Courses Job Ready Program Fresher Trainings AI For Class 7 to 12 Corporate Training Placements Tutorials
Free Learning Resources

IT Tutorials & Interview Prep

Free guides, interview Q&As, and job responsibility breakdowns — curated by industry veterans to help you crack MNC interviews

248+
Tutorial Articles
17
Topic Categories
100%
Free to Read
← Back to Learning Hub

AZ-104: Day 7 — Azure Virtual Networking

Learning Hub Last Updated: Sep 16, 2026

Key Points, Definitions, Diagrams, Term Differences & Q&A

1. 25 Most Important Key Points

  • Azure Virtual Network (VNet) is the fundamental building block for private networking in Azure, letting resources communicate securely with each other, the internet, and on-premises networks.
  • A VNet is scoped to a single region and a single subscription, but it can span multiple Availability Zones within that region.
  • VNets use private IP address ranges defined in CIDR notation (e.g., 10.0.0.0/16), and address ranges must not overlap with any network they will connect to.
  • Subnets divide a VNet into smaller segments, letting administrators organize, secure, and route resources independently.
  • Azure reserves the first four and the last IP address in every subnet for internal use, reducing the usable address count.
  • A Network Security Group (NSG) acts as a basic firewall, filtering inbound and outbound traffic to subnets or individual NICs using allow/deny rules.
  • NSG rules are evaluated by priority number, from lowest to highest, and processing stops as soon as the first matching rule is found.
  • An Application Security Group (ASG) lets administrators group VMs by application role (e.g., "WebServers") and reference that group in NSG rules instead of hardcoding IP addresses.
  • A Route Table (User Defined Route, or UDR) overrides Azure's default system routes to force traffic through a specific path, such as a firewall or network virtual appliance.
  • VNet Peering connects two VNets so resources in each can communicate using private IP addresses as if they were on the same network.
  • VNet Peering traffic stays on Microsoft's private backbone network and never traverses the public internet, giving low latency and high bandwidth.
  • Global VNet Peering connects VNets across different Azure regions, while regional peering connects VNets within the same region.
  • Peering is not transitive — if VNet A peers with VNet B, and VNet B peers with VNet C, VNet A cannot automatically reach VNet C through VNet B.
  • Service Endpoints extend a VNet's private address space to Azure PaaS services (like Storage or SQL) while the service still keeps a public endpoint.
  • Private Endpoints assign a private IP address from the VNet directly to a PaaS service, fully removing its exposure to the public internet.
  • A Public IP address lets a resource be reached from, or reach out to, the internet, while a Private IP is only reachable within the VNet or connected networks.
  • Azure Load Balancer works at Layer 4 (TCP/UDP) distributing traffic across VMs, while Application Gateway works at Layer 7 (HTTP/HTTPS) with URL-based routing and Web Application Firewall (WAF) support.
  • A VPN Gateway creates an encrypted Site-to-Site or Point-to-Site connection between an on-premises network (or device) and an Azure VNet over the public internet.
  • ExpressRoute provides a private, dedicated connection between on-premises infrastructure and Azure that bypasses the public internet, offering higher reliability and lower latency than VPN.
  • Azure-provided DNS handles basic name resolution inside a VNet, while Azure Private DNS Zones allow custom domain names that resolve only within linked VNets.
  • Azure Bastion provides secure RDP/SSH access to VMs directly through the Azure portal, without ever exposing the VM's public IP address.
  • A NAT Gateway lets resources without a public IP make outbound internet connections through a single, static, shared public IP address.
  • Azure Firewall is a managed, stateful, cloud-native firewall offering centralized traffic filtering, threat intelligence, and logging, typically deployed inside a hub-and-spoke design.
  • The Hub-and-Spoke topology centralizes shared services (firewall, gateways) in a "hub" VNet, while workload VNets ("spokes") peer only to the hub rather than to each other.
  • A common student mistake is confusing NSGs (which filter traffic) with Route Tables (which decide the path traffic takes) — the two work together but solve different problems.

Figure 2: How an NSG evaluates rules — lowest priority number wins, first match stops evaluation

2. 20 Definitions with Day-to-Day Examples

Virtual Network (VNet)

Definition: An isolated, private network within Azure that lets resources securely communicate with each other, the internet, and on-premises networks.

Day-to-Day Example: Like a private office building's internal wiring — everything inside can talk to everything else, separate from the outside world.

Subnet

Definition: A smaller range of IP addresses carved out of a VNet's address space to organize and secure groups of resources.

Day-to-Day Example: Like dividing an office building into separate floors, each dedicated to a different department.

