Question 335 of 1,049
AZ-104 Implement and Manage Virtual Networking Practice Question
Exhibit
VNet-DevA address space: 10.20.0.0/16 VNet-DevB address space: 10.20.128.0/17 Peering status: Not created Deployment note: The peering wizard returns an address space overlap error.
Based on the exhibit, two development virtual networks must be peered so the workloads can exchange traffic directly. What should the administrator do first?
⚠ Common exam trap
It's easy for candidates to assume overlapping address spaces can be resolved with routing tweaks (like UDRs) or additional gateways, but Azure explicitly blocks VNet peering when address spaces overlap, requiring a non-overlapping address space as a prerequisite.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change one VNet to a non-overlapping address space before creating the peering.
Azure Virtual Network peering requires that the address spaces of the peered VNets do not overlap. Overlapping address spaces cause routing conflicts because Azure cannot determine which VNet should receive traffic destined for the overlapping range. Therefore, the administrator must first change one VNet to a non-overlapping address space before creating the peering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a VPN gateway in each VNet before attempting peering.
Why it's wrong here
Deploying VPN gateways in both VNets is intended for Site-to-Site, Point-to-Site, or VNet-to-VNet gateway-based connections, neither of which is required or permitted as a fix for standard VNet peering validation. Standard peering connects VNet address spaces directly through Azure's backbone without any gateway, and addition of VPN gateways does not alter the fact that the two address spaces overlap. Moreover, both peering and VNet-to-VNet VPN gateway connections have the same requirement for non-overlapping ranges, so gateways would fail with the same conflict.
When this WOULD be correct
A: Create a VPN gateway in each VNet before attempting peering. This would be correct if the question asked how to connect two VNets across different Azure regions or on-premises networks via a site-to-site VPN, where VPN gateways are required for encrypted tunnel connectivity.
- ✓
Change one VNet to a non-overlapping address space before creating the peering.
Why this is correct
Azure VNet peering does not allow overlapping address spaces. The first step is to redesign one network so its address range does not intersect the other. After the address conflict is removed, peering can be created normally and traffic can flow directly between the VNets.
- ✗
Add a user-defined route to each subnet so the VNets can ignore the overlap.
Why it's wrong here
User-defined routes (UDRs) control the next hop for traffic already flowing within a VNet by matching destination prefixes, but they are data-plane forwarding tables, not control-plane validation overrides. When Azure validates a new peering, it checks for overlapping address spaces before any route is consulted; an overlap triggers a failure that cannot be bypassed with routing policies. Even if peering succeeded, two VNets with overlapping ranges would cause ambiguous destination resolution and asymmetric traffic, so UDRs cannot make the overlap safe or 'ignored'.
When this WOULD be correct
When you need to force traffic between two peered VNets to go through a network virtual appliance (NVA) for inspection, you would add a UDR to each subnet pointing to the NVA's IP as the next hop.
- ✗
Enable service endpoints on both VNets to allow cross-network communication.
Why it's wrong here
Service endpoints extend an Azure VNet's identity to Azure PaaS services (e.g., Azure Storage, Azure SQL) by routing their traffic over the Microsoft backbone, but they do not provide any network-layer connectivity between two virtual networks. Peering is a separate peering resource built on the VNet address spaces; overlapping IP ranges cause the peering setup to fail during validation, or if you do connect, overlapping ranges make traffic ambiguous. Thus, enabling service endpoints has no effect on the overlap condition and cannot serve as a substitute for resolving the address conflict.
When this WOULD be correct
When the question asks how to allow a VNet to securely access an Azure Storage account without using a public IP, enabling service endpoints on the VNet and the storage account would be the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Change one VNet to a non-overlapping address space before creating the peering.Correct answer▾
Why this is correct
Azure VNet peering does not allow overlapping address spaces. The first step is to redesign one network so its address range does not intersect the other. After the address conflict is removed, peering can be created normally and traffic can flow directly between the VNets.
✗Create a VPN gateway in each VNet before attempting peering.Wrong answer — click to see why▾
Why this is wrong here
Azure VNet peering does not require VPN gateways; it uses the Microsoft backbone infrastructure. VPN gateways are only needed for site-to-site or point-to-site connections, not for VNet peering.
★ When this WOULD be the correct answer
A: Create a VPN gateway in each VNet before attempting peering. This would be correct if the question asked how to connect two VNets across different Azure regions or on-premises networks via a site-to-site VPN, where VPN gateways are required for encrypted tunnel connectivity.
Why candidates choose this
Candidates may confuse VNet peering with VPN-based connectivity, assuming that any inter-VNet communication requires a VPN gateway, especially when they have experience with on-premises network connections or cross-region scenarios.
✗Add a user-defined route to each subnet so the VNets can ignore the overlap.Wrong answer — click to see why▾
Why this is wrong here
User-defined routes cannot resolve overlapping IP address spaces; Azure VNet peering requires non-overlapping address spaces, and UDRs do not change the underlying address conflict.
★ When this WOULD be the correct answer
When you need to force traffic between two peered VNets to go through a network virtual appliance (NVA) for inspection, you would add a UDR to each subnet pointing to the NVA's IP as the next hop.
Why candidates choose this
Candidates may think UDRs can override address space conflicts, similar to how they can redirect traffic, but they misunderstand that peering itself fails with overlapping ranges regardless of routing.
✗Enable service endpoints on both VNets to allow cross-network communication.Wrong answer — click to see why▾
Why this is wrong here
Service endpoints do not enable cross-VNet communication; they allow VNet resources to access Azure PaaS services over the Microsoft backbone. Peering requires non-overlapping address spaces, not service endpoints.
★ When this WOULD be the correct answer
When the question asks how to allow a VNet to securely access an Azure Storage account without using a public IP, enabling service endpoints on the VNet and the storage account would be the correct answer.
Why candidates choose this
Candidates may confuse service endpoints with VNet peering, thinking both enable connectivity between VNets, or they may believe endpoints can bypass address overlap issues.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.