4.0 Implement and manage virtual networking AZ-104 Practice Quiz
85 exam-style questions covering 18% of the AZ-104 exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the Microsoft Azure Administrator practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
A support ticket reports a networking issue involving create and configure virtual networks and subnets. Which action is most appropriate?
- A. Create a virtual network with a non-overlapping address space and add subnets sized for the workload
- B. Use Application Insights only for production and skip dev/test environments
- C. Use Azure Spot VMs for stateful database workloads requiring zero downtime
- D. Use a Network Security Group as a stateful application-layer firewall
Virtual network address planning must avoid overlap and leave enough space for resources that will be deployed.
A production connectivity issue requires troubleshooting for create and configure virtual networks and subnets. Which Azure administrator action is correct?
- A. Review reserved Azure IP addresses when planning usable addresses in each subnet
- B. Treat Azure Backup as a substitute for Site Recovery for region-level outages
- C. Use Azure Cost Management to deploy infrastructure code
- D. Treat Azure Policy as an alert system rather than an enforcement mechanism
Azure reserves addresses in every subnet, so the usable capacity is smaller than the CIDR range suggests.
During a network review, the team identifies a requirement for create and configure virtual networks and subnets. What should be configured?
- A. Assign privileged roles permanently to all team members
- B. Create separate subnets for tiers that require different routing or security controls
- C. Use Microsoft Entra roles in place of Azure RBAC roles for resource access
- D. Use AWS Cost Explorer to manage Azure spend
Subnet boundaries allow administrators to apply NSGs, routes, and service integrations to specific groups of resources.
A support ticket reports a networking issue involving create and configure virtual network peering. Which action is most appropriate?
- A. Use Azure Front Door as a layer 4 TCP/UDP load balancer
- B. Create peering from each virtual network to the other and enable traffic options that match the design
- C. Use Azure Monitor without Log Analytics workspaces and store logs only in storage accounts
- D. Create a resource group tag as the alert condition
Virtual network peering must be configured in both directions for private connectivity.
A production connectivity issue requires troubleshooting for create and configure virtual network peering. Which Azure administrator action is correct?
- A. Use NSG Flow Logs without a Log Analytics workspace and expect interactive analytics
- B. Check NSGs, route tables, and DNS after peering when VMs still cannot communicate
- C. Create a storage lifecycle rule to change subnet routing
- D. Place a customer firewall appliance without a user-defined route to direct traffic to it
Peering provides a path, but security rules, routes, and name resolution can still block traffic.
A workload team needs Azure networking support for create and configure virtual networks and subnets. Which option should be selected?
- A. Configure backup reports without delegating ownership to a recipient
- B. Use a single shared admin account for all team members to simplify access
- C. Adjust the subnet address range before deploying resources when the planned IP capacity is insufficient
- D. Assign licenses by editing CSV files instead of using group-based licensing
Subnet sizing is easier to correct before dependent resources consume addresses.
During a network review, the team identifies a requirement for create and configure virtual network peering. What should be configured?
- A. Configure MFA only after a security incident has already occurred
- B. Use Network Watcher Connection Troubleshoot as a packet-capture utility
- C. Enable gateway transit and use remote gateways only when one peered network should share its VPN gateway
- D. Disable soft delete in the vault to reduce storage costs
Gateway transit allows one virtual network to use a gateway in the peered virtual network when configured correctly.
An audit finding shows that the current configuration for create and configure virtual networks and subnets is incomplete. What should be changed?
- A. Treat Azure RBAC role assignments as automatically inherited from on-premises Active Directory
- B. Use a Basic-tier Azure Load Balancer for production workloads
- C. Assign a subscription Owner role to fix packet flow
- D. Enable the required subnet delegation when a PaaS service needs delegated subnet control
Some Azure services require subnet delegation before they can be deployed into the subnet.
Key Terms in This Domain
- Azure Virtual Network (VNet): Private network in Azure with subnets, routing, and security
- Microsoft Entra ID: Cloud-based identity and access management (formerly Azure AD)
- Azure Cost Management: Cost analysis, budgets, alerts, and recommendations for Azure spend
- Azure Advisor: Personalized recommendations across cost, security, performance, reliability
- Azure Files: Managed SMB and NFS file shares in the cloud
- Azure Disk Storage: Managed disks attached to Azure VMs (gp/premium/ultra SSD options)
- Customer managed key (CMK): Bring-your-own key in Azure Key Vault for storage encryption
- Storage firewall and VNet rules: Restrict storage account network access to specific networks/IPs
- Azure Virtual Machine: IaaS Windows or Linux VMs in Azure
- VM size: Performance tier (CPU/memory/network/disk) for a virtual machine
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/microsoft-az-104/implement-and-manage-virtual-networking/
<a href="https://quizbuffet.com/microsoft-az-104/implement-and-manage-virtual-networking/">AZ-104 Azure Administrator Implement and manage virtual networking practice quiz on QuizBuffet</a>
Other AZ-104 Domains
- 1.0 Manage Azure identities and governance
- 2.0 Implement and manage storage
- 3.0 Deploy and manage Azure compute resources
- 5.0 Monitor and maintain Azure resources
← Back to AZ-104 practice test overview
Questions are written against the published AZ-104 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.