Exam objective

AZ-104

Configure secure access to virtual networks

This objective sits in Implement and manage virtual networking, which carries 19% of the Azure Administrator exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Implement and manage virtual networking

NSG1 on Subnet1 keeps only default rules. NSG2 on VM1's NIC allows TCP 80 inbound from the internet. An administrator reports internet clients still cannot reach VM1's port 80. Why?

Rules in a NIC-level NSG apply only to outbound traffic flowsNIC-level NSGs filter both directions; direction is not the issue.
Two NSGs on one path cancel each other and block everythingStacked NSGs are evaluated in sequence, and traffic passes when both allow it.
The subnet NSG runs first and DenyAllInbound drops the packetCorrect · your answerCorrect.
The NIC NSG needs a higher priority number than the subnet NSGPriorities are compared only inside one NSG, never between the subnet and NIC groups.

Correct.

Checked against learn.microsoft.com, September 2026

Concept

When filters stack along an inbound path, the outer layer sees the packet before the inner one, and a drop at the outer layer ends the evaluation. An allow written on the inner layer is only reached by traffic the outer layer already admitted.

Why C

For inbound traffic Azure first processes the NSG associated with the subnet, then the NSG on the network interface. NSG1 has no allow for port 80, so its DenyAllInbound default rule blocks the packet and NSG2 never evaluates it.

Source

For inbound traffic, Azure first processes the rules in a network security group associated with a subnet if one exists. Azure then processes the rules in a network security group associated with the network interface if one exists. This same order of evaluation applies to intra-subnet traffic.

Microsoft Learn: How network security groups filter network traffic, checked September 2026
#nsg#evaluation-order#inbound

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Implement and manage virtual networking

A security team wants to stop all traffic between VMs in the same virtual network unless explicitly allowed. The AllowVNetInBound default rule cannot be deleted. What should the team do?

Sample question 2 of 3

Implement and manage virtual networking

An administrator creates an application security group named AsgApp and adds a NIC from VNet1. Adding a second NIC from VNet2 to the same group fails. What is the reason?

Sample question 3 of 3

Implement and manage virtual networking

A company adds and retires web tier VMs weekly. Each change makes an engineer edit source addresses in several NSG rules. How can the engineer stop maintaining explicit IP addresses?

Full Azure Administrator question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Implement and manage virtual networking