AZ-104 Implement and Manage Virtual Networking Practice Question
A subnet is associated with a NAT gateway, but its route table also contains a 0.0.0.0/0 route to a virtual appliance at 10.2.0.4. The business wants all outbound internet traffic from the VMs to use one static public IP, and inspection by the appliance is no longer required. What should the administrator change?
⚠ Common exam trap
Many exam-takers think adding a public IP to VMs (Option A) is simpler or that service endpoints (Option C) can replace a NAT gateway for general internet access, but they fail to recognize that the existing UDR is the direct conflict preventing the NAT gateway from being the default route for outbound traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remove the 0.0.0.0/0 user-defined route from the subnet.
Removing the 0.0.0.0/0 user-defined route (UDR) from the subnet's route table will allow the NAT gateway to handle all outbound internet traffic. The NAT gateway provides a single static public IP for outbound traffic, and since inspection by the virtual appliance is no longer required, the conflicting UDR that directs traffic to the appliance must be deleted. This ensures that the subnet's default route points to the NAT gateway, which uses Source Network Address Translation (SNAT) to translate private IPs to the static public IP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a public IP address directly to each virtual machine NIC.
Why it's wrong here
Associating a public IP address directly to each VM NIC assigns a unique outbound address per machine, which bypasses the NAT gateway entirely. This defeats the purpose of a single, shared subnet-level outbound IP and also does not address the underlying UDR that sends traffic to the virtual appliance. In addition, per-VM public IPs are typically used for inbound or individual outbound scenarios; they do not interoperate with a NAT gateway to provide a common public address, so the subnet's internet-bound traffic would still follow the appliance route.
When this WOULD be correct
This would be correct if the requirement was for each VM to have its own public IP for direct outbound connectivity, and no centralized public IP or NAT gateway was needed.
- ✓
Remove the 0.0.0.0/0 user-defined route from the subnet.
Why this is correct
The default route to the virtual appliance forces all internet-bound traffic away from the subnet's NAT gateway. Because NAT gateway only handles outbound traffic that is not sent to another next hop, the UDR prevents the NAT gateway from being used. Removing the default route allows the subnet to use the NAT gateway's static public IP for outbound internet connections while keeping routing simple.
- ✗
Enable service endpoints for the subnet.
Why it's wrong here
Service endpoints create a direct, optimized route from the subnet to specific Azure services (such as Azure Storage or SQL Database) using the Azure backbone, but they do not manage general internet-bound traffic. The 0.0.0.0/0 UDR still determines the next hop for all other outbound destinations, so the NAT gateway remains unused. Service endpoints do not provide a public IP address, nor do they modify or remove an existing default route, making them irrelevant to the NAT gateway routing conflict.
When this WOULD be correct
In a scenario where a subnet needs to securely access Azure Storage or SQL Database without going through the internet or a virtual appliance, enabling service endpoints would be the correct answer. For example, if the question asked 'How to ensure VMs in a subnet connect to Azure Storage using the Azure backbone network instead of the internet?'
- ✗
Change the NAT gateway to a zone-redundant SKU.
Why it's wrong here
Selecting a zone-redundant NAT gateway improves availability across availability zones but does nothing to alter the subnet's effective route table. In Azure, a user-defined route (UDR) for 0.0.0.0/0 with a virtual appliance next hop has higher precedence than the system default route that would otherwise point internet-bound traffic to the NAT gateway. Since the existing route table directs outbound traffic to the appliance, the NAT gateway is never selected as the next hop, regardless of its SKU or redundancy level.
When this WOULD be correct
An administrator needs to ensure NAT gateway availability during an availability zone failure. The question would specify that the NAT gateway is currently in a single zone and must tolerate zone outages, making zone-redundant SKU the correct choice.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Remove the 0.0.0.0/0 user-defined route from the subnet.Correct answer▾
Why this is correct
The default route to the virtual appliance forces all internet-bound traffic away from the subnet's NAT gateway. Because NAT gateway only handles outbound traffic that is not sent to another next hop, the UDR prevents the NAT gateway from being used. Removing the default route allows the subnet to use the NAT gateway's static public IP for outbound internet connections while keeping routing simple.
✗Add a public IP address directly to each virtual machine NIC.Wrong answer — click to see why▾
Why this is wrong here
Adding a public IP directly to each VM NIC would bypass the NAT gateway, causing each VM to use its own public IP instead of the single static public IP required by the business.
★ When this WOULD be the correct answer
This would be correct if the requirement was for each VM to have its own public IP for direct outbound connectivity, and no centralized public IP or NAT gateway was needed.
Why candidates choose this
Candidates may think that assigning a public IP to each VM is a straightforward way to provide internet access, without understanding that it conflicts with the NAT gateway's purpose of using a single static IP.
✗Enable service endpoints for the subnet.Wrong answer — click to see why▾
Why this is wrong here
Enabling service endpoints does not affect outbound internet traffic routing; it only allows direct private access to Azure PaaS services from the subnet, bypassing the internet. The requirement is to remove the appliance inspection and use a NAT gateway for internet traffic, which is achieved by removing the conflicting UDR.
★ When this WOULD be the correct answer
In a scenario where a subnet needs to securely access Azure Storage or SQL Database without going through the internet or a virtual appliance, enabling service endpoints would be the correct answer. For example, if the question asked 'How to ensure VMs in a subnet connect to Azure Storage using the Azure backbone network instead of the internet?'
Why candidates choose this
Candidates may confuse service endpoints with a method to control outbound internet traffic, thinking they can replace a NAT gateway or virtual appliance for internet access, when service endpoints are specifically for Azure PaaS services only.
✗Change the NAT gateway to a zone-redundant SKU.Wrong answer — click to see why▾
Why this is wrong here
The question requires all outbound traffic to use one static public IP and no longer needs appliance inspection. Changing the NAT gateway to a zone-redundant SKU does not affect routing; it only provides high availability across availability zones, which is irrelevant to the stated requirements.
★ When this WOULD be the correct answer
An administrator needs to ensure NAT gateway availability during an availability zone failure. The question would specify that the NAT gateway is currently in a single zone and must tolerate zone outages, making zone-redundant SKU the correct choice.
Why candidates choose this
Candidates may think a zone-redundant SKU is necessary for high availability or performance, but the question's focus is on routing and public IP consolidation, not redundancy.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
VPN Gateway and ExpressRoute
Key term
NAT
NAT (Network Address Translation) is a method that allows multiple devices on a private network to share a single public IP address when accessing the internet.
Key term
NAT Gateway
A NAT Gateway is a managed AWS service that allows instances in a private subnet to connect to the internet or other AWS services while preventing the internet from initiating connections back to those instances.
About these practice questions
One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.