dc dotCreds
Designing and Implementing Microsoft Azure Networking Solutions

AZ-700 Practice Test

Start today's 10-question AZ-700 set with source-backed review, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 150 Verified Questions

Questions updated at Jul 10, 2026, 12:01 AM CDT

Guided Course Included Learn AZ-700 step by step. Structured lessons, progress tracking, practice questions, and per-exam Course Notes covering every section in this bank.
Step-by-step lessons Per-exam Course Notes All sections included Practice tied to the same bank
AZ-700 icon

AZ-700

Designing and Implementing Microsoft Azure Networking Solutions

Why this page works

  • Daily exam-aligned questions
  • Source links on every explanation
  • Local progress saved automatically
  • Email sync path ready for later
  • Apps provide deeper drills when available
One-time unlock

Unlock the full AZ-700 bank

150 verified exam-style questions $4.99 one-time No subscription Secure checkout Instant unlock

Get the complete source-backed bank with correct-answer explanations, distractor breakdowns, saved review, full Course Mode, and per-exam Course Notes.

Instant unlock • Secure checkout • No subscription

Exam Mode Practice Mode Course Mode Course Notes Weak-area review Previous scores Source links Every choice explained No ads
See bundle and PDF options Already Pro? Open dashboard

Includes full Course Mode and Course Notes. We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice
Today's 10 AZ-700 questions

Use this AZ-700 practice test to review Designing and Implementing Microsoft Azure Networking Solutions. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

150 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Question 1 of 10
Objective 2.1 Design, implement, and manage connectivity services

A security team is reviewing the configuration of a site-to-site VPN connection between an on-premises network and an Azure virtual network. Which configuration element is crucial for defining the public IP address range used by the on-premises network to establish the VPN tunnel?

Concept tested: Design, implement, and manage connectivity services (2.1)
Question 2 of 10
Objective 1.3 Design and implement core networking infrastructure

A network administrator wants to enable name resolution between Azure virtual networks and on-premises resources. Which Azure DNS capability directly supports this requirement?

Concept tested: Design and implement core networking infrastructure (1.3)
Question 3 of 10
Objective 2.2 Design, implement, and manage connectivity services

A security team requires a VPN gateway capable of handling a minimum throughput of 1.2 Gbps and supporting 61,000 packets per second. Which VPN Gateway SKU fulfills these requirements?

Concept tested: Design, implement, and manage connectivity services (2.2)
Question 4 of 10
Objective 1.11 Design and implement core networking infrastructure

A network engineer is designing a solution to protect virtual network resources from DDoS attacks. Which of the following best describes how Azure DDoS Protection provides this protection?

Concept tested: Design and implement core networking infrastructure (1.11)
Question 5 of 10
Objective 2.1 Design, implement, and manage connectivity services

A network engineer is designing a site-to-site VPN connection between an on-premises network and an Azure virtual network. Which component is essential for defining the public IP address range used by the on-premises network to establish the VPN tunnel?

Concept tested: Design, implement, and manage connectivity services (2.1)
Question 6 of 10
Objective 1.7 Design and implement core networking infrastructure

A virtual network has a VPN gateway, and on-premises prefixes are propagated into the subnet route table. Which next hop type does Azure show for those learned on-premises routes?

Concept tested: Design and implement core networking infrastructure (1.7)
Question 7 of 10
Objective 2.1 Design, implement, and manage connectivity services

A company is establishing a site-to-site VPN connection between their on-premises network and an Azure virtual network. To ensure high availability and redundancy, which VPN Gateway configuration should be implemented?

Concept tested: Design, implement, and manage connectivity services (2.1)
Question 8 of 10
Objective 1.6 Design and implement core networking infrastructure

An organization requires connectivity between virtual networks across different Azure regions while enabling transit of traffic through a central virtual network. Which Azure networking feature directly supports this requirement?

Concept tested: Design and implement core networking infrastructure (1.6)
Question 9 of 10
Objective 2.1 Design, implement, and manage connectivity services

An organization requires a highly available site-to-site VPN connection between their on-premises network and Azure. Which Azure VPN Gateway configuration best ensures continued connectivity during maintenance or failures?

