AZ-104 Implement and Manage Virtual Networking Practice Question
Exhibit
VNet-A address space: 10.0.0.0/16 VNet-B address space: 10.0.1.0/24 Attempt to peer VNet-A and VNet-B: Status: Failed Error: Address space overlap detected Requirement: Both VNets must remain connected, but the address spaces must not overlap.
Based on the exhibit, what is the best change so the VNet peering can be created successfully?
⚠ Common exam trap
It's easy for candidates to confuse overlapping address spaces with routing issues, thinking that adding route tables or enabling gateway transit will fix the peering failure, when in fact the fundamental requirement is non-overlapping IP ranges.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change VNet-B to a non-overlapping address space, such as 10.1.0.0/24.
VNet peering requires that the address spaces of the two virtual networks do not overlap. If VNet-A uses 10.0.0.0/16 and VNet-B also uses 10.0.0.0/16, they conflict, preventing peering. Changing VNet-B to a non-overlapping address space like 10.1.0.0/24 resolves this conflict, allowing the peering to be established.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Change VNet-B to a non-overlapping address space, such as 10.1.0.0/24.
Why this is correct
Azure VNet peering requires that the address spaces do not overlap. Changing VNet-B to a different range removes the conflict and allows peering to be created. The exact new range can vary, but it must not overlap with VNet-A’s 10.0.0.0/16 range.
- ✗
Add a route table to VNet-B before creating the peering.
Why it's wrong here
Adding a route table to VNet-B cannot resolve the overlapping address-space conflict because Azure validates that peered VNet address spaces do not overlap when the peering is created. Route tables only influence data-plane traffic forwarding by specifying next-hop types, but the peering resource will fail to build with an 'Overlapping address spaces' error before any packet routing occurs. Consequently, no amount of custom user-defined routes can make peering succeed; the underlying CIDR blocks must first be made non-overlapping.
When this WOULD be correct
In a scenario where VNet peering is established but traffic fails to route correctly between subnets, adding a route table with specific routes (e.g., to force traffic through a firewall or VPN gateway) would be the correct solution.
- ✗
Enable gateway transit on VNet-A.
Why it's wrong here
Enabling gateway transit on VNet-A configures the VNet to allow a peered VNet to use its VPN or ExpressRoute gateway, but this feature only becomes active after a peering link has been successfully established. Since VNet-A and VNet-B cannot be peered due to overlapping address spaces, there is no peering connection on which to enable transit, so the underlying conflict remains untouched. This option solves a routing and connectivity scenario for valid peerings, not the address allocation problem that blocks peering creation in the first place.
When this WOULD be correct
In a scenario where VNet-A needs to provide a VPN gateway to VNet-B for hybrid connectivity, and VNet-B does not have its own gateway, enabling gateway transit on VNet-A would allow VNet-B to use VNet-A's gateway.
- ✗
Resize VNet-A to 10.0.0.0/15 so both VNets fit.
Why it's wrong here
Resizing VNet-A from 10.0.0.0/16 to 10.0.0.0/15 would broaden its address range to 10.0.0.0–10.1.255.255, which actually increases the overlap with VNet-B's range rather than eliminating it. Azure does not even permit resizing a VNet to a larger prefix that would overlap with another VNet that needs to be peered, and even if the change were allowed, the peering would still be rejected because both VNets would share addresses in the 10.0.x.x block. This change is therefore counterproductive—it exaggerates the exact problem the question asks to fix.
When this WOULD be correct
This option would be correct if the question asked for a change to allow both VNets to communicate via a VPN gateway or to accommodate more resources within VNet-A without overlapping with VNet-B, but the address spaces must be non-overlapping for peering.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Change VNet-B to a non-overlapping address space, such as 10.1.0.0/24.Correct answer▾
Why this is correct
Azure VNet peering requires that the address spaces do not overlap. Changing VNet-B to a different range removes the conflict and allows peering to be created. The exact new range can vary, but it must not overlap with VNet-A’s 10.0.0.0/16 range.
✗Add a route table to VNet-B before creating the peering.Wrong answer — click to see why▾
Why this is wrong here
Adding a route table to VNet-B does not resolve overlapping address spaces, which is the root cause preventing VNet peering. VNet peering requires non-overlapping address ranges; routing tables are irrelevant to this prerequisite.
★ When this WOULD be the correct answer
In a scenario where VNet peering is established but traffic fails to route correctly between subnets, adding a route table with specific routes (e.g., to force traffic through a firewall or VPN gateway) would be the correct solution.
Why candidates choose this
Candidates may confuse connectivity issues with routing problems, assuming that a route table can fix peering failures, or they may think that route tables are required for all peering setups.
✗Enable gateway transit on VNet-A.Wrong answer — click to see why▾
Why this is wrong here
Enabling gateway transit on VNet-A is unrelated to the address overlap issue. The peering fails because VNet-A (10.0.0.0/16) and VNet-B (10.0.0.0/24) have overlapping address spaces, which is not resolved by gateway transit.
★ When this WOULD be the correct answer
In a scenario where VNet-A needs to provide a VPN gateway to VNet-B for hybrid connectivity, and VNet-B does not have its own gateway, enabling gateway transit on VNet-A would allow VNet-B to use VNet-A's gateway.
Why candidates choose this
Candidates may confuse gateway transit as a general fix for peering issues, or think it helps with routing between overlapping VNets, not realizing address overlap is a fundamental constraint.
✗Resize VNet-A to 10.0.0.0/15 so both VNets fit.Wrong answer — click to see why▾
Why this is wrong here
Resizing VNet-A to 10.0.0.0/15 would still overlap with VNet-B's 10.0.0.0/16, as 10.0.0.0/15 includes 10.0.0.0/16. Overlapping address spaces prevent VNet peering from being established.
★ When this WOULD be the correct answer
This option would be correct if the question asked for a change to allow both VNets to communicate via a VPN gateway or to accommodate more resources within VNet-A without overlapping with VNet-B, but the address spaces must be non-overlapping for peering.
Why candidates choose this
Candidates may think that expanding VNet-A's address space will resolve the overlap by making both VNets fit, but they overlook that the expanded range still contains the original overlapping subnet.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Azure Virtual Machine Deployment
Key term
VNet peering
VNet peering is a networking connection that links two virtual networks so they can communicate with each other as if they were a single network.
Key term
VNet
A virtual private network inside a cloud provider that lets you securely connect and isolate your cloud resources.
About these practice questions
One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.