Microsoft Certified:Azure Administrator Associate
Domain 4Objective 1
Configure and Manage Virtual Networks in Azure AZ-104 Practice Questions (Page 1)
Part of the Implement and manage virtual networking domain, which accounts for 15–20% of the AZ-104 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~6–13 in this domain), expect 2–4 from this objective — we provide 14 practice questions to prepare you well beyond it. (estimate)
14questions here
3free pages
6concepts
15–20%of the exam
Questions 1–5
- 1
You have a virtual machine (VM) that needs to be accessible from the internet via a public IP address. You also need to ensure that the public IP address does not change if the VM is stopped and started. What should you do?
Select an answer first - 2
You have two virtual networks in different Azure regions. VNet-A has a VPN gateway, and VNet-B does not. You need to allow resources in VNet-B to use the VPN gateway in VNet-A to connect to on-premises. You create a peering between VNet-A and VNet-B. What else must you configure?
Select an answer first - 3
You have two virtual networks in the same Azure region: VNet-A uses address space 10.1.0.0/16 and VNet-B uses 10.2.0.0/16. You need to enable resources in VNet-A to communicate with resources in VNet-B over the Microsoft backbone. You create a peering from VNet-A to VNet-B and from VNet-B to VNet-A. Both peerings show 'Connected'. However, a VM in VNet-A cannot ping a VM in VNet-B. What is the most likely cause?
Select an answer first - 4
You have a VM that is not reachable from the internet. The VM has a public IP, and the NSG on the NIC allows inbound HTTP (TCP 80). The subnet has an NSG that allows inbound HTTP from the internet. You check the effective security rules and see that the subnet NSG has a rule that denies inbound HTTP from the internet. What is the most likely cause?
Select an answer first - 5
You have a virtual network with a subnet that contains a VM. You need to route all outbound traffic from the VM to a network virtual appliance (NVA) for inspection, except traffic to the Azure DNS service (168.63.129.16). You create a user-defined route with destination 0.0.0.0/0 and next hop set to the NVA. What else should you do to ensure DNS traffic is not sent to the NVA?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “AZ-104” is a trademark of its owner, used for identification only.