AZ-104 Implement and Manage Virtual Networking Practice Question
Exhibit
NSG rule summary: Rule 1: Allow-Web-To-Api, Source=ASG-Web, Destination=ASG-Api, Port=8443, Action=Allow, Priority=300 ASG membership: - WebVM01 NIC = ASG-Web - WebVM02 NIC = ASG-Web - ApiVM01 NIC = none - ApiVM02 NIC = none Observed result: Connections from WebVM01 to ApiVM01 on TCP 8443 fail.
Based on the exhibit, the web tier can reach the API subnet by name, but the traffic is still blocked. What should the administrator do?
⚠ Common exam trap
Watch out — candidates often confuse name resolution with network connectivity, assuming that if a VM can resolve another VM's name via DNS, traffic must be allowed, but NSG rules are evaluated independently of DNS resolution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the API VM NICs to the destination application security group.
The web tier can resolve the API subnet's name, but traffic is still blocked. This indicates that the network security group (NSG) rules are not correctly configured to allow traffic from the web VMs (in ASG-Web) to the API VMs (in ASG-API). By adding the API VM NICs to the destination application security group (ASG), the NSG rule that references ASG-API as the destination will match the API VMs, allowing the traffic. Without this, the NSG rule may be referencing an empty or incorrect destination, causing the traffic to be denied by the default deny rule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add the API VM NICs to the destination application security group.
Why this is correct
The allow rule is written for ASG-Api as the destination, but the exhibit shows that no API NICs are currently members of that ASG. Because NSG rules only match when both source and destination ASG membership is present, traffic will be blocked until the API VM NICs are added to ASG-Api.
- ✗
Increase the priority number of the allow rule so it is evaluated earlier.
Why it's wrong here
NSG rule priority is evaluated from lowest numeric value to highest, so a rule with priority 100 is processed before one with priority 200. Increasing the numeric priority of the allow rule (e.g., from 100 to 200) would cause it to be evaluated later, directly contradicting the intended 'earlier' effect; even if the priority were lowered, the rule still would not match because the destination ASG-Api currently contains no API NICs. Without any members in ASG-Api, the destination field has no concrete IP addresses to compare against the actual packet destination, so no amount of priority reordering can make the rule effective.
When this WOULD be correct
This option would be correct if the allow rule existed but was being overridden by a higher-priority deny rule. In that case, increasing the priority number (making it lower) would allow the allow rule to be evaluated before the deny rule.
- ✗
Replace the ASG with a service endpoint on the API subnet.
Why it's wrong here
Service endpoints are designed to secure outbound traffic from a subnet to specific Azure PaaS services (e.g., Storage, SQL) by providing a direct, private path; they do not influence NSG rule matching between virtual machine NICs. Replacing the destination ASG with a service endpoint would remove the ASG reference entirely, leaving the NSG rule's destination as undefined for VM-to-VM traffic, so the allow rule could not match the API tier's IP addresses. The core issue—that API NICs are not members of ASG-Api—would remain completely unaddressed, and the traffic would still be blocked.
When this WOULD be correct
If the question were about securely accessing an Azure PaaS service (e.g., Azure SQL or Storage) from the API subnet without using a public endpoint, adding a service endpoint on the API subnet would be correct.
- ✗
Remove the web VMs from ASG-Web because ASGs block traffic by default.
Why it's wrong here
Application security groups (ASGs) are purely logical grouping constructs for NICs; they do not enforce or block traffic on their own—only NSG rules with allow or deny actions applied to those groups take effect. Removing the web VMs from ASG-Web would remove the source IPs from the rule's scope, causing the NSG to treat the connection as if from an unknown source that does not match the allow rule, effectively blocking the traffic due to the implicit deny rule, not because ASG-Web blocks anything. The correct fix is to add the API NICs to the destination ASG-Api so the existing allow rule can match both the source and destination groups.
When this WOULD be correct
If the question described a scenario where VMs in an ASG were incorrectly configured with a deny-all rule or the ASG was misapplied, removing them from the ASG could be correct to restore connectivity.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Add the API VM NICs to the destination application security group.Correct answer▾
Why this is correct
The allow rule is written for ASG-Api as the destination, but the exhibit shows that no API NICs are currently members of that ASG. Because NSG rules only match when both source and destination ASG membership is present, traffic will be blocked until the API VM NICs are added to ASG-Api.
✗Increase the priority number of the allow rule so it is evaluated earlier.Wrong answer — click to see why▾
Why this is wrong here
Increasing the priority number (making it higher) would cause the rule to be evaluated later, not earlier, which would not resolve the traffic block. The issue is that the allow rule's destination is not correctly targeting the API VMs, not its priority.
★ When this WOULD be the correct answer
This option would be correct if the allow rule existed but was being overridden by a higher-priority deny rule. In that case, increasing the priority number (making it lower) would allow the allow rule to be evaluated before the deny rule.
Why candidates choose this
Candidates may confuse priority numbers with evaluation order, thinking a higher number means higher priority, or they may assume that traffic is blocked due to rule ordering rather than misconfiguration of the destination.
✗Replace the ASG with a service endpoint on the API subnet.Wrong answer — click to see why▾
Why this is wrong here
Service endpoints secure Azure service access from a subnet, not traffic between VNets or subnets. The issue is east-west traffic blocking, which ASGs solve; service endpoints don't replace ASGs for intra-VNet filtering.
★ When this WOULD be the correct answer
If the question were about securely accessing an Azure PaaS service (e.g., Azure SQL or Storage) from the API subnet without using a public endpoint, adding a service endpoint on the API subnet would be correct.
Why candidates choose this
Candidates may confuse service endpoints with network security groups, thinking they can replace ASGs for general traffic filtering, or they might assume service endpoints provide broader connectivity control.
✗Remove the web VMs from ASG-Web because ASGs block traffic by default.Wrong answer — click to see why▾
Why this is wrong here
ASGs do not block traffic by default; they only define rules for allowed traffic. Removing VMs from an ASG would not resolve the issue of blocked traffic to the API subnet.
★ When this WOULD be the correct answer
If the question described a scenario where VMs in an ASG were incorrectly configured with a deny-all rule or the ASG was misapplied, removing them from the ASG could be correct to restore connectivity.
Why candidates choose this
Candidates may mistakenly think ASGs act like firewalls that block all traffic by default, rather than understanding they are used to group VMs for applying network security rules.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Network Security Groups (NSG)
Key term
Network Security Group
A Network Security Group is a set of rules that controls inbound and outbound traffic to Azure resources like virtual machines and subnets.
Key term
Network security
Network security is the practice of protecting a computer network from unauthorized access, misuse, malfunction, modification, destruction, or improper disclosure, ensuring the confidentiality, integrity, and availability of data and resources.
About these practice questions
This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.