Courseiva
Implement and Manage Virtual NetworkingmediumMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Virtual Networking Practice Question

A web application on a VM is failing on TCP 8443. The administrator wants to capture packets on the VM NIC to inspect retransmissions and handshake details after the test run. Which Network Watcher capability should be used?

⚠ Common exam trap

Many candidates confuse IP flow verify or Connection troubleshoot with packet capture, not realizing that only packet capture provides raw packet data for analyzing retransmissions and handshake details.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Packet capture

Packet capture in Network Watcher allows you to capture network traffic to and from a VM, including TCP retransmissions and handshake details (SYN, SYN-ACK, ACK). This is the correct tool for inspecting raw packets after a test run to diagnose issues like failed connections on TCP 8443.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • IP flow verify

    Why it's wrong here

    IP flow verify evaluates a single simulated packet against the network security group rules for the VM's NIC, telling you only whether an NSG allows or denies a specific source/destination/port combination. It does not capture actual packets, does not check routing, and cannot see protocol-level issues like TCP SYN retransmissions or a half-open connection. Because it tests only one packet at a moment in time, it may allow the flow while the real application connection still fails due to an expired TLS session or dropped handshake.

    When this WOULD be correct

    When an administrator needs to verify whether a specific TCP packet on port 8443 is allowed or blocked by NSG rules, and the question asks for a diagnostic tool to test connectivity without capturing full packet data.

  • Connection troubleshoot

    Why it's wrong here

    Connection troubleshoot performs a live end-to-end check between a VM and a target, evaluating NSG rules, effective routes, and whether a TCP connection to port 8443 can be established. However, it returns only a pass/fail status and latency data, not captured network packets, so it cannot reveal retransmissions, TLS handshake failures, or malformed application responses. If the application port is listening but serving errors, this tool may incorrectly report success.

    When this WOULD be correct

    When the question asks to diagnose a connectivity issue from a VM to a destination (e.g., a specific IP and port) and requires a report on latency, packet loss, and hop-by-hop path, without needing the actual packet data.

  • Packet capture

    Why this is correct

    Packet capture records network traffic on the VM NIC so the administrator can analyze the exchange later. It is the right choice when the problem may involve retransmissions, handshake failures, or other packet-level behavior rather than only a routing or NSG question.

  • Effective routes

    Why it's wrong here

    Effective routes displays the actual list of routes applied to a network interface, showing the next hop for each destination prefix so you can confirm traffic to 8443 leaves via the intended subnet or VPN. It is a static configuration snapshot, not a traffic capture, and it does not report whether packets are dropped, retransmitted, or corrupted. Even with perfect routes, a firewall, load balancer, or the application itself could be causing the failure on TCP 8443.

    When this WOULD be correct

    When a VM cannot connect to a destination and you need to verify if the expected routes (e.g., forced tunneling, UDR) are actually applied to the NIC, Effective routes would be the correct tool to diagnose routing issues.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Packet captureCorrect answer

Why this is correct

Packet capture records network traffic on the VM NIC so the administrator can analyze the exchange later. It is the right choice when the problem may involve retransmissions, handshake failures, or other packet-level behavior rather than only a routing or NSG question.

IP flow verifyWrong answer — click to see why

Why this is wrong here

IP flow verify checks if traffic is allowed or denied to/from a VM, but it does not capture packets for post-run analysis of retransmissions or handshake details.

★ When this WOULD be the correct answer

When an administrator needs to verify whether a specific TCP packet on port 8443 is allowed or blocked by NSG rules, and the question asks for a diagnostic tool to test connectivity without capturing full packet data.

Why candidates choose this

Candidates may confuse IP flow verify with packet capture because both involve network traffic analysis, but IP flow verify is a quick connectivity test, not a capture tool.

Connection troubleshootWrong answer — click to see why

Why this is wrong here

Connection troubleshoot tests connectivity and identifies issues like blocked ports or latency, but it does not capture packets for post-run analysis of retransmissions and handshake details.

★ When this WOULD be the correct answer

When the question asks to diagnose a connectivity issue from a VM to a destination (e.g., a specific IP and port) and requires a report on latency, packet loss, and hop-by-hop path, without needing the actual packet data.

Why candidates choose this

Candidates may confuse 'troubleshoot' with 'capture', thinking that diagnosing a connection problem includes packet-level inspection, but Connection troubleshoot only provides connectivity test results, not raw packet data.

Effective routesWrong answer — click to see why

Why this is wrong here

Effective routes shows the effective routes applied to a VM's NIC, but it does not capture or inspect network packets. It cannot be used to analyze retransmissions or handshake details on TCP 8443.

★ When this WOULD be the correct answer

When a VM cannot connect to a destination and you need to verify if the expected routes (e.g., forced tunneling, UDR) are actually applied to the NIC, Effective routes would be the correct tool to diagnose routing issues.

Why candidates choose this

Candidates may confuse 'effective routes' with 'packet capture' because both involve network troubleshooting, but they serve different purposes: routes deal with path selection, not packet-level inspection.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.