AZ-104 networking guide

AZ-104 Networking Guide: VNets, Subnets, DNS, Load Balancing and Connectivity

AZ-104 networking questions are often difficult because they combine several layers: address space, subnets, peering, user-defined routes, NSGs, application security groups, Bastion, service endpoints, private endpoints, Azure DNS and load balancing. A good answer usually follows the path of traffic rather than changing one random setting.

VNets NSGs Private Endpoints DNS

Direct Answer

AZ-104 networking questions are often difficult because they combine several layers: address space, subnets, peering, user-defined routes, NSGs, application security groups, Bastion, service endpoints, private endpoints, Azure DNS and load balancing. A good answer usually follows the path of traffic rather than changing one random setting.

The official study guide lists virtual networking at 15-20%, but networking knowledge also appears inside storage, compute, monitoring and troubleshooting questions. Treat it as a practical skill, not a memorised domain.

What to Know First

Use these quick points to frame your preparation before you start detailed practice.

Official weight

Implement and manage virtual networking is listed at 15-20%.

Most common trap

Assuming the NSG is wrong before checking DNS, routes and endpoint configuration.

Best habit

Trace source, destination, name resolution, route and security rules.

VNets, Subnets and Peering

You should know how to create and configure virtual networks and subnets, and how peering connects networks. Peering is powerful, but it does not automatically solve every routing, DNS or security requirement.

Practice by drawing the network before answering. Identify address spaces, subnet boundaries, where workloads live and whether traffic must cross a peering, gateway or private endpoint.

NSGs, ASGs and Secure Access

The study guide includes creating and configuring network security groups and application security groups, plus evaluating effective security rules. This means you should understand inbound and outbound rules, priority, source, destination and port.

Application security groups can make rules easier to manage when you want to group VMs by application role. Effective security rules help troubleshoot what is actually applied to a network interface or subnet.

DNS, Private Endpoints and Load Balancing

Private endpoints often introduce DNS considerations. If a PaaS service is reachable privately, the name resolution path must point clients to the private address. Many candidates miss this because they treat connectivity as only an NSG problem.

The guide also includes Azure DNS plus internal and public load balancers. For load balancing questions, identify whether the traffic is public or private, what probe is used and which backend resources should receive traffic.

Networking Troubleshooting Checklist

LayerQuestion to askExample issue
AddressingAre source and destination in valid address spaces?Overlapping VNet ranges can block peering design.
Name resolutionDoes DNS resolve to the expected address?Private endpoint names may need private DNS zone linkage.
RoutingWhich route wins for the destination?A user-defined route may send traffic to the wrong next hop.
SecurityDo NSG rules allow the required flow?A lower-priority deny rule may not matter if a higher-priority allow applies.
Service designIs the right endpoint or load balancer type selected?Public and internal load balancers solve different problems.

Original Networking Scenario

A web VM in one VNet must call an API VM in a peered VNet, but the connection fails. A disciplined AZ-104 answer checks VNet peering status, address ranges, route tables, NSG effective rules and DNS if names are used.

The lesson is to troubleshoot the path. The real exam often rewards candidates who can evaluate connectivity in order instead of jumping to a single familiar service.

Common Mistakes to Avoid

Treating every issue as an NSG issue

Connectivity can fail because of DNS, routes, peering, endpoints or load balancer probes.

Ignoring effective rules

The configured rule list is less important than what applies to the NIC and subnet.

Forgetting private DNS

Private endpoints frequently require DNS configuration for clients to resolve the private address.

How to Practise Network Tracing

For every networking scenario, write the path: source, subnet, route, security control, name resolution, destination and service configuration. This sequence slows you down in a useful way. It stops you from changing an NSG before checking whether the client resolves the right private address.

Practise with small diagrams. Even a simple text diagram can reveal overlapping address spaces, missing peering, incorrect route tables or a private endpoint DNS issue.

Connectivity Questions Beyond the Networking Domain

Networking can appear inside storage, compute and monitoring questions. A storage question may require firewall and private endpoint decisions. A compute question may involve App Service networking or VM connectivity. A monitoring question may use Network Watcher or Connection monitor to troubleshoot a path.

That is why networking preparation should not be isolated. Connect it to the services that depend on it.

Networking Practice Checklist

Before exam day, make sure you can explain VNet peering, subnets, public IPs, user-defined routes, NSGs, application security groups, Bastion, service endpoints, private endpoints, Azure DNS, internal load balancers and public load balancers.

For troubleshooting, practise reading symptoms carefully. If a name resolves publicly when it should resolve privately, the fix may be DNS. If the route points to a network appliance, the fix may be routing. If rules conflict, inspect effective security rules.

How to Use This Guide With AZ-104 Practice

Read the guide once for orientation, then turn it into active practice. Create a short list of decisions you should be able to make after studying this topic. For AZ-104 networking, that means more than recognising terms. You should be able to read a scenario, identify the real requirement, choose the Azure control that fits, and explain why the nearby alternatives are weaker.

After each practice set, review missed questions in three layers. First, identify the domain: identity, governance, storage, compute, networking, monitoring or recovery. Second, identify the mistake type: knowledge gap, wrong scope, missed constraint, timing pressure or distractor confusion. Third, write one repair action that you can complete before the next session.

This is the difference between passive reading and exam preparation. Passive reading makes the topic feel familiar. Active practice makes the topic usable when a new question changes the wording, combines domains or hides the deciding detail near the end of the prompt.

How This Topic Connects to the Rest of AZ-104

No AZ-104 domain lives alone. A compute question may include networking constraints, identity permissions, storage access and monitoring requirements. A governance question may include cost control, management-group scope and resource locks. A storage question may depend on private endpoints, firewall rules, lifecycle management and backup expectations.

When reviewing AZ-104 Networking Guide: VNets, Subnets, DNS, Load Balancing and Connectivity, deliberately connect it to at least two other domains. Ask how the topic changes when security, cost, availability, deployment or recovery becomes the priority. This cross-domain thinking is what makes practice more realistic and prevents the exam from feeling like a set of disconnected trivia questions.

Turn This Guide Into Practice

Use realistic AZ-104 practice to turn knowledge into administrator decisions: read the scenario, identify the scope, choose the right Azure control and review every explanation.

Start AZ-104 practice →

Frequently Asked Questions

Is networking heavily tested on AZ-104?

It is listed at 15-20%, and networking concepts also appear in other domains.

Do I need to know Azure DNS?

Yes. The study guide includes configuring Azure DNS and name resolution.

What is the best way to practise NSGs?

Create small inbound and outbound examples, then inspect effective security rules.

Are private endpoints in scope?

Yes. The study guide includes configuring private endpoints for Azure PaaS.

How should I troubleshoot networking questions?

Trace source, destination, DNS, route, security rule and service configuration in order.

Keep Building AZ-104 Readiness

Review the current Microsoft Learn study guide, practise with original scenarios, and use timed mixed sets when you are close to exam day.

Start preparing for AZ-104 →

Provider disclaimer: Heycademy is not affiliated with or endorsed by Microsoft. This page uses publicly available Microsoft Learn information for preparation guidance and original practice examples only.

Scroll to Top
Heycademy Career Workspace
Try Heycademy Career Workspace
Adaptive assessments • Resume optimization • Interview preparation • Personality insights • Career planning
Free preview and trial available.
Limited Time Offer • GOXERA35 saves 35%