AZ-104 Implement and Manage Virtual Networking Practice Question
A company wants encrypted connectivity between its on-premises network and an Azure VNet. The organization has one edge VPN device at headquarters, and the Azure design must support a classic site-to-site tunnel rather than individual user VPN connections. Which three prerequisites are required? Select three.
⚠ Common exam trap
It's easy for candidates to confuse private endpoints (used for PaaS services) or ExpressRoute peering with the prerequisites for a classic site-to-site VPN, which strictly requires a GatewaySubnet, a public IP on the gateway, and a compatible on-premises VPN device.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a virtual network gateway in a dedicated GatewaySubnet.
Option A is correct because a site-to-site VPN in Azure requires a virtual network gateway (VPN type) deployed into a subnet named exactly GatewaySubnet, which is the dedicated subnet Azure mandates for gateway resources. Option B is correct because the Azure VPN gateway must have a public IP address so the on-premises VPN device can reach it as the tunnel endpoint over the internet. Option C is correct because the on-premises edge device must have a routable public IP and be configured with compatible IKE/IPsec parameters (shared key, encryption, and hashing settings) to establish the IPsec tunnel with the Azure gateway. Option D is not applicable because a private endpoint provides private access to a specific Azure PaaS service, not a site-to-site VPN tunnel between networks. Option E is not applicable because Microsoft peering is an ExpressRoute BGP peering type, not a feature of a VPN virtual network gateway.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy a virtual network gateway in a dedicated GatewaySubnet.
Why this is correct
A virtual network gateway is mandatory for any site-to-site IPsec/IKE tunnel, and it must reside in a subnet named exactly GatewaySubnet. This satisfies the stem's requirement for a classic site-to-site tunnel from the single headquarters edge VPN device, rather than point-to-site connectivity.
- ✓
Assign a public IP address to the Azure VPN gateway.
Why this is correct
The on-premises VPN device must reach a stable, routable endpoint, so the Azure VPN gateway needs a public IP address to terminate the IKE/IPsec tunnel. This satisfies the site-to-site requirement, since private addressing cannot be reached across the internet.
- ✓
Configure the on-premises VPN device with a public IP and supported IKE/IPsec settings.
Why this is correct
The headquarters edge device must present a public IP and use IKE/IPsec settings Azure supports, otherwise the tunnel cannot negotiate. This satisfies the site-to-site constraint, since mismatched encryption parameters or NAT-traversal issues prevent the IPsec association forming.
- ✗
Create a private endpoint for the headquarters network.
Why it's wrong here
A private endpoint serves PaaS resources inside a VNet and provides no tunnel to an on-premises VPN device, so it cannot satisfy site-to-site connectivity. It is tempting because private endpoints deliver private, encrypted access to Azure services, which is correct when exposing a storage account or SQL database without public internet routing.
When this WOULD be correct
A company requires secure, private connectivity from on-premises to an Azure Storage account without traversing the public internet. In that scenario, creating a private endpoint for the storage account in the VNet would be a correct prerequisite.
- ✗
Enable Microsoft peering on the virtual network gateway.
Why it's wrong here
Microsoft peering is an ExpressRoute routing domain, not a virtual network gateway setting, and it does not apply to VPN gateways carrying site-to-site traffic. It is tempting because it enables private connectivity to Microsoft services, which is correct when pairing ExpressRoute circuits with Azure public service access.
When this WOULD be correct
In a scenario requiring private connectivity between Azure and an on-premises network via ExpressRoute, enabling Microsoft peering on the virtual network gateway allows access to Azure PaaS services over the ExpressRoute circuit.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Deploy a virtual network gateway in a dedicated GatewaySubnet.Correct answer▾
Why this is correct
A virtual network gateway is mandatory for any site-to-site IPsec/IKE tunnel, and it must reside in a subnet named exactly GatewaySubnet. This satisfies the stem's requirement for a classic site-to-site tunnel from the single headquarters edge VPN device, rather than point-to-site connectivity.
✗Create a private endpoint for the headquarters network.Wrong answer — click to see why▾
Why this is wrong here
Private endpoints are used for secure access to Azure PaaS services (e.g., Storage, SQL) over a private IP within a VNet, not for establishing site-to-site VPN connectivity between on-premises and Azure.
★ When this WOULD be the correct answer
A company requires secure, private connectivity from on-premises to an Azure Storage account without traversing the public internet. In that scenario, creating a private endpoint for the storage account in the VNet would be a correct prerequisite.
Why candidates choose this
Candidates may confuse 'private endpoint' with 'private IP' or think it provides a secure tunnel, not realizing that site-to-site VPN requires a VPN gateway and public IP, not a private endpoint.
✗Enable Microsoft peering on the virtual network gateway.Wrong answer — click to see why▾
Why this is wrong here
Microsoft peering is used for ExpressRoute, not site-to-site VPN. A classic site-to-site tunnel requires a VPN gateway with a public IP and IKE/IPsec settings, not peering.
★ When this WOULD be the correct answer
In a scenario requiring private connectivity between Azure and an on-premises network via ExpressRoute, enabling Microsoft peering on the virtual network gateway allows access to Azure PaaS services over the ExpressRoute circuit.
Why candidates choose this
Candidates may confuse 'peering' with VPN connectivity or think that enabling peering is a generic step for any hybrid connection, not realizing it's specific to ExpressRoute.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
ExpressRoute Global Reach and FastPath
Key term
Hashing
Hashing is a one-way mathematical function that converts any input data into a fixed-length string of characters, called a hash or digest, which is used to verify data integrity and store passwords securely.
Key term
VNet
A virtual private network inside a cloud provider that lets you securely connect and isolate your cloud resources.
About these practice questions
This AZ-104 question is part of Courseiva's 1,053-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.