Concept tested: Design, implement, and manage connectivity services (2.1)
Question 10 of 10
Objective 1.5 Design and implement core networking infrastructure

A network architect is designing a solution using Azure DNS Private Resolver to manage DNS resolution for several virtual networks. To maximize flexibility and accommodate future growth, what is the maximum number of outbound endpoints that can be configured per DNS forwarding ruleset?

Concept tested: Design and implement core networking infrastructure (1.5)
Locked preview

You are viewing today’s free 10. Unlock 140 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
AZ-700 Pro $4.99 one-time

Pro mode for this exam includes the full bank, Practice Mode, Exam Mode, full Course Mode, and Course Notes.

50 Exam Practice Test $1.99 one-time

A 50-question AZ-700 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Azure Engineer Bundle $9.99 one-time

Unlock Pro mode for Azure fundamentals, administrator, architect, and network engineer practice in one purchase.

Pro mode forAZ-900, AZ-104, AZ-305, AZ-700
Microsoft Access $6.99/month

Unlock Pro mode across Microsoft, Azure, Power Platform, Copilot, and AI practice exams.

Pro mode includesMicrosoft certification practice banks, Azure, Power Platform, Copilot, and AI exams, Includes current and future Microsoft practice banks on dotCreds, Course Mode and Course Notes where available, PDF downloads sold separately where available

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full AZ-700 bank. No ads.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

150 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 140 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

No ads

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily AZ-700 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Official exam resources

Use these official Microsoft resources alongside the daily practice set. They cover the provider's own exam page, study guide, or prep material.

Need adjacent Microsoft practice pages too? Microsoft practice hub.

Source-backed answer review

The free daily AZ-700 set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A security team is reviewing the configuration of a site-to-site VPN connection between an on-premises network and an Azure virtual network. Which configuration element is crucial for defining the public IP address range used by the on-premises network to establish the VPN tunnel?

Answer choices

  1. A. Gateway Private IPs
  2. B. Active-Active Gateways
  3. C. VPN Gateway SKU
  4. D. Local Network Gateway

Correct answer

Local Network Gateway

The Local Network Gateway defines the public IP address range used by the on-premises network to establish the VPN tunnel. Gateway Private IPs are used for ExpressRoute private peering configurations, not VPN tunnels.

Wrong-answer review

  • A. Gateway Private IPs: Gateway Private IPs: Gateway Private IPs addresses a different Azure networking task; this scenario calls for a Local Network Gateway object that represents the on-premises VPN device and prefixes.
  • B. Active-Active Gateways: Active-Active Gateways: Active-Active Gateways addresses a different Azure networking task; this scenario calls for a Local Network Gateway object that represents the on-premises VPN device and prefixes.
  • C. VPN Gateway SKU: VPN Gateway SKU: This SKU does not match the throughput, redundancy, or connection requirement in the scenario.

Objective/domain: Design, implement, and manage connectivity services (2.1)

Source: About VPN Gateway configuration settings

Question 2 A network administrator wants to enable name resolution between Azure virtual networks and on-premises resources. Which Azure DNS capability directly supports this requirement?

Answer choices

  1. A. Private Link integration
  2. B. Enable name resolution between Azure and on-premises resources
  3. C. Public DNS zone management
  4. D. Autoregistration for VMs

Correct answer

Enable name resolution between Azure and on-premises resources

Objective/domain: Design and implement core networking infrastructure (1.3)

Source: What is Azure DNS?

Question 3 A security team requires a VPN gateway capable of handling a minimum throughput of 1.2 Gbps and supporting 61,000 packets per second. Which VPN Gateway SKU fulfills these requirements?

Answer choices

  1. A. VpnGw1
  2. B. VpnGw3
  3. C. VpnGw2
  4. D. VpnGw1AZ

Correct answer

VpnGw2

Objective/domain: Design, implement, and manage connectivity services (2.2)

Source: About VPN Gateway SKUs

Question 4 A network engineer is designing a solution to protect virtual network resources from DDoS attacks. Which of the following best describes how Azure DDoS Protection provides this protection?

