DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft AZ-700 Practice Questions & Answers 2026 Part2 | Microsoft Azure Networking Solutions

Are you preparing for the Microsoft AZ-700 certification exam? SPOTO offers the Microsoft AZ-700 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
You are planning an Azure Point-to-Site (P2S) VPN that will use OpenVPN.Users will authenticate by using an on-premises Active Directory domain.Which additional service should you deploy to support the VPN authentication?
A. an Azure key vault
B. a RADIUS server
C. a certification authority
D. Microsoft Entra Application Proxy
View answer
Correct Answer: B

View The Updated AZ-700 Exam Questions

SPOTO Provides 100% Real AZ-700 Exam Questions for You to Pass Your AZ-700 Exam!

Question #2
You have five virtual machines that run Windows Server. Each virtual machine hosts a different web app. You plan to use an Azure application gateway to provide access to each web app by using a hostname of www.contoso.com and a different URL path for each web app, for example: https://www.contoso.com/app1. You need to control the flow of traffic based on the URL path. What should you configure?
A. HTTP settings
B. listeners
C. rules
D. rewrites
View answer
Correct Answer: C
Question #3
Your company has a single on-premises datacenter in Washington DC. The East US Azure region has a peering location in Washington DC.The company only has Azure resources in the East US region.You need to implement ExpressRoute to support up to 1 Gbps. You must use only ExpressRoute Unlimited data plans. The solution must minimize costs.Which type of ExpressRoute circuits should you create?
A. xpressRoute Local
B. xpressRoute Direct
C. xpressRoute Premium
D. xpressRoute Standard
View answer
Correct Answer: A
Question #4
What should you implement to meet the virtual network requirements for the virtual machines that connect to Vnet4 and Vnet5?
A. a private endpoint
B. a routing table
C. a service endpoint
D. a private link service
E. a virtual network peering
View answer
Correct Answer: E
Question #5
You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains a subnet named Subnet1 You deploy an instance of Azure Application Gateway v2 named AppGw1 to Subnet1. You create a network security group (NSG) named NSG1 and link NSG1 to Subnet1. You need to ensure that AppGw1 will only load balance traffic that originates from VNet1. The solution must minimize the impact on the functionality of AppGw1. What should you add to NSG1?
A. an outbound rule that has a priority 100 and blocks all internet traffic
B. an outbound rule that has a priority of 4096 and blocks all internet traffic
C. an inbound rule that has a priority of 4096 and blocks all internet traffic
D. an inbound rule that has a priority of 100 and blocks all internet traffic
View answer
Correct Answer: C
Question #6
You have an on-premises server named Server1 that runs Windows Server.You have an Azure subscription that contains a virtual network named VNet1.You plan to connect Server1 to VNet1 by using Azure Network Adapter.You need to minimize how long it takes to deploy the adapter to Server1.What should you create first?
A. a route server
B. an Azure Bastion host
C. a private endpoint
D. an Azure VPN gateway
View answer
Correct Answer: D
Question #7
Azure virtual networks in the East US Azure region as shown in the following table.The virtual networks are peered to one another. Each virtual network contains four subnets.You plan to deploy a virtual machine named VM1 that will inspect and route traffic between all the subnets on both the virtual networks.What is the minimum number of IP addresses that you must assign to VM1?
A.
B.
C.
D.
View answer
Correct Answer: B
Question #8
What should you implement to meet the virtual network requirements for the virtual machines that connect to Vnet4 and Vnet5?
A. a private endpoint
B. a routing table
C. a service endpoint
D. a private link service
E. a virtual network peering
View answer
Correct Answer: E
Question #9
You have an Azure subscription. You need to deploy an App Service web app named App1 that will use an Azure application gateway. The estimated usage for App1 is 250,000 persistent connections. What is the minimum number of app instances you should configure?
A. 1
B. 10
C. 100
D. 1000
View answer
Correct Answer: C
Question #10
You are planning an Azure Point-to-Site (P2S) VPN that will use OpenVPN.Users will authenticate by an on-premises Active Directory domain.Which additional service should you deploy to support the VPN authentication?
A. n Azure key vault
B. RADIUS server
C. certification authority
D. zure Active Directory (Azure AD) Application Proxy
View answer
Correct Answer: B
Question #11
