exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 5 question 29 discussion

Actual exam question from Microsoft's AZ-104
Question #: 29
Topic #: 5
[All AZ-104 Questions]

You have two subscriptions named Subscription1 and Subscription2. Each subscription is associated to a different Azure AD tenant.
Subscription1 contains a virtual network named VNet1. VNet1 contains an Azure virtual machine named VM1 and has an IP address space of 10.0.0.0/16.
Subscription2 contains a virtual network named VNet2. VNet2 contains an Azure virtual machine named VM2 and has an IP address space of 10.10.0.0/24.
You need to connect VNet1 to VNet2.
What should you do first?

  • A. Move VM1 to Subscription2.
  • B. Move VNet1 to Subscription2.
  • C. Modify the IP address space of VNet2.
  • D. Provision virtual network gateways.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mlantonis
Highly Voted 3 years, 9 months ago
Correct Answer: D There is no overlap between the VNets: VNet1: 10.0.0.0/16 - CIDR IP Range 10.0.0.0 - 10.0.255.255 VNet2: 10.10.0.0/24 - CIDR IP Range 10.10.0.0 - 10.0.0.255 Note: If a virtual network has address ranges that overlap with another virtual network or on-premises network, the two networks can't be connected. You can connect virtual networks (VNets) by using the VNet-to-VNet connection type. Virtual networks can be in different regions and from different subscriptions. When you connect VNets from different subscriptions, the subscriptions don't need to be associated with the same Active Directory tenant. Reference: https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-howto-vnet-vnet-resource-manager-portal https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpngateways
upvoted 137 times
Jayad
2 years, 11 months ago
Nicely explained
upvoted 3 times
...
Alex2022_31
2 years, 1 month ago
Correct answer and well explained There is a typo in your VNet2 CIDR IP Rage : 10.10.0.0 - 10.10.0.255 (instead of 10.0.0.255) :)
upvoted 10 times
...
cassucena
2 years, 4 months ago
a peering is not possible in this situation? tks
upvoted 4 times
...
OlehT
1 year, 1 month ago
mistake: VNet2: 10.10.0.0/24 - CIDR IP Range 10.10.0.0 - 10.10.0.255 (not 10.0.0.255)
upvoted 1 times
...
...
fedztedz
Highly Voted 4 years, 2 months ago
Answer is correct. "D" . It is a VNET to VNET connection where there is no IP overlap exists. Also, No need to have the same Azure AD. They just need to have a Virtual network gateway to communicate using Public IP where it is secured using SSTP or IKEv2
upvoted 70 times
magichappens
2 years, 11 months ago
I found answer D is the only one that makes sense as well but I actually miss "peering" here as this would be a way better way of connecting both VNET´s. Its supported for cross tenant and cross subscription connections so it would be more accurate.
upvoted 7 times
...
...
[Removed]
Most Recent 5 months, 1 week ago
Selected Answer: D
D is correct
upvoted 1 times
...
Surs
5 months, 2 weeks ago
Question is outdated. We can create a peering between VNets in different subs and tenants following the steps provided in the article link below: https://learn.microsoft.com/en-us/azure/virtual-network/create-peering-different-subscriptions?tabs=create-peering-portal
upvoted 3 times
Surs
5 months, 2 weeks ago
However, if these are the only options available, then D is the right answer. https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-howto-vnet-vnet-resource-manager-portal
upvoted 1 times
...
...
pasangawa
5 months, 4 weeks ago
Selected Answer: D
no overlapping of IP here. vpn peering should work on different subscription however since not on the choices can do virtual network gateways. https://learn.microsoft.com/en-us/azure/virtual-network/create-peering-different-subscriptions?tabs=create-peering-portal "A virtual network peering can't be created between two virtual networks deployed through the classic deployment model. If you need to connect virtual networks that were both created through the classic deployment model, you can use an Azure VPN Gateway to connect the virtual networks."
upvoted 1 times
...
[Removed]
6 months ago
Answer D is correct. Vnet Peering is unavailable because those subscriptions are under different tenants. That means the only way to connect is to use Vnet-toVnet connection type.
upvoted 1 times
...
Ahkhan
1 year, 3 months ago
They could have just peered the two vNets as we can peer vNets in 2 different subscriptions. Can I enable virtual network peering if my virtual networks belong to subscriptions within different Microsoft Entra tenants? Yes. It's possible to establish virtual network peering (whether local or global) if your subscriptions belong to different Microsoft Entra tenants. You can do this via the Azure portal, PowerShell, or the Azure CLI. https://learn.microsoft.com/en-us/azure/virtual-network/virtual-networks-faq
upvoted 4 times
...
CyberKelev
2 years ago
Selected Answer: D
To connect VNet1 to VNet2, you need to create a site-to-site VPN connection between the two virtual networks. The first step to accomplish this is to provision virtual network gateways in both subscriptions. Therefore, the correct answer is: D. Provision virtual network gateways. Once the virtual network gateways are provisioned, you can configure the VPN connection between them to enable traffic to flow between VNet1 and VNet2. Moving VM1 to Subscription2 or modifying the IP address space of VNet2 is not required to establish the VPN connection between the two virtual networks. Similarly, moving VNet1 to Subscription2 is not required, but you may need to create a peering connection between the virtual networks after the VPN connection is established to enable communication between the virtual machines.
upvoted 2 times
...
EmnCours
2 years, 6 months ago
Selected Answer: D
Correct Answer: D
upvoted 1 times
...
El7arani
2 years, 7 months ago
Selected Answer: D
D is correct
upvoted 1 times
...
nkhan19
2 years, 7 months ago
Selected Answer: C
C. Modify the IP address space of VNet2. B/C you have 10.10.0.0/24 , no space for GatewaySubnet only after modifying address space, you can create Gw Subnet and then add gw for VNet-VNet
upvoted 2 times
...
Lazylinux
2 years, 8 months ago
Selected Answer: D
D is correct Create a virtual network ***( That is the Gateway Subnet)*** Create a VPN gateway, A resource that provides a virtual VPN appliance for the VNet. It is responsible for routing traffic from the on-premises network to the VNet
upvoted 3 times
Tyy27
2 years, 7 months ago
good man for commenting the correct answers recently in these discussions
upvoted 2 times
...
...
EleChie
2 years, 8 months ago
Answer is correct: (the VNets IP ranges are confusing many of you) VNet1: 10.0.0.0/16 - CIDR IP Range 10.0.0.0 - 10.0.255.255 VNet2: 10.10.0.0/24 - CIDR IP Range 10.10.0.0 - 10.0.0.255 As we see the VNet2 range is not part of the VNet1 IP range, So there is no overlap between these two VNets. and therefore no need to modify the IP address space of VNet2
upvoted 2 times
...
pappkarcsiii
3 years ago
Selected Answer: D
Answer is correct. "D" . It is a VNET to VNET connection where there is no IP overlap exists.
upvoted 1 times
...
Barrie
3 years, 4 months ago
Got to think this question is out of date. I wouldn't do any of the provided options. A global VNET peer achieves the required outcome, without the need for additional infrastructure.
upvoted 10 times
...
maxmarco71
3 years, 4 months ago
ANSWER IS "D" CORRECT NO Overlapping. Proof using https://network00.com/NetworkTools/IPv4CheckOverlappingNetworks/
upvoted 1 times
...
AubinBakana
3 years, 6 months ago
They should have asked - what's the best way. Because top 2 options do lead to the solution, with a little more effort. Answer is correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago