CloudExamCheap

AZ-700 Practice Exam: Azure Network Engineer Associate

224 questions · 120 min timed mode · Microsoft Azure · Updated 2026

VNets, ExpressRoute, Front Door, firewalls — Azure networking without the packet-loss nightmares.

What you'll be tested on

Sample AZ-700 questions

Your company has a single on-premises datacenter in Washington DC. The East US Azure region has a peering location in Washington DC. The company only has Azure resources in the East US region. You need to implement ExpressRoute to support up to 1 Gbps. You must use only ExpressRoute Unlimited data plans. The solution must minimize costs. Which type of ExpressRoute circuits should you create?
  1. ExpressRoute Local
  2. ExpressRoute Direct
  3. ExpressRoute Premium
  4. ExpressRoute Standard
Show answerA — ExpressRoute Local
ExpressRoute Local is correct. The Local SKU is the cheapest ExpressRoute option and is available only when the peering location (Washington DC) is in the same metro as the target Azure region (East US), which matches this scenario exactly. Local supports up to 1 Gbps circuits and includes unlimited data transfer by default. Standard costs more and would also work with an Unlimited data plan, but it is not the minimum-cost choice. Premium adds global connectivity that is unnecessary here. ExpressRoute Direct provides dedicated 10 or 100 Gbps physical ports, which far exceeds the requirement.
You are planning an Azure Point-to-Site (P2S) VPN that will use OpenVPN. Users will authenticate by an on-premises Active Directory domain. Which additional service should you deploy to support the VPN authentication?
  1. an Azure key vault
  2. a RADIUS server
  3. a certification authority
  4. Azure Active Directory (Azure AD) Application Proxy
Show answerB — a RADIUS server
A RADIUS server is correct. When a Point-to-Site VPN uses OpenVPN and users must authenticate against an on-premises Active Directory domain, the VPN gateway supports RADIUS authentication. You deploy a RADIUS server (typically NPS) that integrates with the on-premises AD domain and point the gateway at it. A certification authority is only needed for certificate-based authentication, not AD username and password. Azure Key Vault stores certificates and secrets but performs no authentication. Azure AD Application Proxy publishes on-premises web apps and has no role in VPN authentication.
You fail to establish a Site-to-Site VPN connection between your company's main office and an Azure virtual network. You need to troubleshoot what prevents you from establishing the IPsec tunnel. Which diagnostic log should you review?
  1. IKEDiagnosticLog
  2. RouteDiagnosticLog
  3. GatewayDiagnosticLog
  4. TunnelDiagnosticLog
Show answerA — IKEDiagnosticLog
IKEDiagnosticLog is correct. This diagnostic log on the VPN gateway records detailed IKE and IPsec negotiation events, including proposal mismatches, pre-shared key errors, and peer reachability failures, which is exactly the data needed when an IPsec tunnel cannot be established. RouteDiagnosticLog captures BGP route advertisement information and is useful after the tunnel is up. GatewayDiagnosticLog records gateway configuration events. TunnelDiagnosticLog logs tunnel state changes and statistics such as disconnect reasons, but IKE-level handshake failures during tunnel setup are diagnosed in IKEDiagnosticLog.

Access plans

AccessPrice
3 months$8.99$3.99
1 year$14.99$8.99
Lifetime$24.99$14.99
Practice AZ-700 now →
Free preview inside — try 5 questions before you pay anything.

FAQ

How many practice questions are in this AZ-700 bank?
224 questions covering the current AZ-700 Azure Network Engineer Associate syllabus, every one with the correct answer and an explanation.
How long is the real AZ-700 exam?
The official AZ-700 exam gives you 120 minutes. Our timed exam mode uses the same limit so the pace feels familiar.
What does AZ-700 access cost?
Plans start at $3.99 for 3 months. One payment, no subscription — and far cheaper than retaking the real exam.