Courseiva
Deploy and Manage Azure ComputemediumMultiple ChoiceObjective-mapped

AZ-104 Deploy and Manage Azure Compute Practice Question

An operations team must administer Windows and Linux VMs that have no public IP addresses. They want to connect from a browser without installing a VPN client and without exposing RDP or SSH to the internet. Which Azure service should they deploy?

⚠ Common exam trap

Candidates often confuse Azure Bastion with a VPN gateway or jump box, mistakenly thinking a VPN client or public IP is required for administrative access, when Bastion eliminates both by proxying connections directly from the Azure portal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Azure Bastion

Azure Bastion provides secure, seamless RDP and SSH connectivity to virtual machines directly from the Azure portal over TLS, without requiring a public IP address on the VM, a VPN client, or exposing RDP/SSH ports to the internet. It uses a hardened bastion host inside the virtual network, proxying connections via the browser, which satisfies the requirement for browser-based access without additional client software.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Azure Load Balancer

    Why it's wrong here

    Azure Load Balancer operates at Layer 4 and distributes TCP/UDP traffic to healthy back-end VM instances based on load-balancing rules. While it could forward RDP/SSH traffic to a VM's private IP, it only passes the connection through — it does not authenticate users, restrict source IPs, or render the underlying OS session in a secured browser context. Exposing management ports through a public load balancer frontend would also expand the attack surface, making it unsuitable for controlled administrative access compared to Bastion.

    When this WOULD be correct

    When the question asks for distributing incoming traffic across multiple VMs to ensure high availability and scalability, and the VMs have public IPs or are accessible via other means, Azure Load Balancer would be the correct answer.

  • Azure Bastion

    Why this is correct

    Azure Bastion provides secure browser-based RDP and SSH access to VMs in a virtual network without needing public IP addresses on the VMs. It also avoids exposing management ports directly to the internet and does not require the user to install a VPN client. This makes it a strong fit for controlled administrative access in locked-down environments.

  • VPN Gateway point-to-site only

    Why it's wrong here

    A point-to-site VPN Gateway creates an encrypted IPsec/IKE tunnel from an individual client machine to an Azure virtual network, requiring a VPN client and an authentication mechanism such as certificates or Azure AD. It does not provide browser-based, portal-native RDP or SSH console access to VMs, and it does not eliminate the need for the VM to be reachable and have the appropriate ports open internally. Even when a client is connected to the VNet, the user must launch a separate RDP/SSH client to reach the VM, so this is a network-level connectivity service rather than a centralized management access tool.

    When this WOULD be correct

    A question where users need secure remote access from remote locations without public IPs on VMs, but are allowed to install a VPN client on their devices, and the requirement is to avoid exposing RDP/SSH to the internet.

  • Application Gateway

    Why it's wrong here

    Azure Application Gateway is an HTTP/HTTPS Layer-7 load balancer designed to route web traffic based on URL paths or host headers, with features like TLS termination and Web Application Firewall. It does not natively proxy non-HTTP protocols such as RDP (port 3389) or SSH (port 22), nor does it offer interactive console or browser-based sessions to a VM's operating system. As a result, it cannot be used for administrative access even though it sits in front of a VNet's resources.

    When this WOULD be correct

    When the requirement is to expose web applications to the internet with SSL termination, URL-based routing, and Web Application Firewall (WAF) protection, and the VMs have private IPs behind the gateway.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Azure BastionCorrect answer

Why this is correct

Azure Bastion provides secure browser-based RDP and SSH access to VMs in a virtual network without needing public IP addresses on the VMs. It also avoids exposing management ports directly to the internet and does not require the user to install a VPN client. This makes it a strong fit for controlled administrative access in locked-down environments.

Azure Load BalancerWrong answer — click to see why

Why this is wrong here

Azure Load Balancer distributes network traffic but does not provide secure browser-based RDP/SSH access to VMs without public IPs; it operates at the transport layer and cannot replace a jump server or bastion host.

★ When this WOULD be the correct answer

When the question asks for distributing incoming traffic across multiple VMs to ensure high availability and scalability, and the VMs have public IPs or are accessible via other means, Azure Load Balancer would be the correct answer.

Why candidates choose this

Candidates may confuse load balancing with providing access, thinking that a load balancer can somehow enable connectivity to VMs without public IPs, or they may misremember that Bastion is a load balancer service.

VPN Gateway point-to-site onlyWrong answer — click to see why

Why this is wrong here

VPN Gateway point-to-site requires installing a VPN client on the browser machine, which contradicts the requirement of no VPN client installation.

★ When this WOULD be the correct answer

A question where users need secure remote access from remote locations without public IPs on VMs, but are allowed to install a VPN client on their devices, and the requirement is to avoid exposing RDP/SSH to the internet.

Why candidates choose this

Candidates may think point-to-site VPN provides browser-based access without public IPs, but overlook the client installation requirement.

Application GatewayWrong answer — click to see why

Why this is wrong here

Application Gateway is a layer-7 load balancer that requires public IPs for frontend and does not provide secure browser-based RDP/SSH access to VMs without public IPs.

★ When this WOULD be the correct answer

When the requirement is to expose web applications to the internet with SSL termination, URL-based routing, and Web Application Firewall (WAF) protection, and the VMs have private IPs behind the gateway.

Why candidates choose this

Candidates may confuse Application Gateway's web application delivery with remote access, or think its WAF and SSL features can secure RDP/SSH traffic.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.