Microsoft AZ-700 Exam Syllabus Topics:
| Topic | Details |
|---|---|
Design, Implement, and Manage Hybrid Networking (10-15%) | |
| Design, implement, and manage a site-to-site VPN connection | - design a site-to-site VPN connection for high availability - select an appropriate virtual network (VNet) gateway SKU - identify when to use policy-based VPN versus route-based VPN - create and configure a local network gateway - create and configure an IPsec/IKE policy - create and configure a virtual network gateway - diagnose and resolve virtual network gateway connectivity issues |
| Design, implement, and manage a point-to-site VPN connection | - select an appropriate virtual network gateway SKU - plan and configure RADIUS authentication - plan and configure certificate-based authentication - plan and configure OpenVPN authentication - plan and configure Azure Active Directory (Azure AD) authentication - implement a VPN client configuration file - diagnose and resolve client-side and authentication issues |
| Design, implement, and manage Azure ExpressRoute | - choose between provider and direct model (ExpressRoute Direct) - design and implement Azure cross-region connectivity between multiple ExpressRoute locations - select an appropriate ExpressRoute SKU and tier - design and implement ExpressRoute Global Reach - design and implement ExpressRoute FastPath - choose between private peering only, Microsoft peering only, or both - configure private peering - configure Microsoft peering - create and configure an ExpressRoute gateway - connect a virtual network to an ExpressRoute circuit - recommend a route advertisement configuration - configure encryption over ExpressRoute - implement Bidirectional Forwarding Detection - diagnose and resolve ExpressRoute connection issues |
Design and Implement Core Networking Infrastructure (20-25%) | |
| Design and implement private IP addressing for VNets | - create a VNet - plan and configure subnetting for services, including VNet gateways, private endpoints, firewalls, application gateways, and VNet-integrated platform services - plan and configure subnet delegation - plan and configure subnetting for Azure Route Server |
| Design and implement name resolution | - design public DNS zones - design private DNS zones - design name resolution inside a VNet - configure a public or private DNS zone - link a private DNS zone to a VNet |
| Design and implement cross-VNet connectivity | - design service chaining, including gateway transit - design VPN connectivity between VNets - implement VNet peering |
| Design and implement an Azure Virtual WAN architecture | - design an Azure Virtual WAN architecture, including selecting types and services - connect a VNet gateway to Azure Virtual WAN - create a hub in Virtual WAN - create a network virtual appliance (NVA) in a virtual hub - configure virtual hub routing - create a connection unit |
Design and Implement Routing (25-30%) | |
| Design, implement, and manage VNet routing | - design and implement user-defined routes (UDRs) - associate a route table with a subnet - configure forced tunneling - diagnose and resolve routing issues - design and implement Azure Route Server |
| Design and implement an Azure Load Balancer | - choose an Azure Load Balancer SKU (Basic versus Standard) - choose between public and internal - create and configure an Azure Load Balancer (including cross-region) - implement a load balancing rule - create and configure inbound NAT rules - create explicit outbound rules for a load balancer |
| Design and implement Azure Application Gateway | - recommend Azure Application Gateway deployment options - choose between manual and autoscale - create a back-end pool - configure health probes - configure listeners - configure routing rules - configure HTTP settings - configure Transport Layer Security (TLS) - configure rewrite sets |
| Implement Azure Front Door | - choose an Azure Front Door SKU - configure health probes, including customization of HTTP response codes - configure SSL termination and end-to-end SSL encryption - configure multisite listeners - configure back-end targets - configure routing rules, including redirection rules |
| Implement an Azure Traffic Manager profile | - configure a routing method (mode) - configure endpoints - create HTTP settings |
| Design and implement an Azure Virtual Network NAT | - choose when to use a Virtual Network NAT - allocate public IP or public IP prefixes for a NAT gateway - associate a Virtual Network NAT with a subnet |
Secure and Monitor Networks (15-20%) | |
| Design, implement, and manage an Azure Firewall deployment | - design an Azure Firewall deployment - create and implement an Azure Firewall deployment - configure Azure Firewall rules - create and implement Azure Firewall Manager policies - create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub - integrate an Azure Virtual WAN hub with a third-party NVA |
| Implement and manage network security groups (NSGs) | - create an NSG - associate an NSG to a resource - create an application security group (ASG) - associate an ASG to a NIC - create and configure NSG rules - interpret NSG flow logs - validate NSG flow rules - verify IP flow |
| Implement a Web Application Firewall (WAF) deployment | - configure detection or prevention mode - configure rule sets for Azure Front Door, including Microsoft managed and user defined - configure rule sets for Application Gateway, including Microsoft managed and user defined - implement a WAF policy - associate a WAF policy |
| Monitor networks | - configure network health alerts and logging by using Azure Monitor - create and configure a Connection Monitor instance - configure and use Traffic Analytics - configure NSG flow logs - enable and configure diagnostic logging - configure Azure Network Watcher |
Design and Implement Private Access to Azure Services (10-15%) | |
| Design and implement Azure Private Link service and Azure Private Endpoint | - create a Private Link service - plan private endpoints - create private endpoints - configure access to private endpoints - integrate Private Link with DNS - integrate a Private Link service with on-premises clients |
| Design and implement service endpoints | - create service endpoints - configure service endpoint policies - configure service tags - configure access to service endpoints |
| Configure VNet integration for dedicated platform as a service (PaaS) services | - configure App Service for regional VNet integration - configure Azure Kubernetes Service (AKS) for regional VNet integration - configure clients to access App Service Environment |
If you have experience in planning, applying, and maintaining Azure networking solutions, skilled in Azure administration, and you are proficient in hybrid networking, routing, security, connectivity, as well as private access to Azure services, then you are ready to prove your skills by passing the Microsoft AZ-700 exam. The exam testifies that you as an Azure Network Engineer are well-qualified in dealing with Azure networking solutions and competent enough in utilizing such methods as Azure CLI, Azure ARM templates, and PowerShell. In addition, you can deliver Azure solutions through communicating with cloud admins, app developers, security engineers, and DevOps engineers. Passing the exam earns you the Microsoft Certified: Azure Network Engineer Associate certification.
