mediumMultiple Choice
CV0-004 Practice Question: Is troubleshooting a connectivity issue between…
A cloud engineer is troubleshooting a connectivity issue between two virtual networks in different regions. The engineer has verified that the virtual networks are peered and the routing tables are correct. Which of the following is the MOST likely cause of the issue?
⚠ Common exam trap
The trap here is that candidates often overlook NSGs and jump to routing or gateway issues, but in a peered VNet scenario with correct routing, NSGs are the primary layer-4 filter that can silently drop traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A network security group blocking the traffic
Network security groups (NSGs) operate at the subnet or NIC level and can filter traffic between peered virtual networks even when routing is correctly configured. Since the engineer has verified peering and routing tables, the most likely remaining cause is an NSG rule explicitly or implicitly denying the traffic, as NSGs are stateful and evaluated after routing decisions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Incorrect route tables on the virtual network gateway
Why it's wrong here
The stem already states routing tables are correct, so a gateway route-table error contradicts the given evidence. Gateway route tables are the correct focus when traffic traverses a VPN or ExpressRoute gateway rather than direct virtual network peering, which bypasses gateways.
- ✗
A physical cable disconnection in the datacenter
Why it's wrong here
Cloud providers abstract the physical underlay, so a single cable fault cannot selectively break one peering while other traffic flows; provider redundancy masks it. Physical cabling is the correct consideration for on-premises cross-connects or dedicated interconnect circuits, not provider-managed regional peering.
- ✓
A network security group blocking the traffic
Why this is correct
Network security groups filter traffic at the subnet or NIC level independently of peering and routing, so a deny rule silently drops packets even when connectivity paths are correct. Inspecting NSG rules on both virtual networks is therefore the most likely explanation for the blocked cross-region traffic.
- ✗
Incorrect DNS resolution
Why it's wrong here
DNS resolution affects name-to-address mapping, not packet forwarding; if routes and peering are correct, IP-level connectivity still works and name lookups would fail separately. DNS is the right suspect when hosts resolve incorrectly while raw IP reachability succeeds.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.