Network Security Group (NSG)

Definition: A set of allow/deny security rules that filters inbound and outbound network traffic to Azure resources.

Day-to-Day Example: Like a security guard at a door checking a list of who is allowed in or out.

Application Security Group (ASG)

Definition: A logical grouping of VMs by application role, used inside NSG rules instead of individual IP addresses.

Day-to-Day Example: Like giving every employee on the sales team the same badge color instead of listing each person by name.

Route Table (User Defined Route)

Definition: A set of custom rules that overrides Azure's default routing to control the path network traffic takes.

Day-to-Day Example: Like a custom detour sign redirecting delivery trucks through a specific checkpoint instead of the default road.

VNet Peering

Definition: A connection linking two Virtual Networks so resources in each can communicate privately using internal IP addresses.

Day-to-Day Example: Like two neighboring office buildings connecting a private hallway between them instead of using the public street.

Global VNet Peering

Definition: VNet Peering between Virtual Networks located in different Azure regions.

Day-to-Day Example: Like connecting two branch offices in different cities with a private, direct courier route.

Service Endpoint

Definition: A feature that extends a VNet's private address space to an Azure PaaS service, keeping traffic on the Azure backbone.

Day-to-Day Example: Like giving delivery trucks a private highway lane to a warehouse, even though the warehouse still has a public front door.

Private Endpoint

Definition: A network interface with a private IP address that connects privately and securely to a PaaS service, removing its public exposure.

Day-to-Day Example: Like installing a private back entrance to the warehouse so trucks never use the public front door at all.

Public IP Address

Definition: An internet-routable address that allows a resource to be reached from, or reach out to, the internet.

Day-to-Day Example: Like a storefront's public street address that any customer can visit.

Private IP Address

Definition: An internal address only reachable within the VNet or networks connected to it.

Day-to-Day Example: Like an internal office extension number that only coworkers inside the building can dial.

Azure Load Balancer

Definition: A Layer 4 (TCP/UDP) service that distributes incoming network traffic across multiple VMs for availability and performance.

Day-to-Day Example: Like a host at a restaurant sending guests to whichever open table is next, without caring what they plan to order.

Application Gateway

Definition: A Layer 7 (HTTP/HTTPS) web traffic load balancer with URL-based routing and Web Application Firewall (WAF) capability.

Day-to-Day Example: Like a smart receptionist who reads each visitor's request and directs them to the right department, while also screening out troublemakers.

VPN Gateway

Definition: An Azure resource that creates an encrypted connection between an on-premises network (or device) and a VNet over the public internet.

Day-to-Day Example: Like a locked, armored courier van driving over ordinary public roads.

ExpressRoute

Definition: A private, dedicated connection between on-premises infrastructure and Azure that does not travel over the public internet.

Day-to-Day Example: Like a private rail line built directly between two company sites, separate from public traffic entirely.

Azure Private DNS Zone

Definition: A DNS zone that resolves custom domain names privately, only for VNets linked to it.

Day-to-Day Example: Like an internal company phone directory that only employees can look up, unlisted anywhere public.

Azure Bastion

Definition: A fully managed service providing secure RDP/SSH access to VMs through the Azure portal, without exposing a public IP.

Day-to-Day Example: Like entering a secured building through a monitored front desk instead of climbing through a window.

NAT Gateway

Definition: A service that lets resources without public IPs make outbound internet connections through one shared, static public IP.

Day-to-Day Example: Like an office's single shared mailroom address used to send outgoing mail for everyone inside.

Azure Firewall

Definition: A managed, stateful, cloud-native firewall providing centralized traffic filtering, threat intelligence, and logging.

Day-to-Day Example: Like a company's central security checkpoint that every outgoing and incoming shipment must pass through.

Hub-and-Spoke Topology

Definition: A network design where a central "hub" VNet hosts shared services, and "spoke" VNets peer only to the hub, not to each other.

Day-to-Day Example: Like airline routes where regional airports (spokes) all connect through one major hub airport instead of flying directly to each other.

