Skip to main content

Coverage matrix

This matrix maps every AZ-700 study guide objective (April 2026) to the challenge(s) that cover it.

Domain 1: Design and implement core networking infrastructure (25–30%)

Design and implement IP addressing for Azure resources

ObjectiveChallenge
Plan and implement network segmentation and address spaces01
Create a virtual network (VNet)01
Plan and configure subnetting for services (gateways, PE, SE, firewalls, App GW, Bastion)02
Plan and configure subnet delegation02
Plan and configure shared or dedicated subnets02
Create a prefix for public IP addresses01
Choose when to use a public IP address prefix01
Plan and implement a custom public IP address prefix (BYOIP)01
Create a public IP address01
Associate public IP addresses to resources01

Design and implement name resolution

ObjectiveChallenge
Design name resolution inside a VNet03, 04
Configure DNS settings for a VNet03, 04
Design public DNS zones03
Design private DNS zones04
Configure public and private DNS zones03, 04
Link a private DNS zone to a VNet04
Design and implement Azure DNS Private Resolver05

Design and implement VNet connectivity and routing

ObjectiveChallenge
Design service chaining, including gateway transit06
Implement VNet peering06
Implement and manage virtual network connectivity by using Azure Virtual Network Manager07
Design and implement user-defined routes (UDRs)08
Associate a route table with a subnet08
Configure forced tunneling08
Diagnose and resolve routing issues08, 11
Design and implement Azure Route Server09
Identify appropriate use cases for Azure NAT Gateway10
Implement Azure NAT Gateway10

Monitor networks

ObjectiveChallenge
Configure monitoring, network diagnostics, and logs in Azure Network Watcher11
Monitor and troubleshoot network health by using Azure Network Watcher11
Monitor and troubleshoot networks by using Azure Monitor for Networks12
Activate and monitor DDoS protection13
Evaluate network security recommendations (Defender for Cloud Secure Score)13
Evaluate network security recommendations (attack paths)13
Identify network resources by using Microsoft Defender for Cloud Security Explorer13

Domain 2: Design, implement, and manage connectivity services (20–25%)

Design, implement, and manage a site-to-site VPN connection

ObjectiveChallenge
Design a site-to-site VPN connection, including for high availability14, 15
Select an appropriate virtual network gateway SKU16
Implement a site-to-site VPN connection14
Identify when to use a policy-based VPN versus a route-based VPN16
Create and configure a local network gateway14
Create and configure an IPsec/IKE policy16
Create and configure a virtual network gateway14
Diagnose and resolve virtual network gateway connectivity issues24
Implement Azure Extended Network15

Design, implement, and manage a point-to-site VPN connection

ObjectiveChallenge
Select an appropriate virtual network gateway SKU for P2S17
Select and configure a tunnel type17
Select an appropriate authentication method18
Configure RADIUS authentication18
Configure authentication by using Microsoft Entra ID18
Implement a VPN client configuration file17
Diagnose and resolve client-side and authentication issues24
Specify Azure requirements for Always On VPN18
Specify Azure requirements for Azure Network Adapter17

Design, implement, and manage Azure ExpressRoute

ObjectiveChallenge
Select an ExpressRoute connectivity model19
Select an appropriate ExpressRoute SKU and tier19
Design and implement ExpressRoute (cross-region, redundancy, DR)19, 20
Design and implement ExpressRoute options (Global Reach, FastPath, Direct)20
Choose between Azure private peering only, Microsoft peering only, or both19, 21
Configure Azure private peering19
Configure Microsoft peering21
Create and configure an ExpressRoute gateway19
Connect a virtual network to an ExpressRoute circuit19
Recommend a route advertisement configuration21
Configure encryption over ExpressRoute21
Implement Bidirectional Forwarding Detection20
Diagnose and resolve ExpressRoute connection issues24

Design and implement an Azure Virtual WAN architecture

ObjectiveChallenge
Select a Virtual WAN SKU22
Design a Virtual WAN architecture22
Create a virtual hub in Virtual WAN22
Choose an appropriate scale unit for each gateway type22
Deploy a gateway into a virtual hub22
Configure virtual hub routing23
Integrate a virtual hub with a third-party NVA23

Domain 3: Design and implement application delivery services (15–20%)

Design and implement Azure Load Balancer and Azure Traffic Manager

ObjectiveChallenge
Map requirements to features and capabilities of Azure Load Balancer25
Identify appropriate use cases for Azure Load Balancer25, 33
Choose an Azure Load Balancer SKU and tier25
Choose between public and internal load balancers25
Choose between regional and cross-region load balancers26
Create and configure an Azure Load Balancer25
Implement Azure Traffic Manager27
Implement Gateway Load Balancer26
Implement a load balancing rule25
Create and configure inbound NAT rules25
Create and configure explicit outbound rules (SNAT)26

Design and implement Azure Application Gateway

ObjectiveChallenge
Map requirements to features and capabilities of Azure Application Gateway28, 33
Identify appropriate use cases for Azure Application Gateway28, 33
Choose between manual and autoscale30
Create a backend pool28
Configure health probes30
Configure listeners28
Configure routing rules28
Configure HTTP settings28
Configure TLS29
Configure rewrite rule sets29

Design and implement Azure Front Door

ObjectiveChallenge
Map requirements to features and capabilities of Azure Front Door31, 33
Identify appropriate use cases for Azure Front Door31, 33
Choose an appropriate tier31
Configure an Azure Front Door (routing, origins, endpoints)31
Configure TLS termination and end-to-end TLS encryption31
Configure caching31
Configure traffic acceleration31
Implement rules, URL rewrite, and URL redirect32
Secure an origin by using Azure Private Link in Azure Front Door32

Domain 4: Design and implement private access to Azure services (10–15%)

ObjectiveChallenge
Plan private endpoints34
Create private endpoints34, 35
Configure access to private endpoints34
Create a Private Link service36
Integrate Private Link and Private Endpoint with DNS34, 37
Integrate a Private Link service with on-premises clients37

Design and implement service endpoints

ObjectiveChallenge
Choose when to use a service endpoint38, 39
Create service endpoints38
Configure service endpoint policies38
Configure access to service endpoints38

Domain 5: Design and implement Azure network security services (15–20%)

Implement and manage network security groups

ObjectiveChallenge
Create a network security group (NSG)40
Associate a NSG to a resource40
Create an application security group (ASG)40
Associate an ASG to a network interface40
Create and configure NSG inbound and outbound security rules40
Implement virtual network flow logs41
Interpret virtual network flow logs41
Verify IP flow41
Configure an NSG for remote server administration (Azure Bastion)41
Implement and manage virtual network security by using Azure Virtual Network Manager48

Design and implement Azure Firewall and Azure Firewall Manager

ObjectiveChallenge
Map requirements to features and capabilities of Azure Firewall42
Select an appropriate Azure Firewall SKU43
Design an Azure Firewall deployment42
Create and implement an Azure Firewall deployment42
Configure Azure Firewall rules42
Create and implement Azure Firewall Manager policies43
Create a secure hub by deploying Azure Firewall inside a Virtual WAN hub44

Design and implement a Web Application Firewall (WAF) deployment

ObjectiveChallenge
Map requirements to features and capabilities of WAF45, 46
Design a WAF deployment45
Configure detection or prevention mode45
Configure rule sets for WAF on Azure Front Door46
Configure rule sets for WAF on Application Gateway45
Implement a WAF policy45, 46
Associate a WAF policy45, 46

Coverage: 100% — Every objective from the official AZ-700 study guide (April 2026) is mapped to at least one challenge.