sets. Azure Front Door tiers, routing, origins and endpoints, TLS, caching, rules, URL rewrite and redirect, and Private Link origins.
Design and implement private access to Azure services — 10-15%
Planning and creating private endpoints, configuring access to them, creating a Private Link service, integrating both with DNS, and reaching a Private Link service from on-premises clients. Choosing when a service endpoint is enough, creating service endpoints, and service endpoint policies and access.
Design and implement Azure network security services — 15-20%
Network security groups and application security groups, their rules, virtual network flow logs, IP flow verify, rules for remote administration including Azure Bastion, and security administration with Azure Virtual Network Manager. Azure Firewall SKUs, design and rules, Azure Firewall Manager policies and secured virtual hubs. Web Application Firewall design, detection versus prevention mode, rule sets on Azure Front Door and Application Gateway, and WAF policies.
The full bullet-level list lives in the official study guide. Treat it as your checklist:
The Official AZ-700 Study Guide
How This Maps to CertiAce Practice Modules
The CertiAce question bank is organized by the eight modules of the official AZ-700 learning path on Microsoft Learn, so you can drill each area in isolation. Modules and domains are not one-to-one: two modules cover core infrastructure, two split connectivity services, two cover application delivery, and the security module also carries DDoS Protection, which the outline files under core infrastructure:
| CertiAce practice module | What you will drill there |
|---|---|
| Introduction to Azure Virtual Networks | Address spaces and subnets, public IP prefixes, DNS zones and Private Resolver, peering, user-defined routes, Route Server, NAT Gateway |
| Design and implement hybrid networking | Site-to-site and point-to-site VPN gateways, SKUs, IPsec/IKE policies, authentication, Virtual WAN hubs and routing |
| Design and implement Azure ExpressRoute | Connectivity models, SKUs and tiers, peerings, Global Reach, FastPath, ExpressRoute Direct, redundancy, troubleshooting |
| Load balance non-HTTP(S) traffic in Azure | Load Balancer SKUs, rules, probes, inbound NAT and outbound rules, Gateway Load Balancer, Traffic Manager |
| Load balance HTTP(S) traffic in Azure | Application Gateway listeners, probes, routing and rewrite rules, TLS; Front Door tiers, routing, caching, Private Link origins |
| Design and implement network security | NSGs and ASGs, service tags, Azure Bastion rules, Virtual Network Manager security admin rules, Azure Firewall and Firewall Manager, WAF policies, DDoS Protection |
| Design and implement private access to Azure Services | Private endpoints, Private Link service, DNS integration, service endpoints and policies |
| Design and implement network monitoring | Network Watcher diagnostics, virtual network flow logs and traffic analytics, Azure Monitor for Networks, Defender for Cloud network recommendations |
Where AZ-700 Fits
| Certification | What it validates | When to take it |
|---|---|---|
| Microsoft Certified: Azure Fundamentals (AZ-900) | Cloud concepts, core Azure services and the vocabulary of governance and pricing | Optional first step if you are new to Azure |
| Microsoft Certified: Azure Administrator Associate (AZ-104) | Managing identities, governance, storage, compute and virtual networking in Azure | Optional before AZ-700; it builds the resource-management experience the AZ-700 audience profile expects |
| Microsoft Certified: Azure Network Engineer Associate (AZ-700, this exam) | Designing, implementing and managing Azure networking: core infrastructure, hybrid connectivity, application delivery, private access and security | You are here |
| Microsoft Certified: Azure Solutions Architect Expert (AZ-305) | Designing identity, governance, storage, business continuity and infrastructure solutions | A later step if you move into architecture; its prerequisite is Azure Administrator Associate (AZ-104), not AZ-700 |
AZ-700 has no listed prerequisite certification, but Microsoft expects experience creating and managing compute, storage and networking resources in Azure, so if you have not administered Azure before, Microsoft Certified: Azure Administrator Associate (exam AZ-104) is a sensible first step. The certification is a specialization rather than a gateway: no expert certification lists Azure Network Engineer Associate as a prerequisite, and Microsoft Certified: Azure Solutions Architect Expert (exam AZ-305) requires Azure Administrator Associate (AZ-104) instead.
Before You Start
The exam assumes real networking experience and hands-on time in Azure, not just reading. Check yourself against this table. Anything unfamiliar is where your preparation should start:
| Area | You should be comfortable with |
|---|---|
| Networking fundamentals | IP addressing and CIDR subnetting, DNS, routing and BGP basics, TCP/IP, common protocols and ports |
| Hybrid connectivity | How site-to-site VPNs, IPsec and WAN links work, on-premises firewalls and virtualization |
| Azure resource management | Creating and managing compute, storage and networking resources in the portal, with everyday Azure PowerShell or Azure CLI commands |
| Identity and security basics | Microsoft Entra ID authentication, role-based access control, least privilege, certificates and TLS |
| Resilience and recovery | Availability zones and regions, high availability, disaster recovery and what a failover involves |
Step-by-Step Study Plan
How long you need depends on where you start. Treat these estimates as planning guidance and adjust them to your starting knowledge and weekly study hours:
| Your starting point | Suggested prep time |
|---|---|
| You work with Azure networking weekly | 3 to 5 weeks |
| Experienced network engineer, newer to Azure | 5 to 8 weeks |
| Azure administrator with limited networking depth | 6 to 10 weeks |
Step 1: Read the Official Study Guide
Skim the full skills-measured list once, and mark every bullet you could not explain to a colleague. That marked-up list is your personal syllabus: everything else in this plan exists to clear it. The current list is the July 27, 2026 version; its change log records only minor changes, so material built for the previous outline is still broadly aligned.
