dc dotCreds
Microsoft Azure Network Engineer Associate (AZ-700)

AZ-700 Practice Test

Work through a fresh 10-question AZ-700 set every day from the same verified live bank used by the app, with exact source links and a countdown to the next rotation.

10 daily web questions Source-backed explanations 7-day score history Questions updated at Jun 22, 2026, 1:01 PM CDT
AZ-700 icon

AZ-700

Microsoft Azure Network Engineer Associate (AZ-700)

Why this page works

  • Daily exam-aligned questions
  • Source links on every explanation
  • Local progress saved automatically
  • Email sync path ready for later
  • Apps provide deeper drills when available
One-time unlock

Unlock the full AZ-700 bank

Get 150 verified questions, every choice explained, Exam Mode, Practice Mode, random tests, readiness tracking, previous scores, and no ads.

Secure checkout by Stripe. Instant unlock on this page. No subscription.

See bundle and PDF options Already Pro? Open dashboard

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Free AZ-700 practice questions

The website gives you a real daily 10-question AZ-700 set with explanations and source links. If you want the full bank, weak-domain targeting, readiness tracking, and longer tests, use the app.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

150 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Question 1 of 10
Objective 1.9 Design and implement core networking infrastructure

To enable both IPv4 and IPv6 outbound connectivity for subnets within a virtual network, which approach is recommended?

Concept tested: Design and implement core networking infrastructure (1.9)
Question 2 of 10
Objective 2.2 Design, implement, and manage connectivity services

An organization requires a VPN gateway with a minimum throughput of 700 Mbps per tunnel and supports approximately 66,000 packets per second. Which VPN Gateway SKU best meets these requirements?

Concept tested: Design, implement, and manage connectivity services (2.2)
Question 3 of 10
Objective 1.6 Design and implement core networking infrastructure

An organization requires connectivity between virtual networks across different Azure regions while enabling transit of traffic through a central virtual network. Which Azure networking feature directly supports this requirement?

Concept tested: Design and implement core networking infrastructure (1.6)
Question 4 of 10
Objective 2.1 Design, implement, and manage connectivity services

A network engineer is designing a site-to-site VPN connection between an on-premises network and an Azure virtual network. Which component is essential for defining the public IP address range used by the on-premises network to establish the VPN tunnel?

Concept tested: Design, implement, and manage connectivity services (2.1)
Question 5 of 10
Objective 1.8 Design and implement core networking infrastructure

What is the primary benefit of utilizing Azure Route Server for network routing?

Concept tested: Design and implement core networking infrastructure (1.8)
Question 6 of 10
Objective 2.2 Design, implement, and manage connectivity services

A security team requires a VPN gateway capable of handling a minimum throughput of 1.2 Gbps and supporting 61,000 packets per second. Which VPN Gateway SKU fulfills these requirements?

Concept tested: Design, implement, and manage connectivity services (2.2)
Question 7 of 10
Objective 1.4 Design and implement core networking infrastructure

A virtual network requires automatic DNS record updates when virtual machines are created and deleted. How is this functionality achieved?

Concept tested: Design and implement core networking infrastructure (1.4)
Question 8 of 10
Objective 2.1 Design, implement, and manage connectivity services

A company is establishing a site-to-site VPN connection between their on-premises network and an Azure virtual network. To ensure high availability and redundancy, which VPN Gateway configuration should be implemented?

Concept tested: Design, implement, and manage connectivity services (2.1)
Question 9 of 10
Objective 1.7 Design and implement core networking infrastructure

During troubleshooting of outbound connectivity issues from a subnet, a network engineer observes traffic is not reaching an on-premises destination. Which of the following best describes the 'Next Hop Type' associated with a user-defined route (UDR) designed to direct traffic to that on-premises network?

Concept tested: Design and implement core networking infrastructure (1.7)
Question 10 of 10
Objective 2.1 Design, implement, and manage connectivity services

A security team is reviewing the configuration of a site-to-site VPN connection between an on-premises network and an Azure virtual network. Which configuration element is crucial for defining the public IP address range used by the on-premises network to establish the VPN tunnel?

Concept tested: Design, implement, and manage connectivity services (2.1)
Locked preview

You are viewing today’s free 10. Unlock 140 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
AZ-700 Pro $4.99 one-time

Best if you only need this one certification.

Azure Engineer Bundle $9.99 one-time

Azure fundamentals, administrator, architect, and network engineer practice in one unlock. Best for learners moving from Azure beginner to cloud engineer / architect roles.

