AZ-104 Implement and Manage Virtual Networking Practice Question
An administrator is deploying a new VPN gateway in an existing VNet. The GatewaySubnet currently uses a /28 range, and the deployment fails because the selected gateway configuration does not have enough available IP addresses. What is the best action?
⚠ Common exam trap
A common mix-up: candidates assume a /28 subnet is always sufficient because it works for smaller gateways, but they overlook that larger SKUs or active-active configurations require more IPs, and Azure's reservation of 5 addresses per subnet further reduces usable space.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Expand GatewaySubnet to a larger range, such as /27, and redeploy the VPN gateway.
The GatewaySubnet requires a minimum /27 range to support most VPN gateway SKUs, as Azure reserves several IP addresses for internal use and the gateway instances need at least 3–6 usable IPs depending on the SKU. Expanding the subnet to /27 provides enough addresses (32 total, minus reserved) to satisfy the gateway's allocation requirements, allowing the deployment to succeed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Move one of the gateway's NICs into a normal workload subnet.
Why it's wrong here
A VPN gateway is a fully managed service whose backend instances live exclusively inside the GatewaySubnet; you cannot manually move one of its virtual NICs to a normal workload subnet. Doing so would violate Azure's delegation for that subnet and break the gateway's data path, since VPN traffic routing depends on the dedicated gateway IP configuration. The error stems from having too few usable addresses in GatewaySubnet for the chosen gateway SKU, not from where the NICs are physically attached. The only valid remedy is to provide a larger GatewaySubnet (for example, /27) and redeploy the gateway.
When this WOULD be correct
If a question asks how to free up IP addresses in a subnet for a new resource, and the subnet contains a VM with an unused NIC, moving that NIC to another subnet could release its IP address.
- ✓
Expand GatewaySubnet to a larger range, such as /27, and redeploy the VPN gateway.
Why this is correct
GatewaySubnet is a dedicated subnet for VPN gateway resources, and the gateway requires enough free IP addresses to deploy and operate. If the current prefix is too small for the chosen configuration, the correct fix is to expand the subnet to a larger size, such as /27, if the VNet address space allows it. After resizing, the administrator can retry the gateway deployment with adequate capacity.
- ✗
Create a private endpoint inside GatewaySubnet to reserve extra addresses.
Why it's wrong here
Private endpoints attach to a VNet through a NIC in a regular subnet and are used to connect privately to PaaS services; they are not allowed inside GatewaySubnet because that subnet is delegated exclusively to Microsoft.Network/vpnGateways. Even if you could place one there, it would only consume an IP, not free up or reserve capacity for the VPN gateway's scale units. A private endpoint cannot increase the gateway's available address pool or lower the SKU's IP requirement. The correct action is to enlarge the GatewaySubnet address range to satisfy the gateway's own address demands.
When this WOULD be correct
A question where a service needs to be accessed securely from on-premises without exposing it to the internet, and the subnet has sufficient IP capacity. For example: 'You need to access an Azure Storage account from on-premises over a private connection. What should you create in a subnet?'
- ✗
Enable BGP so the gateway needs fewer IP addresses.
Why it's wrong here
Enabling BGP on a VPN gateway configures dynamic routing to exchange routes with on-premises peers, but it has no effect on the number of IP addresses the gateway consumes. The GatewaySubnet must supply a fixed set of addresses for gateway instances and Azure's internal management, regardless of whether BGP is enabled. The minimum subnet size is /29 for a standalone gateway, and deploying a SKU requiring more scale units or an active-active setup needs a larger prefix such as /27. Thus, BGP cannot reduce the subnet's IP demand and would not resolve an insufficient-capacity error.
When this WOULD be correct
In a scenario where a VPN gateway is failing to establish BGP peering due to missing configuration, enabling BGP on the gateway and the on-premises device would be the correct action to allow dynamic route exchange.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Expand GatewaySubnet to a larger range, such as /27, and redeploy the VPN gateway.Correct answer▾
Why this is correct
GatewaySubnet is a dedicated subnet for VPN gateway resources, and the gateway requires enough free IP addresses to deploy and operate. If the current prefix is too small for the chosen configuration, the correct fix is to expand the subnet to a larger size, such as /27, if the VNet address space allows it. After resizing, the administrator can retry the gateway deployment with adequate capacity.
✗Move one of the gateway's NICs into a normal workload subnet.Wrong answer — click to see why▾
Why this is wrong here
Moving a gateway NIC into a normal workload subnet is not supported; VPN gateway NICs must reside in the GatewaySubnet. This action would break the gateway deployment.
★ When this WOULD be the correct answer
If a question asks how to free up IP addresses in a subnet for a new resource, and the subnet contains a VM with an unused NIC, moving that NIC to another subnet could release its IP address.
Why candidates choose this
Candidates may think that moving NICs is a general method to free IP addresses, not realizing that gateway NICs are tied to the GatewaySubnet and cannot be relocated.
✗Create a private endpoint inside GatewaySubnet to reserve extra addresses.Wrong answer — click to see why▾
Why this is wrong here
Creating a private endpoint inside GatewaySubnet does not increase the number of available IP addresses for the VPN gateway; private endpoints consume IP addresses from the subnet, making the shortage worse.
★ When this WOULD be the correct answer
A question where a service needs to be accessed securely from on-premises without exposing it to the internet, and the subnet has sufficient IP capacity. For example: 'You need to access an Azure Storage account from on-premises over a private connection. What should you create in a subnet?'
Why candidates choose this
Candidates may confuse private endpoints with a method to reserve or allocate IP addresses, not realizing they actually consume addresses and are unrelated to gateway IP requirements.
✗Enable BGP so the gateway needs fewer IP addresses.Wrong answer — click to see why▾
Why this is wrong here
Enabling BGP does not reduce the number of IP addresses required by the VPN gateway; BGP is a routing protocol that exchanges routes, not a method to change IP address consumption. The gateway still needs the same number of IP addresses for its instances.
★ When this WOULD be the correct answer
In a scenario where a VPN gateway is failing to establish BGP peering due to missing configuration, enabling BGP on the gateway and the on-premises device would be the correct action to allow dynamic route exchange.
Why candidates choose this
Candidates may mistakenly think BGP reduces IP address usage because BGP can aggregate routes, but this does not affect the gateway's own IP address requirements.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
VPN Gateway and ExpressRoute
Key term
VPN
A VPN (Virtual Private Network) creates a secure, encrypted tunnel between your device and a remote server, protecting your data and hiding your online activity.
Key term
VNet
A virtual private network inside a cloud provider that lets you securely connect and isolate your cloud resources.
About these practice questions
Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.