Microsoft has launched the New Azure AZ-720: Troubleshooting Microsoft Azure Connectivity Exam for candidates to get familiar with networking and hybrid settings, as well as routing, permissions, and account restrictions. The Az-720 exam focuses on developing skills and the ability to detect problems with business continuity, hybrid environments, Infrastructure as a Service (IaaS), Platform as a Service (PaaS), access control, networking, and virtual machine connection using readily available tools is required for the exam.
Microsoft AZ-720: Knowledge Required
Candidates for the Azure Support Engineer for Connectivity Specialty certification are support engineers who have subject matter expertise in using advanced troubleshooting methods to resolve networking and connectivity issues in Azure. Second, professionals in this field are capable of troubleshooting issues with Azure Virtual Machines, virtual networks, and hybrid connections between on-premises and Azure services. They use a variety of methods and technology to diagnose and uncover the root causes of complex situations.
Exam Details
- The Microsoft AZ-720 exam contains 40-60 questions.
- On the Microsoft AZ-720, questions can be scenario-based single-answer, or multiple-choice.
- Multiple-choice questions that must be answered in the correct order
- drag-and-drop questions
- review of grades
- dragging and dropping
To pass the exam, however, a candidate must obtain a score of 700 or higher. Furthermore, the exam is only available in English and costs $165 USD.
Exam Course Outline
To assist in better preparation for the AZ-720 exam, Microsoft provides a course outline that covers the major sections. This includes the following:
1. Troubleshoot business continuity issues (5–10%)
Troubleshoot backup issues
- review and interpret backup logs – https://docs.microsoft.com/en-us/azure/backup/backup-azure-vms-troubleshoot
- troubleshoot Azure virtual machines backup issues including restarting a failed backup job – https://docs.microsoft.com/en-us/azure/backup/backup-azure-mars-troubleshoot
- troubleshoot issues with Azure Backup agents – https://docs.microsoft.com/en-us/azure/backup/backup-azure-mars-troubleshoot
- troubleshooting Azure Backup Server issues – https://docs.microsoft.com/en-us/azure/backup/backup-azure-mabs-troubleshoot
- checking scheduled backups – https://docs.microsoft.com/en-us/azure/backup/backup-azure-vms-troubleshoot
Check recovery issues
- troubleshooting Azure Site Recovery issues – https://docs.microsoft.com/en-us/troubleshoot/azure/site-recovery/troubleshoot-azure-recovery-services
- check site recovery in hybrid scenarios that include Hyper-V, VMware ESX, or System Center Configuration, Manager – https://docs.microsoft.com/en-us/azure/site-recovery/vmware-azure-troubleshoot-replication, https://docs.microsoft.com/en-us/azure/site-recovery/hyper-v-azure-troubleshoot
- troubleshooting restore issues when using Azure Backup Agent, Azure backup, or Azure Backup Server – https://docs.microsoft.com/en-us/azure/backup/backup-azure-vm-file-recovery-troubleshoot, https://docs.microsoft.com/en-us/azure/backup/backup-azure-vms-troubleshoot#restore
- check issues recovering files from an Azure virtual machine backup – https://docs.microsoft.com/en-us/azure/backup/backup-azure-vm-file-recovery-troubleshoot
2. Troubleshoot hybrid and cloud connectivity issues (20–25%)
Troubleshooting virtual network (VNet) connectivity
- troubleshooting virtual private network (VPN) gateway transit issues – https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/hybrid-networking/troubleshoot-vpn
- Also, check hub-and-spoke VNet configuration issues – https://docs.microsoft.com/en-us/azure/network-watcher/diagnose-vm-network-routing-problem
- furthermore, troubleshooting global VNet peering connectivity issues – https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-peering-overview#requirements-and-constraints
- moreover, check peered connections – https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-troubleshoot-peering-issues
Troubleshooting name resolution issues
- check name resolution for scenarios that use Azure-provided name resolution – https://docs.microsoft.com/en-us/azure/virtual-network/monitor-virtual-network
- also, troubleshoot name resolution for scenarios that use custom DNS servers – https://docs.microsoft.com/en-us/windows-server/networking/dns/troubleshoot/troubleshoot-dns-server
- furthermore, review and interpret DNS audit logs – https://docs.microsoft.com/en-us/azure/dns/dns-alerts-metrics
- moreover, troubleshooting name resolution for Azure private DNS zones – https://docs.microsoft.com/en-us/azure/private-link/troubleshoot-private-endpoint-connectivity
- also, check issues with DNS records at public DNS providers – https://www.pcwdld.com/nslookup-dns-records
- furthermore, diagnose domain delegation issues – https://support.microsoft.com/en-us/topic/kerberos-authentication-and-troubleshooting-delegation-issues-f4279b52-72d5-55af-f445-cc9fb16e9550
Troubleshoot point-to-site virtual private network (VPN) connectivity