What’s includedAZ-900, AZ-104, AZ-305, AZ-700
Microsoft Access $6.99/month

Unlock Microsoft, Azure, Power Platform, Copilot, and AI practice exams.

Why it fitsUnlock Microsoft, Azure, Power Platform, Copilot, and AI practice exams, Includes current and future Microsoft practice banks on dotCreds, Best for learners taking more than one Microsoft exam, PDF downloads sold separately where available

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full AZ-700 bank. No ads.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

150 full-bank questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 140 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

No ads

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily AZ-700 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Official exam resources

Use these official Microsoft resources alongside the daily practice set. They cover the provider's own exam page, study guide, or prep material.

Need adjacent Microsoft practice pages too? Microsoft practice hub.

Source-backed answer review

The free daily AZ-700 set includes crawlable question text, answer choices, the correct answer explanation, wrong-answer distractor explanations when the reviewed bank provides them, objective mapping, and source links. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 To enable both IPv4 and IPv6 outbound connectivity for subnets within a virtual network, which approach is recommended?

Answer choices

  1. A. Azure Firewall configured with SNAT port allocation
  2. B. A StandardV2 NAT gateway configured with a public IP prefix
  3. C. Load balancer outbound rules for both IPv4 and IPv6 traffic
  4. D. A Standard NAT gateway for IPv4 traffic and load balancer outbound rules for IPv6 traffic

Correct answer

A Standard NAT gateway for IPv4 traffic and load balancer outbound rules for IPv6 traffic

Correct answer: A Standard NAT gateway for IPv4 traffic and load balancer outbound rules for IPv6 traffic. The excerpt explicitly states that to support both IPv4 and IPv6 outbound connectivity, you can use a Standard NAT gateway for IPv4 and load balancer outbound rules for IPv6. Azure Firewall provides outbound connectivity, but it is not the recommended solution for IPv6 traffic in this scenario.

Objective/domain: Design and implement core networking infrastructure (1.9)

Source: What is Azure NAT Gateway?

Question 2 An organization requires a VPN gateway with a minimum throughput of 700 Mbps per tunnel and supports approximately 66,000 packets per second. Which VPN Gateway SKU best meets these requirements?

Answer choices

  1. A. VpnGw3
  2. B. VpnGw2
  3. C. VpnGw1
  4. D. VpnGw1AZ

Correct answer

VpnGw3

The VpnGw3 SKU provides a throughput of 700 Mbps and supports 66,000 packets per second, aligning with the stated requirements. While VpnGw1AZ also supports 66,000 packets per second, it only offers a throughput of 650 Mbps, which is below the minimum requirement.

Objective/domain: Design, implement, and manage connectivity services (2.2)

Source: About VPN Gateway SKUs

Question 3 An organization requires connectivity between virtual networks across different Azure regions while enabling transit of traffic through a central virtual network. Which Azure networking feature directly supports this requirement?

Answer choices

  1. A. Global virtual network peering
  2. B. Local virtual network peering
  3. C. ExpressRoute connectivity
  4. D. VPN gateway transit

Correct answer

Global virtual network peering

Global virtual network peering enables connectivity across regions and supports gateway transit, fulfilling the organization's needs. Local peering only connects virtual networks within the same region, and while ExpressRoute and VPN gateways provide connectivity, they don't inherently offer the transit functionality of global peering.

Objective/domain: Design and implement core networking infrastructure (1.6)

Source: Virtual network peering

Question 4 A network engineer is designing a site-to-site VPN connection between an on-premises network and an Azure virtual network. Which component is essential for defining the public IP address range used by the on-premises network to establish the VPN tunnel?

Answer choices

  1. A. VPN Gateway
  2. B. Local Network Gateway
  3. C. Virtual Network Gateway
  4. D. ExpressRoute Private Peering

Correct answer

Local Network Gateway

The Local Network Gateway defines the public IP address space of the on-premises network, enabling the VPN Gateway to establish a connection. ExpressRoute Private Peering is used for different connectivity scenarios, not site-to-site VPNs.

Objective/domain: Design, implement, and manage connectivity services (2.1)

Source: About VPN Gateway configuration settings

Question 5 What is the primary benefit of utilizing Azure Route Server for network routing?

Answer choices

  1. A. Enforcing strict network security policies.
  2. B. Accelerating internet-bound traffic.
  3. C. Providing centralized network address translation (NAT).
  4. D. Simplifying route table management and maintenance.

Correct answer

Simplifying route table management and maintenance.

Correct answer: Simplifying route table management and maintenance.. Azure Route Server simplifies route table management by automating the exchange of routes and reducing manual configuration. NAT is a separate function handled by devices like Azure Firewall, not Route Server.

