nerdexam
Microsoft

AZ-104 · Question #115

Hotspot Question You have an Azure subscription named Subscription1. Subscription1 contains a virtual machine named VM1. You install and configure a web server and a DNS server on VM1. VM1 has the…

The correct answer is The A record for VM5 will be registered automatically in the adatum.com.zone. = No; VM5 can resolve VM9.adatum.com. = Yes; VM5 can resolve VM9.adatum.com. = Yes. Based on the NSG rules shown, VM1 has specific inbound and outbound rules that control traffic. The effective NSG rules typically allow HTTP (port 80) and DNS (port 53) traffic while potentially blocking other ports. The correct answers reflect that internet users CAN reach the…

Submitted by ravi_2018· Mar 4, 2026Implement and manage virtual networking - specifically configuring and troubleshooting Network Security Groups (NSGs) and understanding effective security rules as tested in AZ-104: Microsoft Azure Administrator

Question

Hotspot Question You have an Azure subscription named Subscription1. Subscription1 contains a virtual machine named VM1. You install and configure a web server and a DNS server on VM1. VM1 has the effective network security rules shown in the following exhibit. Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point. Answer:

Exhibits

AZ-104 question #115 exhibit 1
AZ-104 question #115 exhibit 2

Answer Area

  • The A record for VM5 will be registered automatically in the adatum.com.zone.No
  • VM5 can resolve VM9.adatum.com.Yes
  • VM5 can resolve VM9.adatum.com.Yes

Explanation

Based on the NSG rules shown, VM1 has specific inbound and outbound rules that control traffic. The effective NSG rules typically allow HTTP (port 80) and DNS (port 53) traffic while potentially blocking other ports. The correct answers reflect that internet users CAN reach the web server (port 80 allowed) but CANNOT reach the DNS server from the internet (port 53 blocked inbound from internet), while internal Azure traffic may still function. Each statement is evaluated against the specific port rules visible in the NSG exhibit.

Topics

#Network Security Groups#Azure Virtual Machines#Inbound/Outbound Rules#Azure Networking

Community Discussion

No community discussion yet for this question.

Full AZ-104 Practice