Courseiva
Implement and Manage Virtual NetworkingmediumMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Virtual Networking Practice Question

Exhibit

NSG: App-NSG inbound rules; Priority 100: Deny TCP 443, Source=VirtualNetwork, Destination=Any; Priority 110: Allow TCP 443, Source=WebTierASG, Destination=DbTierASG; Priority 200: Allow TCP 443, Source=AzureLoadBalancer, Destination=Any; Default rule: DenyAllInBound.

Based on the exhibit, what should the administrator change so the web tier can reach the database tier on TCP 443 without opening the subnet more broadly?

⚠ Common exam trap

Watch out — candidates often assume default rules block unwanted traffic, but Azure NSG default rules are permissive for virtual network traffic, so an explicit deny rule is necessary to restrict access, and priority order must be managed carefully to ensure allow rules are evaluated before deny rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Move the allow rule for WebTierASG to a priority lower than 100.

The administrator must ensure the allow rule for WebTierASG is evaluated before the deny-all rule. In Azure Network Security Groups (NSGs), rules are processed in priority order (lower numbers first). The current deny rule at priority 100 blocks all traffic from VirtualNetwork, including TCP 443 from the web tier. By moving the allow rule to a priority lower than 100 (e.g., 90), it will be evaluated first, permitting TCP 443 traffic from WebTierASG to the database tier, while the deny rule still blocks all other traffic from the virtual network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Move the allow rule for WebTierASG to a priority lower than 100.

    Why this is correct

    The allow rule for WebTierASG is currently assigned a priority number above 100, and because Azure processes NSG rules in ascending priority order, the deny rule at priority 100 is evaluated first and drops the traffic before the allow rule can run. Moving the ASG allow rule to a lower number, such as 90, ensures it is evaluated before the deny rule, permitting the intended traffic while still letting the deny rule apply to everything else. This is the only change that directly resolves the rule-order conflict without altering the overall security intent.

  • Delete the deny rule because default rules already block unwanted traffic.

    Why it's wrong here

    Deleting the custom deny rule removes the only explicit control that restricts traffic based on the intended policy, because the default inbound rules only permit traffic from the virtual network and load balancer while denying all other Internet traffic without differentiating sources. This would expose additional traffic patterns that the deny rule was deliberately blocking, violating the principle of least privilege. The default rules are not equivalent to the deny rule, so removing it would change the security posture rather than fix the priority conflict.

    When this WOULD be correct

    In a scenario where the question states that the default rules already block unwanted traffic and there is no need for explicit deny rules, or if the deny rule is redundant because the default inbound rule 'DenyAllInBound' is already in place and the allow rule is sufficient.

  • Change the deny rule source from VirtualNetwork to Internet.

    Why it's wrong here

    Changing the deny rule source from VirtualNetwork to Internet would make the rule apply only to inbound Internet traffic, meaning internal virtual network traffic would no longer be subject to that restriction. This weakens the intended restriction model because the original rule was designed to block traffic from the entire VirtualNetwork, not just external sources. Even if it allowed the WebTierASG traffic, it would also allow other internal traffic that should still be denied, so it is not a targeted fix.

    When this WOULD be correct

    This option would be correct if the question asked how to block inbound traffic from the internet to a subnet while allowing traffic from within the virtual network, and the existing deny rule was blocking all traffic.

  • Change the default inbound rule to AllowVnetInBound.

    Why it's wrong here

    Azure default security rules are immutable system-managed rules; you cannot modify or replace them through custom rules. AllowVnetInBound is already in effect for virtual network traffic by default, but it does not override a custom deny rule with a higher priority. Changing the default rule would require recreating the entire NSG or using an override, which is not possible, and it would not address the precedence issue that causes the ASG allow rule to be skipped.

