Courseiva
Implement and Manage Virtual NetworkingmediumMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Virtual Networking Practice Question

A web tier and an app tier run on separate Azure VMs in the same region. Each VM's NIC is added to an application security group named WebASG or AppASG. The administrator must allow only the web tier to connect to the app tier on TCP 8443, and future VM scale-outs must be included automatically. Which NSG rule should be created?

⚠ Common exam trap

Many exam-takers confuse network security groups (NSGs) with route tables, thinking that routing can enforce access control, or they default to using static IP addresses in NSG rules, missing the dynamic, group-based capability of application security groups that automatically includes new VMs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

An inbound rule with source WebASG, destination AppASG, protocol TCP, and destination port 8443.

Application security groups (ASGs) allow you to configure network security as a natural extension of an application's structure, enabling you to group VMs by their roles (e.g., web tier, app tier) and define rules based on those groups. By creating an inbound NSG rule with source WebASG and destination AppASG on TCP port 8443, any VM added to WebASG can initiate traffic to any VM in AppASG, and future scale-outs are automatically included without manual IP updates. This approach is dynamic, scalable, and aligns with the requirement for automatic inclusion of new VMs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • An inbound rule that uses the current web VM's private IP as the source and the current app VM's private IP as the destination.

    Why it's wrong here

    Hard-coding the current web VM's private IP as the source and the app VM's private IP as the destination creates a brittle rule that breaks the moment either VM is recreated, scale-set scaled out, or a new tier member is added; the rule must be manually updated for every IP change or new instance. Application security groups (ASGs) solve this by letting the rule reference role-based groups, so new members are automatically included without rewriting the NSG rule.

    When this WOULD be correct

    If the question required restricting access to a single, specific VM (e.g., a management VM) and did not require automatic inclusion of new VMs, using static private IPs would be appropriate.

  • An inbound rule with source WebASG, destination AppASG, protocol TCP, and destination port 8443.

    Why this is correct

    Using application security groups is the best fit because the rule follows the role of the VM, not a fixed IP address. When new web or app VMs are added to their respective ASGs, the NSG rule automatically covers them. This provides least-privilege connectivity between tiers while keeping the configuration maintainable during scale-out and redeployment events.

  • A route table that sends TCP 8443 traffic from the web subnet to the app subnet.

    Why it's wrong here

    A route table (UDR) controls the next hop for traffic based on destination IP prefixes, not the TCP destination port, so it cannot permit or deny TCP 8443 between the web and app subnets. Even if a UDR directed 8443 traffic toward the app subnet, it would only change the path; it has no filtering capability. Access control for specific ports must be enforced by an NSG or a firewall, not by routing logic.

    When this WOULD be correct

    A question where the requirement is to force traffic from the web subnet to the app subnet through a specific next hop (e.g., a firewall or NVA) for inspection, and the goal is routing control, not access control based on ASGs.

  • An Azure Firewall application rule collection that permits all traffic between the two subnets.

    Why it's wrong here

    An Azure Firewall application rule collection is designed to allow outbound access based on FQDN/URLs (e.g., HTTP/S), not to filter east-west TCP port 8443 traffic between subnets by IP; network rules would be needed for that, and opening all traffic between the subnets violates least privilege. This approach is also far heavier than an NSG for simple tier-to-tier filtering, because Azure Firewall is a fully managed central service rather than a lightweight, subnet- or ASG-scoped rule.

    When this WOULD be correct

    This option would be correct if the question required filtering outbound HTTP/S traffic from the web tier to the internet, or if it required centralized logging and inspection of all traffic between subnets using Azure Firewall, and the question explicitly stated to use Azure Firewall instead of NSGs.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

An inbound rule with source WebASG, destination AppASG, protocol TCP, and destination port 8443.Correct answer

Why this is correct

Using application security groups is the best fit because the rule follows the role of the VM, not a fixed IP address. When new web or app VMs are added to their respective ASGs, the NSG rule automatically covers them. This provides least-privilege connectivity between tiers while keeping the configuration maintainable during scale-out and redeployment events.

An inbound rule that uses the current web VM's private IP as the source and the current app VM's private IP as the destination.Wrong answer — click to see why

Why this is wrong here

This rule uses static private IPs, so it fails to automatically include future VM scale-outs, violating the requirement for automatic inclusion.

★ When this WOULD be the correct answer

If the question required restricting access to a single, specific VM (e.g., a management VM) and did not require automatic inclusion of new VMs, using static private IPs would be appropriate.

Why candidates choose this

Candidates may think that specifying exact IPs provides precise control, overlooking the need for scalability and dynamic membership provided by application security groups.

A route table that sends TCP 8443 traffic from the web subnet to the app subnet.Wrong answer — click to see why

Why this is wrong here

Route tables control IP routing between subnets, not traffic filtering. They cannot enforce application-layer allow rules like TCP port 8443, and they don't integrate with application security groups for automatic scale-out inclusion.

★ When this WOULD be the correct answer

A question where the requirement is to force traffic from the web subnet to the app subnet through a specific next hop (e.g., a firewall or NVA) for inspection, and the goal is routing control, not access control based on ASGs.

Why candidates choose this

Candidates may confuse routing with network security, thinking that directing traffic via a route table can restrict which ports are allowed, or they may assume route tables can filter traffic like a firewall rule.

An Azure Firewall application rule collection that permits all traffic between the two subnets.Wrong answer — click to see why

Why this is wrong here

Azure Firewall application rules are for outbound HTTP/S traffic from applications, not for inbound network filtering between VMs. This question requires an NSG rule, not a firewall rule, and the requirement is for inbound connectivity from web to app tier.

★ When this WOULD be the correct answer

This option would be correct if the question required filtering outbound HTTP/S traffic from the web tier to the internet, or if it required centralized logging and inspection of all traffic between subnets using Azure Firewall, and the question explicitly stated to use Azure Firewall instead of NSGs.

Why candidates choose this

Candidates may think Azure Firewall is a more comprehensive solution for controlling traffic between tiers, or they may confuse application rules with network rules, assuming it can filter inbound traffic between VMs.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Go deeper

Related to this question

About these practice questions

This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on AZ-104

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Based on the exhibit, web servers can reach a backend VM only after it is added to a specific group. What should the administrator change to allow the traffic to match the existing NSG rule?

medium
  • A.Add api01's NIC to ASG-Api.
  • B.Move the deny rule to priority 100.
  • C.Change the source of the allow rule from ASG-Web to VirtualNetwork.
  • D.Place api01 in the same subnet as web01.

Why A: The exhibit shows that the NSG rule allows traffic from ASG-Web to ASG-Api. Since web01 is in ASG-Web, traffic from web01 to api01 is only permitted if api01 is a member of ASG-Api. Adding api01's NIC to ASG-Api ensures the destination matches the NSG rule, allowing the traffic.

Variation 2. A team manages many application VMs and backend VMs. The VM IP addresses change whenever they are rebuilt, but the same traffic rule must always allow the app tier to reach the backend tier on TCP 8443. What should the administrator use in the NSG rule?

easy
  • A.Static private IP addresses for each virtual machine.
  • B.Application Security Groups for the app and backend VMs.
  • C.A user-defined route between the app and backend subnets.
  • D.An availability set for each tier.

Why B: Application Security Groups (ASGs) allow you to group VMs logically and reference them directly in NSG rules without relying on static IP addresses. Since the VM IPs change on rebuild, ASGs ensure the NSG rule for TCP 8443 always applies to the correct app and backend tiers, regardless of IP changes.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.