mediummultiple choiceObjective-mapped

A subnet is associated with a NAT gateway, but its route table also contains a 0.0.0.0/0 route to a virtual appliance at 10.2.0.4. The business wants all outbound internet traffic from the VMs to use one static public IP, and inspection by the appliance is no longer required. What should the administrator change?

Question 1mediummultiple choice
Full question →

A subnet is associated with a NAT gateway, but its route table also contains a 0.0.0.0/0 route to a virtual appliance at 10.2.0.4. The business wants all outbound internet traffic from the VMs to use one static public IP, and inspection by the appliance is no longer required. What should the administrator change?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

Add a public IP address directly to each virtual machine NIC.

Per-VM public IPs do not provide a single shared outbound address for the entire subnet.

B

Best answer

Remove the 0.0.0.0/0 user-defined route from the subnet.

The default route to the virtual appliance forces all internet-bound traffic away from the subnet's NAT gateway. Because NAT gateway only handles outbound traffic that is not sent to another next hop, the UDR prevents the NAT gateway from being used. Removing the default route allows the subnet to use the NAT gateway's static public IP for outbound internet connections while keeping routing simple.

C

Distractor review

Enable service endpoints for the subnet.

Service endpoints improve access to supported Azure services, but they do not provide a subnet-wide public outbound IP.

D

Distractor review

Change the NAT gateway to a zone-redundant SKU.

NAT gateway does not use a zone-redundant SKU to solve routing precedence or outbound IP selection.

Common exam trap

Common exam trap: usable hosts are not the same as total addresses

Subnetting questions often tempt you into counting all addresses. In normal IPv4 subnets, the network and broadcast addresses are not usable host addresses.

Technical deep dive

How to think about this question

Subnetting questions test whether you can identify the network, broadcast address, usable range, mask and correct subnet. Slow down enough to calculate the block size correctly.

KKey Concepts to Remember

  • CIDR notation defines the prefix length.
  • Block size helps identify subnet boundaries.
  • Network and broadcast addresses are not usable hosts in normal IPv4 subnets.
  • The required host count determines the smallest suitable subnet.

TExam Day Tips

  • Write the block size before choosing the subnet.
  • Check whether the question asks for hosts, subnets or a specific address range.
  • Do not confuse /24, /25, /26 and /27 host counts.

Related practice questions

Related AZ-104 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this AZ-104 question test?

CIDR notation defines the prefix length.

What is the correct answer to this question?

The correct answer is: Remove the 0.0.0.0/0 user-defined route from the subnet. — A NAT gateway provides a stable outbound public IP for traffic that reaches the internet, but a user-defined route to a virtual appliance takes precedence for that destination. If 0.0.0.0/0 points to the appliance, the NAT gateway will not be used for general internet traffic. Since inspection is no longer required, the correct fix is to remove the overriding default route so the subnet can use the NAT gateway as intended. Why others are wrong: Adding public IPs to each VM defeats the goal of one shared outbound address. Service endpoints are for private access to Azure PaaS services, not internet egress. NAT gateway behavior is not controlled by a special SKU change; the blocking issue here is the UDR that overrides outbound path selection.

What should I do if I get this AZ-104 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.