Courseiva
Implement and Manage Virtual NetworkingmediumMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Virtual Networking Practice Question

You have two virtual networks named VNet-Hub and VNet-Spoke1 in the same Azure region. Resources in the two VNets must communicate privately over the Microsoft backbone without using a VPN gateway. What should you configure?

⚠ Common exam trap

A common mix-up: candidates confuse VNet peering with VPN gateway-based solutions, assuming a VPN is required for private connectivity, but VNet peering directly meets the requirement without any gateway or public internet exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

VNet peering

VNet peering enables direct, private connectivity between two virtual networks in the same Azure region using the Microsoft backbone infrastructure. It does not require a VPN gateway, public IP addresses, or any internet transit, making it the correct choice for private communication between VNet-Hub and VNet-Spoke1.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • VNet peering

    Why this is correct

    This is the direct and simplest solution for private VNet connectivity in Azure.

  • A site-to-site VPN

    Why it's wrong here

    A VPN is unnecessary for two Azure VNets in this scenario.

    When this WOULD be correct

    A site-to-site VPN would be correct if the question required connecting an on-premises network to Azure VNets over the internet with encrypted traffic, or connecting VNets in different Azure regions where VNet peering is not supported or when cross-region connectivity must be encrypted.

  • A public load balancer

    Why it's wrong here

    A public load balancer does not provide VNet-to-VNet connectivity.

    When this WOULD be correct

    You need to distribute incoming internet traffic across multiple virtual machines in a backend pool for high availability and scalability. A public load balancer would be the correct choice.

  • An NSG outbound deny rule

    Why it's wrong here

    An NSG rule would restrict traffic, not enable it.

    When this WOULD be correct

    You need to block all outbound traffic from a subnet to the internet while allowing traffic to a specific service via service tags. An NSG outbound deny rule with a higher priority deny-all rule and an allow rule for the service tag would be correct.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

VNet peeringCorrect answer

Why this is correct

This is the direct and simplest solution for private VNet connectivity in Azure.

A site-to-site VPNWrong answer — click to see why

Why this is wrong here

A site-to-site VPN requires a VPN gateway and uses encrypted tunnels over the public internet, not the Microsoft backbone. The question specifies private communication over the Microsoft backbone without a VPN gateway, so this option does not meet the requirements.

★ When this WOULD be the correct answer

A site-to-site VPN would be correct if the question required connecting an on-premises network to Azure VNets over the internet with encrypted traffic, or connecting VNets in different Azure regions where VNet peering is not supported or when cross-region connectivity must be encrypted.

Why candidates choose this

Candidates may think a VPN is the only way to connect VNets privately, not realizing that VNet peering provides private connectivity over the Microsoft backbone without a VPN gateway.

A public load balancerWrong answer — click to see why

Why this is wrong here

A public load balancer distributes incoming internet traffic to backend resources and does not enable private communication between virtual networks over the Microsoft backbone.

★ When this WOULD be the correct answer

You need to distribute incoming internet traffic across multiple virtual machines in a backend pool for high availability and scalability. A public load balancer would be the correct choice.

Why candidates choose this

Candidates may mistakenly think a load balancer can route traffic between VNets because it handles network traffic, but it is designed for load balancing, not VNet-to-VNet connectivity.

An NSG outbound deny ruleWrong answer — click to see why

Why this is wrong here

An NSG outbound deny rule blocks traffic but does not enable private connectivity between VNets; it cannot establish communication over the Microsoft backbone.

★ When this WOULD be the correct answer

You need to block all outbound traffic from a subnet to the internet while allowing traffic to a specific service via service tags. An NSG outbound deny rule with a higher priority deny-all rule and an allow rule for the service tag would be correct.

Why candidates choose this

Candidates may think that controlling outbound traffic with NSG rules is sufficient to enable private communication, misunderstanding that NSGs only filter traffic and do not create network paths.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on AZ-104

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. VNet-Hub and VNet-Spoke1 are in the same region and subscription. Resources in the two VNets must communicate over the Microsoft backbone without using a VPN gateway. What should you configure?

medium
  • A.VNet peering
  • B.A site-to-site VPN gateway in each VNet
  • C.A private endpoint
  • D.A service endpoint

Why A: VNet peering enables direct connectivity between two virtual networks in the same region and subscription over the Microsoft backbone, without requiring a VPN gateway or public internet. This is the correct solution because it provides low-latency, private communication using the Azure infrastructure, and it supports resources in both VNets to communicate as if they were on the same network.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.