Your company has offices in New York and Amsterdam. The company has an Azure subscription. Both offices connect to Azure by using a Site-to-Site VPN connection.The office in Amsterdam uses resources in the North Europe Azure region. The office in New York uses resources in the East US Azure region.You need to implement ExpressRoute circuits to connect each office to the nearest Azure region. Once the ExpressRoute circuits are connected, the on-premises computers in the Amsterdam office must be able to connect to the on-premises servers in the New York office by using the ExpressRoute circuits.Which ExpressRoute option should you use?
A. xpressRoute FastPath
B. xpressRoute Global Reach
C. xpressRoute Direct
D. xpressRoute Local
View answer
Correct Answer: B
Question #12
You have an Azure subscription that contains a virtual network named VNet1 and the virtual machines shown in the following table.All the virtual machines are connected to Vnet1.You need to ensure that the applications hosted on the virtual machines can be accessed from the internet. The solution must ensure that the virtual machines share a single public IP address.What should you use?
A. an internal load balancer
B. Azure Application Gateway
C. a NAT gateway
D. a public load balancer
View answer
Correct Answer: D
Question #13
Your company has offices in New York and Amsterdam. The company has an Azure subscription. Both offices connect to Azure by using a Site-to-Site VPN connection.The office in Amsterdam uses resources in the North Europe Azure region. The office in New York uses resources in the East US Azure region.You need to implement ExpressRoute circuits to connect each office to the nearest peering location. Once the ExpressRoute circuits are connected, the on-premises computers in the Amsterdam office must be able to connect to the on-premises servers in the New York office by using the ExpressRoute circuits.Which ExpressRoute option should you use?
A. ExpressRoute FastPath
B. ExpressRoute Global Reach
C. ExpressRoute Direct
D. ExpressRoute Local
View answer
Correct Answer: B
Question #14
You fail to establish a Site-to-Site VPN connection between your company's main office and an Azure virtual network.You need to troubleshoot what prevents you from establishing the IPsec tunnel.Which diagnostic log should you review?
A. IKEDiagnosticLog
B. RouteDiagnosticLog
C. GatewayDiagnosticLog
D. TunnelDiagnosticLog
View answer
Correct Answer: A
Question #15
You have an Azure subscription that contains the resources shown in the following table.You create a virtual network named Vnet2 in the West US region.You plan to enable peering between Vnet1 and Vnet2.You need to ensure that the virtual machines connected to Vnet2 can connect to VM1 and VM2 via LB1.What should you do?
A. From the Peerings settings of Vnet2, set Traffic forwarded from remote virtual network to Allow
B. Change the Floating IP configurations of LB1
C. From the Peerings settings of Vnet1, set Traffic forwarded from remote virtual network to Allow
D. Change the SKU of LB1
View answer
Correct Answer: D
Question #16
Your company has offices in New York and Amsterdam. The company has an Azure subscription. Both offices connect to Azure by using a Site-to-Site VPNconnection.The office in Amsterdam uses resources in the North Europe Azure region. The office in New York uses resources in the East US Azure region.You need to implement ExpressRoute circuits to connect each office to the nearest Azure region. Once the ExpressRoute circuits are connected, the on-premisescomputers in the Amsterdam office must be able to connect to the on-premises servers in the New York office by using the ExpressRoute circuits.Which ExpressRoute option should you use?
A. ExpressRoute FastPath
B. ExpressRoute Global Reach
C. ExpressRoute Direct
D. ExpressRoute Local
View answer
Correct Answer: B
Question #17
You have an application named App1 that listens for incoming requests on a preconfigured group of 50 TCP ports and UDP ports.You install App1 on 10 Azure virtual machines.You need to implement load balancing for App1 across all the virtual machines. The solution must minimize the number of load balancing rules.What should you include in the solution?
A. zure Application Gateway V2 that has multiple listeners
B. zure Standard Load Balancer that has Floating IP enabled
C. zure Standard Load Balancer that has high availability (HA) ports enabled
D. zure Application Gateway v2 that has multiple site hosting enabled
View answer
Correct Answer: A
Question #18
You have an Azure application gateway named AppGW1 that balances requests to a web app named App1. You need to modify the server variables in the response header of App1. What should you configure on AppGW1?
A. rules
B. HTTP settings
C. rewrites
D. listeners
View answer
Correct Answer: C
Question #19
Reference Scenario: click here You need to configure the default route in Vnet2 and Vnet3. The solution must meet the virtual networking requirements. What should you use to configure the default route?
A. a user-defined route assigned to GatewaySubnet in Vnet2 and Vnet3
B. a user-defined route assigned to GatewaySubnet in Vnet1
C. BGP route exchange
D. route filters
