Courseiva
Implement and Manage Virtual NetworkingeasyMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Virtual Networking Practice Question

Exhibit

Effective routes for Subnet-Apps:
0.0.0.0/0 -> Virtual appliance 10.1.1.4
10.50.1.0/24 -> Internet
10.0.0.0/8 -> Virtual network
Observed destination: 10.50.1.20

Based on the exhibit, which next hop will Azure use for traffic from the VM to 10.50.1.20?

⚠ Common exam trap

Many exam-takers assume private IP traffic always stays within Azure or follows the default route, but Azure prioritizes more specific routes regardless of IP address range.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Internet, because the /24 route is more specific than the default route.

Azure uses the most specific route (longest prefix match) to determine next hop. The route for 10.50.1.0/24 with next hop Internet is more specific than the default route 0.0.0.0/0, so traffic to 10.50.1.20 will be forwarded to the Internet, not the virtual appliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Virtual appliance 10.1.1.4, because all traffic always follows the default route.

    Why it's wrong here

    The default route 0.0.0.0/0 is never the automatic choice for every destination; it is used only when no other route has a longer prefix. Here the destination 10.50.1.20 lies inside 10.50.1.0/24, which is a more-specific prefix than 0.0.0.0/0, so the /24 route is selected. Because that /24 route specifies Internet as its next hop, the virtual appliance 10.1.1.4 is bypassed, even though the appliance is attached to the default route.

    When this WOULD be correct

    If the question had a route table with only a default route (0.0.0.0/0) pointing to the virtual appliance and no more specific route for 10.50.1.0/24, then traffic to 10.50.1.20 would follow the default route to the virtual appliance.

  • Internet, because the /24 route is more specific than the default route.

    Why this is correct

    Azure uses longest-prefix match when selecting a route. The destination 10.50.1.20 falls within 10.50.1.0/24, which is more specific than the 0.0.0.0/0 default route. Therefore, the Internet next hop is chosen instead of the virtual appliance.

  • Virtual network, because private IP addresses always stay inside Azure.

    Why it's wrong here

    Azure does not treat all private IP ranges as 'virtual network scope' when a user-defined route explicitly overrides them. Although 10.50.1.20 is private, the effective route table contains 10.50.1.0/24 with Internet as its next hop, and longest-prefix selection sends traffic to that next hop. Thus, private address traffic can be directed out of the virtual network just like public traffic, as long as the selected route's next-hop type supports it.

    When this WOULD be correct

    This option would be correct if the destination IP were within the virtual network's address space (e.g., 10.1.0.0/16) and no custom route overrides the default system route, so traffic would stay within the virtual network.

  • No route is selected, so the packet is dropped before leaving the subnet.

    Why it's wrong here

    This is incorrect because Azure's effective route table already includes both 10.50.1.0/24 and 0.0.0.0/0, so the lookup for 10.50.1.20 succeeds. Longest-prefix matching designates a route, and the packet is forwarded to that route's next hop rather than being dropped. Azure only drops a packet at this stage if no matching route exists or if the selected route is a Blackhole, neither of which applies here.

    When this WOULD be correct

    This option would be correct if the question stated that no route matches the destination IP (e.g., 10.50.1.20) in the effective routes table, and the default route is also absent, causing Azure to drop the packet.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Internet, because the /24 route is more specific than the default route.Correct answer

Why this is correct

Azure uses longest-prefix match when selecting a route. The destination 10.50.1.20 falls within 10.50.1.0/24, which is more specific than the 0.0.0.0/0 default route. Therefore, the Internet next hop is chosen instead of the virtual appliance.

Virtual appliance 10.1.1.4, because all traffic always follows the default route.Wrong answer — click to see why

Why this is wrong here

The default route (0.0.0.0/0) is less specific than the /24 route to 10.50.1.0/24, so Azure uses the more specific route (Internet) instead of the virtual appliance.

★ When this WOULD be the correct answer

If the question had a route table with only a default route (0.0.0.0/0) pointing to the virtual appliance and no more specific route for 10.50.1.0/24, then traffic to 10.50.1.20 would follow the default route to the virtual appliance.

Why candidates choose this

Candidates may mistakenly think the default route always applies or forget that more specific routes take precedence over the default route.

Virtual network, because private IP addresses always stay inside Azure.Wrong answer — click to see why

Why this is wrong here

The VM's traffic to 10.50.1.20 is destined for a public IP range, and Azure's system routes do not force private IP traffic to stay inside Azure; instead, the most specific route (the /24 route to the Internet) is used.

★ When this WOULD be the correct answer

This option would be correct if the destination IP were within the virtual network's address space (e.g., 10.1.0.0/16) and no custom route overrides the default system route, so traffic would stay within the virtual network.

Why candidates choose this

Candidates may mistakenly believe that all private IP addresses are non-routable and must remain within Azure, ignoring that Azure can route private IP traffic to the Internet via a default route or custom routes.

No route is selected, so the packet is dropped before leaving the subnet.Wrong answer — click to see why

Why this is wrong here

Azure does not drop packets for a valid private IP like 10.50.1.20; it uses the most specific route. A /24 route to the Internet exists, so traffic is forwarded, not dropped.

★ When this WOULD be the correct answer

This option would be correct if the question stated that no route matches the destination IP (e.g., 10.50.1.20) in the effective routes table, and the default route is also absent, causing Azure to drop the packet.

Why candidates choose this

Candidates may think that if no explicit route matches, Azure drops the packet, forgetting that the default route (0.0.0.0/0) always exists and matches any IP not covered by a more specific route.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.