AZ-104 Implement and Manage Virtual Networking Practice Question
Administrators need to connect to Windows and Linux VMs from the Azure portal using a browser. The VMs do not have public IP addresses, and the security team does not want a VPN client installed on admin laptops. Which service should be deployed?
⚠ Common exam trap
Watch out — candidates often confuse Azure Bastion with a VPN gateway or assume that an NSG with RDP/SSH rules alone is sufficient for secure browser-based access, overlooking the requirement for no public IPs and no client software.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Bastion
Azure Bastion provides secure, seamless RDP and SSH connectivity to Azure VMs directly from the Azure portal over TLS, without requiring public IP addresses on the VMs or a VPN client on the admin's laptop. It uses a hardened bastion host deployed in the same virtual network, acting as a jump server that brokers browser-based connections, meeting both the security and connectivity requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure VPN Gateway
Why it's wrong here
Azure VPN Gateway establishes an encrypted IPsec/IKE tunnel between an on-premises network or client and the virtual network, enabling connectivity to the VNet address space. However, it is a network-layer connectivity service, not a session gateway; administrators still need a remote desktop client or SSH client and a reachable IP address for each VM. It doesn't provide browser-based, portal-integrated management sessions, and it doesn't prevent VMs from requiring public IPs if they aren't reachable over the tunnel. Thus it doesn't fulfill the specific 'connect from browser' requirement.
When this WOULD be correct
An exam question where administrators need to securely connect on-premises networks to Azure VMs over the internet, and installing a VPN client on admin laptops is acceptable, would make Azure VPN Gateway the correct answer.
- ✗
Azure Load Balancer
Why it's wrong here
Azure Load Balancer is a Layer-4 traffic distribution service that spreads incoming requests across backend pool VMs and can apply health probes and NAT rules. While inbound NAT rules can technically forward a frontend port to a VM's RDP/SSH port, that exposes management endpoints through the load balancer's public frontend and adds configuration overhead per VM. It provides no authentication, no session recording, and no browser-based console, so it isn't designed or recommended as a secure shell access solution. In contrast, Azure Bastion is purpose-built for secure administrative connectivity.
When this WOULD be correct
A question requiring high availability and load distribution for web applications across multiple VMs, where the goal is to distribute incoming traffic and ensure fault tolerance, not to provide secure administrative access.
- ✗
A network security group with RDP and SSH rules
Why it's wrong here
An NSG is a distributed firewall that filters allowed or denied inbound and outbound traffic at the subnet or NIC level using rules such as 3389 (RDP) and 22 (SSH). Configuring allow rules only opens a path if the VM has a public IP or a routed private address that the administrator can reach; it does not create a secure, auditing-friendly management plane. Opening RDP/SSH to the internet can expose administrative ports to brute-force attacks. Therefore, an NSG is a supporting security control, not the actual secure connectivity mechanism required.
When this WOULD be correct
This option would be correct in a scenario where VMs already have public IP addresses and the question asks how to restrict inbound RDP/SSH access to specific source IPs or deny all inbound traffic except from a management subnet, using NSG rules.
- ✓
Azure Bastion
Why this is correct
Azure Bastion provides secure browser-based RDP and SSH to VMs that have no public IP addresses. It keeps management traffic inside Azure and avoids exposing administrative ports to the internet or requiring a client VPN on the administrator's device.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Azure BastionCorrect answer▾
Why this is correct
Azure Bastion provides secure browser-based RDP and SSH to VMs that have no public IP addresses. It keeps management traffic inside Azure and avoids exposing administrative ports to the internet or requiring a client VPN on the administrator's device.
✗Azure VPN GatewayWrong answer — click to see why▾
Why this is wrong here
Azure VPN Gateway requires a VPN client installed on admin laptops to establish a site-to-site or point-to-site connection, which conflicts with the security team's requirement of no VPN client installation.
★ When this WOULD be the correct answer
An exam question where administrators need to securely connect on-premises networks to Azure VMs over the internet, and installing a VPN client on admin laptops is acceptable, would make Azure VPN Gateway the correct answer.
Why candidates choose this
Candidates may think VPN Gateway provides browser-based connectivity without client software, but it actually requires a VPN client for point-to-site connections, making it tempting but incorrect here.
✗Azure Load BalancerWrong answer — click to see why▾
Why this is wrong here
Azure Load Balancer distributes traffic to VMs but does not provide inbound RDP/SSH connectivity without public IPs or a jump box; it operates at the transport layer and cannot replace a secure bastion host for browser-based access.
★ When this WOULD be the correct answer
A question requiring high availability and load distribution for web applications across multiple VMs, where the goal is to distribute incoming traffic and ensure fault tolerance, not to provide secure administrative access.
Why candidates choose this
Candidates may think a load balancer can be used to reach VMs internally, confusing its traffic distribution role with a gateway for administrative access, especially when VMs lack public IPs.
✗A network security group with RDP and SSH rulesWrong answer — click to see why▾
Why this is wrong here
A network security group (NSG) with RDP and SSH rules controls inbound traffic at the subnet or NIC level, but it does not provide browser-based connectivity without public IPs or a VPN. The VMs lack public IPs, so NSG rules alone cannot enable access from the Azure portal.
★ When this WOULD be the correct answer
This option would be correct in a scenario where VMs already have public IP addresses and the question asks how to restrict inbound RDP/SSH access to specific source IPs or deny all inbound traffic except from a management subnet, using NSG rules.
Why candidates choose this
Candidates may think that allowing RDP/SSH in an NSG is sufficient for connectivity, overlooking the requirement for browser-based access without public IPs or VPN clients.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Managed Identities for Azure Resources
Key term
Azure Bastion
Azure Bastion is a fully managed PaaS service that provides secure and seamless RDP and SSH connectivity to virtual machines directly through the Azure portal without exposing public IP addresses.
Key term
Azure portal
The Azure portal is a web-based, unified console that lets you build, manage, and monitor everything from simple web apps to complex cloud deployments using a graphical user interface.
About these practice questions
This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.