View answer
Correct Answer: B
Question #20
You have an Azure Front Door instance named FD1 that is protected by using Azure Web Application Firewall (WAF).FD1 uses a frontend host named app1.contoso.com to provide access to Azure web apps hosted in the East US Azure region and the West US Azure region.You need to configure FD1 to block requests to app1.contoso.com from all countries other than the United States.What should you include in the WAF policy?
A. custom rule that uses a rate limit rule
B. frontend host association
C. custom rule that uses a match rule
D. managed rule set
View answer
Correct Answer: C
Question #21
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an Azure subscription that contains an Azure Virtual WAN named VWAN1. VWAN1 contains a hub named Hub1. Hub1 has a security status of Unsecured.You need to ensure that the security status of Hub1 is marked as Secured.Solution: You implement an Azure Front Door profile.Does this meet the requirement?
A. Yes
B. No
View answer
Correct Answer: B
Question #22
You are planning an Azure deployment that will contain three virtual networks in the East US Azure region as shown in the following table.A Site-to-Site VPN will connect Vnet1 to your company's on-premises network.You need to recommend a solution that ensures that the virtual machines on all the virtual networks can communicate with the on-premises network. The solution must minimize costs.What should you recommend for Vnet2 and Vnet3?
A. VNet-to-VNet VPN connections
B. peering
C. service endpoints
D. route tables
View answer
Correct Answer: B
Question #23
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have two Azure virtual networks named Vnet1 and Vnet2.You have a Windows 10 device named Client1 that connects to Vnet1 by using a Point-to-Site (P2S) IKEv2 VPN.You implement virtual network peering between Vnet1 and Vnet2. Vnet1 allows gateway transit. Vnet2 can use the remote gateway.You discover that Client1 cannot communicate with Vnet2.You need to ensure that Client1 can communicate with Vnet2.Solution: You enable BGP on the gateway of Vnet1.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #24
You have an Azure subscription that contains a user named Admin1 and a resource group named RG1.
A. User Access Administrator
B. Network Contributor
C. Resource Policy Contributor
D. Monitoring Contributor
View answer
Correct Answer: A
Question #25
You have an Azure virtual network and an on-premises datacenter.You are planning a Site-to-Site VPN connection between the datacenter and the virtual network.Which two resources should you include in your plan? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.
A. a user-defined route
B. a virtual network gateway
C. Azure Firewall
D. Azure Web Application Firewall (WAF)
E. an on-premises data gateway
F. an Azure application gateway
G. a local network gateway
View answer
Correct Answer: BG
Question #26
You plan to publish a website that will use an FQDN of www.contoso.com. The website will be hosted by using the Azure App Service apps shown in the following table.
A. two A records that map www
B. a CNAME record that maps www
C. a CNAME record that maps www
D. a TXT record that contains a string of as1
View answer
Correct Answer: C
Question #27
You have an on-premises datacenter named Site1 that contains a firewall named FW1. FW1 connects to the internet.You have an Azure subscription that contains the resources shown in the following table.You plan to connect Site1 to Hub1 by using a site-to-site connection.You need to configure the site-to-site connection to FW1.What should you create in VWAN1?
A. a VPN site
B. a virtual network connection
C. a network virtual appliance (NVA)
D. a User VPN configuration
View answer
Correct Answer: A
Question #28
You have an Azure virtual network and an on-premises datacenter.You are planning a Site-to-Site VPN connection between the datacenter and the virtual network.Which two resources should you include in your plan? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.
A. user-defined route
B. virtual network gateway
C. zure Firewall
D. zure Web Application Firewall (WAF)
E. n on-premises data gateway
F. n Azure application gateway
G. local network gateway
View answer
Correct Answer: BG
Question #29
You have an Azure subscription that contains a virtual network.You plan to deploy an Azure VPN gateway and 90 Site-to-Site VPN connections. The solution must meet the following requirements:Ensure that the Site-to-Site VPN connections remain available if an Azure datacenter fails.Minimize costs.Which gateway SKU should you specify?
A. VpnGw1AZ
B. VpnGw2AZ
C. VpnGw4AZ
D. VpnGw5AZ
View answer
Correct Answer: C
Question #30
Your company has two on-premises sites in New York and Los Angeles.
A. Host Standby Routing Protocol (HSRP)
B. Border Gateway Protocol (BGP)
C. Virtual Router Redundancy Protocol (VRRP)
View answer
Correct Answer: B

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us