AZ-104 Implement and Manage Virtual Networking Practice Question
A Linux VM in a subnet must accept SSH only from the corporate admin subnet 10.8.4.0/24. The subnet NSG currently has an Allow-SSH rule for Any at priority 300 and a Deny-SSH rule for Any at priority 200. Administrators from 10.8.4.0/24 still cannot connect. What change should the administrator make?
⚠ Common exam trap
A common mix-up: candidates confuse 'lower priority' with a higher numeric value, thinking a rule with priority 400 is 'lower' than 200, when in fact NSG rules use ascending numeric priority where lower numbers are evaluated first and take precedence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add an Allow-SSH rule for 10.8.4.0/24 with a priority lower than 200.
In an NSG, rules are processed in priority order from lowest number to highest, and the first matching rule wins, so the Deny-SSH rule at priority 200 is evaluated before the Allow-SSH rule at priority 300 and blocks all SSH traffic including from 10.8.4.0/24. The correct fix is to add an Allow-SSH rule for 10.8.4.0/24 with a priority lower than 200 (for example 100), so it is evaluated before the deny rule and permits the admin subnet. Option A does not help because changing the protocol to Any still leaves the deny rule at a lower priority number than the allow rule, so it still matches first. Option C makes the problem worse by moving the allow rule to priority 400, which is evaluated even later. Option D is irrelevant because NSG filtering, not routing, is what is blocking the SSH connection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the deny rule protocol from TCP to Any so the allow rule is evaluated first.
Why it's wrong here
Changing the deny rule's protocol does not alter evaluation order; NSG rules are processed by priority number, so priority 200 still denies before the priority-300 allow. Protocol scoping is tempting for narrowing a rule's coverage, and would be correct when restricting which transport a rule matches.
When this WOULD be correct
This would be correct if the question stated that the Deny rule only blocks TCP traffic and SSH uses UDP, requiring the deny rule's protocol to be changed to Any to block SSH.
- ✓
Add an Allow-SSH rule for 10.8.4.0/24 with a priority lower than 200.
Why this is correct
NSG rules are evaluated by priority, and the lowest number wins. A deny rule at 200 blocks SSH before the allow at 300 is considered. The fix is to add a more specific allow rule for the admin subnet with a higher priority, such as 100, so it is evaluated first. That keeps SSH restricted to approved administrators while preserving the existing deny for everyone else.
- ✗
Move the existing Allow-SSH rule to priority 400 so it applies later.
Why it's wrong here
Raising the allow rule to priority 400 moves it further down the evaluation order, so the priority-200 deny continues to win. Reordering rules is tempting because priority controls precedence, and would be correct if the allow rule needed to sit above a lower-priority deny.
When this WOULD be correct
In a scenario where a lower-priority allow rule is blocking desired traffic due to a higher-priority deny rule, and you need to ensure the allow rule is evaluated after the deny rule (e.g., if the deny rule should only block certain sources, but you want to allow all others after the deny).
- ✗
Add a route table to the subnet so the SSH packets follow a different path.
Why it's wrong here
User-defined routes govern packet forwarding, not security filtering, so the NSG's priority-200 deny still blocks SSH from 10.8.4.0/24. Route tables are tempting because they shape traffic paths, and would be correct when traffic must traverse a firewall appliance or network virtual appliance.
When this WOULD be correct
In a scenario where a subnet has two network interfaces (e.g., a firewall appliance) and traffic must be forced through a specific path for inspection, adding a route table (UDR) to override the default route would be correct.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Add an Allow-SSH rule for 10.8.4.0/24 with a priority lower than 200.Correct answer▾
Why this is correct
NSG rules are evaluated by priority, and the lowest number wins. A deny rule at 200 blocks SSH before the allow at 300 is considered. The fix is to add a more specific allow rule for the admin subnet with a higher priority, such as 100, so it is evaluated first. That keeps SSH restricted to approved administrators while preserving the existing deny for everyone else.
✗Change the deny rule protocol from TCP to Any so the allow rule is evaluated first.Wrong answer — click to see why▾
Why this is wrong here
Changing the deny rule protocol from TCP to Any does not affect rule evaluation order; NSGs evaluate rules by priority, and the Deny-SSH rule at priority 200 still blocks all SSH traffic regardless of protocol scope.
★ When this WOULD be the correct answer
This would be correct if the question stated that the Deny rule only blocks TCP traffic and SSH uses UDP, requiring the deny rule's protocol to be changed to Any to block SSH.
Why candidates choose this
Candidates may mistakenly think that broadening the deny rule's protocol will allow the allow rule to be evaluated first, misunderstanding NSG priority logic.
✗Move the existing Allow-SSH rule to priority 400 so it applies later.Wrong answer — click to see why▾
Why this is wrong here
Increasing the priority number (to 400) makes the rule apply later (lower priority), but the existing Deny-SSH rule at priority 200 will still block SSH traffic before any lower-priority allow rule is evaluated. The deny rule must be overridden by a higher-priority (lower number) allow rule.
★ When this WOULD be the correct answer
In a scenario where a lower-priority allow rule is blocking desired traffic due to a higher-priority deny rule, and you need to ensure the allow rule is evaluated after the deny rule (e.g., if the deny rule should only block certain sources, but you want to allow all others after the deny).
Why candidates choose this
Candidates may think that moving the allow rule to a higher priority number (lower priority) will cause it to be evaluated later, potentially overriding the deny rule, but they misunderstand that NSG rules are evaluated in priority order (lower number = higher priority) and the first matching rule applies.
✗Add a route table to the subnet so the SSH packets follow a different path.Wrong answer — click to see why▾
Why this is wrong here
The issue is that the Deny-SSH rule at priority 200 blocks all SSH traffic, including from 10.8.4.0/24. Adding a route table does not affect NSG rule evaluation; NSGs filter traffic based on rules regardless of routing.
★ When this WOULD be the correct answer
In a scenario where a subnet has two network interfaces (e.g., a firewall appliance) and traffic must be forced through a specific path for inspection, adding a route table (UDR) to override the default route would be correct.
Why candidates choose this
Candidates may confuse network security groups with routing, thinking that changing the path of packets can bypass NSG rules, or they may overcomplicate the problem by assuming a routing issue when it's purely a rule priority problem.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
About these practice questions
This AZ-104 question is part of Courseiva's 1,053-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.