- troubleshoot Windows VPN client configuration issues – https://docs.microsoft.com/en-us/troubleshoot/windows-client/networking/l2tp-ipsec-vpn-client-connection-issue
- also, check OpenVPN VPN client configuration issues
- furthermore, troubleshoot macOS VPN client configuration issues
- moreover, troubleshooting issues with certificate-based VPN connections – https://docs.microsoft.com/en-us/windows-server/remote/remote-access/vpn/always-on-vpn/deploy/always-on-vpn-deploy-troubleshooting
- also, check issues with RADIUS-based VPN connections – https://docs.microsoft.com/en-us/windows-server/remote/remote-access/ras/otp/configure/step-2-configure-the-radius-server, https://docs.microsoft.com/en-us/windows-server/remote/remote-access/vpn/always-on-vpn/deploy/always-on-vpn-deploy-troubleshooting
- furthermore, troubleshooting Azure Active Directory (Azure AD) authentication issues – https://docs.microsoft.com/en-us/azure/active-directory/hybrid/tshoot-connect-password-hash-synchronization, https://docs.microsoft.com/en-us/azure/active-directory/hybrid/tshoot-connect-pass-through-authentication, https://docs.microsoft.com/en-us/azure/active-directory/hybrid/tshoot-connect-connectivity
Troubleshooting site-to-site virtual private network connectivity
- review and interpret network logs and captured network traffic from a VPN gateway – https://docs.microsoft.com/en-us/azure/vpn-gateway/troubleshoot-vpn-with-azure-diagnostics
- also, determine the root cause for latency issues within site-to-site VPNs – https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-troubleshoot-site-to-site-cannot-connect, https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-troubleshoot-site-to-site-disconnected-intermittently
- furthermore, review and interpret gateway configuration scripts – https://docs.microsoft.com/en-us/azure/vpn-gateway/create-routebased-vpn-gateway-powershell, https://docs.microsoft.com/en-us/azure/vpn-gateway/create-routebased-vpn-gateway-cli
- moreover, reset a VPN gateway – https://docs.microsoft.com/en-us/azure/vpn-gateway/reset-gateway#:~:text=In%20the%20portal%2C%20navigate%20to,VPN%20gateway%20is%20rebooted%20immediately.
- also, troubleshoot gateway issues by running Log Analytics queries – https://docs.microsoft.com/en-us/azure/azure-monitor/agents/agent-windows-troubleshoot
Troubleshoot Azure ExpressRoute connectivity issues
- determine whether routes are live and correctly configured – https://docs.microsoft.com/en-us/azure/expressroute/expressroute-troubleshooting-expressroute-overview
- also, validate the peering configuration for an ExpressRoute circuit – https://docs.microsoft.com/en-us/azure/expressroute/expressroute-troubleshooting-expressroute-overview
- furthermore, reset an ExpressRoute circuit – https://docs.microsoft.com/en-us/azure/expressroute/reset-circuit
- moreover, troubleshoot route filtering –https://docs.microsoft.com/en-us/azure/expressroute/how-to-routefilter-powershell
- also, troubleshoot custom-defined routes – https://docs.microsoft.com/en-us/azure/virtual-network/diagnose-network-routing-problem
- furthermore, determine the root cause for latency issues related to ExpressRoute – https://docs.microsoft.com/en-us/azure/expressroute/expressroute-troubleshooting-network-performance
3. Troubleshoot Platform as a Service issues (5–10%)
Check PaaS services
- troubleshooting issues connecting to a PaaS – https://docs.microsoft.com/en-us/azure/azure-sql/database/troubleshoot-common-errors-issues
- also, troubleshoot firewalls for PaaS services – https://docs.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud
- furthermore, troubleshooting PaaS configuration issues – https://docs.microsoft.com/en-us/azure/cloud-services/cloud-services-troubleshoot-deployment-problems
- moreover, determine the root cause for service-level throttling – https://docs.microsoft.com/en-us/troubleshoot/azure/virtual-machines/troubleshooting-throttling-errors
Troubleshooting PaaS integration issues
- troubleshooting issues integrating PaaS services with virtual networks – https://docs.microsoft.com/en-us/azure/app-service/overview-vnet-integration
- check subnet delegation issues – https://docs.microsoft.com/en-us/azure/virtual-network/subnet-delegation-overview
- troubleshooting issues with private endpoints and service endpoints – https://docs.microsoft.com/en-us/azure/private-link/troubleshoot-private-endpoint-connectivity, https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-service-endpoints-overview
- troubleshoot issues with Azure Private Link – https://docs.microsoft.com/en-us/azure/private-link/troubleshoot-private-link-connectivity
4. Troubleshoot authentication and access control issues (15–20%)
Troubleshoot Azure AD authentication
- determine why on-premises systems cannot connect to Azure resources – https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/howto-troubleshoot-sign-in-errors
- troubleshooting Azure AD configuration issues
- troubleshoot self-service password reset issues – https://docs.microsoft.com/en-us/azure/active-directory/authentication/troubleshoot-sspr
