Virtual Networks, Subnets, Routing and Peering
Networking questions test virtual network creation, subnet configuration, peering, public IPs, user-defined routes, and network connectivity troubleshooting.
How to study for AZ-104
Treat each AZ-104 item as an admin workflow: identify the scope, resource type, access boundary, deployment method, monitoring signal, or recovery requirement.
Core concepts
Concept 1
Virtual Networks, Subnets, Routing and Peering questions reward operational Azure administration judgment rather than simple service-name recall.
Exam cue: Identify the Azure scope: tenant, management group, subscription, resource group, resource, subnet, or identity.
Concept 2
The best answer identifies the scope, resource type, access path, deployment method, monitoring signal, and recovery requirement.
Exam cue: Match the tool to the administrative task: manage access, deploy, secure, monitor, back up, or troubleshoot.
Concept 3
Eliminate answers that confuse RBAC with policy, public access with private access, monitoring with backup, or templates with manual changes.
Exam cue: Prefer least privilege, repeatable deployment, protected storage, private networking, and validated recovery.
Risk pitfalls and guardrails
Using Azure Policy when the question asks who is allowed to perform an action.
Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.
Opening public access when private endpoints, service endpoints, or NSGs meet the requirement.
Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.
Assuming backup exists before checking vault, policy, retention, and restore validation.
Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.
Memory anchors
Virtual Network
A virtual network provides private network connectivity for Azure resources.
Subnet
A subnet divides virtual network address space into segments.
VNet Peering
Virtual network peering connects virtual networks through private Azure backbone connectivity.
Public IP
A public IP address provides internet-reachable addressing for supported resources.
UDR
A user-defined route overrides default routing for selected traffic paths.
Route Table
A route table contains user-defined routes associated with subnets.
Effective Route
Effective routes show the routes that apply to a network interface.
Connectivity Troubleshooting
Connectivity troubleshooting checks routes, security rules, DNS, endpoints, and service health.
Address Space
Address space defines the IP ranges available to a virtual network.
Gateway Transit
Gateway transit allows peered networks to use a shared VPN or ExpressRoute gateway where configured.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A VNet uses 10.10.0.0/16. The administrator must create two subnets that do not overlap. Which design is valid?
A /29 Azure subnet is proposed for an application that needs five usable private addresses. Why is it too small?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
