mediummultiple choiceObjective-mapped

A company has a hub virtual network that contains a custom DNS server at 10.20.0.4. A new spoke virtual network is peered to the hub. VMs in the spoke can reach other resources in Azure, but they cannot resolve internal names such as app01.corp.local. What should the administrator configure to fix name resolution for the spoke VMs?

Question 1mediummultiple choice
Full question →

A company has a hub virtual network that contains a custom DNS server at 10.20.0.4. A new spoke virtual network is peered to the hub. VMs in the spoke can reach other resources in Azure, but they cannot resolve internal names such as app01.corp.local. What should the administrator configure to fix name resolution for the spoke VMs?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

Add a user-defined route that sends DNS traffic to the hub virtual network.

Routes control packet forwarding, but they do not tell Azure which DNS server to use for name resolution.

B

Best answer

Set the spoke virtual network's custom DNS server to 10.20.0.4.

This directs VMs in the spoke to query the hub DNS server for internal names. In a hub-and-spoke design, peering alone does not make Azure use a custom DNS server automatically. Configuring the spoke VNet to use 10.20.0.4 ensures clients send DNS queries to the server that already hosts the corporate zone records.

C

Distractor review

Create an NSG rule that allows UDP port 53 from the spoke subnet to the hub subnet.

An NSG can permit DNS traffic, but it does not configure which DNS server the VMs should query.

D

Distractor review

Enable gateway transit on the hub peering so name resolution flows through the VPN gateway.

Gateway transit is for shared gateway routing to on-premises networks, not for selecting a DNS server in Azure.

Common exam trap

Common exam trap: usable hosts are not the same as total addresses

Subnetting questions often tempt you into counting all addresses. In normal IPv4 subnets, the network and broadcast addresses are not usable host addresses.

Technical deep dive

How to think about this question

Subnetting questions test whether you can identify the network, broadcast address, usable range, mask and correct subnet. Slow down enough to calculate the block size correctly.

KKey Concepts to Remember

  • CIDR notation defines the prefix length.
  • Block size helps identify subnet boundaries.
  • Network and broadcast addresses are not usable hosts in normal IPv4 subnets.
  • The required host count determines the smallest suitable subnet.

TExam Day Tips

  • Write the block size before choosing the subnet.
  • Check whether the question asks for hosts, subnets or a specific address range.
  • Do not confuse /24, /25, /26 and /27 host counts.

Related practice questions

Related AZ-104 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this AZ-104 question test?

CIDR notation defines the prefix length.

What is the correct answer to this question?

The correct answer is: Set the spoke virtual network's custom DNS server to 10.20.0.4. — The spoke VNet must be configured to use the custom DNS server IP so its VMs know where to send name resolution requests. Peering does not automatically inherit DNS settings, and Azure-provided DNS will not know about internal corporate zones. Setting the spoke VNet's DNS server to 10.20.0.4 is the standard fix when a hub hosts authoritative internal name resolution. Why others are wrong: A user-defined route cannot change DNS server selection. NSG rules can permit or block the DNS port, but they do not provide name resolution configuration. Gateway transit helps spokes use the hub's VPN or ExpressRoute gateway for routed connectivity to on-premises networks; it does not make Azure resolve names through the gateway.

What should I do if I get this AZ-104 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.