AZ-700 — Frequently Asked Questions
Community-vetted answers to 40 common questions about this exam.
Questions from real practice questions
Each Q&A comes from a specific community question — follow the link for its full analysis.
Upgrading ExpressRoute Standard Gateway for FastPath
Seamless Gateway Migration does not support upgrading from a Standard (non-AZ) gateway to an AZ-enabled SKU like ErGw3AZ. Doing so requires a full replacement, causing downtime.
No, High Performance does not support FastPath. Only Ultra Performance and ErGw3AZ SKUs support this feature.
Azure NAT Gateway Minimum Subnets for VM1/VM2
You cannot associate a NAT Gateway with a subnet that contains resources using Basic Public IP addresses, as this would override their direct internet access.
Yes, while the NAT Gateway resource is regional, it must be associated with a specific subnet to handle outbound traffic for VMs within that subnet.
Azure DNS Private Resolver Minimum Deployment
No, resolvers are regional. You must deploy at least one resolver per region where you need to connect VNets or provide endpoints.
While 1 resolver might suffice for one direction, the requirement for Server1 to resolve Azure names requires an inbound endpoint in the Azure region, necessitating a second resolver or complex peering.
How Does a Service Endpoint Policy Enable Paired-Region Storage Access?
RA-GRS adds read-only secondary endpoints for storage1 in its paired region, but the subnet's Microsoft.Storage service endpoint stays region-scoped until a service endpoint policy is applied to that subnet.
Deleting the endpoint drops storage1's current service-endpoint access and does not change the endpoint's regional scope; recreating it returns the same regional endpoint, leaving the paired region unreachable.
Minimum DDoS Network Protection Plans for Cost Minimization
Yes. A single DDoS Network Protection plan can be associated with any VNet across all subscriptions within the same Azure AD tenant.
No. The pricing is flat per tenant/per region pair, regardless of the number of public IP addresses protected by the linked VNets.
Minimum Azure Service Endpoints for Peered VNets
No. A single service endpoint for 'Microsoft.Storage' secures traffic to all storage accounts accessible from that subnet.
No. Peering provides connectivity, but you must still explicitly enable the service endpoint policy on the subnet to restrict access and optimize routing.
Azure Service Endpoint Policy for Batch Storage Access
An alias specifies the service type (e.g., Microsoft.Storage), not a specific resource. To target storage1, you must add it as a resource.
No, enabling the endpoint allows traffic from the subnet to the service, but a Service Endpoint Policy is needed to restrict that traffic to specific resources.
Private Endpoint UDR Routing Prerequisite
Delegation assigns subnet control to a specific Azure service provider. Since Private Endpoints are managed by the Virtual Network infrastructure, they conflict with delegation.
No. Private endpoints rely on the Azure backbone and UDRs for routing. A load balancer is used for inbound/outbound traffic distribution, not internal endpoint routing.
Entra ID P2S VPN Client Compatibility on macOS
Native IKEv2 on macOS does not support the protocol extensions required for Microsoft Entra ID authentication, necessitating the OpenVPN client.
No, Windows devices support both the native IKEv2 client and the OpenVPN client for Entra ID authentication, offering more flexibility than macOS.
Azure Network Watcher Connection Monitor for Latency
Yes, a single Connection Monitor resource can monitor multiple endpoint pairs, including those in different Azure regions and on-premises locations.
Network Watcher is a regional control plane. You don't need a new instance in every region to perform monitoring; Connection Monitor in one region can handle cross-region checks.
Minimum Application Security Groups for Peered VNets
Yes, an ASG is a logical grouping that can include VMs from any VNet in the same subscription or via peering, provided they are in the same tenant.
A single ASG cannot enforce directional restrictions between its members easily. Separate groups allow precise NSG rules defining who can talk to whom.
Azure Front Door Rate Limiting Configuration
No, rate limiting is a feature provided by Azure WAF custom rules when integrated with Front Door Premium.
Yes, when a WAF policy is associated with a Front Door profile, its rules apply to all backend pools and endpoints managed by that profile.
Does Azure Firewall Mark a Virtual WAN Hub as Secured?
NSGs attach to subnets and NICs to filter layer-4 traffic; they cannot be attached to a Virtual WAN hub, so they never change Hub1's Unsecured status.
Yes. Only an in-hub Azure Firewall managed by Azure Firewall Manager (or an equivalent managed NVA) converts Hub1 to a secured virtual hub; a spoke firewall leaves the status Unsecured.
How Do You Block Azure IMDS Access with NSG1?
A raw IP rule can be error-prone and harder to maintain; AzurePlatformIMDS is the supported service tag that represents the IMDS endpoint and requires less administrative effort.
IMDS requests are initiated outbound from the VM to 169.254.169.254. An inbound rule does not stop that request, and default inbound rules already deny unsolicited inbound traffic.
Azure Traffic Analytics Aggregated Flow Entries
No. It aggregates by the full five-tuple including Source IP, Destination IP, Source Port, Destination Port, and Protocol.
Different source ports mean the connections are distinct flows. Even if destination IPs/ports are the same, differing source ports create separate aggregated entries.
Azure Firewall TLS Inspection for AVD Host Pool Outbound Traffic
Azure Firewall provides its own SNAT for outbound traffic; a NAT gateway is used for outbound connectivity when not routing through a firewall, not for TLS decryption.
The firewall's managed identity is represented as an enterprise application; granting it access to the Key Vault certificate is required for TLS inspection.
Azure Network Watcher Packet Capture Storage Locations
No, only General Purpose v2 standard storage accounts are supported for storing packet capture files.
If you select the local file path option, captures are saved directly to the VM's disk (e.g., /var/captures on Linux).
Azure Firewall KMS Activation Rule
Adding a route changes the path but does not bypass Azure Firewall application rules. If the Firewall blocks the traffic, the route change alone will not enable activation.
Yes, Azure Firewall Network Rules can utilize Service Tags to simplify management of destination addresses for known Azure services.
Azure Private Link Service Configuration for VM Access
A Private Endpoint connects to a specific Azure service resource. For a VM, you must expose it via a Private Link Service, which requires a Load Balancer frontend IP configuration.
No, when used with Private Link, the Standard Load Balancer should be configured without a public IP address to ensure traffic remains within the Azure backbone.
Minimum DDoS Network Protection Plans for Multiple VNets
A single plan can be associated with up to 100 virtual networks across subscriptions in the same tenant, so you do not need one plan per VNet or subscription.
No, DDoS IP Protection is enabled per public IP address and does not require a DDoS protection plan, unlike DDoS Network Protection.
Ready to practice?
Access 100 AZ-700 questions with instant feedback and detailed explanations.
View AZ-700 Practice Questions →← Back to AZ-700 Designing and Implementing Microsoft Azure Networking Solutions Study Guide