AZ-104 Implement and Manage Virtual Networking Practice Question
After a user-defined route and VNet peering were added, a VM in a spoke subnet still does not reach 10.20.4.8 as expected. You need to confirm which route Azure will actually select on that VM's NIC, including any propagated routes and the route that wins. Which Network Watcher tool should you use?
⚠ Common exam trap
A common mix-up: candidates confuse 'IP flow verify' (which checks NSG rules) with route verification, but IP flow verify does not show the routing table or the winning route for a destination IP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Effective routes
Effective routes displays the actual routes applied to a network interface, including user-defined routes (UDRs), BGP-propagated routes, and VNet peering routes, along with the route priority (based on the longest prefix match and route source precedence). This allows you to see exactly which route wins for the destination 10.20.4.8, resolving why the VM cannot reach it despite the configured UDR and peering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Connection troubleshoot
Why it's wrong here
Connection troubleshoot tests live end-to-end connectivity from the source VM to a destination, reporting reachability, latency, and hop-by-hop details, but its goal is to validate whether traffic can flow, not to enumerate the route table entries on the NIC. While it may flag a routing issue as part of the diagnostic, it does not list the selected next hop or the specific user-defined route that the VM will use. Therefore it cannot replace the Effective routes view, which shows the actual route table selected for the NIC.
When this WOULD be correct
Connection troubleshoot would be correct if the question asked to diagnose why a VM cannot reach a specific IP address, including checking for network security group (NSG) rules, user-defined routes, and path latency, without needing to see the effective route table.
- ✓
Effective routes
Why this is correct
Effective routes is the correct tool because it displays the complete route table that the network interface actually uses, combining system routes, user-defined routes, and VNet peering routes. After adding a user-defined route or a VNet peering, the blade shows the next hop type and next hop IP address for each destination prefix, including any 0.0.0.0/0 override. This lets you confirm exactly which route the VM will use for a given destination, based on longest prefix match and route priority.
- ✗
IP flow verify
Why it's wrong here
IP flow verify tests whether a specific packet (source IP, destination IP, port, and protocol) is allowed or denied by the network security group rules on a VM or subnet. It evaluates only NSG rule evaluation, not the route table; the result can be 'allowed' or 'denied' based on security rules, but it says nothing about whether the packet will be routed through a VNet peering or a user-defined route. To determine the next hop for a destination, you must check Effective routes, because routing and NSG filtering are separate functions.
When this WOULD be correct
IP flow verify would be correct if the question asked: 'You need to test whether a specific TCP packet from a VM to 10.20.4.8 is allowed or blocked by NSG rules, and you suspect a security rule is causing the issue.'
- ✗
Packet capture
Why it's wrong here
Packet capture collects the actual network traffic sent and received by the VM, saving packets in .pcap or other formats for offline analysis of payloads, retransmissions, or application behavior. It provides no visibility into the Azure control plane's route selection logic, so it cannot reveal which route table entry or next hop applies to a destination. Even if you capture packets, you would need Effective routes to determine whether the VM attempted to send traffic via a peering gateway, virtual appliance, or the internet.
When this WOULD be correct
Packet capture would be correct when you need to inspect actual packets sent/received by a VM to diagnose issues like packet loss, retransmissions, or protocol-level problems, such as verifying if traffic is being dropped by a firewall or if TCP handshake completes.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Effective routesCorrect answer▾
Why this is correct
Effective routes is the correct tool because it displays the complete route table that the network interface actually uses, combining system routes, user-defined routes, and VNet peering routes. After adding a user-defined route or a VNet peering, the blade shows the next hop type and next hop IP address for each destination prefix, including any 0.0.0.0/0 override. This lets you confirm exactly which route the VM will use for a given destination, based on longest prefix match and route priority.
✗Connection troubleshootWrong answer — click to see why▾
Why this is wrong here
Connection troubleshoot tests end-to-end connectivity between a source and destination, but it does not show the effective route table applied to a specific NIC. The question asks to confirm which route Azure will select, which requires viewing the effective routes, not testing connectivity.
★ When this WOULD be the correct answer
Connection troubleshoot would be correct if the question asked to diagnose why a VM cannot reach a specific IP address, including checking for network security group (NSG) rules, user-defined routes, and path latency, without needing to see the effective route table.
Why candidates choose this
Candidates may think that testing connectivity (Connection troubleshoot) will reveal routing issues, but it only reports connectivity success/failure and potential issues, not the actual route selection logic.
✗IP flow verifyWrong answer — click to see why▾
Why this is wrong here
IP flow verify tests connectivity by checking if traffic is allowed or denied by security rules, but it does not show the actual route selected from multiple possible routes, including propagated routes. The question asks for confirming which route wins, which requires effective routes.
★ When this WOULD be the correct answer
IP flow verify would be correct if the question asked: 'You need to test whether a specific TCP packet from a VM to 10.20.4.8 is allowed or blocked by NSG rules, and you suspect a security rule is causing the issue.'
Why candidates choose this
Candidates may confuse connectivity testing with route verification, thinking IP flow verify can also diagnose routing issues because it tests end-to-end connectivity.
✗Packet captureWrong answer — click to see why▾
Why this is wrong here
Packet capture captures raw network traffic but does not analyze routing tables or show which route is selected for a specific destination. It cannot confirm the effective route on a VM's NIC.
★ When this WOULD be the correct answer
Packet capture would be correct when you need to inspect actual packets sent/received by a VM to diagnose issues like packet loss, retransmissions, or protocol-level problems, such as verifying if traffic is being dropped by a firewall or if TCP handshake completes.
Why candidates choose this
Candidates may think packet capture is the most comprehensive tool for network troubleshooting, not realizing that the question specifically asks about route selection, which is a routing table analysis problem, not a packet-level inspection.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Managed Identities for Azure Resources
Key term
VNet
A virtual private network inside a cloud provider that lets you securely connect and isolate your cloud resources.
Key term
VNet peering
VNet peering is a networking connection that links two virtual networks so they can communicate with each other as if they were a single network.
About these practice questions
One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.