    When this WOULD be correct

    This would be correct if the question asked to ensure that all resources within the virtual network can communicate with each other by default, without any specific restrictions, and the current default rule is set to deny.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Move the allow rule for WebTierASG to a priority lower than 100.Correct answer

Why this is correct

The allow rule for WebTierASG is currently assigned a priority number above 100, and because Azure processes NSG rules in ascending priority order, the deny rule at priority 100 is evaluated first and drops the traffic before the allow rule can run. Moving the ASG allow rule to a lower number, such as 90, ensures it is evaluated before the deny rule, permitting the intended traffic while still letting the deny rule apply to everything else. This is the only change that directly resolves the rule-order conflict without altering the overall security intent.

Delete the deny rule because default rules already block unwanted traffic.Wrong answer — click to see why

Why this is wrong here

Deleting the deny rule would allow all traffic from VirtualNetwork to the database subnet, including traffic from other subnets, which violates the requirement to restrict access to only the web tier on TCP 443.

★ When this WOULD be the correct answer

In a scenario where the question states that the default rules already block unwanted traffic and there is no need for explicit deny rules, or if the deny rule is redundant because the default inbound rule 'DenyAllInBound' is already in place and the allow rule is sufficient.

Why candidates choose this

Candidates may think that default rules (like DenyAllInBound) automatically block unwanted traffic, so deleting explicit deny rules seems logical, but they overlook that the default rule is overridden by higher-priority allow rules, and the deny rule here is needed to block traffic from other subnets.

Change the deny rule source from VirtualNetwork to Internet.Wrong answer — click to see why

Why this is wrong here

Changing the deny rule source to 'Internet' would block traffic from the internet but not from other subnets within the virtual network, so the web tier would still be unable to reach the database tier due to the existing deny rule.

★ When this WOULD be the correct answer

This option would be correct if the question asked how to block inbound traffic from the internet to a subnet while allowing traffic from within the virtual network, and the existing deny rule was blocking all traffic.

Why candidates choose this

Candidates may think that changing the source to 'Internet' will allow internal traffic while blocking external, but they overlook that the deny rule still blocks all traffic from the specified source, and the web tier is within the virtual network.

Change the default inbound rule to AllowVnetInBound.Wrong answer — click to see why

Why this is wrong here

Changing the default inbound rule to AllowVnetInBound would allow all traffic from within the virtual network, which is too broad and does not restrict access to only the web tier on TCP 443.

★ When this WOULD be the correct answer

This would be correct if the question asked to ensure that all resources within the virtual network can communicate with each other by default, without any specific restrictions, and the current default rule is set to deny.

Why candidates choose this

Candidates may think that modifying default rules is a simple way to allow traffic, not realizing that it opens up the subnet more broadly than required.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on AZ-104

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Based on the exhibit, why is the administrator's HTTPS test still being denied, and what should be changed?

easy
  • A.Increase the deny rule priority number from 200 to 300.
  • B.Move Allow-HTTPS-Admin to a priority lower than 200.
  • C.Change Allow-HTTPS-Admin to use protocol Any.
  • D.Assign a public IP address to the VM.

Why B: The administrator's HTTPS test is denied because Azure Network Security Groups (NSGs) process rules in priority order, from lowest to highest numeric value. The deny rule at priority 200 is evaluated before the allow rule at priority 300, so the HTTPS traffic is blocked. To allow HTTPS traffic, the allow rule must have a lower priority number (e.g., 100) than the deny rule, ensuring it is evaluated first. Option B correctly identifies that moving Allow-HTTPS-Admin to a priority lower than 200 (i.e., a smaller number) will allow the traffic before the deny rule is applied.

Variation 2. A subnet NSG contains a deny RDP rule from Any at priority 200. The administrator must allow RDP from 10.8.0.0/24 to the virtual machines in that subnet. What should the administrator do?

easy
  • A.Create an allow rule with a higher priority number than 200.
  • B.Create an allow rule with a lower priority number than 200.
  • C.Add a route table entry for TCP 3389.
  • D.Disable the default security rules on the NSG.

Why B: B is correct because NSG rules are evaluated in priority order, with lower numbers having higher priority. The existing deny rule at priority 200 blocks all RDP traffic. To allow RDP from 10.8.0.0/24, a new allow rule must be created with a priority lower than 200 (e.g., 150) so it is evaluated before the deny rule, permitting the specific traffic.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.