Courseiva

AZ-104 · topic practice

Implement and Manage Virtual Networking practice questions

Use this page to practise Implement and Manage Virtual Networking questions for this certification. Focus on how the exam tests implement and manage virtual networking in scenario format — understanding the why behind each answer builds more durable knowledge than memorising options.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Implement and Manage Virtual Networking

What the exam tests

What to know about Implement and Manage Virtual Networking

Implement and Manage Virtual Networking questions on this certification test your ability to deploy and manage implement and manage virtual networking concepts in scenario-based situations.

Core Implement and Manage Virtual Networking concepts and how they apply in real-world cloud scenarios.

How to deploy implement and manage virtual networking correctly and verify the outcome.

Troubleshooting implement and manage virtual networking issues by interpreting error output and system state.

Cloud best practices and Implement and Manage Virtual Networking design trade-offs tested by this certification.

Watch out for

Common Implement and Manage Virtual Networking exam traps

  • Selecting the most expensive service when a simpler managed option meets the requirement.
  • Forgetting that cloud resources must be explicitly secured — defaults are rarely secure.
  • Choosing a global service fix when the issue is region-specific.
  • Overlooking cost implications of cross-region data transfer in architecture questions.

Practice set

Implement and Manage Virtual Networking questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full VPN explanation →

A network team wants to send diagnostic logs from an Azure VPN gateway to a Log Analytics workspace. Which command should be used to configure this?

Exhibit

Goal: Centralized logging server = 192.0.2.50

Which statement best explains the value of enabling both Azure Network Watcher NSG flow logs and Azure role-based access control (RBAC) for your Azure network resources?

A network team wants name resolution and visibility into traffic patterns. Which two Azure services directly match those goals?

An administrator needs to collect activity logs and performance data from multiple Azure virtual machines into a single workspace for querying and alerting. What should be configured?

A network administrator wants a subscription-based mechanism to receive real-time operational updates from Azure virtual network resources as configurations change, instead of polling periodically. Which Azure service should be used?

Exhibit

collector: 10.10.10.50
subscription: interface-counters
mode: periodic 1000ms
encoding: GPB
Question 6hardmultiple choice
Review the full routing breakdown →

Traffic from VM-App01 is unexpectedly reaching the internet through a virtual appliance. You need to see which routes are currently applied to the VM network interface. Which Azure tool should you use?

A VM in subnet S1 has two network security groups applied: one at the subnet and one directly on the NIC. The subnet NSG contains DenyAllInbound at priority 100 and AllowHTTPSFromOffice at priority 200. The NIC NSG contains AllowHTTPSFromOffice at priority 150 and no deny rules. Office users still cannot reach the VM on TCP 443. Which statement is correct? Select one.

A workload in a VNet must connect to Azure SQL Database over a private IP address, and the database must not be reachable through its public endpoint. Users should still connect by using the normal server name. What should you configure?

A Windows VM in VNet-App must access an Azure Files share over a private IP address. The storage account must not be reachable through its public endpoint, and the VM should resolve the file share name without custom host-file entries. Which three actions are required? Select three.

Question 10hardmulti select
Read the full DNS explanation →

A VM in VNet-Prod must connect to Azure SQL Database over a private IP address, and the VM should resolve the server name automatically without manual DNS entries. Which three actions are required? Select three.

Question 11mediummultiple choice
Review the full subnetting walkthrough →

A subnet contains 15 backend VMs that only need outbound internet access for patching and package downloads. Security wants all outbound connections to use one static public IP address, and no VM should have a public IP assigned directly. What should you configure?

Question 12mediummultiple choice
Review the full subnetting walkthrough →

A route table on a subnet contains this user-defined route: - 0.0.0.0/0 -> Virtual appliance 10.0.0.4 The subnet is peered to another VNet with address space 10.2.0.0/16. A VM in the subnet sends traffic to 10.2.2.7, and Network Watcher shows the next hop as Virtual network peering instead of the appliance. What explains this result?

Question 13mediummultiple choice
Review the full subnetting walkthrough →

An administrator plans to peer VNet-A with VNet-B so two application tiers can communicate over private IPs. VNet-A uses 10.20.0.0/16. VNet-B currently uses 10.20.1.0/24, and both VNets already contain subnets that must remain intact. The peering operation fails. What should the administrator do first?

Based on the exhibit, HTTPS traffic from the admin workstation is still being blocked. What change should the administrator make?

Exhibit

Inbound NSG rules on AppSubnet:
Priority 200  Deny-All-Inbound      Any      Any      Any      Any    Deny
Priority 250  Allow-HTTPS-Admin     TCP      203.0.113.20/32   Any   443    Allow
Priority 300  Allow-HTTPS-Internet  TCP      Internet          Any   443    Allow
Test source IP: 203.0.113.20
Observed result: TCP 443 denied
Question 15mediummultiple choice
Review the full subnetting walkthrough →

Two VM scale sets named Web and App run in separate subnets. The App subnet NSG already contains Deny-All-Inbound at priority 300. The business wants only the Web tier to connect to the App tier on TCP 8443, and any new scale-out instances must be included automatically. What should the administrator add?

Question 16mediummultiple choice
Read the full VPN explanation →

A subnet must send traffic to on-premises networks through a VPN gateway, but internet-bound traffic should use the Azure platform's normal outbound path and not be forced through a virtual appliance. The administrator wants to avoid creating a 0.0.0.0/0 user-defined route. Which design meets the requirement?

Question 17easymultiple choice
Review the full subnetting walkthrough →

Based on the exhibit, which subnet prefix should be used for Subnet A so it can support about 30 VM NICs?

Exhibit

Planned VNet address space: 10.70.0.0/16
Subnet A requirement: about 30 VM NICs
Subnet B requirement: about 8 VM NICs and one future jump box
Azure reserves 5 IP addresses in each subnet

An application in AppSubnet must access an Azure Storage account over the public endpoint, but only traffic from that subnet should be allowed, and the traffic should stay on the Microsoft backbone. The administrator does not want to create a private IP for the service. Which two actions should be taken? Select two.

Question 19easymultiple choice
Review the full subnetting walkthrough →

A storage account must be reachable only from resources in one Azure subnet, and traffic must use a private IP rather than the public endpoint. Which configuration should the administrator implement?

Question 20easymultiple choice
Read the full NAT/PAT explanation →

Based on the exhibit, what should the administrator change so outbound internet traffic uses the NAT gateway?

Exhibit

Subnet-Web configuration:
- NAT gateway: nat-web
- Route table association: rt-web
Route table rt-web:
- 0.0.0.0/0 -> Virtual appliance 10.1.0.4
- 10.1.0.0/16 -> Virtual network
Observed issue: Internet-bound traffic still exits through the virtual appliance.

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Implement and Manage Virtual Networking sessions

Start a Implement and Manage Virtual Networking only practice session

Every question in these sessions is drawn from the Implement and Manage Virtual Networking domain — nothing else.

Related practice questions

Related AZ-104 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the AZ-104 exam test about Implement and Manage Virtual Networking?
Implement and Manage Virtual Networking questions on this certification test your ability to deploy and manage implement and manage virtual networking concepts in scenario-based situations.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Implement and Manage Virtual Networking questions in a focused session?
Yes — the session launcher on this page draws every question from the Implement and Manage Virtual Networking domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other AZ-104 topics?
Use the topic links above to move to related areas, or go back to the AZ-104 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the AZ-104 exam covers. They are not copied from any real exam or dump site.