easymultiple choiceObjective-mapped

Exhibit

NSG rule summary:
Rule 1: Allow-Web-To-Api, Source=ASG-Web, Destination=ASG-Api, Port=8443, Action=Allow, Priority=300
ASG membership:
- WebVM01 NIC = ASG-Web
- WebVM02 NIC = ASG-Web
- ApiVM01 NIC = none
- ApiVM02 NIC = none
Observed result: Connections from WebVM01 to ApiVM01 on TCP 8443 fail.

Based on the exhibit, the web tier can reach the API subnet by name, but the traffic is still blocked. What should the administrator do?

Question 1easymultiple choice
Full question →

Based on the exhibit, the web tier can reach the API subnet by name, but the traffic is still blocked. What should the administrator do?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Best answer

Add the API VM NICs to the destination application security group.

The allow rule is written for ASG-Api as the destination, but the exhibit shows that no API NICs are currently members of that ASG. Because NSG rules only match when both source and destination ASG membership is present, traffic will be blocked until the API VM NICs are added to ASG-Api.

B

Distractor review

Increase the priority number of the allow rule so it is evaluated earlier.

A higher priority number is evaluated later, not earlier, so this would make the rule less likely to match first.

C

Distractor review

Replace the ASG with a service endpoint on the API subnet.

Service endpoints are unrelated to NSG source and destination matching between virtual machine tiers.

D

Distractor review

Remove the web VMs from ASG-Web because ASGs block traffic by default.

ASGs do not block traffic by themselves; they are grouping objects used by NSG rules to match sets of NICs.

Common exam trap

Common exam trap: usable hosts are not the same as total addresses

Subnetting questions often tempt you into counting all addresses. In normal IPv4 subnets, the network and broadcast addresses are not usable host addresses.

Technical deep dive

How to think about this question

Subnetting questions test whether you can identify the network, broadcast address, usable range, mask and correct subnet. Slow down enough to calculate the block size correctly.

KKey Concepts to Remember

  • CIDR notation defines the prefix length.
  • Block size helps identify subnet boundaries.
  • Network and broadcast addresses are not usable hosts in normal IPv4 subnets.
  • The required host count determines the smallest suitable subnet.

TExam Day Tips

  • Write the block size before choosing the subnet.
  • Check whether the question asks for hosts, subnets or a specific address range.
  • Do not confuse /24, /25, /26 and /27 host counts.

Related practice questions

Related AZ-104 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this AZ-104 question test?

CIDR notation defines the prefix length.

What is the correct answer to this question?

The correct answer is: Add the API VM NICs to the destination application security group. — The NSG rule is correctly written to allow traffic from ASG-Web to ASG-Api, but the exhibit shows the destination ASG has no members. An ASG-based rule cannot match a VM NIC that is not assigned to the destination ASG. The fix is to add ApiVM01 and ApiVM02 NICs to ASG-Api so the allow rule can apply to the intended destination systems. Why others are wrong: Priority numbers work in ascending order, so making the number larger delays evaluation. Service endpoints are for Azure PaaS access and do not affect ASG-based security rules. ASGs are matching groups, not blocking objects; removing the web VMs would only break the source match and does not solve the issue.

What should I do if I get this AZ-104 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.