Figure 3: Hub-and-Spoke VNet topology — spokes peer with the hub, not with each other

Figure 4: VPN Gateway (encrypted, over the internet) vs. ExpressRoute (private, dedicated circuit)

3. Differences Between Key Technical Terms (10)

1. Network Security Group (NSG) vs. Application Security Group (ASG)

FeatureNSGASG
PurposeFilters inbound/outbound traffic with allow/deny rulesGroups VMs by application role for use inside NSG rules
Works alone?Yes — a complete filtering mechanism on its ownNo — always referenced inside an NSG rule
Common confusionMistaken as only working with individual IPsIt's a label, not a rule engine, on its own



 

2. NSG vs. Route Table (UDR)

FeatureNSGRoute Table (UDR)
Question answeredIs this traffic allowed?Which path should this traffic take?
FocusSecurity filteringTraffic direction / next hop
ExampleBlock inbound port 3389 from the internetSend all outbound traffic through a firewall appliance



 

3. VNet Peering vs. VPN Gateway

FeatureVNet PeeringVPN Gateway
ConnectsVNet to VNetOn-premises network (or device) to a VNet
PathMicrosoft private backboneEncrypted tunnel over the public internet
Typical useLinking Azure VNets togetherConnecting a branch office or remote user to Azure



 

4. Regional Peering vs. Global Peering

FeatureRegional PeeringGlobal Peering
ScopeVNets in the same regionVNets in different regions
LatencyLower (same region)Slightly higher (cross-region)
Common confusionAssumed to be the only type availableMistaken as requiring a VPN Gateway instead



 

5. Service Endpoint vs. Private Endpoint

FeatureService EndpointPrivate Endpoint
PaaS still has a public IP?YesNo — fully private
IP address usedTraffic tagged with VNet identity, service keeps public IPService gets a private IP from the VNet
Security levelGood — restricts to VNet, but public endpoint remainsStronger — removes public exposure entirely



 

6. Public IP vs. Private IP

FeaturePublic IPPrivate IP
Reachable fromThe internetOnly within the VNet or connected networks
Typical useWeb-facing resources, VPN endpointsInternal communication between resources
Common confusionAssumed every resource needs oneMistaken as unreachable even from peered VNets



 

7. Load Balancer vs. Application Gateway

FeatureLoad BalancerApplication Gateway
OSI layerLayer 4 (TCP/UDP)Layer 7 (HTTP/HTTPS)
Routing intelligenceBased on IP/port onlyBased on URL path, host header, etc.
Extra capabilityNone built inWeb Application Firewall (WAF)



 

8. VPN Gateway vs. ExpressRoute

FeatureVPN GatewayExpressRoute
PathPublic internet (encrypted)Private, dedicated circuit
Reliability / latencyGood, but internet-dependentHigher reliability, lower and more predictable latency
Best suited forSmaller sites, quick setup, remote usersLarge enterprises needing consistent, high-volume connectivity



 

9. Azure DNS (Public) vs. Azure Private DNS Zone

FeatureAzure DNS (Public)Azure Private DNS Zone
Resolvable fromAnywhere on the internetOnly VNets linked to the zone
Typical useHosting a public website's domainInternal service names like db.internal.contoso.com
Common confusionAssumed to be the same service as Private DNSMistaken as visible outside the linked VNets



 

10. Hub-and-Spoke vs. Full Mesh (Direct Peer-to-Peer) Topology

FeatureHub-and-SpokeFull Mesh
Peering patternEach spoke peers only with the hubEvery VNet peers directly with every other VNet
Management complexityLow — centralized in the hubHigh — grows quickly as VNets are added
Best suited forEnterprises with shared services (firewall, gateway)Very small numbers of VNets needing direct links



 

4. Theoretical Questions (15)

Q1. What is an Azure Virtual Network (VNet), and what is its main purpose?

Answer: A VNet is an isolated, private network in Azure that lets resources communicate securely with each other, the internet, and on-premises networks; its main purpose is to provide a private, controllable networking boundary in the cloud.

Q2. What is a subnet, and why do administrators divide a VNet into multiple subnets?

Answer: A subnet is a smaller IP address range carved out of a VNet; administrators use multiple subnets to organize resources by role (web, app, data) and apply different security and routing rules to each group.

Q3. How does an NSG decide whether to allow or block a piece of traffic?

Answer: An NSG evaluates its rules in order of priority number, from lowest to highest, and applies the first rule that matches the traffic, stopping evaluation at that point.

Q4. What problem does an Application Security Group (ASG) solve?

Answer: An ASG lets administrators group VMs by application role and reference that group name in NSG rules, avoiding the need to hardcode and continually update individual IP addresses.

Q5. What is a Route Table (UDR), and when would an administrator need one?

Answer: A Route Table (User Defined Route) overrides Azure's default routing so traffic follows a custom path; it's needed when traffic must be forced through a firewall or network virtual appliance instead of going directly to its destination.

Q6. What is VNet Peering, and why is traffic through it considered fast and secure?

Answer: VNet Peering connects two VNets so resources communicate using private IP addresses; it's fast and secure because the traffic travels over Microsoft's private backbone network rather than the public internet.

Q7. Why is VNet Peering described as "not transitive"?

