Azure Virtual Network Design
This module covers the core components of Azure virtual networking.
Topics include:
- Designing Azure Virtual Networks
- Creating and configuring subnets
- IP address planning
- Public IP addresses
- Private IP addresses
- Azure DNS
- Custom DNS
- Name resolution
- Virtual Network Peering
- Routing
- Route tables
- Azure Virtual Network NAT
Participants learn how to design address spaces and subnet structures for different workload requirements.
Hybrid Networking
This module focuses on connectivity between Azure and on-premises environments.
Topics include:
- Site-to-Site VPN
- Point-to-Site VPN
- Certificate-based authentication
- RADIUS-based authentication
- Azure Virtual WAN
- Virtual hubs
- Hybrid connectivity architecture
- Network Virtual Appliances
- NVA integration
Learners compare approaches for connecting branch offices, data centres, and remote users to Azure.
ExpressRoute Deployment
This module examines private and dedicated connectivity to Azure.
Topics include:
- ExpressRoute planning
- ExpressRoute circuit deployment
- Private peering
- Microsoft peering
- ExpressRoute Global Reach
- ExpressRoute FastPath
- Performance considerations
- ExpressRoute troubleshooting
Participants evaluate use cases in which ExpressRoute offers advantages over internet-based connectivity.
Load Balancing Non-HTTP(S) Traffic
This section focuses on balancing TCP and UDP traffic.
Topics include:
- Azure Load Balancer
- Internal Load Balancer
- External Load Balancer
- Backend pools
- Health probes
- Load balancing rules
- Azure Traffic Manager
- DNS-based load balancing
Participants compare regional and global traffic distribution approaches.
Load Balancing HTTP(S) Traffic
This module focuses on application delivery services for web workloads.
Topics include:
- Azure Application Gateway
- Layer 7 load balancing
- Web Application Firewall
- WAF policies
- Azure Front Door
- Global HTTP(S) load balancing
- Failover
- Application acceleration
Learners evaluate which services are appropriate for internal, regional, and global web traffic.
Network Security
This module examines controls used to protect Azure networks.
Topics include:
- Network Security Groups
- NSG rules
- Inbound and outbound security
- Azure Firewall
- Firewall Policies
- Azure Firewall Manager
- Azure DDoS Protection
- Web Application Firewall
- Application protection
- Network segmentation
Participants learn how multiple layers of network security can be combined to protect Azure workloads.
Private Access to Azure Services
This module focuses on providing private connectivity to Azure platform services.
Topics include:
- Service Endpoints
- Azure Private Link
- Private Endpoints
- Azure DNS integration
- Custom DNS integration
- Private endpoint name resolution
- Restricting public access
- Private connectivity to Azure services
Participants learn how to reduce internet exposure and provide controlled access to cloud services.
Network Monitoring and Diagnostics
This module covers monitoring and troubleshooting Azure networking environments.
Topics include:
- Azure Monitor
- Network Watcher
- Network diagnostics
- NSG Flow Logs
- Traffic Analytics
- Connection Monitor
- Connectivity monitoring
- Network metrics
- Diagnostic logs
- Performance analysis
Learners develop the skills to identify connectivity issues, investigate traffic flows, and monitor overall network health.
Exams and Assessments
This course supports learners preparing for the Microsoft Certified: Azure Network Engineer Associate certification.
The associated exam is:
AZ-700: Designing and Implementing Microsoft Azure Networking Solutions
The exam is not included with the course and must be booked separately.
There are no formal examinations or assessments included in the programme.
Learning is reinforced through:
- Scenario-based exercises
- Guided labs
- Architecture design activities
- Network troubleshooting exercises
- Knowledge checks