Courseiva
Implement and Manage Virtual NetworkingeasyMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Virtual Networking Practice Question

Exhibit

VNet-A address space: 10.0.0.0/16
VNet-B address space: 10.0.1.0/24
Attempt to peer VNet-A and VNet-B:
Status: Failed
Error: Address space overlap detected

Requirement: Both VNets must remain connected, but the address spaces must not overlap.

Based on the exhibit, what is the best change so the VNet peering can be created successfully?

⚠ Common exam trap

It's easy for candidates to confuse overlapping address spaces with routing issues, thinking that adding route tables or enabling gateway transit will fix the peering failure, when in fact the fundamental requirement is non-overlapping IP ranges.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Change VNet-B to a non-overlapping address space, such as 10.1.0.0/24.

VNet peering requires that the address spaces of the two virtual networks do not overlap. If VNet-A uses 10.0.0.0/16 and VNet-B also uses 10.0.0.0/16, they conflict, preventing peering. Changing VNet-B to a non-overlapping address space like 10.1.0.0/24 resolves this conflict, allowing the peering to be established.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Change VNet-B to a non-overlapping address space, such as 10.1.0.0/24.

    Why this is correct

    Azure VNet peering requires that the address spaces do not overlap. Changing VNet-B to a different range removes the conflict and allows peering to be created. The exact new range can vary, but it must not overlap with VNet-A’s 10.0.0.0/16 range.

  • Add a route table to VNet-B before creating the peering.

    Why it's wrong here

    Adding a route table to VNet-B cannot resolve the overlapping address-space conflict because Azure validates that peered VNet address spaces do not overlap when the peering is created. Route tables only influence data-plane traffic forwarding by specifying next-hop types, but the peering resource will fail to build with an 'Overlapping address spaces' error before any packet routing occurs. Consequently, no amount of custom user-defined routes can make peering succeed; the underlying CIDR blocks must first be made non-overlapping.

    When this WOULD be correct

    In a scenario where VNet peering is established but traffic fails to route correctly between subnets, adding a route table with specific routes (e.g., to force traffic through a firewall or VPN gateway) would be the correct solution.

  • Enable gateway transit on VNet-A.

    Why it's wrong here

    Enabling gateway transit on VNet-A configures the VNet to allow a peered VNet to use its VPN or ExpressRoute gateway, but this feature only becomes active after a peering link has been successfully established. Since VNet-A and VNet-B cannot be peered due to overlapping address spaces, there is no peering connection on which to enable transit, so the underlying conflict remains untouched. This option solves a routing and connectivity scenario for valid peerings, not the address allocation problem that blocks peering creation in the first place.

    When this WOULD be correct

    In a scenario where VNet-A needs to provide a VPN gateway to VNet-B for hybrid connectivity, and VNet-B does not have its own gateway, enabling gateway transit on VNet-A would allow VNet-B to use VNet-A's gateway.

  • Resize VNet-A to 10.0.0.0/15 so both VNets fit.

    Why it's wrong here

    Resizing VNet-A from 10.0.0.0/16 to 10.0.0.0/15 would broaden its address range to 10.0.0.0–10.1.255.255, which actually increases the overlap with VNet-B's range rather than eliminating it. Azure does not even permit resizing a VNet to a larger prefix that would overlap with another VNet that needs to be peered, and even if the change were allowed, the peering would still be rejected because both VNets would share addresses in the 10.0.x.x block. This change is therefore counterproductive—it exaggerates the exact problem the question asks to fix.

    When this WOULD be correct

    This option would be correct if the question asked for a change to allow both VNets to communicate via a VPN gateway or to accommodate more resources within VNet-A without overlapping with VNet-B, but the address spaces must be non-overlapping for peering.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Change VNet-B to a non-overlapping address space, such as 10.1.0.0/24.Correct answer

Why this is correct

Azure VNet peering requires that the address spaces do not overlap. Changing VNet-B to a different range removes the conflict and allows peering to be created. The exact new range can vary, but it must not overlap with VNet-A’s 10.0.0.0/16 range.

Add a route table to VNet-B before creating the peering.Wrong answer — click to see why

Why this is wrong here

Adding a route table to VNet-B does not resolve overlapping address spaces, which is the root cause preventing VNet peering. VNet peering requires non-overlapping address ranges; routing tables are irrelevant to this prerequisite.

★ When this WOULD be the correct answer

In a scenario where VNet peering is established but traffic fails to route correctly between subnets, adding a route table with specific routes (e.g., to force traffic through a firewall or VPN gateway) would be the correct solution.

Why candidates choose this

Candidates may confuse connectivity issues with routing problems, assuming that a route table can fix peering failures, or they may think that route tables are required for all peering setups.

Enable gateway transit on VNet-A.Wrong answer — click to see why

Why this is wrong here

Enabling gateway transit on VNet-A is unrelated to the address overlap issue. The peering fails because VNet-A (10.0.0.0/16) and VNet-B (10.0.0.0/24) have overlapping address spaces, which is not resolved by gateway transit.

★ When this WOULD be the correct answer

In a scenario where VNet-A needs to provide a VPN gateway to VNet-B for hybrid connectivity, and VNet-B does not have its own gateway, enabling gateway transit on VNet-A would allow VNet-B to use VNet-A's gateway.

Why candidates choose this

Candidates may confuse gateway transit as a general fix for peering issues, or think it helps with routing between overlapping VNets, not realizing address overlap is a fundamental constraint.

Resize VNet-A to 10.0.0.0/15 so both VNets fit.Wrong answer — click to see why

Why this is wrong here

Resizing VNet-A to 10.0.0.0/15 would still overlap with VNet-B's 10.0.0.0/16, as 10.0.0.0/15 includes 10.0.0.0/16. Overlapping address spaces prevent VNet peering from being established.

★ When this WOULD be the correct answer

This option would be correct if the question asked for a change to allow both VNets to communicate via a VPN gateway or to accommodate more resources within VNet-A without overlapping with VNet-B, but the address spaces must be non-overlapping for peering.

Why candidates choose this

Candidates may think that expanding VNet-A's address space will resolve the overlap by making both VNets fit, but they overlook that the expanded range still contains the original overlapping subnet.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.