AZ-104 Implement and Manage Virtual Networking Practice Question
A VM in a subnet has both a subnet-level NSG and a NIC-level NSG. The subnet NSG allows inbound TCP 22 from the VirtualNetwork service tag, but the NIC NSG denies inbound TCP 22 from the same source. An administrator says the subnet rule should be enough because it allows the traffic. What is the actual behavior?
⚠ Common exam trap
A common mix-up: candidates assume subnet-level NSGs take precedence over NIC-level NSGs, but Azure actually applies both and the most restrictive rule (any deny) wins, making it critical to check both NSGs for conflicting rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The traffic is blocked because a deny in either NSG is effective.
When both a subnet-level NSG and a NIC-level NSG are applied to a virtual machine, network traffic is evaluated against both NSGs. The effective rule is the most restrictive: if either NSG contains a deny rule that matches the traffic, the traffic is blocked. In this scenario, the NIC-level NSG explicitly denies inbound TCP 22 from the VirtualNetwork service tag, so even though the subnet NSG allows it, the deny at the NIC level takes precedence and the traffic is blocked.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The allow rule wins because subnet NSGs always override NIC NSGs.
Why it's wrong here
Subnet NSGs and NIC NSGs do not have a hierarchical relationship where one overrides the other; Azure evaluates both scopes independently for every packet. Within a single NSG, rules are processed by priority number, but that priority does not apply across NSGs. A subnet NSG allow rule cannot supersede a NIC NSG deny rule, nor can a NIC NSG allow rule override a subnet NSG deny. The effective result is that traffic must be allowed by both layers — a deny at either scope blocks the traffic.
When this WOULD be correct
This option would be correct in a scenario where the question states that subnet NSGs have higher priority than NIC NSGs, or that subnet NSG rules override NIC NSG rules. For example, if the question specified that subnet NSGs are applied after NIC NSGs and can override them, then an allow at the subnet level would win.
- ✓
The traffic is blocked because a deny in either NSG is effective.
Why this is correct
Azure treats subnet and NIC NSGs as independent security layers that both apply to the packet. For a connection to succeed, traffic must be permitted by the effective rules of BOTH the subnet NSG and the NIC NSG. If either NSG contains a matching deny rule, that packet is immediately discarded — a later allow rule in the other NSG has no chance to override it. This is true regardless of whether the deny comes from the subnet layer or the NIC layer.
- ✗
The traffic is allowed because service tags bypass NIC-level rules.
Why it's wrong here
Service tags are just logical groupings of Azure service IP prefixes that can be used as source or destination in an NSG rule; they are a convenience for writing rules, not a bypass mechanism. A service tag–based allow rule in one NSG still requires that the other NSG also permit the traffic. If the NIC-level NSG has a deny rule (or the subnet NSG denies), the service tag's allow rule in the other scope does not prevent the packet from being dropped. The tag never exempts traffic from evaluation at any other NSG scope.
When this WOULD be correct
If the question stated that the NIC NSG has no rule for TCP 22 and the subnet NSG allows it, then the traffic would be allowed because subnet NSG rules apply to all VMs in the subnet unless overridden by a NIC NSG rule.
- ✗
The connection succeeds unless a route table sends the traffic elsewhere.
Why it's wrong here
A route table only determines the next hop for traffic based on the destination IP, such as sending it to a virtual appliance or VPN gateway; it does not alter NSG permit/deny decisions. Network security groups are evaluated before the packet is forwarded according to the effective route, and a matching deny rule will block the packet before it can leave the subnet. Therefore, the presence of a custom route has no bearing on whether a deny rule in either NSG causes the connection to fail — the connection succeeds only if the route is valid AND both NSG layers allow the traffic.
When this WOULD be correct
A VM in a subnet has a subnet NSG allowing inbound TCP 22 from the VirtualNetwork service tag, but a route table on the subnet redirects traffic to a network virtual appliance. In this case, the connection may fail if the appliance does not forward the traffic, even though the NSG allows it.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓The traffic is blocked because a deny in either NSG is effective.Correct answer▾
Why this is correct
Azure treats subnet and NIC NSGs as independent security layers that both apply to the packet. For a connection to succeed, traffic must be permitted by the effective rules of BOTH the subnet NSG and the NIC NSG. If either NSG contains a matching deny rule, that packet is immediately discarded — a later allow rule in the other NSG has no chance to override it. This is true regardless of whether the deny comes from the subnet layer or the NIC layer.
✗The allow rule wins because subnet NSGs always override NIC NSGs.Wrong answer — click to see why▾
Why this is wrong here
In Azure, NSG rules are evaluated in order of priority, and a deny rule in either the subnet or NIC NSG will block traffic, regardless of an allow rule in the other NSG. Subnet NSGs do not override NIC NSGs; both are evaluated, and the most restrictive rule applies.
★ When this WOULD be the correct answer
This option would be correct in a scenario where the question states that subnet NSGs have higher priority than NIC NSGs, or that subnet NSG rules override NIC NSG rules. For example, if the question specified that subnet NSGs are applied after NIC NSGs and can override them, then an allow at the subnet level would win.
Why candidates choose this
Candidates may think that subnet-level NSGs are applied after NIC-level NSGs and thus can override them, or they may confuse NSG evaluation with route table precedence where subnet routes override NIC routes.
✗The traffic is allowed because service tags bypass NIC-level rules.Wrong answer — click to see why▾
Why this is wrong here
Service tags do not bypass NSG rules; NSGs are evaluated in order of priority, and a deny rule in the NIC NSG will block traffic regardless of the subnet NSG allow rule.
★ When this WOULD be the correct answer
If the question stated that the NIC NSG has no rule for TCP 22 and the subnet NSG allows it, then the traffic would be allowed because subnet NSG rules apply to all VMs in the subnet unless overridden by a NIC NSG rule.
Why candidates choose this
Candidates may mistakenly believe that service tags have special privileges or that subnet-level rules take precedence over NIC-level rules, leading them to think the allow rule overrides the deny.
✗The connection succeeds unless a route table sends the traffic elsewhere.Wrong answer — click to see why▾
Why this is wrong here
In Azure, NSG rules are evaluated in order of priority, and a deny rule in either the subnet or NIC NSG will block traffic. Route tables do not affect NSG rule evaluation; they only influence traffic routing.
★ When this WOULD be the correct answer
A VM in a subnet has a subnet NSG allowing inbound TCP 22 from the VirtualNetwork service tag, but a route table on the subnet redirects traffic to a network virtual appliance. In this case, the connection may fail if the appliance does not forward the traffic, even though the NSG allows it.
Why candidates choose this
Candidates may confuse the role of NSGs and route tables, thinking that routing decisions can override NSG rules, or they may incorrectly assume that a route table can bypass NSG deny rules.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Azure Virtual Machine Deployment
Key term
Subnet
A subnet is a logical subdivision of an IP network, created by partitioning a larger network address space using subnet masks.
Key term
TCP
TCP (Transmission Control Protocol) is a core internet protocol that ensures data is sent reliably and in order between devices over a network.
About these practice questions
One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.