Courseiva
Implement and Manage Virtual NetworkingmediumMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Virtual Networking Practice Question

A subnet is associated with a NAT gateway, but its route table also contains a 0.0.0.0/0 route to a virtual appliance at 10.2.0.4. The business wants all outbound internet traffic from the VMs to use one static public IP, and inspection by the appliance is no longer required. What should the administrator change?

⚠ Common exam trap

Many exam-takers think adding a public IP to VMs (Option A) is simpler or that service endpoints (Option C) can replace a NAT gateway for general internet access, but they fail to recognize that the existing UDR is the direct conflict preventing the NAT gateway from being the default route for outbound traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Remove the 0.0.0.0/0 user-defined route from the subnet.

Removing the 0.0.0.0/0 user-defined route (UDR) from the subnet's route table will allow the NAT gateway to handle all outbound internet traffic. The NAT gateway provides a single static public IP for outbound traffic, and since inspection by the virtual appliance is no longer required, the conflicting UDR that directs traffic to the appliance must be deleted. This ensures that the subnet's default route points to the NAT gateway, which uses Source Network Address Translation (SNAT) to translate private IPs to the static public IP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Add a public IP address directly to each virtual machine NIC.

    Why it's wrong here

    Associating a public IP address directly to each VM NIC assigns a unique outbound address per machine, which bypasses the NAT gateway entirely. This defeats the purpose of a single, shared subnet-level outbound IP and also does not address the underlying UDR that sends traffic to the virtual appliance. In addition, per-VM public IPs are typically used for inbound or individual outbound scenarios; they do not interoperate with a NAT gateway to provide a common public address, so the subnet's internet-bound traffic would still follow the appliance route.

    When this WOULD be correct

    This would be correct if the requirement was for each VM to have its own public IP for direct outbound connectivity, and no centralized public IP or NAT gateway was needed.

  • Remove the 0.0.0.0/0 user-defined route from the subnet.

    Why this is correct

    The default route to the virtual appliance forces all internet-bound traffic away from the subnet's NAT gateway. Because NAT gateway only handles outbound traffic that is not sent to another next hop, the UDR prevents the NAT gateway from being used. Removing the default route allows the subnet to use the NAT gateway's static public IP for outbound internet connections while keeping routing simple.

  • Enable service endpoints for the subnet.

    Why it's wrong here

    Service endpoints create a direct, optimized route from the subnet to specific Azure services (such as Azure Storage or SQL Database) using the Azure backbone, but they do not manage general internet-bound traffic. The 0.0.0.0/0 UDR still determines the next hop for all other outbound destinations, so the NAT gateway remains unused. Service endpoints do not provide a public IP address, nor do they modify or remove an existing default route, making them irrelevant to the NAT gateway routing conflict.

    When this WOULD be correct

    In a scenario where a subnet needs to securely access Azure Storage or SQL Database without going through the internet or a virtual appliance, enabling service endpoints would be the correct answer. For example, if the question asked 'How to ensure VMs in a subnet connect to Azure Storage using the Azure backbone network instead of the internet?'

  • Change the NAT gateway to a zone-redundant SKU.

    Why it's wrong here

    Selecting a zone-redundant NAT gateway improves availability across availability zones but does nothing to alter the subnet's effective route table. In Azure, a user-defined route (UDR) for 0.0.0.0/0 with a virtual appliance next hop has higher precedence than the system default route that would otherwise point internet-bound traffic to the NAT gateway. Since the existing route table directs outbound traffic to the appliance, the NAT gateway is never selected as the next hop, regardless of its SKU or redundancy level.

    When this WOULD be correct

    An administrator needs to ensure NAT gateway availability during an availability zone failure. The question would specify that the NAT gateway is currently in a single zone and must tolerate zone outages, making zone-redundant SKU the correct choice.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Remove the 0.0.0.0/0 user-defined route from the subnet.Correct answer

Why this is correct

The default route to the virtual appliance forces all internet-bound traffic away from the subnet's NAT gateway. Because NAT gateway only handles outbound traffic that is not sent to another next hop, the UDR prevents the NAT gateway from being used. Removing the default route allows the subnet to use the NAT gateway's static public IP for outbound internet connections while keeping routing simple.

Add a public IP address directly to each virtual machine NIC.Wrong answer — click to see why

Why this is wrong here

Adding a public IP directly to each VM NIC would bypass the NAT gateway, causing each VM to use its own public IP instead of the single static public IP required by the business.

★ When this WOULD be the correct answer

This would be correct if the requirement was for each VM to have its own public IP for direct outbound connectivity, and no centralized public IP or NAT gateway was needed.

Why candidates choose this

Candidates may think that assigning a public IP to each VM is a straightforward way to provide internet access, without understanding that it conflicts with the NAT gateway's purpose of using a single static IP.

Enable service endpoints for the subnet.Wrong answer — click to see why

Why this is wrong here

Enabling service endpoints does not affect outbound internet traffic routing; it only allows direct private access to Azure PaaS services from the subnet, bypassing the internet. The requirement is to remove the appliance inspection and use a NAT gateway for internet traffic, which is achieved by removing the conflicting UDR.

★ When this WOULD be the correct answer

In a scenario where a subnet needs to securely access Azure Storage or SQL Database without going through the internet or a virtual appliance, enabling service endpoints would be the correct answer. For example, if the question asked 'How to ensure VMs in a subnet connect to Azure Storage using the Azure backbone network instead of the internet?'

Why candidates choose this

Candidates may confuse service endpoints with a method to control outbound internet traffic, thinking they can replace a NAT gateway or virtual appliance for internet access, when service endpoints are specifically for Azure PaaS services only.

Change the NAT gateway to a zone-redundant SKU.Wrong answer — click to see why

Why this is wrong here

The question requires all outbound traffic to use one static public IP and no longer needs appliance inspection. Changing the NAT gateway to a zone-redundant SKU does not affect routing; it only provides high availability across availability zones, which is irrelevant to the stated requirements.

★ When this WOULD be the correct answer

An administrator needs to ensure NAT gateway availability during an availability zone failure. The question would specify that the NAT gateway is currently in a single zone and must tolerate zone outages, making zone-redundant SKU the correct choice.

Why candidates choose this

Candidates may think a zone-redundant SKU is necessary for high availability or performance, but the question's focus is on routing and public IP consolidation, not redundancy.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.