AZ-104: Virtual Networking
Virtual Networking is one of the skill areas tested on the Azure Administrator (AZ-104) exam. Below are free AZ-104 practice questions with worked answers and a concept diagram — each with a plain-language explanation. Practice the first 10 questions of AZ-104 free, no signup.
The concept, in one picture
2 free AZ-104 Virtual Networking questions
You manage an Azure subscription with two virtual networks, VNet-A and VNet-B. VNet-A hosts a VPN gateway (route-based/dynamic routing) that terminates a site-to-site tunnel to your on-premises network, and you have also set up a point-to-site (P2S) VPN from a Windows 11 client to VNet-A. You then create a peering between VNet-A and VNet-B. On-premises hosts can now reach VNet-B, but the P2S Windows client still cannot. Your goal is to let the P2S client reach VNet-B. Proposed solution: On VNet-B, enable the peering option 'Allow gateway transit'. Does this meet the goal?
- Enabling 'Allow gateway transit' on VNet-B lets the point-to-site client reach VNet-B.No
The answer is No. 'Allow gateway transit' must be enabled on the peering of the VNet that actually hosts the gateway (VNet-A); the peer that borrows the gateway (VNet-B) instead needs 'Use remote gateways'. Enabling gateway transit on VNet-B is therefore the wrong side of the peering. Moreover, whenever peering or topology changes, P2S clients must download and reinstall the VPN client configuration package before the new routes reach the client, so this setting alone would not fix P2S connectivity anyway. (Note: P2S and VNet-peering gateway transit both require a route-based VPN gateway, which is why the gateway here is route-based.)
Several application servers run as Azure virtual machines inside one virtual network, VNet2. A group of employees who travel and work from home need to reach these VMs securely from their individual laptops over the internet — there is no corporate datacenter to connect back through. Which connectivity option should you deploy?
- ✓ A Point-to-Site (P2S) VPN gateway connection
- A Site-to-Site (S2S) VPN gateway connection
- A VNet-to-VNet connection between two Azure virtual networks
- A Multi-Site VPN connecting several on-premises locations
A Point-to-Site VPN establishes a secure tunnel from a single client device (such as a remote worker's laptop) directly to an Azure VNet, which is exactly the scenario for individual roaming users with no on-premises network. Site-to-Site and Multi-Site VPNs join one or more on-premises datacenters to Azure through a local VPN device, not individual laptops. A VNet-to-VNet connection links two Azure virtual networks together and does nothing for client devices.
Practice AZ-104 free
The first 10 questions of every exam are free. No signup, no email wall.
Start practicing →Get a free AZ-104 study plan by email
A short plan to work through AZ-104 by skill area, plus a note when we add new questions. Optional — the practice above stays free. No spam, unsubscribe anytime.