Courseiva
Implement and Manage Virtual NetworkingmediumMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Virtual Networking Practice Question

Frontend VMs in one subnet must reach backend VMs on TCP 8443. The backend VMs are rebuilt frequently, so their private IP addresses change often. The administrator wants to avoid updating NSG rules every time the backend IPs change. What should be used in the NSG rule?

⚠ Common exam trap

Test-takers frequently confuse Application Security Groups with Network Security Groups themselves, or think that service endpoints or private endpoints are designed for VM-to-VM communication, when in fact they are for securing access to Azure PaaS services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Application Security Groups for the frontend and backend tiers.

Application Security Groups (ASGs) allow you to group VMs logically by function (e.g., frontend, backend) and reference those groups in NSG rules. Since the backend VMs are rebuilt frequently and their private IPs change, using ASGs in the NSG rule (source = frontend ASG, destination = backend ASG, port = 8443) eliminates the need to update IP addresses manually. The NSG rule remains valid as long as the VMs are assigned to the correct ASG, regardless of IP changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Application Security Groups for the frontend and backend tiers.

    Why this is correct

    Application Security Groups let you reference groups of VMs in NSG rules instead of individual IP addresses. That is ideal when backend IPs change often because the rule continues to target the backend application tier rather than a specific address. The administrator can place the frontend VMs in one ASG and the backend VMs in another, then allow TCP 8443 between those groups without constantly editing the NSG.

  • A service endpoint on the backend subnet.

    Why it's wrong here

    Service endpoints are intended to secure connectivity between a virtual network and Azure PaaS services, such as Azure Storage or Azure SQL, by ensuring traffic to those services goes over the Azure backbone and never leaves the virtual network. They do not apply to VM-to-VM traffic, and they do not filter based on TCP port 8443 or allow you to define logical tiers like frontend and backend. Adding a service endpoint to the backend subnet only affects connections from that subnet to supported Azure services; it has no effect on whether a frontend VM can reach a backend VM on a given port.

    When this WOULD be correct

    When you need to restrict access from a subnet to a specific Azure service (e.g., Azure Storage or SQL Database) over the Azure backbone network, ensuring traffic never leaves the Microsoft network.

  • A route table with a next hop of Virtual network gateway.

    Why it's wrong here

    A route table with a next hop of Virtual network gateway controls the path that network traffic takes, not whether that traffic is permitted or denied. This option would force traffic intended for the backend to route through a virtual network gateway, which is neither necessary nor correct for VM-to-VM communication within the same virtual network, and it does not filter by protocol or port. It also does not provide any mechanism to group the frontend or backend VMs, so the rule would remain tied to specific IP addresses and would not adapt when backend VMs are added or removed.

    When this WOULD be correct

    In a scenario where you need to force traffic from a subnet to go through a network virtual appliance (NVA) or VPN gateway for inspection or hybrid connectivity, a route table with a next hop of Virtual network gateway would be correct. For example, to route all outbound traffic from a subnet through an on-premises firewall via a site-to-site VPN.

  • A private endpoint for each backend VM.

    Why it's wrong here

    A private endpoint is designed to give a PaaS service (such as Azure Storage or SQL Database) a private IP address in a virtual network, enabling you to reach that service over a private connection. It does not apply to IaaS workloads like VMs, and it provides no mechanism to group VMs or define inbound access rules between tiers. Even if you created a private endpoint for every backend VM, you would still need separate network security rules to allow TCP 8443, and you would lose the benefit of dynamically referencing a group of backend VMs when their IPs change.

    When this WOULD be correct

    A question where backend VMs need to securely access an Azure PaaS service (e.g., Azure SQL Database or Storage Account) without using public endpoints, and the PaaS service's IP addresses are not relevant because the connection is over a private IP.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Application Security Groups for the frontend and backend tiers.Correct answer

Why this is correct

Application Security Groups let you reference groups of VMs in NSG rules instead of individual IP addresses. That is ideal when backend IPs change often because the rule continues to target the backend application tier rather than a specific address. The administrator can place the frontend VMs in one ASG and the backend VMs in another, then allow TCP 8443 between those groups without constantly editing the NSG.

A service endpoint on the backend subnet.Wrong answer — click to see why

Why this is wrong here

A service endpoint secures Azure service traffic (e.g., to Azure Storage) to a subnet, not TCP traffic between VMs. It does not allow dynamic IP-based rules for backend VMs.

★ When this WOULD be the correct answer

When you need to restrict access from a subnet to a specific Azure service (e.g., Azure Storage or SQL Database) over the Azure backbone network, ensuring traffic never leaves the Microsoft network.

Why candidates choose this

Candidates may confuse service endpoints with a method to secure intra-VNet traffic, not realizing they are designed for Azure PaaS services, not VM-to-VM communication.

A route table with a next hop of Virtual network gateway.Wrong answer — click to see why

Why this is wrong here

Route tables control traffic routing, not security filtering. A route table with a next hop of Virtual network gateway would redirect traffic to a VPN gateway, which does not solve the need to allow TCP 8443 traffic to dynamically changing backend IPs without updating NSG rules.

★ When this WOULD be the correct answer

In a scenario where you need to force traffic from a subnet to go through a network virtual appliance (NVA) or VPN gateway for inspection or hybrid connectivity, a route table with a next hop of Virtual network gateway would be correct. For example, to route all outbound traffic from a subnet through an on-premises firewall via a site-to-site VPN.

Why candidates choose this

Candidates may confuse routing with security, thinking that directing traffic through a gateway can implicitly control access, or they may believe that a route table can replace NSG rules for traffic filtering.

A private endpoint for each backend VM.Wrong answer — click to see why

Why this is wrong here

Private endpoints are used to securely access Azure PaaS services over a private IP address, not to allow VMs in one subnet to communicate with VMs in another subnet within the same VNet. They do not solve the problem of dynamic private IP addresses for backend VMs.

★ When this WOULD be the correct answer

A question where backend VMs need to securely access an Azure PaaS service (e.g., Azure SQL Database or Storage Account) without using public endpoints, and the PaaS service's IP addresses are not relevant because the connection is over a private IP.

Why candidates choose this

Candidates may confuse private endpoints with a method to assign static private IPs to VMs, or think that private endpoints can be used for VM-to-VM communication within a VNet.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.