Answer: Because if VNet A peers with VNet B, and VNet B peers with VNet C, VNet A cannot automatically reach VNet C — a direct peering connection would need to be created between A and C.

Q8. What is the key difference between a Service Endpoint and a Private Endpoint?

Answer: A Service Endpoint keeps the PaaS service's public endpoint but restricts and optimizes traffic from the VNet, while a Private Endpoint assigns the service a private IP inside the VNet, removing public exposure entirely.

Q9. How do Azure Load Balancer and Application Gateway differ in what they can route on?

Answer: Load Balancer works at Layer 4 and routes based only on IP address and port, while Application Gateway works at Layer 7 and can route based on URL path, host header, or other HTTP-level details, and adds Web Application Firewall protection.

Q10. What is the core difference between a VPN Gateway connection and an ExpressRoute connection?

Answer: A VPN Gateway creates an encrypted connection over the public internet, while ExpressRoute is a private, dedicated circuit that bypasses the public internet, offering more predictable performance and reliability.

Q11. What is the difference between Azure-provided DNS and an Azure Private DNS Zone?

Answer: Azure-provided DNS handles basic default name resolution automatically inside a VNet, while a Private DNS Zone lets an organization define its own custom domain names that resolve only within the VNets linked to that zone.

Q12. What problem does Azure Bastion solve?

Answer: Azure Bastion lets administrators securely RDP or SSH into VMs directly through the Azure portal without ever assigning the VM a public IP address, reducing its exposure to internet-based attacks.

Q13. What does a NAT Gateway do for resources that don't have a public IP?

Answer: A NAT Gateway lets those resources initiate outbound connections to the internet through a single, shared, static public IP address, without needing a public IP of their own.

Q14. What is Azure Firewall, and how does it typically fit into a network design?

Answer: Azure Firewall is a managed, stateful, cloud-native firewall that centrally filters traffic and applies threat intelligence; it's typically deployed in the hub VNet of a hub-and-spoke design so all spokes route through it.

Q15. What is the Hub-and-Spoke topology, and what is its main advantage?

Answer: It's a design where a central hub VNet hosts shared services (like a firewall or gateway) and spoke VNets peer only with the hub; its main advantage is centralizing management and security instead of configuring every VNet individually.

5. Scenario-Based Questions (8)

Q1. A company needs its Web, Application, and Database tiers to be logically separated within a single VNet, each with different security rules. What should they configure?

Answer: They should create separate subnets for Web, Application, and Database tiers within the VNet, and apply a distinct NSG to each subnet to enforce tier-specific security rules.

Q2. An administrator wants to reference a group of 20 web server VMs in an NSG rule without listing each VM's IP address individually, and wants the rule to keep working automatically as VMs are added or removed.

Answer: They should create an Application Security Group (ASG) for the web servers, add the VM NICs to it, and reference the ASG inside the NSG rule instead of individual IP addresses.

Q3. A company wants all outbound traffic from its Application subnet to pass through a third-party firewall appliance before reaching the internet, instead of going directly.

Answer: They should create a Route Table (User Defined Route) that sends the Application subnet's outbound traffic to the firewall appliance's private IP as the next hop, then associate that route table with the subnet.

Q4. Two VNets in the same Azure region need their VMs to communicate using private IP addresses with minimal latency. What should be configured?

Answer: They should configure Regional VNet Peering between the two VNets, allowing their resources to communicate privately over Microsoft's backbone network.

Q5. A company wants its on-premises SQL Server to securely sync data with an Azure SQL Database, keeping traffic off the public internet entirely, and needs guaranteed low, predictable latency.

Answer: They should provision an ExpressRoute circuit, giving them a private, dedicated connection between on-premises infrastructure and Azure that bypasses the public internet.

Q6. A security team wants an Azure Storage Account to be reachable only from inside its VNet, with absolutely no public internet exposure.

Answer: They should configure a Private Endpoint for the Storage Account, which assigns it a private IP address inside the VNet and removes its public endpoint from being reachable.

Q7. An e-commerce site needs incoming HTTPS traffic routed to different backend pools based on the URL path (e.g., /images vs. /api), plus protection against common web attacks.

Answer: They should deploy an Application Gateway with URL-based routing rules and enable its Web Application Firewall (WAF) to route traffic correctly and protect against common web-based attacks.

Q8. A growing company has one hub VNet with a shared firewall and five separate spoke VNets for different departments, and wants all internet-bound traffic from every spoke inspected centrally.

Answer: They should keep the Hub-and-Spoke topology, peer each spoke only to the hub, and configure route tables in each spoke that force outbound traffic through the Azure Firewall sitting in the hub VNet.