Topic module

Secure Virtual Network Access

Secure networking questions test NSGs, ASGs, effective rules, Azure Bastion, service endpoints, private endpoints, and secure PaaS access.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for AZ-104

Treat each AZ-104 item as an admin workflow: identify the scope, resource type, access boundary, deployment method, monitoring signal, or recovery requirement.

Core concepts

Concept 1

Secure Virtual Network Access questions reward operational Azure administration judgment rather than simple service-name recall.

Exam cue: Identify the Azure scope: tenant, management group, subscription, resource group, resource, subnet, or identity.

Concept 2

The best answer identifies the scope, resource type, access path, deployment method, monitoring signal, and recovery requirement.

Exam cue: Match the tool to the administrative task: manage access, deploy, secure, monitor, back up, or troubleshoot.

Concept 3

Eliminate answers that confuse RBAC with policy, public access with private access, monitoring with backup, or templates with manual changes.

Exam cue: Prefer least privilege, repeatable deployment, protected storage, private networking, and validated recovery.

Risk pitfalls and guardrails

Using Azure Policy when the question asks who is allowed to perform an action.

Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.

Opening public access when private endpoints, service endpoints, or NSGs meet the requirement.

Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.

Assuming backup exists before checking vault, policy, retention, and restore validation.

Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.

Memory anchors

NSG

A network security group filters inbound and outbound traffic using security rules.

ASG

An application security group groups virtual machines for NSG rule targeting.

Effective Rule

Effective security rules show the combined NSG rules applied to a network interface.

Azure Bastion

Azure Bastion provides secure browser-based RDP or SSH access without public VM exposure.

Service Endpoint

A service endpoint extends virtual network identity to supported Azure services.

Private Endpoint

A private endpoint exposes a service privately through a network interface in a virtual network.

Private Link

Private Link supports private connectivity to supported services.

Inbound Rule

An inbound rule controls traffic entering a subnet or network interface.

Outbound Rule

An outbound rule controls traffic leaving a subnet or network interface.

Secure Access

Secure access limits exposure, identity, ports, and management paths.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

An NSG has an inbound Allow rule at priority 300 and a matching Deny rule at priority 200. What is the result?

An administrator tries to create two NSG rules with priority 250 in the same direction. What should happen?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.