Exam objective
AZ-104Configure secure access to virtual networks
This objective sits in Implement and manage virtual networking, which carries 19% of the Azure Administrator exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.
Objective title verbatim from the official objectives. Microsoft Azure exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
NSG1 on Subnet1 keeps only default rules. NSG2 on VM1's NIC allows TCP 80 inbound from the internet. An administrator reports internet clients still cannot reach VM1's port 80. Why?
Correct.
Checked against learn.microsoft.com, September 2026Concept
When filters stack along an inbound path, the outer layer sees the packet before the inner one, and a drop at the outer layer ends the evaluation. An allow written on the inner layer is only reached by traffic the outer layer already admitted.
Why C
For inbound traffic Azure first processes the NSG associated with the subnet, then the NSG on the network interface. NSG1 has no allow for port 80, so its DenyAllInbound default rule blocks the packet and NSG2 never evaluates it.
Source
Microsoft Learn: How network security groups filter network traffic, checked September 2026For inbound traffic, Azure first processes the rules in a network security group associated with a subnet if one exists. Azure then processes the rules in a network security group associated with the network interface if one exists. This same order of evaluation applies to intra-subnet traffic.
Now you: practice questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
A security team wants to stop all traffic between VMs in the same virtual network unless explicitly allowed. The AllowVNetInBound default rule cannot be deleted. What should the team do?
Sample question 2 of 3
An administrator creates an application security group named AsgApp and adds a NIC from VNet1. Adding a second NIC from VNet2 to the same group fails. What is the reason?
Sample question 3 of 3
A company adds and retires web tier VMs weekly. Each change makes an engineer edit source addresses in several NSG rules. How can the engineer stop maintaining explicit IP addresses?
Full Azure Administrator question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.