What is the exam cost of the Microsoft AZ-700 Exam
The cost of a Microsoft AZ-700 convention exam is $165 USD.
Reference: https://docs.microsoft.com/en-us/learn/certifications/exams/az-700
Exam Details for You to Know
Knowing more about the AZ-700 exam, its content falls into 5 parts. Each part is dedicated to a specific topic and checks definite skills. The first topic refers to the design, implementation, and managing hybrid networking. This implies that you possess skills to design, apply and operate a site-to-site VPN connection and a point-to-site VPN connection. Thus, you should be proficient in dealing with such concepts as a site-to-site VPN connection, VNet gateway, policy-based VPN, IPsec policy, local and virtual network gateways. In addition, your knowledge of how to plan RADIUS authentication, Open VPN authentication, Azure AD authentication will be checked. To add more, your skills in dealing with Azure ExpressRoute will be measured. So, be ready to demonstrate your ability to work with ExpressRoute SKU, ExpressRoute Global Reach, ExpressRoute FastPath, private and Microsoft peering.
The second topic focuses on the design and implementing core networking infrastructure. Here, you are expected to deal with private IP addressing for VNets, implementing name resolution, applying cross-VNet connectivity, and an Azure Virtual WAN architecture. In this domain, you should be capable of creating a VNet, configuring subnetting for services and Azure Route Server, creating subnet delegation, public and private DNS zones, and applying VNet peering. You also must be able to design an Azure Virtual WAN architecture, create a network virtual appliance, a hub in Virtual WAN, and a connection unit.
The third topic aims to check your skills in routing design and implementation. In this part, you will be tested on your ability to create, apply, and operate VNet routing, design and deal with an Azure Load Balancer, design and utilize Azure Application Gateway. In addition, you also should have the skills necessary to apply Azure Front Door and an Azure Traffic Manager profile, and create and apply an Azure Virtual Network NAT.
The fourth topic is centered on securing and monitoring networks. In this part, you should have skills to design, implement, operate an Azure Firewall deployment, implement and operate network security groups, WAF deployment. The potential candidates have to know how to monitor networks, including configuring network health alerts, using Traffic Analytics, configuring NSG flow logs and Azure Network Watcher.
The fifth topic aims to check your skills to design and implement private access to Azure Services. Here, your skills in using Azure Private Link service, Azure Private Endpoint, and service endpoints will be checked. You will need to demonstrate your ability to plan and create private endpoints, create a Private Link service, along with access to private endpoints. The following subtopic revolves around your expertise in configuring VNet integration for the given platform as a PaaS service. So, you should be experienced in how to configure App Service for regional VNet integration, create AKS, and access App Service Environment by configuring clients.
Microsoft AZ-700 Exam Overview:
| Certification Vendor: | Microsoft |
| Exam Name: | Designing and Implementing Microsoft Azure Networking Solutions |
| Exam Number: | AZ-700 |
| Exam Format: | Multiple choice, Multiple response, Case study, Drag and drop, Best answer |
| Real Exam Qty: | 40-60 |
| Passing Score: | 700/1000 |
| Certificate Validity Period: | 1 year |
| Available Languages: | English, Japanese, Simplified Chinese, Korean, German, French, Spanish, Portuguese (Brazil) |
| Exam Price: | $165 USD (varies by region) |
| Exam Duration: | 120 minutes |
| Related Certifications: | AZ-104 Microsoft Azure Administrator AZ-305 Azure Solutions Architect Expert |
| Recommended Training: | Microsoft Learn AZ-700 Learning Path Official Microsoft Azure Networking Documentation |
| Exam Registration: | Pearson VUE Microsoft Exams Microsoft AZ-700 Certification Page |
| Sample Questions: | Microsoft AZ-700 Sample Questions |
| Exam Way: | Online proctored or in-person test center (Pearson VUE) |
| Pre Condition: | No mandatory prerequisites. AZ-104 Microsoft Azure Administrator certification or equivalent knowledge is recommended. |
| Official Syllabus URL: | https://learn.microsoft.com/en-us/credentials/certifications/exams/az-700/ |

We're so confident of our products that we provide no hassle product exchange.


By Mamie