Step 2: Schedule Your Exam
Choose a realistic target date after reviewing the skills list and your available study time. A date on the calendar turns studying into a countdown, so pick one using the prep-time table above and plan backwards from it.
The exam is offered in English, German, Spanish, French, Italian, Japanese, Korean, Portuguese (Brazil), Chinese (Simplified) and Chinese (Traditional). If the exam is not available in your native language, check the English as a Second Language accommodation and arrange any approved extra time before booking.
Certification and Exam Details Page
Step 3: Work Through the Official Learning Path
Complete the AZ-700 learning path on Microsoft Learn: a single path of eight modules that the CertiAce practice modules follow one-to-one, so you can benchmark each module as soon as you finish it. Take notes on concepts you cannot explain in simple terms, and flag anything that needs hands-on practice. For every service, record the SKU or tier choices and the subnet it needs; the exam leans on those details.
Step 4: Watch a Full Video Course
Microsoft Learn's own AZ-700 course series on YouTube covers the whole syllabus in eleven videos, just under four hours, with one episode per learning-path module. Watch it as a second pass after the learning path, pausing to replicate the key configurations in your own subscription, and rewatch the episodes behind your weakest practice modules. It predates the July 27, 2026 skills update, whose changes are minor.
AZ-700: Designing and Implementing Microsoft Azure Networking Solutions (Microsoft Learn on YouTube)
Step 5: Get Hands-On Practice
AZ-700 is a hands-on engineer exam: many questions describe a topology or a symptom and ask which component, setting or sequence fixes it. Create a free Azure account and work through the official lab exercises for the course, seventeen exercises organized by the same eight modules. Make sure you personally touch:
- An address plan with dedicated subnets for a VPN gateway, Azure Bastion, Azure Firewall and private endpoints
- Public and private DNS zones, a private zone linked to a virtual network, and resolving a private endpoint name from a VM
- Virtual network peering, user-defined routes, and a network interface's effective routes
- A VPN gateway for site-to-site or point-to-site access, and a Virtual WAN hub
- A Standard load balancer with health probes, inbound NAT and outbound rules, then an Application Gateway and a Front Door profile with a WAF policy
- NSGs and application security groups checked with IP flow verify, Azure Firewall with a firewall policy, and virtual network flow logs
The free account's credit supports many of the core exercises, but VPN gateways, ExpressRoute circuits, Azure Firewall, Application Gateway and Front Door are chargeable: delete each lab's resource group when you finish, and learn from the documentation what you cannot deploy, such as a provider-connected ExpressRoute circuit. Repeat the key tasks in PowerShell and the Azure CLI, not only the portal.
Official AZ-700 Lab Instructions
Step 6: Benchmark Your Knowledge
Use CertiAce to benchmark your readiness module by module. The practice modules map to the exam domains as shown above, so use the module mapping and the topics behind your missed questions to identify the skills-measured areas to revisit. Microsoft also offers a free official practice assessment on the certification page. Aim for consistent performance across every module, not one lucky high score; if a topic is unstable, go back to learning plus hands-on practice. Watch for questions that separate similar services: service endpoints versus private endpoints, and Load Balancer versus Application Gateway versus Front Door.
Official AZ-700 Practice Assessment
Step 7: Take the Exam
The day before, review only your weak topics and the numbers you find hard to remember, such as minimum subnet sizes and gateway SKU limits. No brand-new material. On exam day, read each question for what it is truly asking, eliminate wrong options first, and find the constraint that decides the answer: no public exposure, lowest latency, minimal cost, or the fewest changes.
Worth knowing before you sit down:
- Microsoft Learn is available during the exam in a split screen. Use it to check details you genuinely need: the timer keeps running, and the exam is deliberately too long to look up every answer. Browsing is limited to Microsoft Learn itself (no Q&A, practice assessments, or profile), and personal notes and other websites are unavailable.
- You can take unscheduled breaks, but the clock keeps running and you cannot return to questions you already saw.
- Case studies lock when you leave them: finish each one before moving on, because you cannot revisit its questions afterwards.
- Try the exam sandbox beforehand so the question formats and interface hold no surprises: Exam Sandbox
Additional Learning Resources
| Resource | Type | Why it is useful |
|---|---|---|
| AZ-700: Designing and Implementing Microsoft Azure Networking Solutions | YouTube playlist | Microsoft Learn's official eleven-video course series, one episode per learning-path module |
| Preparing for AZ-700 - Design and implement core networking infrastructure (1 of 5) | Video series | Five Exam Readiness Zone episodes, one per skill area; they show an older outline, so use the current study guide for weights |
| Official AZ-700 Lab Instructions | Hands-on labs | The seventeen exercises behind the official course, organized by module |
| Hub-spoke network topology in Azure | Architecture | The reference design most AZ-700 scenarios are built on: hub, spokes, shared services and inspection |
| Azure Virtual Network documentation | Docs | Address spaces, subnets, peering, routing, NAT Gateway and service endpoints |
| VPN Gateway documentation | Docs | Site-to-site and point-to-site design, SKUs, IPsec/IKE policies and troubleshooting |
| ExpressRoute documentation | Docs | Connectivity models, peerings, Global Reach, FastPath, ExpressRoute Direct and resiliency designs |
Realistic AZ-700 exam-style questions with instant feedback and detailed explanations.
Practice AZ-700 now