Courseiva

AZ-104 · topic practice

Implement and Manage Virtual Networking practice questions

This domain covers Azure virtual networks, subnets, IP addressing, network security groups, routing, peering, private endpoints, and name resolution. The exam tests these through scenario-based questions requiring you to configure, secure, and troubleshoot connectivity using the portal, CLI, or PowerShell. Expect tasks on NSG rules, UDRs, VNet peering, and Azure DNS.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Implement and Manage Virtual Networking

What the exam tests

What to know about Implement and Manage Virtual Networking

Candidates must configure VNets, subnets, NSGs, UDRs, peering, private endpoints, and Azure DNS using portal, CLI, or PowerShell. Get subnet delegation and NSG rule priority right, since misconfigured rules block traffic.

Create and configure VNets, subnets, and IP addressing including service endpoints.

Configure NSG rules and application security groups to filter traffic.

Implement VNet peering, user-defined routes, and Azure DNS zones.

Set up private endpoints and Azure Bastion for secure access.

Watch out for

Common Implement and Manage Virtual Networking exam traps

  • ▸Forgetting that NSG rules are stateful and that default rules allow VNet traffic but deny internet inbound.
  • ▸Assuming VNet peering is transitive; it is not, so you need UDRs or gateways for spoke-to-spoke.
  • ▸Overlooking that Azure reserves the first four and last IP address in each subnet.

Practice set

Implement and Manage Virtual Networking questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full VPN explanation →

A network team wants to send diagnostic logs from an Azure VPN gateway to a Log Analytics workspace. Which command should be used to configure this?

Exhibit

Goal: Centralized logging server = 192.0.2.50

Which statement best explains the value of enabling both Azure Network Watcher NSG flow logs and Azure role-based access control (RBAC) for your Azure network resources?

A network team wants name resolution and visibility into traffic patterns. Which two Azure services directly match those goals?

An administrator needs to collect activity logs and performance data from multiple Azure virtual machines into a single workspace for querying and alerting. What should be configured?

A network administrator wants a subscription-based mechanism to receive real-time operational updates from Azure virtual network resources as configurations change, instead of polling periodically. Which Azure service should be used?

Exhibit

collector: 10.10.10.50
subscription: interface-counters
mode: periodic 1000ms
encoding: GPB
Question 6hardmultiple choice
Review the full routing breakdown →

Traffic from VM-App01 is unexpectedly reaching the internet through a virtual appliance. You need to see which routes are currently applied to the VM network interface. Which Azure tool should you use?

A VM in subnet S1 has two network security groups applied: one at the subnet and one directly on the NIC. The subnet NSG contains DenyAllInbound at priority 100 and AllowHTTPSFromOffice at priority 200. The NIC NSG contains AllowHTTPSFromOffice at priority 150 and no deny rules. Office users still cannot reach the VM on TCP 443. Which statement is correct? Select one.

A workload in a VNet must connect to Azure SQL Database over a private IP address, and the database must not be reachable through its public endpoint. Users should still connect by using the normal server name. What should you configure?

Question 9mediummultiple choice
Read the full VPN explanation →

A subnet has a user-defined route for 0.0.0.0/0 that sends all outbound traffic to a virtual appliance. Traffic to 10.20.4.12 must instead go directly to an Azure VPN gateway. What should you configure?

A Windows VM in VNet-App must access an Azure Files share over a private IP address. The storage account must not be reachable through its public endpoint, and the VM should resolve the file share name without custom host-file entries. Which three actions are required? Select three.

Two virtual networks are in different subscriptions. VNet-A uses 10.20.0.0/16 and VNet-B uses 10.20.128.0/17. A design review also states that traffic between two spoke VNets should flow through a hub VNet instead of directly between spokes. Which two statements are correct? Select two.

Question 12hardmulti select
Read the full DNS explanation →

A VM in VNet-Prod must connect to Azure SQL Database over a private IP address, and the VM should resolve the server name automatically without manual DNS entries. Which three actions are required? Select three.

Question 13mediummultiple choice
Review the full subnetting walkthrough →

A subnet contains 15 backend VMs that only need outbound internet access for patching and package downloads. Security wants all outbound connections to use one static public IP address, and no VM should have a public IP assigned directly. What should you configure?

Question 14mediummultiple choice
Review the full subnetting walkthrough →

A route table on a subnet contains this user-defined route: - 0.0.0.0/0 -> Virtual appliance 10.0.0.4 The subnet is peered to another VNet with address space 10.2.0.0/16. A VM in the subnet sends traffic to 10.2.2.7, and Network Watcher shows the next hop as Virtual network peering instead of the appliance. What explains this result?

Question 15mediummultiple choice
Review the full subnetting walkthrough →

An administrator plans to peer VNet-A with VNet-B so two application tiers can communicate over private IPs. VNet-A uses 10.20.0.0/16. VNet-B currently uses 10.20.1.0/24, and both VNets already contain subnets that must remain intact. The peering operation fails. What should the administrator do first?

A branch office with a static public IP needs encrypted connectivity to an Azure virtual network so users can access private Azure VMs and internal services. The connection should support a site-to-site design and not rely on public IPs for the Azure resources themselves. Which service should the administrator deploy?

Based on the exhibit, HTTPS traffic from the admin workstation is still being blocked. What change should the administrator make?

Exhibit

Inbound NSG rules on AppSubnet:
Priority 200  Deny-All-Inbound      Any      Any      Any      Any    Deny
Priority 250  Allow-HTTPS-Admin     TCP      203.0.113.20/32   Any   443    Allow
Priority 300  Allow-HTTPS-Internet  TCP      Internet          Any   443    Allow
Test source IP: 203.0.113.20
Observed result: TCP 443 denied
Question 18mediummultiple choice
Review the full subnetting walkthrough →

Two VM scale sets named Web and App run in separate subnets. The App subnet NSG already contains Deny-All-Inbound at priority 300. The business wants only the Web tier to connect to the App tier on TCP 8443, and any new scale-out instances must be included automatically. What should the administrator add?

Question 19mediummultiple choice
Read the full VPN explanation →

A subnet must send traffic to on-premises networks through a VPN gateway, but internet-bound traffic should use the Azure platform's normal outbound path and not be forced through a virtual appliance. The administrator wants to avoid creating a 0.0.0.0/0 user-defined route. Which design meets the requirement?

An application in AppSubnet must access an Azure Storage account over the public endpoint, but only traffic from that subnet should be allowed, and the traffic should stay on the Microsoft backbone. The administrator does not want to create a private IP for the service. Which two actions should be taken? Select two.

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Implement and Manage Virtual Networking sessions

Start a Implement and Manage Virtual Networking only practice session

Every question in these sessions is drawn from the Implement and Manage Virtual Networking domain — nothing else.

Related practice questions

Related AZ-104 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the AZ-104 exam test about Implement and Manage Virtual Networking?
Candidates must configure VNets, subnets, NSGs, UDRs, peering, private endpoints, and Azure DNS using portal, CLI, or PowerShell. Get subnet delegation and NSG rule priority right, since misconfigured rules block traffic.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Implement and Manage Virtual Networking questions in a focused session?
Yes — the session launcher on this page draws every question from the Implement and Manage Virtual Networking domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other AZ-104 topics?
Use the topic links above to move to related areas, or go back to the AZ-104 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the AZ-104 exam covers. They are not copied from any real exam or dump site.