Courseiva
Implement and Manage Virtual NetworkingmediumMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Virtual Networking Practice Question

A web tier and an app tier run in separate subnets. Each VM NIC is placed in an application security group named WebASG or AppASG. The administrator must allow only the web tier to reach the app tier on TCP port 8443 and block all other inbound traffic to the app tier. Which NSG rule should be created on the app subnet?

⚠ Common exam trap

Watch out — candidates often confuse priority numbering—thinking a higher number means higher priority—or mistakenly assume that allowing traffic from the entire virtual network is sufficient, overlooking the need to restrict the source to only the web tier via ASGs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Allow TCP 8443 from WebASG to AppASG with a priority lower number than the deny rule.

NSG rules are evaluated in priority order, with lower numbers having higher priority. By placing an Allow rule for TCP 8443 from WebASG to AppASG with a lower priority number than a subsequent Deny-All rule, only traffic from the web tier is permitted, and all other inbound traffic to the app subnet is blocked. This leverages application security groups (ASGs) to define fine-grained, role-based network security policies without relying on IP addresses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Allow TCP 8443 from WebASG to AppASG with a priority lower number than the deny rule.

    Why this is correct

    This is the most precise approach because it targets the source and destination groups instead of broad IP ranges. The rule must use a lower priority number than the deny-all rule so it is evaluated first. That lets only the web tier reach the app tier on TCP 8443 while preserving the block on all other inbound traffic.

  • Allow TCP 8443 from the entire virtual network to the app subnet with a lower priority than the deny rule.

    Why it's wrong here

    Using the entire virtual network as the source allows every subnet, including management or other workloads, to reach the app tier on TCP 8443, which violates least-privilege access. The correct rule should scope the source to the web tier's application security group and the destination to the app tier's ASG, not broad IP/subnet ranges. This over-permissive rule unnecessarily expands the attack surface and could be blocked by security policy.

    When this WOULD be correct

    If the requirement were to allow all VMs within the virtual network (e.g., for internal management or inter-tier communication) to reach the app tier on TCP 8443, and only block traffic from outside the virtual network, then allowing from the entire virtual network with a lower priority than a deny-all rule would be correct.

  • Allow UDP 8443 from WebASG to AppASG with any priority below 65000.

    Why it's wrong here

    UDP is the wrong transport protocol because the application listens on TCP 8443, and an NSG rule for UDP never matches TCP segments, so the traffic would still be blocked. Additionally, the phrase "any priority below 65000" is not guaranteed to outrank the existing deny-all rule; the numeric value must be lower than that specific deny rule's priority. The protocol mismatch alone makes this option invalid.

    When this WOULD be correct

    If the question required allowing UDP traffic on port 8443 from WebASG to AppASG, and the deny rule had a priority of 65000, then a rule with any priority below 65000 would be correct.

  • Allow TCP 8443 from WebASG to AppASG with a priority higher number than the deny rule.

    Why it's wrong here

    An NSG rule with a higher numeric priority is evaluated later than the deny-all rule, so the deny rule matches first and drops the TCP 8443 traffic before the allow rule can be considered. In Azure, lower numbers win, so to override a deny rule the allow must have a smaller priority value. Thus even though the source and destination ASGs are correctly identified, the ordering defeats the rule.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Allow TCP 8443 from WebASG to AppASG with a priority lower number than the deny rule.Correct answer

Why this is correct

This is the most precise approach because it targets the source and destination groups instead of broad IP ranges. The rule must use a lower priority number than the deny-all rule so it is evaluated first. That lets only the web tier reach the app tier on TCP 8443 while preserving the block on all other inbound traffic.

Allow TCP 8443 from the entire virtual network to the app subnet with a lower priority than the deny rule.Wrong answer — click to see why

Why this is wrong here

This rule allows traffic from the entire virtual network, not just the web tier, violating the requirement to restrict access solely to the web tier. The app subnet would be exposed to all VMs in the virtual network, including potentially malicious or unintended sources.

★ When this WOULD be the correct answer

If the requirement were to allow all VMs within the virtual network (e.g., for internal management or inter-tier communication) to reach the app tier on TCP 8443, and only block traffic from outside the virtual network, then allowing from the entire virtual network with a lower priority than a deny-all rule would be correct.

Why candidates choose this

Candidates may mistakenly think that since the web and app tiers are in the same virtual network, allowing traffic from the entire virtual network is sufficient and simpler. They overlook the need for granular control using application security groups to restrict access to only the web tier.

Allow UDP 8443 from WebASG to AppASG with any priority below 65000.Wrong answer — click to see why

Why this is wrong here

The question specifies TCP port 8443, but option C incorrectly uses UDP. Also, the priority requirement is not about being below 65000; it must be lower than the deny rule's priority.

★ When this WOULD be the correct answer

If the question required allowing UDP traffic on port 8443 from WebASG to AppASG, and the deny rule had a priority of 65000, then a rule with any priority below 65000 would be correct.

Why candidates choose this

Candidates may confuse TCP and UDP ports, or think that any priority below 65000 is sufficient without considering the relative priority to the deny rule.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Go deeper

Related to this question

About these practice questions

Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on AZ-104

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A three-tier application uses separate web and app VMs that are scaled in and out regularly. The administrator must allow only the web tier to connect to the app tier on TCP 8080 without continually updating IP addresses. What should be configured in the NSG rule?

medium
  • A.Use application security groups for the web and app tiers and reference those groups in the NSG rule.
  • B.Add a subnet-to-subnet peering connection between the web and app subnets.
  • C.Create a load balancer backend pool rule for TCP 8080.
  • D.Use a user-defined route that sends TCP 8080 traffic to the app tier.

Why A: Application security groups (ASGs) allow you to group VMs logically by their application role (e.g., web tier, app tier) and reference those groups directly in NSG rules. This eliminates the need to maintain individual IP addresses or CIDR ranges when VMs scale in or out, because the NSG rule dynamically applies to all VMs in the ASG. By creating an inbound NSG rule that allows TCP 8080 from the web-tier ASG to the app-tier ASG, the administrator achieves the required connectivity without manual IP updates.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.