nerdexam
Microsoft

AZ-104 · Question #828

Hotspot Question You have an Azure subscription that contains the virtual networks shown in the following table. The subscription contains the virtual machines shown in the following table. For each o

The correct answer is Policy1 can be associated to Subnet2. = Yes; Policy2 can be associated to Subnet1. = No; Policy2 can be associated to Subnet3. = Yes. Azure Network Policy (NAT Gateway policy or Network Security Group policy) association rules are based on the region and resource group alignment between the policy and the subnet's virtual network. Policy1 can be associated to Subnet2 because they share compatible regional and n

Submitted by chiamaka_o· Mar 4, 2026Configure and manage virtual networking in Azure, including associating network policies (such as NAT Gateway or NSG policies) to subnets based on regional compatibility and resource constraints - typically covered under 'Implement and Manage Virtual Networking' in AZ-104 or AZ-700 certification domains.

Question

Hotspot Question You have an Azure subscription that contains the virtual networks shown in the following table. The subscription contains the virtual machines shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:

Exhibits

AZ-104 question #828 exhibit 1
AZ-104 question #828 exhibit 2

Answer Area

  • Policy1 can be associated to Subnet2.Yes
  • Policy2 can be associated to Subnet1.No
  • Policy2 can be associated to Subnet3.Yes

Explanation

Azure Network Policy (NAT Gateway policy or Network Security Group policy) association rules are based on the region and resource group alignment between the policy and the subnet's virtual network. Policy1 can be associated to Subnet2 because they share compatible regional and network configurations. Policy2 cannot be associated to Subnet1 because there is a regional or VNet mismatch (e.g., different regions or incompatible configurations), but Policy2 can be associated to Subnet3 because it meets the required compatibility criteria such as being in the same region or having no conflicting resources like VMs with public IPs already assigned.

Topics

#Azure Virtual Networks#Network Security Groups#NAT Gateway#Subnet Policy Association

Community Discussion

No community discussion yet for this question.

Full AZ-104 Practice