Courseiva
Implement and Manage Virtual NetworkingmediumMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Virtual Networking Practice Question

Administrators need to connect to Windows and Linux VMs from the Azure portal using a browser. The VMs do not have public IP addresses, and the security team does not want a VPN client installed on admin laptops. Which service should be deployed?

⚠ Common exam trap

Watch out — candidates often confuse Azure Bastion with a VPN gateway or assume that an NSG with RDP/SSH rules alone is sufficient for secure browser-based access, overlooking the requirement for no public IPs and no client software.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Azure Bastion

Azure Bastion provides secure, seamless RDP and SSH connectivity to Azure VMs directly from the Azure portal over TLS, without requiring public IP addresses on the VMs or a VPN client on the admin's laptop. It uses a hardened bastion host deployed in the same virtual network, acting as a jump server that brokers browser-based connections, meeting both the security and connectivity requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Azure VPN Gateway

    Why it's wrong here

    Azure VPN Gateway establishes an encrypted IPsec/IKE tunnel between an on-premises network or client and the virtual network, enabling connectivity to the VNet address space. However, it is a network-layer connectivity service, not a session gateway; administrators still need a remote desktop client or SSH client and a reachable IP address for each VM. It doesn't provide browser-based, portal-integrated management sessions, and it doesn't prevent VMs from requiring public IPs if they aren't reachable over the tunnel. Thus it doesn't fulfill the specific 'connect from browser' requirement.

    When this WOULD be correct

    An exam question where administrators need to securely connect on-premises networks to Azure VMs over the internet, and installing a VPN client on admin laptops is acceptable, would make Azure VPN Gateway the correct answer.

  • Azure Load Balancer

    Why it's wrong here

    Azure Load Balancer is a Layer-4 traffic distribution service that spreads incoming requests across backend pool VMs and can apply health probes and NAT rules. While inbound NAT rules can technically forward a frontend port to a VM's RDP/SSH port, that exposes management endpoints through the load balancer's public frontend and adds configuration overhead per VM. It provides no authentication, no session recording, and no browser-based console, so it isn't designed or recommended as a secure shell access solution. In contrast, Azure Bastion is purpose-built for secure administrative connectivity.

    When this WOULD be correct

    A question requiring high availability and load distribution for web applications across multiple VMs, where the goal is to distribute incoming traffic and ensure fault tolerance, not to provide secure administrative access.

  • A network security group with RDP and SSH rules

    Why it's wrong here

    An NSG is a distributed firewall that filters allowed or denied inbound and outbound traffic at the subnet or NIC level using rules such as 3389 (RDP) and 22 (SSH). Configuring allow rules only opens a path if the VM has a public IP or a routed private address that the administrator can reach; it does not create a secure, auditing-friendly management plane. Opening RDP/SSH to the internet can expose administrative ports to brute-force attacks. Therefore, an NSG is a supporting security control, not the actual secure connectivity mechanism required.

    When this WOULD be correct

    This option would be correct in a scenario where VMs already have public IP addresses and the question asks how to restrict inbound RDP/SSH access to specific source IPs or deny all inbound traffic except from a management subnet, using NSG rules.

  • Azure Bastion

    Why this is correct

    Azure Bastion provides secure browser-based RDP and SSH to VMs that have no public IP addresses. It keeps management traffic inside Azure and avoids exposing administrative ports to the internet or requiring a client VPN on the administrator's device.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Azure BastionCorrect answer

Why this is correct

Azure Bastion provides secure browser-based RDP and SSH to VMs that have no public IP addresses. It keeps management traffic inside Azure and avoids exposing administrative ports to the internet or requiring a client VPN on the administrator's device.

Azure VPN GatewayWrong answer — click to see why

Why this is wrong here

Azure VPN Gateway requires a VPN client installed on admin laptops to establish a site-to-site or point-to-site connection, which conflicts with the security team's requirement of no VPN client installation.

★ When this WOULD be the correct answer

An exam question where administrators need to securely connect on-premises networks to Azure VMs over the internet, and installing a VPN client on admin laptops is acceptable, would make Azure VPN Gateway the correct answer.

Why candidates choose this

Candidates may think VPN Gateway provides browser-based connectivity without client software, but it actually requires a VPN client for point-to-site connections, making it tempting but incorrect here.

Azure Load BalancerWrong answer — click to see why

Why this is wrong here

Azure Load Balancer distributes traffic to VMs but does not provide inbound RDP/SSH connectivity without public IPs or a jump box; it operates at the transport layer and cannot replace a secure bastion host for browser-based access.

★ When this WOULD be the correct answer

A question requiring high availability and load distribution for web applications across multiple VMs, where the goal is to distribute incoming traffic and ensure fault tolerance, not to provide secure administrative access.

Why candidates choose this

Candidates may think a load balancer can be used to reach VMs internally, confusing its traffic distribution role with a gateway for administrative access, especially when VMs lack public IPs.

A network security group with RDP and SSH rulesWrong answer — click to see why

Why this is wrong here

A network security group (NSG) with RDP and SSH rules controls inbound traffic at the subnet or NIC level, but it does not provide browser-based connectivity without public IPs or a VPN. The VMs lack public IPs, so NSG rules alone cannot enable access from the Azure portal.

★ When this WOULD be the correct answer

This option would be correct in a scenario where VMs already have public IP addresses and the question asks how to restrict inbound RDP/SSH access to specific source IPs or deny all inbound traffic except from a management subnet, using NSG rules.

Why candidates choose this

Candidates may think that allowing RDP/SSH in an NSG is sufficient for connectivity, overlooking the requirement for browser-based access without public IPs or VPN clients.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Go deeper

Related to this question

About these practice questions

This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.