Objective/domain: Design and implement core networking infrastructure (1.8)

Source: What is Azure Route Server?

Question 6 A security team requires a VPN gateway capable of handling a minimum throughput of 1.2 Gbps and supporting 61,000 packets per second. Which VPN Gateway SKU fulfills these requirements?

Answer choices

  1. A. VpnGw1
  2. B. VpnGw3
  3. C. VpnGw2
  4. D. VpnGw1AZ

Correct answer

VpnGw2

The VpnGw2 SKU provides a throughput of 1.2 Gbps and supports 61,000 packets per second, meeting the specified requirements. While VpnGw3 also offers 1.2 Gbps throughput, it supports a higher packet rate of 66,000, making VpnGw2 the more appropriate choice for this scenario.

Objective/domain: Design, implement, and manage connectivity services (2.2)

Source: About VPN Gateway SKUs

Question 7 A virtual network requires automatic DNS record updates when virtual machines are created and deleted. How is this functionality achieved?

Answer choices

  1. A. Configuring a network security group (NSG) rule to manage DNS traffic.
  2. B. Linking the virtual network to a private zone with autoregistration enabled.
  3. C. Implementing a custom script to modify DNS records in a public zone.
  4. D. Creating a virtual network peering connection to a different virtual network.

Correct answer

Linking the virtual network to a private zone with autoregistration enabled.

Correct answer: Linking the virtual network to a private zone with autoregistration enabled.. Linking a virtual network to a private zone with autoregistration enabled automatically registers virtual machines and removes their DNS records upon deletion. Network security groups control network traffic, not DNS record management, and custom scripts would be complex and error-prone.

Objective/domain: Design and implement core networking infrastructure (1.4)

Source: What is Azure Private DNS?

Question 8 A company is establishing a site-to-site VPN connection between their on-premises network and an Azure virtual network. To ensure high availability and redundancy, which VPN Gateway configuration should be implemented?

Answer choices

  1. A. A single VPN Gateway with a Basic SKU.
  2. B. A VPN Gateway with a VNet integration configured.
  3. C. An active-active gateway configuration with multiple VPN Gateways.
  4. D. A gateway with private IPs for ExpressRoute private peering.

Correct answer

An active-active gateway configuration with multiple VPN Gateways.

Correct answer: An active-active gateway configuration with multiple VPN Gateways.. An active-active gateway configuration provides redundancy by utilizing multiple VPN Gateways, ensuring connectivity even if one gateway fails. While ExpressRoute private peering utilizes gateways, it's not the primary solution for high availability in a site-to-site VPN scenario.

Objective/domain: Design, implement, and manage connectivity services (2.1)

Source: About VPN Gateway configuration settings

Question 9 During troubleshooting of outbound connectivity issues from a subnet, a network engineer observes traffic is not reaching an on-premises destination. Which of the following best describes the 'Next Hop Type' associated with a user-defined route (UDR) designed to direct traffic to that on-premises network?

Answer choices

  1. A. Internet
  2. B. None
  3. C. Virtual network
  4. D. Default

Correct answer

Virtual network

Correct answer: Virtual network. User-defined routes allow you to specify a custom next hop for traffic, often directing it to a virtual appliance or VPN gateway for on-premises connectivity. 'None' is used for system routes that use the default Azure infrastructure, not custom UDRs.

Objective/domain: Design and implement core networking infrastructure (1.7)

Source: Virtual network traffic routing

Question 10 A security team is reviewing the configuration of a site-to-site VPN connection between an on-premises network and an Azure virtual network. Which configuration element is crucial for defining the public IP address range used by the on-premises network to establish the VPN tunnel?

Answer choices

  1. A. Gateway Private IPs
  2. B. Active-Active Gateways
  3. C. VPN Gateway SKU
  4. D. Local Network Gateway

Correct answer

Local Network Gateway

The Local Network Gateway defines the public IP address range used by the on-premises network to establish the VPN tunnel. Gateway Private IPs are used for ExpressRoute private peering configurations, not VPN tunnels.

Objective/domain: Design, implement, and manage connectivity services (2.1)

Source: About VPN Gateway configuration settings

Where to go after the daily web set

How are AZ-700 questions generated?

dotCreds builds AZ-700 practice questions from public exam objectives and Microsoft Learn and exam-objective references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start AZ-700 practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.

Why use the app when available?

The web page is the quick daily practice layer. If a dotCreds app is available for AZ-700, the app is better for larger banks, focused weak-domain drills, longer review sessions, and mobile study routines.