DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft AZ-700 Practice Questions & Answers 2026 Part3 | Microsoft Azure Networking Solutions

Are you preparing for the Microsoft AZ-700 certification exam? SPOTO offers the Microsoft AZ-700 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
You have an Azure subscription that contains the resources shown in the following table.Gateway1 provides access to App1 by using a URL of https://app1.contoso.com.You create a new web app named App2.You need to configure Gateway1 to enable access to App2 by using a URL of https://app2.contoso.com. The solution must minimize administrative effort.What should you configure on Gateway1?
A. backend pool and a routing rule
B. listener and a routing rule
C. listener, a backend pool, and a routing rule
D. listener and a backend pool
View answer
Correct Answer: B

View The Updated AZ-700 Exam Questions

SPOTO Provides 100% Real AZ-700 Exam Questions for You to Pass Your AZ-700 Exam!

Question #2
You need to provide connectivity to storage1. The solution must meet the PaaS networking requirements and the business requirements. What should you include in the solution?
A. a service endpoint
B. Azure Front Door
C. a private endpoint
D. Azure Traffic Manager
View answer
Correct Answer: D
Question #3
You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains a subnet named Subnet1.You deploy an instance of Azure Application Gateway v2 named AppGw1 to Subnet1. You create a network security group (NSG) named NSG1 and link NSG1 to Subnet1.You need to ensure that AppGw1 will only load balance traffic that originates from VNet1. The solution must minimize the impact on the functionality of AppGw1.What should you add to NSG1?
A. n outbound rule that has a priority of 4096 and blocks all internet traffic
B. n inbound rule that has a priority of 4096 and blocks all internet traffic
C. n inbound rule that has a priority of 100 and blocks all internet traffic
D. n outbound rule that has a priority 100 and blocks all internet traffic
View answer
Correct Answer: B
Question #4
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have two Azure virtual networks named Vnet1 and Vnet2.You have a Windows 10 device named Client1 that connects to Vnet1 by using a Point-to-Site (P2S) IKEv2 VPN.You implement virtual network peering between Vnet1 and Vnet2. Vnet1 allows gateway transit. Vnet2 can use the remote gateway.You discover that Client1 cannot communicate with Vnet2.You need to ensure that Client1 can communicate with Vnet2.Solution: You enable BGP on the gateway of Vnet1.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #5
You have 10 Azure App Service instances. Each instance hosts the same web app. Each instance is in a different Azure region. You need to configure Azure Traffic Manager to direct users to the instance that has the lowest latency. Which routing method should you use?
A. performance
B. geographic
C. weighted
D. priority
View answer
Correct Answer: D
Question #6
Reference Scenario: click here What should you implement to meet the virtual network requirements for the virtual machines that connect to Vnet4 and Vnet5?
A. a private endpoint
B. a virtual network peering
C. a private link service
D. a routing table
E. a service endpoint
View answer
Correct Answer: B
Question #7
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have two Azure virtual networks named Vnet1 and Vnet2.You have a Windows 10 device named Client1 that connects to Vnet1 by using a Point-to-Site (P2S) IKEv2 VPN.You implement virtual network peering between Vnet1 and Vnet2. Vnet1 allows gateway transit. Vnet2 can use the remote gateway.You discover that Client1 cannot communicate with Vnet2.You need to ensure that Client1 can communicate with Vnet2.Solution: You enable BGP on the gateway of Vnet1.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #8
You have an on-premises datacenter and an Azure subscription.You plan to implement ExpressRoute FastPath.You need to create an ExpressRoute gateway. The solution must minimize downtime if a single Azure datacenter fails.Which SKU should you use?
A. ErGw1AZ
B. High performance
C. Ultra performance
D. ErGw3AZ
E. ErGw2AZ
View answer
Correct Answer: D
Question #9
You have 10 on-premises networks that are connected by using a 3rd party Software Defined Wide Area Network (SD-WAN) solution. You have an Azure subscription that contains five virtual networks.You plan to connect the Azure virtual networks and the on-premises networks by using an Azure Virtual WAN with a single virtual WAN hub.You need to ensure that the Azure Virtual WAN can act as a node in the 3rd party SD-WAN solution.What should you include in the solution?
A. An Azure Virtual WAN ExpressRoute gateway
B. A Network Virtual Appliance (NVA)
C. A Site to site gateway (VPN gateway)
D. A Point to site gateway (User VPN gateway)
View answer
Correct Answer: B
Question #10
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have two Azure virtual networks named Vnet1 and Vnet2.You have a Windows 10 device named Client1 that connects to Vnet1 by using a Point-to-Site (P2S) IKEv2 VPN.You implement virtual network peering between Vnet1 and Vnet2. Vnet1 allows gateway transit. Vnet2 can use the remote gateway.You discover that Client1 cannot communicate with Vnet2.You need to ensure that Client1 can communicate with Vnet2.Solution: You enable BGP on the gateway of Vnet1.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #11
