Courseiva
Implement and Manage Virtual NetworkingmediumMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Virtual Networking Practice Question

A VM in a subnet has both a subnet-level NSG and a NIC-level NSG. The subnet NSG allows inbound TCP 22 from the VirtualNetwork service tag, but the NIC NSG denies inbound TCP 22 from the same source. An administrator says the subnet rule should be enough because it allows the traffic. What is the actual behavior?

⚠ Common exam trap

A common mix-up: candidates assume subnet-level NSGs take precedence over NIC-level NSGs, but Azure actually applies both and the most restrictive rule (any deny) wins, making it critical to check both NSGs for conflicting rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The traffic is blocked because a deny in either NSG is effective.

When both a subnet-level NSG and a NIC-level NSG are applied to a virtual machine, network traffic is evaluated against both NSGs. The effective rule is the most restrictive: if either NSG contains a deny rule that matches the traffic, the traffic is blocked. In this scenario, the NIC-level NSG explicitly denies inbound TCP 22 from the VirtualNetwork service tag, so even though the subnet NSG allows it, the deny at the NIC level takes precedence and the traffic is blocked.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The allow rule wins because subnet NSGs always override NIC NSGs.

    Why it's wrong here

    Subnet NSGs and NIC NSGs do not have a hierarchical relationship where one overrides the other; Azure evaluates both scopes independently for every packet. Within a single NSG, rules are processed by priority number, but that priority does not apply across NSGs. A subnet NSG allow rule cannot supersede a NIC NSG deny rule, nor can a NIC NSG allow rule override a subnet NSG deny. The effective result is that traffic must be allowed by both layers — a deny at either scope blocks the traffic.

    When this WOULD be correct

    This option would be correct in a scenario where the question states that subnet NSGs have higher priority than NIC NSGs, or that subnet NSG rules override NIC NSG rules. For example, if the question specified that subnet NSGs are applied after NIC NSGs and can override them, then an allow at the subnet level would win.

  • The traffic is blocked because a deny in either NSG is effective.

    Why this is correct

    Azure treats subnet and NIC NSGs as independent security layers that both apply to the packet. For a connection to succeed, traffic must be permitted by the effective rules of BOTH the subnet NSG and the NIC NSG. If either NSG contains a matching deny rule, that packet is immediately discarded — a later allow rule in the other NSG has no chance to override it. This is true regardless of whether the deny comes from the subnet layer or the NIC layer.

  • The traffic is allowed because service tags bypass NIC-level rules.

    Why it's wrong here

    Service tags are just logical groupings of Azure service IP prefixes that can be used as source or destination in an NSG rule; they are a convenience for writing rules, not a bypass mechanism. A service tag–based allow rule in one NSG still requires that the other NSG also permit the traffic. If the NIC-level NSG has a deny rule (or the subnet NSG denies), the service tag's allow rule in the other scope does not prevent the packet from being dropped. The tag never exempts traffic from evaluation at any other NSG scope.

    When this WOULD be correct

    If the question stated that the NIC NSG has no rule for TCP 22 and the subnet NSG allows it, then the traffic would be allowed because subnet NSG rules apply to all VMs in the subnet unless overridden by a NIC NSG rule.

  • The connection succeeds unless a route table sends the traffic elsewhere.

    Why it's wrong here

    A route table only determines the next hop for traffic based on the destination IP, such as sending it to a virtual appliance or VPN gateway; it does not alter NSG permit/deny decisions. Network security groups are evaluated before the packet is forwarded according to the effective route, and a matching deny rule will block the packet before it can leave the subnet. Therefore, the presence of a custom route has no bearing on whether a deny rule in either NSG causes the connection to fail — the connection succeeds only if the route is valid AND both NSG layers allow the traffic.

    When this WOULD be correct

    A VM in a subnet has a subnet NSG allowing inbound TCP 22 from the VirtualNetwork service tag, but a route table on the subnet redirects traffic to a network virtual appliance. In this case, the connection may fail if the appliance does not forward the traffic, even though the NSG allows it.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

The traffic is blocked because a deny in either NSG is effective.Correct answer

Why this is correct

Azure treats subnet and NIC NSGs as independent security layers that both apply to the packet. For a connection to succeed, traffic must be permitted by the effective rules of BOTH the subnet NSG and the NIC NSG. If either NSG contains a matching deny rule, that packet is immediately discarded — a later allow rule in the other NSG has no chance to override it. This is true regardless of whether the deny comes from the subnet layer or the NIC layer.

The allow rule wins because subnet NSGs always override NIC NSGs.Wrong answer — click to see why

Why this is wrong here

In Azure, NSG rules are evaluated in order of priority, and a deny rule in either the subnet or NIC NSG will block traffic, regardless of an allow rule in the other NSG. Subnet NSGs do not override NIC NSGs; both are evaluated, and the most restrictive rule applies.

★ When this WOULD be the correct answer

This option would be correct in a scenario where the question states that subnet NSGs have higher priority than NIC NSGs, or that subnet NSG rules override NIC NSG rules. For example, if the question specified that subnet NSGs are applied after NIC NSGs and can override them, then an allow at the subnet level would win.

Why candidates choose this

Candidates may think that subnet-level NSGs are applied after NIC-level NSGs and thus can override them, or they may confuse NSG evaluation with route table precedence where subnet routes override NIC routes.

The traffic is allowed because service tags bypass NIC-level rules.Wrong answer — click to see why

Why this is wrong here

Service tags do not bypass NSG rules; NSGs are evaluated in order of priority, and a deny rule in the NIC NSG will block traffic regardless of the subnet NSG allow rule.

★ When this WOULD be the correct answer

If the question stated that the NIC NSG has no rule for TCP 22 and the subnet NSG allows it, then the traffic would be allowed because subnet NSG rules apply to all VMs in the subnet unless overridden by a NIC NSG rule.

Why candidates choose this

Candidates may mistakenly believe that service tags have special privileges or that subnet-level rules take precedence over NIC-level rules, leading them to think the allow rule overrides the deny.

The connection succeeds unless a route table sends the traffic elsewhere.Wrong answer — click to see why

Why this is wrong here

In Azure, NSG rules are evaluated in order of priority, and a deny rule in either the subnet or NIC NSG will block traffic. Route tables do not affect NSG rule evaluation; they only influence traffic routing.

★ When this WOULD be the correct answer

A VM in a subnet has a subnet NSG allowing inbound TCP 22 from the VirtualNetwork service tag, but a route table on the subnet redirects traffic to a network virtual appliance. In this case, the connection may fail if the appliance does not forward the traffic, even though the NSG allows it.

Why candidates choose this

Candidates may confuse the role of NSGs and route tables, thinking that routing decisions can override NSG rules, or they may incorrectly assume that a route table can bypass NSG deny rules.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.