Courseiva
Implement and Manage Virtual NetworkingmediumMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Virtual Networking Practice Question

A VM in a spoke subnet must send all traffic destined for 172.16.0.0/12 to a firewall appliance at 10.1.1.4. All other destinations should continue to use Azure system routes. Which user-defined route should the administrator add to the subnet route table?

⚠ Common exam trap

Watch out — candidates often confuse the 'Virtual appliance' next hop with 'Virtual network gateway' or assume a default route (0.0.0.0/0) is needed, but the requirement specifically limits the forced tunneling to only the 172.16.0.0/12 range, not all traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Destination 172.16.0.0/12 with next hop Virtual appliance and next hop address 10.1.1.4.

A user-defined route (UDR) with destination 172.16.0.0/12 and next hop type 'Virtual appliance' (with IP 10.1.1.4) overrides the default Azure system route for that prefix, forcing all traffic to the 172.16.0.0/12 range through the firewall at 10.1.1.4. This satisfies the requirement while leaving all other destinations (including 0.0.0.0/0) to be handled by Azure's default system routes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Destination 0.0.0.0/0 with next hop Internet.

    Why it's wrong here

    A 0.0.0.0/0 route is a default route that matches all outbound traffic, not specifically traffic destined for 172.16.0.0/12. Because 172.16.0.0/12 is a private RFC1918 range, forwarding it to the Internet would cause Azure to drop the packets, as the Internet is not a valid next hop for private address space. This would also override the built-in system routes and send all non-matching traffic to the Internet, completely bypassing the virtual appliance and failing the stated requirement.

    When this WOULD be correct

    If the requirement were to force all outbound internet traffic from the subnet through a firewall for inspection, a route with destination 0.0.0.0/0 and next hop Virtual appliance (with the firewall's IP) would be correct.

  • Destination 172.16.0.0/12 with next hop Virtual appliance and next hop address 10.1.1.4.

    Why this is correct

    A UDR should match the exact destination prefix that must be redirected. By adding 172.16.0.0/12 with next hop type Virtual appliance and the firewall private IP, Azure sends only that traffic to the appliance. All other traffic continues to follow the built-in system routes.

  • Destination 172.16.0.0/12 with next hop Virtual network gateway.

    Why it's wrong here

    A virtual network gateway next hop is designed for VPN or ExpressRoute connectivity between a VNet and on-premises networks or between VNets, not for sending traffic to an internal virtual appliance. Even with destination 172.16.0.0/12, the gateway would attempt to route packets over the gateway tunnel or connection, which is not configured to reach the firewall at 10.1.1.4. This would also require gateway-based routing logic and would fail to deliver traffic to the spoke network's destinations, unlike a user-defined route that explicitly points to the appliance's private IP.

    When this WOULD be correct

    If the question required sending traffic to 172.16.0.0/12 through a VPN or ExpressRoute connection (e.g., on-premises network), then the next hop would be Virtual network gateway.

  • Destination 172.16.0.0/12 with next hop None.

    Why it's wrong here

    Setting the next hop to None for the 172.16.0.0/12 prefix creates a blackhole route, which causes Azure to silently drop all packets matching that destination. This is typically used to intentionally discard traffic, not to forward it through a firewall for inspection or policy enforcement. Since the virtual appliance at 10.1.1.4 is never designated as the next hop, traffic cannot reach its intended destinations beyond the appliance, making this option incorrect.

    When this WOULD be correct

    This option would be correct if the requirement was to block all traffic to 172.16.0.0/12 (e.g., for security or compliance reasons) by dropping it at the subnet level, effectively creating a blackhole route.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Destination 172.16.0.0/12 with next hop Virtual appliance and next hop address 10.1.1.4.Correct answer

Why this is correct

A UDR should match the exact destination prefix that must be redirected. By adding 172.16.0.0/12 with next hop type Virtual appliance and the firewall private IP, Azure sends only that traffic to the appliance. All other traffic continues to follow the built-in system routes.

Destination 0.0.0.0/0 with next hop Internet.Wrong answer — click to see why

Why this is wrong here

The question requires traffic to 172.16.0.0/12 to be sent to a firewall, not all traffic. A 0.0.0.0/0 route would send all internet-bound traffic to the firewall, which is not the requirement and would break internet connectivity.

★ When this WOULD be the correct answer

If the requirement were to force all outbound internet traffic from the subnet through a firewall for inspection, a route with destination 0.0.0.0/0 and next hop Virtual appliance (with the firewall's IP) would be correct.

Why candidates choose this

Candidates may mistakenly think that a default route is needed to override system routes for the specific destination, or they confuse the need to route all traffic through the firewall with the specific requirement for only 172.16.0.0/12.

Destination 172.16.0.0/12 with next hop Virtual network gateway.Wrong answer — click to see why

Why this is wrong here

The next hop must be a virtual appliance (firewall) at 10.1.1.4, not a virtual network gateway. A virtual network gateway is used for VPN or ExpressRoute connections, not for routing to a firewall.

★ When this WOULD be the correct answer

If the question required sending traffic to 172.16.0.0/12 through a VPN or ExpressRoute connection (e.g., on-premises network), then the next hop would be Virtual network gateway.

Why candidates choose this

Candidates may confuse a virtual appliance firewall with a virtual network gateway, or think that any network virtual appliance is a gateway.

Destination 172.16.0.0/12 with next hop None.Wrong answer — click to see why

Why this is wrong here

Setting next hop to 'None' drops traffic to 172.16.0.0/12 instead of forwarding it to the firewall at 10.1.1.4, which violates the requirement that all traffic to that range must go through the firewall.

★ When this WOULD be the correct answer

This option would be correct if the requirement was to block all traffic to 172.16.0.0/12 (e.g., for security or compliance reasons) by dropping it at the subnet level, effectively creating a blackhole route.

Why candidates choose this

Candidates might think 'None' means no explicit next hop, so the system route would apply, but in Azure UDR, 'None' explicitly drops traffic, not falls back to system routes.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on AZ-104

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A VM in a subnet must send traffic to 172.16.0.0/16 through a network virtual appliance, but all other destinations should continue using the default Azure system routes. What should the administrator add to the subnet route table?

easy
  • A.A route for 0.0.0.0/0 with next hop Virtual appliance.
  • B.A route for 172.16.0.0/16 with next hop Virtual appliance.
  • C.An NSG deny rule for all other destinations.
  • D.A service endpoint for the 172.16.0.0/16 network.

Why B: The requirement is to route traffic destined for 172.16.0.0/16 through a network virtual appliance (NVA) while leaving all other traffic to use the default Azure system routes. Adding a user-defined route (UDR) with destination 172.16.0.0/16 and next hop Virtual appliance overrides the default system route for that specific prefix, ensuring traffic to that range is forwarded to the NVA. All other destinations remain unaffected because the 0.0.0.0/0 default route is not modified.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.