Answer choices

  1. A. Azure DDoS Protection applies custom mitigation policies tailored to each individual resource.
  2. B. Azure DDoS Protection provides enhanced mitigation features through application design best practices alone.
  3. C. Azure DDoS Protection requires manual configuration of mitigation strategies for each virtual network.
  4. D. Azure DDoS Protection applies three auto-tuned mitigation policies (TCP SYN, TCP, and UDP) for each public IP.

Correct answer

Azure DDoS Protection applies three auto-tuned mitigation policies (TCP SYN, TCP, and UDP) for each public IP.

Objective/domain: Design and implement core networking infrastructure (1.11)

Source: Azure DDoS Protection overview

Question 5 A network engineer is designing a site-to-site VPN connection between an on-premises network and an Azure virtual network. Which component is essential for defining the public IP address range used by the on-premises network to establish the VPN tunnel?

Answer choices

  1. A. VPN Gateway
  2. B. Local Network Gateway
  3. C. Virtual Network Gateway
  4. D. ExpressRoute Private Peering

Correct answer

Local Network Gateway

Objective/domain: Design, implement, and manage connectivity services (2.1)

Source: About VPN Gateway configuration settings

Question 6 A virtual network has a VPN gateway, and on-premises prefixes are propagated into the subnet route table. Which next hop type does Azure show for those learned on-premises routes?

Answer choices

  1. A. Internet
  2. B. None
  3. C. Virtual network gateway
  4. D. Virtual network

Correct answer

Virtual network gateway

Objective/domain: Design and implement core networking infrastructure (1.7)

Source: Azure virtual network traffic routing

Question 7 A company is establishing a site-to-site VPN connection between their on-premises network and an Azure virtual network. To ensure high availability and redundancy, which VPN Gateway configuration should be implemented?

Answer choices

  1. A. A single VPN Gateway with a Basic SKU.
  2. B. A VPN Gateway with a VNet integration configured.
  3. C. An active-active gateway configuration with multiple VPN Gateways.
  4. D. A gateway with private IPs for ExpressRoute private peering.

Correct answer

An active-active gateway configuration with multiple VPN Gateways.

Objective/domain: Design, implement, and manage connectivity services (2.1)

Source: About VPN Gateway configuration settings

Question 8 An organization requires connectivity between virtual networks across different Azure regions while enabling transit of traffic through a central virtual network. Which Azure networking feature directly supports this requirement?

Answer choices

  1. A. Global virtual network peering
  2. B. Local virtual network peering
  3. C. ExpressRoute connectivity
  4. D. VPN gateway transit

Correct answer

Global virtual network peering

Objective/domain: Design and implement core networking infrastructure (1.6)

Source: Virtual network peering

Question 9 An organization requires a highly available site-to-site VPN connection between their on-premises network and Azure. Which Azure VPN Gateway configuration best ensures continued connectivity during maintenance or failures?

Answer choices

  1. A. An active-active gateway configuration with multiple VPN Gateways.
  2. B. A single VPN Gateway with a Basic SKU.
  3. C. A gateway configured with a single local network gateway.
  4. D. A VPN Gateway utilizing ExpressRoute private peering.

Correct answer

An active-active gateway configuration with multiple VPN Gateways.

Objective/domain: Design, implement, and manage connectivity services (2.1)

Source: About VPN Gateway configuration settings

Question 10 A network architect is designing a solution using Azure DNS Private Resolver to manage DNS resolution for several virtual networks. To maximize flexibility and accommodate future growth, what is the maximum number of outbound endpoints that can be configured per DNS forwarding ruleset?

Answer choices

  1. A. 5
  2. B. 1000
  3. C. 15
  4. D. 2

Correct answer

2

Objective/domain: Design and implement core networking infrastructure (1.5)

Source: What is Azure DNS Private Resolver?

Where to go after the daily web set

How are AZ-700 questions generated?

dotCreds builds AZ-700 practice questions from public exam objectives and Microsoft Learn and exam-objective references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start AZ-700 practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.

Why use the app when available?

The web page is the quick daily practice layer. If a dotCreds app is available for AZ-700, the app is better for larger banks, focused weak-domain drills, longer review sessions, and mobile study routines.