mediummultiple choiceObjective-mapped

A subnet uses a route table with gateway route propagation disabled so internet-bound traffic can be forced through a network virtual appliance. After the change, VMs in the subnet can no longer reach servers in the on-premises network 172.16.0.0/16 over the VPN gateway. What should the administrator add to the route table?

Question 1mediummultiple choice
Full question →

A subnet uses a route table with gateway route propagation disabled so internet-bound traffic can be forced through a network virtual appliance. After the change, VMs in the subnet can no longer reach servers in the on-premises network 172.16.0.0/16 over the VPN gateway. What should the administrator add to the route table?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Best answer

A user-defined route for 172.16.0.0/16 with next hop type Virtual network gateway.

When gateway route propagation is disabled, the subnet no longer learns on-premises routes automatically from the VPN gateway. Adding a specific route for the on-premises prefix with next hop Virtual network gateway restores reachability to that network while keeping the forced-tunneling design for other traffic.

B

Distractor review

A user-defined route for 172.16.0.0/16 with next hop type Internet.

Sending on-premises traffic to the Internet would not reach the private VPN network and would break the intended hybrid path.

C

Distractor review

An NSG allow rule for TCP 172.16.0.0/16.

NSGs operate on ports and protocols, not destination route selection, so they cannot restore the missing hybrid route.

D

Distractor review

A service endpoint for the on-premises network range.

Service endpoints are only for supported Azure services and do not apply to arbitrary on-premises prefixes over a VPN gateway.

Common exam trap

Common exam trap: usable hosts are not the same as total addresses

Subnetting questions often tempt you into counting all addresses. In normal IPv4 subnets, the network and broadcast addresses are not usable host addresses.

Technical deep dive

How to think about this question

Subnetting questions test whether you can identify the network, broadcast address, usable range, mask and correct subnet. Slow down enough to calculate the block size correctly.

KKey Concepts to Remember

  • CIDR notation defines the prefix length.
  • Block size helps identify subnet boundaries.
  • Network and broadcast addresses are not usable hosts in normal IPv4 subnets.
  • The required host count determines the smallest suitable subnet.

TExam Day Tips

  • Write the block size before choosing the subnet.
  • Check whether the question asks for hosts, subnets or a specific address range.
  • Do not confuse /24, /25, /26 and /27 host counts.

Related practice questions

Related AZ-104 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this AZ-104 question test?

CIDR notation defines the prefix length.

What is the correct answer to this question?

The correct answer is: A user-defined route for 172.16.0.0/16 with next hop type Virtual network gateway. — Disabling gateway route propagation removes automatically learned routes, including routes to on-premises networks connected through the VPN gateway. To restore access to 172.16.0.0/16 while preserving the forced-tunneling design, the administrator should add a specific UDR for that prefix with next hop type Virtual network gateway. This reintroduces the hybrid route without changing the rest of the traffic flow. Why others are wrong: B sends the traffic to the wrong next hop and would not reach the private on-premises network. C confuses security filtering with routing; an NSG allow rule does not create connectivity. D is unrelated to on-premises networks and cannot be used for arbitrary private address ranges behind a VPN gateway.

What should I do if I get this AZ-104 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.