Courseiva
Implement and Manage Virtual NetworkinghardMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Virtual Networking Practice Question

After a user-defined route and VNet peering were added, a VM in a spoke subnet still does not reach 10.20.4.8 as expected. You need to confirm which route Azure will actually select on that VM's NIC, including any propagated routes and the route that wins. Which Network Watcher tool should you use?

⚠ Common exam trap

A common mix-up: candidates confuse 'IP flow verify' (which checks NSG rules) with route verification, but IP flow verify does not show the routing table or the winning route for a destination IP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Effective routes

Effective routes displays the actual routes applied to a network interface, including user-defined routes (UDRs), BGP-propagated routes, and VNet peering routes, along with the route priority (based on the longest prefix match and route source precedence). This allows you to see exactly which route wins for the destination 10.20.4.8, resolving why the VM cannot reach it despite the configured UDR and peering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Connection troubleshoot

    Why it's wrong here

    Connection troubleshoot tests live end-to-end connectivity from the source VM to a destination, reporting reachability, latency, and hop-by-hop details, but its goal is to validate whether traffic can flow, not to enumerate the route table entries on the NIC. While it may flag a routing issue as part of the diagnostic, it does not list the selected next hop or the specific user-defined route that the VM will use. Therefore it cannot replace the Effective routes view, which shows the actual route table selected for the NIC.

    When this WOULD be correct

    Connection troubleshoot would be correct if the question asked to diagnose why a VM cannot reach a specific IP address, including checking for network security group (NSG) rules, user-defined routes, and path latency, without needing to see the effective route table.

  • Effective routes

    Why this is correct

    Effective routes is the correct tool because it displays the complete route table that the network interface actually uses, combining system routes, user-defined routes, and VNet peering routes. After adding a user-defined route or a VNet peering, the blade shows the next hop type and next hop IP address for each destination prefix, including any 0.0.0.0/0 override. This lets you confirm exactly which route the VM will use for a given destination, based on longest prefix match and route priority.

  • IP flow verify

    Why it's wrong here

    IP flow verify tests whether a specific packet (source IP, destination IP, port, and protocol) is allowed or denied by the network security group rules on a VM or subnet. It evaluates only NSG rule evaluation, not the route table; the result can be 'allowed' or 'denied' based on security rules, but it says nothing about whether the packet will be routed through a VNet peering or a user-defined route. To determine the next hop for a destination, you must check Effective routes, because routing and NSG filtering are separate functions.

    When this WOULD be correct

    IP flow verify would be correct if the question asked: 'You need to test whether a specific TCP packet from a VM to 10.20.4.8 is allowed or blocked by NSG rules, and you suspect a security rule is causing the issue.'

  • Packet capture

    Why it's wrong here

    Packet capture collects the actual network traffic sent and received by the VM, saving packets in .pcap or other formats for offline analysis of payloads, retransmissions, or application behavior. It provides no visibility into the Azure control plane's route selection logic, so it cannot reveal which route table entry or next hop applies to a destination. Even if you capture packets, you would need Effective routes to determine whether the VM attempted to send traffic via a peering gateway, virtual appliance, or the internet.

    When this WOULD be correct

    Packet capture would be correct when you need to inspect actual packets sent/received by a VM to diagnose issues like packet loss, retransmissions, or protocol-level problems, such as verifying if traffic is being dropped by a firewall or if TCP handshake completes.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Effective routesCorrect answer

Why this is correct

Effective routes is the correct tool because it displays the complete route table that the network interface actually uses, combining system routes, user-defined routes, and VNet peering routes. After adding a user-defined route or a VNet peering, the blade shows the next hop type and next hop IP address for each destination prefix, including any 0.0.0.0/0 override. This lets you confirm exactly which route the VM will use for a given destination, based on longest prefix match and route priority.

Connection troubleshootWrong answer — click to see why

Why this is wrong here

Connection troubleshoot tests end-to-end connectivity between a source and destination, but it does not show the effective route table applied to a specific NIC. The question asks to confirm which route Azure will select, which requires viewing the effective routes, not testing connectivity.

★ When this WOULD be the correct answer

Connection troubleshoot would be correct if the question asked to diagnose why a VM cannot reach a specific IP address, including checking for network security group (NSG) rules, user-defined routes, and path latency, without needing to see the effective route table.

Why candidates choose this

Candidates may think that testing connectivity (Connection troubleshoot) will reveal routing issues, but it only reports connectivity success/failure and potential issues, not the actual route selection logic.

IP flow verifyWrong answer — click to see why

Why this is wrong here

IP flow verify tests connectivity by checking if traffic is allowed or denied by security rules, but it does not show the actual route selected from multiple possible routes, including propagated routes. The question asks for confirming which route wins, which requires effective routes.

★ When this WOULD be the correct answer

IP flow verify would be correct if the question asked: 'You need to test whether a specific TCP packet from a VM to 10.20.4.8 is allowed or blocked by NSG rules, and you suspect a security rule is causing the issue.'

Why candidates choose this

Candidates may confuse connectivity testing with route verification, thinking IP flow verify can also diagnose routing issues because it tests end-to-end connectivity.

Packet captureWrong answer — click to see why

Why this is wrong here

Packet capture captures raw network traffic but does not analyze routing tables or show which route is selected for a specific destination. It cannot confirm the effective route on a VM's NIC.

★ When this WOULD be the correct answer

Packet capture would be correct when you need to inspect actual packets sent/received by a VM to diagnose issues like packet loss, retransmissions, or protocol-level problems, such as verifying if traffic is being dropped by a firewall or if TCP handshake completes.

Why candidates choose this

Candidates may think packet capture is the most comprehensive tool for network troubleshooting, not realizing that the question specifically asks about route selection, which is a routing table analysis problem, not a packet-level inspection.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.