- troubleshooting issues with multifactor authentication – https://docs.microsoft.com/en-us/troubleshoot/azure/active-directory/troubleshoot-azure-mfa-issue
Check hybrid authentication
- troubleshooting Azure AD Connect synchronization issues – https://docs.microsoft.com/en-us/azure/active-directory/hybrid/tshoot-connect-objectsync
- check Azure AD to Active Directory Domain Services (Azure AD DS) integration issues – https://docs.microsoft.com/en-us/azure/active-directory-domain-services/troubleshoot
- troubleshooting connectivity issues between Azure AD and Active Directory Federation Services (AD FS) – https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/troubleshoot-ad-fs-issues
- troubleshoot issues with pass-through authentication and password hash synchronization – https://docs.microsoft.com/en-us/azure/active-directory/hybrid/tshoot-connect-password-hash-synchronization, https://docs.microsoft.com/en-us/azure/active-directory/hybrid/tshoot-connect-pass-through-authentication
- troubleshooting Azure AD Application Proxy connectivity issues – https://docs.microsoft.com/en-us/azure/active-directory/app-proxy/application-proxy-troubleshoot
Diagnosing authorization issues
- troubleshooting role-based access control (RBAC) issues – https://auth0.com/docs/troubleshoot/authentication-issues/troubleshoot-rbac-authorization
- troubleshoot issues storing encrypted passwords in Azure Key Vault – https://docs.microsoft.com/en-us/azure/key-vault/general/troubleshooting-access-issues
- troubleshooting sign-in issues related to Azure AD Conditional Access policies – https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/troubleshoot-conditional-access
5. Troubleshoot networks (25–30%)
Troubleshoot Azure network security issues
- determine why Azure Web Application Firewall is blocking traffic – https://docs.microsoft.com/en-us/azure/web-application-firewall/ag/web-application-firewall-troubleshoot
- troubleshoot encryption and certificate issues for point-to-site and site-to-site scenarios – https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-troubleshoot-vpn-point-to-site-connection-problems, https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-troubleshoot-site-to-site-cannot-connect
Troubleshooting Azure network security groups (NSGs)
- diagnose NSG configuration issues – https://docs.microsoft.com/en-us/azure/virtual-network/diagnose-network-traffic-filter-problem
- review and interpret NSG flow logs – https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-read-nsg-flow-logs
- determine whether a VM or a group of VMs is associated with an application security group (ASG)
Troubleshooting Azure Firewall issues
- troubleshooting an application, network, and infrastructure rules – https://docs.microsoft.com/en-us/azure/firewall/firewall-diagnostics
- troubleshoot network address translation (NAT) and distributed network address translation (DNAT) rules – https://docs.microsoft.com/en-us/azure/firewall/firewall-workbook
- troubleshooting Azure Firewall Manager configuration issues – https://docs.microsoft.com/en-us/azure/firewall-manager/deployment-overview
Diagnosing latency issues
- determine the root cause for VM-level throttling- https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-bandwidth-testing
- deciding the root cause for latency issues when connecting to Azure virtual machines – https://docs.microsoft.com/en-us/azure/virtual-network/troubleshoot-vm-connectivity
- determining the root cause for throttling between source and destination resources – https://docs.microsoft.com/en-us/azure/virtual-network/virtual-machine-network-throughput
- troubleshoot bandwidth availability issues – https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-connectivity-portal
- determine whether resource response times meet service-level agreements (SLAs) – https://docs.microsoft.com/en-us/azure/expressroute/expressroute-troubleshooting-network-performance
Troubleshoot routing and traffic control
- review and interpret route tables – https://docs.microsoft.com/en-us/azure/virtual-network/manage-route-table, https://docs.microsoft.com/en-us/azure/virtual-network/monitor-virtual-network
- troubleshooting asymmetric routing – https://docs.microsoft.com/en-us/azure/expressroute/expressroute-asymmetric-routing
- troubleshooting issues with user-defined routes – https://docs.microsoft.com/en-us/azure/virtual-network/diagnose-network-routing-problem
- troubleshoot issues related to forced tunneling – https://docs.microsoft.com/en-us/azure/virtual-network/diagnose-network-routing-problem
- troubleshooting Border Gateway Protocol (BGP) issues – https://docs.microsoft.com/en-us/azure/vpn-gateway/troubleshoot-vpn-with-azure-diagnostics#RouteDiagnosticLog
- troubleshoot virtual network peering, transitive routing, and service chaining – https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-troubleshoot-peering-issues, https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-configure-vnet-connections
