Microsoft Azure Network Engineer Associate Certification

Certification guide

The AZ-700 is Microsoft’s associate-level networking specialty for engineers running the network side of Azure. Passing it earns the Microsoft Certified: Azure Network Engineer Associate credential and validates that you can design, implement, and manage Azure networking end-to-end: core VNet infrastructure, hybrid connectivity, application delivery, private access, and network security.

It sits one level above AZ-104 in Microsoft’s Azure path. The AZ-104 asks whether you can operate a subscription and know that a VNet is a thing; AZ-700 asks whether you can actually build the network — subnet planning that reserves the right five addresses, gateway transit that flows the right direction, DNS zones linked to the right VNets, ExpressRoute peering that carries the right traffic, and firewalls that inspect the right hops.

Exam · AZ-700 Level · Associate Questions · 40–60 typical Time · ~100 min Pass · 700 / 1000 Cost · $165 USD

The exam mixes multiple choice, multiple response, drag-and-drop, and case studies, and some sittings include hands-on portal labs where you configure a resource inside a real Azure interface. Microsoft no longer publishes a fixed question count or time limit, so the numbers above are the ranges most candidates encounter. There are no formal prerequisites, but AZ-104 or equivalent hands-on Azure experience is strongly assumed — a candidate who can’t navigate the portal will spend half the exam learning basics instead of demonstrating networking skill.

Microsoft last updated the skills-measured list on April 24, 2026 with minor refinements across all five domains — no weightings shifted, no domains were added or removed. Materials aligned to the current outline remain valid.

Design and implement core networking infrastructure

Domain 1 · 25–30%

The largest domain and the foundation for everything else. Covers IP addressing and subnet planning (including the five reserved IPs per subnet, subnet delegation for services like SQL Managed Instance, and public IP prefixes including BYOIP); DNS design across public and private zones with virtual network links and the DNS Private Resolver for hybrid resolution; VNet connectivity through peering, gateway transit, service chaining, and user-defined routes; the Azure Route Server for dynamic route exchange with NVAs; NAT Gateway for outbound SNAT; and network monitoring through Network Watcher, Azure Monitor for Networks, DDoS Protection, and Defender for Cloud.

Design, implement, and manage connectivity services

Domain 2 · 20–25%

Hybrid connectivity — where most enterprise design decisions actually get made. Site-to-site VPN configuration including active-active vs active-standby, policy-based vs route-based tunnels, VPN gateway SKU sizing, and local network gateway setup. Point-to-site VPN with the OpenVPN / IKEv2 / SSTP trade-offs and authentication choices spanning certificates, RADIUS, and Microsoft Entra ID. ExpressRoute end-to-end: circuit models, SKUs and tiers, private vs Microsoft peering, and options like Global Reach, FastPath, ExpressRoute Direct, and encryption over the circuit. Azure Virtual WAN as the managed hub-and-spoke transit fabric with routing intent, secured hubs, and any-to-any connectivity.

Design and implement application delivery services

Domain 3 · 15–20%

The layer-4 and layer-7 traffic distribution stack. Azure Load Balancer at layer 4 — Standard SKU features, HA ports, zone redundancy, internal vs public frontends, cross-region load balancing, inbound NAT rules, and explicit outbound SNAT rules. Azure Application Gateway at layer 7 within a region — backend pools, health probes, path- and host-based routing, TLS termination and re-encryption, and rewrite rules. Azure Front Door at the global edge — Standard vs Premium tiers, routing rules, caching, TLS termination end-to-end, and Private Link origins so a global service can front a private backend. Traffic Manager rounds out the picture as the DNS-layer global router.

Design and implement private access to Azure services

Domain 4 · 10–15%

The smallest domain by weight but heavily concept-tested. Private endpoints assign a private IP inside your VNet to a PaaS resource, disable the public endpoint, and — critically — depend on a linked Private DNS zone (like privatelink.database.windows.net) to resolve the resource’s FQDN to that private IP. Private Link service is the provider side: publish a workload behind a Standard internal Load Balancer so customer VNets can connect via their own private endpoint, controlled by visibility and auto-approval lists. Service endpoints are the older, lighter alternative — traffic stays destined to the public IP but takes an optimized backbone path, and can be scoped further with service endpoint policies. Knowing exactly when each option fits (and specifically what fails with the other) is where the exam scores you.

Design and implement Azure network security services

Domain 5 · 15–20%

Network Security Groups with rule priority evaluation, application security groups for tag-based grouping, virtual network flow logs, IP Flow Verify, and effective security rules for troubleshooting. Azure Virtual Network Manager’s security admin rules that evaluate before NSGs and cannot be overridden by workload owners — the enterprise-scale enforcement layer. Azure Firewall in Basic, Standard, and Premium SKUs, with the Premium features (TLS inspection, IDPS, URL filtering, web categories) called out separately, alongside DNAT rule design and Firewall Manager for hierarchical policy across multiple firewalls. Web Application Firewall on both Application Gateway (regional, deeper session features) and Front Door (global edge filtering), with detection vs prevention mode, custom rules, and exclusions for false positives.

The passing score is 700 on a 1000-point scaled scale — not a raw 70%. Microsoft applies statistical scaling per form so a set of harder questions is worth more per correct answer than an easier set. Practice at a 70% raw-score bar is the honest equivalent — enough to prove you’re not passing on luck when the exam serves you a hard form, but tight enough that you feel the pressure. The exam uses a compensatory model, so strong performance in the heavier domains can offset weaker showings elsewhere; you don’t need to pass each domain individually.

Microsoft Azure Network Engineer Associate — Practice Exam

Comprehensive practice bank for the AZ-700 Microsoft Azure Network Engineer Associate certification exam. Questions are weighted to the official exam domain distribution (Core Networking 27.5%, Connectivity…

65 questions 100 min pass 70%
Subscribe to start

Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by Microsoft Corporation. “Microsoft,” “Azure,” “Microsoft Certified,” and “Azure Network Engineer Associate” are trademarks of Microsoft Corporation. AZ-700 is Microsoft’s exam code for the Designing and Implementing Microsoft Azure Networking Solutions exam and is used here nominatively to identify the certification these study materials are designed to prepare candidates for.

All questions, explanations, and study content on Certifym.net are original works authored by Certifym Exam Services, LLC. Nothing on this site is drawn from actual exam content, from Microsoft’s official practice assessment, or from any third-party question bank. Blueprint domain names and weightings referenced above are cited from Microsoft’s publicly published exam skills outline.