You have Azure App Service apps in the West US Azure region as shown in the following table.You need to ensure that all the apps can access the resources in a virtual network named VNet1 without forwarding traffic through the internet.How many integration subnets should you create?
A.
B.
C.
D.
E.
View answer
Correct Answer: C
Question #12
You have an Azure subscription that contains the following resources:A virtual network named Vnet1Two subnets named subnet1 and AzureFirewallSubnetA public Azure Firewall named FW1A route table named RT1 that is associated to Subnet1A rule routing of 0.0.0.0/0 to FW1 in RT1After deploying 10 servers that run Windows Server to Subnet1, you discover that none of the virtual machines were activated.You need to ensure that the virtual machines can be activated.What should you do?
A. n FW1, configure a DNAT rule for port 1688
B. eploy an application security group that allows outbound traffic to 1688
C. dd an internet route to RT1 for the Azure Key Management Service (KMS)
D. eploy an Azure Standard Load Balancer that has an outbound NAT rule
View answer
Correct Answer: C
Question #13
You have an Azure virtual network named Vnet1. You need to ensure that the virtual machines in Vnet1 can access only the Azure SQL resources in the East US Azure region. The virtual machines must be prevented from accessing any Azure Storage resources. Which two outbound network security group (NSG) rules should you create? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point
A. a deny rule that has a source of Virtual Network service tag and a destination of Sql service tag
B. a deny rule that has a source of IP address range of Vnet1 and destination of Storage service tag
C. a deny rule that has a source of VirtualNetwork service tag and a destination of 168
D. an allow rule that has a source of IP address range of Vnet1 and destination of Sql
View answer
Correct Answer: BD
Question #14
SIMULATION
A. See explanation below
B. Placeholder
C. Placeholder
D. Placeholder
View answer
Correct Answer: A
Question #15
You are planning the IP addressing for the subnets in Azure virtual networks.Which type of resource requires IP addresses in the subnets?
A. internal load balancers
B. storage account
C. serviice endpoints
D. service endpoint policies
View answer
Correct Answer: A
Question #16
You have an on-premises datacenter named DC1 that contains two routers.You have an Azure subscription. The subscription contains a virtual network named VNet1 and a zone- redundant ExpressRoute virtual network gateway named GW1 that uses the ErGw3Az SKU. GW1 is attached to VNet1DC1 is connected to VNet1 by using an ExpressRoute Standard circuit named Circuit1. The DC1 routers are configured as endpoints for Circuit1. Circuit1 traffic traverses two physical links.During a link outage, the connection takes three minutes to fail over.You need to ensure that failovers between the links take less than one second.What should you do?
A. For Circuit1, select FastPath
B. On the routers, configure Bidirectional Forwarding Detection (BFD)
C. For GW1, change SKU to UltraPerformance
D. For GW1, set Active-active mode to Enabled
View answer
Correct Answer: B
Question #17
You have three on-premises networks.You have an Azure subscription that contains a Basic Azure virtual WAN. The virtual WAN contains a single virtual hub and a virtual network gateway that is limited to a throughput of 1 Gbps.The on-premises networks connect to the virtual WAN by using Site-to-Site (S2S) VPN connections.You need to increase the throughput of the virtual WAN to 3 Gbps. The solution must minimize administrative effort.What should you do?
A. Upgrade the virtual WAN to the Standard SKU
B. Add an additional VPN gateway to the Azure subscription
C. Create an additional virtual hub
D. Increase the number of gateway scale units
View answer
Correct Answer: D
Question #18
You have an instance of Azure Web Application Firewall (WAF) on Azure Front Door.You plan to create a WAF rule that will block high rates of requests from a single IP address.You need to query Log Analytics to identify the optimal threshold for the rule.Which table should you query in Log Analytics?
A. AZFWThreatIntel
B. AzureDiagnostics
C. SecurityDetection
D. AGWFirewallLogs
View answer
Correct Answer: B
Question #19
Your company has a single on-premises datacenter in Washington DC. The East US Azure region has a peering location in Washington DC.The company only has Azure resources in the East US region.You need to implement ExpressRoute to support up to 1 Gbps. You must use only ExpressRoute Unlimited data plans. The solution must minimize costs.Which type of ExpressRoute circuits should you create?
A. ExpressRoute Local
B. ExpressRoute Direct
C. ExpressRoute Premium
D. ExpressRoute Standard
View answer
Correct Answer: A
Question #20
You fail to establish a Site-to-Site VPN connection between your company's main office and an Azure virtual network.You need to troubleshoot what prevents you from establishing the IPsec tunnel.Which diagnostic log should you review?
A. KEDiagnosticLog
B. outeDiagnosticLog
C. atewayDiagnosticLog
