Courseiva
Implement and Manage Virtual NetworkingmediumMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Virtual Networking Practice Question

An administrator is deploying a new VPN gateway in an existing VNet. The GatewaySubnet currently uses a /28 range, and the deployment fails because the selected gateway configuration does not have enough available IP addresses. What is the best action?

⚠ Common exam trap

A common mix-up: candidates assume a /28 subnet is always sufficient because it works for smaller gateways, but they overlook that larger SKUs or active-active configurations require more IPs, and Azure's reservation of 5 addresses per subnet further reduces usable space.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Expand GatewaySubnet to a larger range, such as /27, and redeploy the VPN gateway.

The GatewaySubnet requires a minimum /27 range to support most VPN gateway SKUs, as Azure reserves several IP addresses for internal use and the gateway instances need at least 3–6 usable IPs depending on the SKU. Expanding the subnet to /27 provides enough addresses (32 total, minus reserved) to satisfy the gateway's allocation requirements, allowing the deployment to succeed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Move one of the gateway's NICs into a normal workload subnet.

    Why it's wrong here

    A VPN gateway is a fully managed service whose backend instances live exclusively inside the GatewaySubnet; you cannot manually move one of its virtual NICs to a normal workload subnet. Doing so would violate Azure's delegation for that subnet and break the gateway's data path, since VPN traffic routing depends on the dedicated gateway IP configuration. The error stems from having too few usable addresses in GatewaySubnet for the chosen gateway SKU, not from where the NICs are physically attached. The only valid remedy is to provide a larger GatewaySubnet (for example, /27) and redeploy the gateway.

    When this WOULD be correct

    If a question asks how to free up IP addresses in a subnet for a new resource, and the subnet contains a VM with an unused NIC, moving that NIC to another subnet could release its IP address.

  • Expand GatewaySubnet to a larger range, such as /27, and redeploy the VPN gateway.

    Why this is correct

    GatewaySubnet is a dedicated subnet for VPN gateway resources, and the gateway requires enough free IP addresses to deploy and operate. If the current prefix is too small for the chosen configuration, the correct fix is to expand the subnet to a larger size, such as /27, if the VNet address space allows it. After resizing, the administrator can retry the gateway deployment with adequate capacity.

  • Create a private endpoint inside GatewaySubnet to reserve extra addresses.

    Why it's wrong here

    Private endpoints attach to a VNet through a NIC in a regular subnet and are used to connect privately to PaaS services; they are not allowed inside GatewaySubnet because that subnet is delegated exclusively to Microsoft.Network/vpnGateways. Even if you could place one there, it would only consume an IP, not free up or reserve capacity for the VPN gateway's scale units. A private endpoint cannot increase the gateway's available address pool or lower the SKU's IP requirement. The correct action is to enlarge the GatewaySubnet address range to satisfy the gateway's own address demands.

    When this WOULD be correct

    A question where a service needs to be accessed securely from on-premises without exposing it to the internet, and the subnet has sufficient IP capacity. For example: 'You need to access an Azure Storage account from on-premises over a private connection. What should you create in a subnet?'

  • Enable BGP so the gateway needs fewer IP addresses.

    Why it's wrong here

    Enabling BGP on a VPN gateway configures dynamic routing to exchange routes with on-premises peers, but it has no effect on the number of IP addresses the gateway consumes. The GatewaySubnet must supply a fixed set of addresses for gateway instances and Azure's internal management, regardless of whether BGP is enabled. The minimum subnet size is /29 for a standalone gateway, and deploying a SKU requiring more scale units or an active-active setup needs a larger prefix such as /27. Thus, BGP cannot reduce the subnet's IP demand and would not resolve an insufficient-capacity error.

    When this WOULD be correct

    In a scenario where a VPN gateway is failing to establish BGP peering due to missing configuration, enabling BGP on the gateway and the on-premises device would be the correct action to allow dynamic route exchange.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Expand GatewaySubnet to a larger range, such as /27, and redeploy the VPN gateway.Correct answer

Why this is correct

GatewaySubnet is a dedicated subnet for VPN gateway resources, and the gateway requires enough free IP addresses to deploy and operate. If the current prefix is too small for the chosen configuration, the correct fix is to expand the subnet to a larger size, such as /27, if the VNet address space allows it. After resizing, the administrator can retry the gateway deployment with adequate capacity.

Move one of the gateway's NICs into a normal workload subnet.Wrong answer — click to see why

Why this is wrong here

Moving a gateway NIC into a normal workload subnet is not supported; VPN gateway NICs must reside in the GatewaySubnet. This action would break the gateway deployment.

★ When this WOULD be the correct answer

If a question asks how to free up IP addresses in a subnet for a new resource, and the subnet contains a VM with an unused NIC, moving that NIC to another subnet could release its IP address.

Why candidates choose this

Candidates may think that moving NICs is a general method to free IP addresses, not realizing that gateway NICs are tied to the GatewaySubnet and cannot be relocated.

Create a private endpoint inside GatewaySubnet to reserve extra addresses.Wrong answer — click to see why

Why this is wrong here

Creating a private endpoint inside GatewaySubnet does not increase the number of available IP addresses for the VPN gateway; private endpoints consume IP addresses from the subnet, making the shortage worse.

★ When this WOULD be the correct answer

A question where a service needs to be accessed securely from on-premises without exposing it to the internet, and the subnet has sufficient IP capacity. For example: 'You need to access an Azure Storage account from on-premises over a private connection. What should you create in a subnet?'

Why candidates choose this

Candidates may confuse private endpoints with a method to reserve or allocate IP addresses, not realizing they actually consume addresses and are unrelated to gateway IP requirements.

Enable BGP so the gateway needs fewer IP addresses.Wrong answer — click to see why

Why this is wrong here

Enabling BGP does not reduce the number of IP addresses required by the VPN gateway; BGP is a routing protocol that exchanges routes, not a method to change IP address consumption. The gateway still needs the same number of IP addresses for its instances.

★ When this WOULD be the correct answer

In a scenario where a VPN gateway is failing to establish BGP peering due to missing configuration, enabling BGP on the gateway and the on-premises device would be the correct action to allow dynamic route exchange.

Why candidates choose this

Candidates may mistakenly think BGP reduces IP address usage because BGP can aggregate routes, but this does not affect the gateway's own IP address requirements.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.