- troubleshooting routing configuration issues in Azure – https://docs.microsoft.com/en-us/azure/virtual-network/diagnose-network-routing-problem
Troubleshooting load-balancing issues
- determine whether VMs in a load-balanced cluster is healthy – https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-custom-probe-overview
- troubleshoot issues with Azure Load Balancer – https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-troubleshoot
- also, review and interpret load balancer rules – https://docs.microsoft.com/en-us/azure/load-balancer/manage-rules-how-to
- moreover, troubleshoot traffic distribution issues – https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-troubleshoot-backend-traffic
- furthermore, evaluate the configuration of Azure Traffic Manager – https://docs.microsoft.com/en-us/azure/traffic-manager/traffic-manager-testing-settings, https://docs.microsoft.com/en-us/azure/traffic-manager/traffic-manager-diagnostic-logs
- also, troubleshoot issues with Azure Traffic Manager profiles – https://docs.microsoft.com/en-us/azure/traffic-manager/traffic-manager-troubleshooting-degraded
- also, troubleshooting port exhaustion issues – https://docs.microsoft.com/en-us/windows/client-management/troubleshoot-tcpip-port-exhaust
- furthermore, troubleshoot issues with Azure Front Door – https://docs.microsoft.com/en-us/azure/frontdoor/troubleshoot-issues
- moreover, troubleshooting issues with Azure Application Gateway – https://docs.microsoft.com/en-us/azure/application-gateway/log-analytics, https://docs.microsoft.com/en-us/azure/application-gateway/troubleshoot-app-service-redirection-app-service-url, https://docs.microsoft.com/en-us/azure/application-gateway/application-gateway-backend-health-troubleshooting
6. Troubleshoot VM connectivity issues (5–10%)
Diagnosing Azure Bastion
- troubleshooting issues deploying Azure Bastion – https://docs.microsoft.com/en-us/azure/bastion/tutorial-create-host-portal, https://docs.microsoft.com/en-us/azure/bastion/troubleshoot
- also, check connectivity issues- https://docs.microsoft.com/en-us/azure/bastion/troubleshoot
- furthermore, troubleshoot authorization issues – https://docs.microsoft.com/en-us/azure/bastion/troubleshoot
Troubleshooting just-in-time (JIT) VM access
- validate connectivity with a VM – https://docs.microsoft.com/en-us/azure/defender-for-cloud/just-in-time-access-usage?tabs=jit-config-asc%2Cjit-request-asc
- also, troubleshoot Microsoft Defender for Cloud configuration issues – https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/troubleshoot-onboarding?view=o365-worldwide
- furthermore, determine which resources are authorized to use JIT VM access – https://docs.microsoft.com/en-us/azure/defender-for-cloud/just-in-time-access-overview
Let us now have a look at some of the learning resources –
Microsoft Learning Path
Microsoft offers a learning path that includes modules to help you study for your exams. Visit the Microsoft official website to learn everything you need to know about the AZ-720 exam and how to prepare for it. Candidates will also benefit from the modules covered in this course in terms of improved subject learning and exam passing. The test learning path, on the other hand, includes the following:
Azure Support Engineer for Connectivity Specialty
Working with cloud-based assets necessitates the use of networking. This learning path covers the various connectivity issues that a network engineer may face, as well as the troubleshooting techniques for resolving them.
Microsoft Docs
The Microsoft documentation is a knowledge base that contains in-depth information about the AZ-720 exam test subjects. Reading Microsoft documentation can also help you learn about the various sizes of different Azure services. This is made up of courses that will teach you a lot about the various services and ideas covered in the exam.
Online Study Groups
When it comes to studying for tests, candidates may benefit from online study groups. In other words, joining study groups will keep you in touch with experts and professionals who have previously walked this path. This group can also be used to discuss any test-related issues or problems, as well as to study for the AZ-720 exam.
How are Beta Exams Scored?
Because the scoring model for the exam has not yet been finalized, you do not receive a score immediately after completing a beta exam.
You typically receive your exam score about two weeks after the exam becomes available worldwide (known as “live”)—this can take up to 16 weeks, depending on when you took the exam during the beta period. This time frame reflects the thorough process used to evaluate the beta exam results, which included statistically analyzing the data to assess the performance of each question and reading and evaluating all comments provided during the beta exam. The rescore process begins the day the exams go live, and final scores are released about 10 business days later.
Beta exam participation is entirely voluntary, and Microsoft makes no promises or guarantees about the beta exam process, the availability of your scores, or the timing of your results.