Courseiva
Implement and Manage Virtual NetworkingmediumMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Virtual Networking Practice Question

A backend tier runs on three Azure VMs. The VMs are rebuilt frequently and receive new private IP addresses during redeployment. The administrator must allow inbound TCP 1433 from the app tier without rewriting the NSG rule each time the backend VMs change. What should be used?

⚠ Common exam trap

Many candidates confuse application security groups with network security groups or think that a load balancer or service endpoint can solve dynamic IP changes, but only ASGs provide a logical grouping that automatically follows VM IP changes without manual rule updates.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

An application security group referenced by the NSG rule

An application security group (ASG) allows you to group VMs logically (e.g., by tier) and reference that group in a network security group (NSG) rule. When backend VMs are rebuilt and receive new private IPs, the ASG membership is automatically updated, so the NSG rule continues to apply without manual changes. This makes ASG the correct choice for dynamic environments where IP addresses change frequently.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Individual private IP addresses assigned directly in the NSG rule

    Why it's wrong here

    Hard-coding individual private IP addresses in an NSG rule only works while those addresses are stable and known in advance. If the VMs are rebuilt, Azure typically assigns new private IPs, or if you force static IPs you must manually edit every rule after each rebuild, making this approach brittle and high-maintenance. It also fails to capture the backend tier as a logical unit, so adding or removing a VM requires rewriting security rules.

    When this WOULD be correct

    If the backend VMs had static private IP addresses that never change, assigning those IPs directly in an NSG rule would be a valid approach to allow inbound traffic from the app tier.

  • An application security group referenced by the NSG rule

    Why this is correct

    Application security groups let you group VMs logically and reference that group in NSG rules. When the backend VMs are rebuilt or their IPs change, the rule still applies as long as the NICs remain members of the ASG, which reduces manual maintenance.

  • A service endpoint enabled on the subnet

    Why it's wrong here

    A service endpoint extends a subnet's routing to secure connectivity to supported Azure PaaS services (such as Azure SQL Database or Storage), but it does not act as an NSG source/destination and does not group VMs. Even with the endpoint enabled, a backend-tier NSG rule still needs an explicit source or destination construct; the endpoint only prevents traffic to that PaaS service from leaving the Microsoft backbone. Thus it doesn't help when rebuilt VMs need to be targeted as a group.

    When this WOULD be correct

    A question where the backend tier is an Azure SQL Database (PaaS) instead of VMs, and the requirement is to restrict access from a specific subnet to the database. In that case, enabling a service endpoint on the subnet and creating a firewall rule for the subnet would be correct.

  • A load balancer inbound NAT rule on port 1433

    Why it's wrong here

    An inbound NAT rule on a load balancer maps a specific frontend port to a designated port on a single VM, and it exists to reach an individual instance (for example, RDP/SSH), not to express a security rule for an entire tier. On port 1433 it might expose SQL Server instances, but it neither groups the backend VMs nor makes them easier to reference in an NSG after a rebuild. NAT rules work in combination with NSGs, but they do not simplify the NSG rule itself.

    When this WOULD be correct

    A load balancer inbound NAT rule would be correct if the question required mapping a single public port to a specific backend VM for RDP/SSH access, and the backend VMs had static private IPs or the NAT rule was dynamically updated via automation.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

An application security group referenced by the NSG ruleCorrect answer

Why this is correct

Application security groups let you group VMs logically and reference that group in NSG rules. When the backend VMs are rebuilt or their IPs change, the rule still applies as long as the NICs remain members of the ASG, which reduces manual maintenance.

Individual private IP addresses assigned directly in the NSG ruleWrong answer — click to see why

Why this is wrong here

Individual private IP addresses change each time the VMs are rebuilt, requiring NSG rule updates. This does not meet the requirement to avoid rewriting rules.

★ When this WOULD be the correct answer

If the backend VMs had static private IP addresses that never change, assigning those IPs directly in an NSG rule would be a valid approach to allow inbound traffic from the app tier.

Why candidates choose this

Candidates may think that specifying IP addresses directly is the most straightforward way to control access, overlooking the dynamic nature of the IPs in this scenario.

A service endpoint enabled on the subnetWrong answer — click to see why

Why this is wrong here

A service endpoint secures Azure service access from a subnet to a specific service (e.g., Azure SQL Database) and does not filter traffic between VMs within a VNet. It cannot be used to allow inbound TCP 1433 from the app tier to backend VMs with dynamic private IPs.

★ When this WOULD be the correct answer

A question where the backend tier is an Azure SQL Database (PaaS) instead of VMs, and the requirement is to restrict access from a specific subnet to the database. In that case, enabling a service endpoint on the subnet and creating a firewall rule for the subnet would be correct.

Why candidates choose this

Candidates may confuse service endpoints with network security groups, thinking they can filter traffic between VMs. They might also recall that service endpoints improve security for Azure services and incorrectly assume they can replace NSG rules for VM-to-VM traffic.

A load balancer inbound NAT rule on port 1433Wrong answer — click to see why

Why this is wrong here

A load balancer inbound NAT rule translates a specific frontend port to a backend VM's private IP and port, but it does not solve the problem of changing private IPs because the NAT rule must be updated each time the backend VM's IP changes, which is the same rewriting issue the question aims to avoid.

★ When this WOULD be the correct answer

A load balancer inbound NAT rule would be correct if the question required mapping a single public port to a specific backend VM for RDP/SSH access, and the backend VMs had static private IPs or the NAT rule was dynamically updated via automation.

Why candidates choose this

Candidates may think a load balancer can handle changing IPs automatically, but inbound NAT rules are static mappings; they confuse load balancing (which distributes traffic) with NAT rules (which target specific VMs).

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.