D. unnelDiagnosticLog
View answer
Correct Answer: A
Question #21
You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains an Azure Virtual Desktop host pool named Pool1. You need to implement Azure Firewall and TLS inspection for all the outbound traffic from Pool1. Which two resources should you configure? Each correct answer present part of the solution. NOTE: Each correct answer is worth one point
A. an Azure Private DNS zone
B. a private endpoint
C. an Azure key vault
D. an Azure NAT gateway
E. a Microsoft Entra enterprise app
F. a managed identity
View answer
Correct Answer: DF
Question #22
You have an Azure subscription that contains the resources shown in the following table. You create a service endpoint policy that has the following settings: * Associated subnets: Subnet 1 * Service: Microsoft.Storage * Scope: Single account * Resource: storage1 Which resources can VM1 access?
A. Astorage1 in the East US Azure region and its replica in the paired region
B. Bstorage1 and storage2 in the East US Azure region and their replicas in the paired region
C. Cstorage1 in the East US Azure region only
D. Dstorage1 and storage2 in the East US Azure region only
View answer
Correct Answer: C
Question #23
You plan to configure BGP for a Site-to-Site VPN connection between a datacenter and Azure.Which two Azure resources should you configure? Each correct answer presents a part of the solution. (Choose two.)NOTE: Each correct selection is worth one point.
A. a virtual network gateway
B. Azure Application Gateway
C. Azure Firewall
D. a local network gateway
E. Azure Front Door
View answer
Correct Answer: AD
Question #24
You need to connect Vnet2 and Vnet3. The solution must meet the virtual networking requirements and the business requirements. Which two actions should you include in the solution? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
A. On the peerings from Vnet2 and Vnet3, select Use remote gateways
B. On the peering from Vnet1, select Allow forwarded traffic
C. On the peering from Vnet1, select Use remote gateways
D. On the peering from Vnet1, select Allow gateway transit
E. On the peerings from Vnet2 and Vnet3, select Allow gateway transit
View answer
Correct Answer: BD
Question #25
What should you implement to meet the virtual network requirements for the virtual machines that connect to Vnet4 and Vnet5?
A. a private endpoint
B. a routing table
C. a service endpoint
D. a private link service
E. a virtual network peering
View answer
Correct Answer: E
Question #26
You have an Azure application gateway named AGW1 that has a routing rule named Rule1. Rule 1 directs traffic for http://www.contoso.com to a backend pool named Pool1. Pool1 targets an Azure virtual machine scale set named VMSS1. You deploy another virtual machine scale set named VMSS2. You need to configure AGW1 to direct all traffic for http://www.adatum.com to VMSS2. The solution must ensure that requests to http://www.contoso.com continue to be directed to Pool1. Which three actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point. https://docs.microsoft.com/en-us/azure/application-gateway/configuration-overview
A. Add a backend pool
B. Modify an HTTP setting
C. Add an HTTP setting
D. Add a listener
E. Add a rule
View answer
Correct Answer: ADE
Question #27
You have an Azure virtual machine named VM1. You need to capture all the network traffic of VM1 by using Azure Network Watcher. To which locations can the capture be written?
A. Aa file path on VM1 only
B. Bblob storage only
C. Ca premium storage account only
D. Dblob storage and a file path on VM1 only
E. Eblob storage and a premium storage account only
F. Fblob storage, a file path on VM1, and a premium storage account
View answer
Correct Answer: D
Question #28
You have an Azure virtual network named Vnet1 and an on-premises network. The on-premises network has policy-based VPN devices.In Vnet1, you deploy a virtual network gateway named GW1 that uses a SKU of VpnGw1 and is route-based.You have a Site-to-Site VPN connection for GW1 as shown in the following exhibit.You need to ensure that the on-premises network can connect to the route-based GW1.What should you do before you create the connection?
A. Set Connection Mode to ResponderOnly
B. Set BGP to Enabled
C. Set Use Azure Private IP Address to Enabled
D. Set IPsec / IKE policy to Custom
View answer
Correct Answer: D
Question #29
You have an Azure virtual network and an on-premises datacenter.You need to implement a Site-to-Site VPN connection between the datacenter and the virtual network.Which two resources should you create? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
A. a virtual network gateway
B. Azure Firewall
C. a local network gateway
D. Azure Web Application Firewall (WAF)
E. an on-premises data gateway
F. an Azure application gateway
G. a user-defined route
View answer
Correct Answer: AC
Question #30
You are planning an Azure Point-to-Site (P2S) VPN that will use OpenVPN.Users will authenticate by an on-premises Active Directory domain.Which additional service should you deploy to support the VPN authentication?
A. an Azure key vault
B. a RADIUS server
C. a certification authority
D. Azure Active Directory (Azure AD) Application Proxy
View answer
Correct Answer: B

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us