AZ-104 Scenario Guide: Read Diagrams, Code, and Evidence

Practise interpreting AZ-104 network diagrams, deployment dependencies, and monitoring evidence without guessing from familiar service names.

Use IT Mastery to practise Azure decisions with varied scenarios. The refreshed AZ-104 questions include diagrams, code, and tables where these make the task clearer. This guide shows how to turn an exhibit into a defensible decision.

The worked examples below are original explanatory examples, not official Microsoft questions or copied exam content. For answer choices and explanations from the current practice set, use the free practice page .

Read the requirement before selecting a control

  1. State the outcome: restore data, allow a particular flow, deploy a resource, or notify an operator.
  2. Find the scope: tenant, subscription, resource group, individual resource, subnet, or workspace.
  3. Identify decisive evidence: a permission, rule, reference, error, timestamp, or connection.
  4. Apply every stated constraint: least privilege, existing resources, required availability, or limited disruption.
  5. Check completeness: an answer must satisfy the whole requirement, including necessary dependencies.

A familiar service name is a candidate solution, not evidence that it fits.

Read a network diagram as a set of relationships

Suppose a diagram shows direct peering between AppVNet and HubVNet, and between HubVNet and DataVNet. The scenario states there is no forwarding appliance or other transit configuration.

The two lines establish two direct relationships. They do not establish direct peering between AppVNet and DataVNet. Ordinary VNet peering is nontransitive: an intermediate peered VNet does not automatically forward traffic between the others. Microsoft’s peering guidance describes connectivity and service chaining separately.

Before deciding whether an application can connect, also check any supplied routes, NSGs, DNS results, and endpoint permissions. A valid network path does not prove application access.

Reading habit: say what each line means. Do not infer a route from the visual position of a box, and do not treat an unlabeled line as proof of an unstated connection.

Read a deployment diagram as prerequisites

Bicep describes the resources Azure should deploy. A dependency diagram can show that a network interface needs a subnet and a public IP, while a VM needs the network interface.

ResourcePrerequisites shown in this example
Virtual networkNone
Public IPNone
SubnetVirtual network
Network interfaceSubnet and public IP
Virtual machineNetwork interface

The virtual network and public IP can deploy independently. The VM must wait for its required network interface, which in turn waits for its prerequisites. The relevant skill is identifying those dependencies and any available parallelism. Resource declaration order alone does not establish deployment order. See Bicep resource dependencies .

Reading habit: follow the arrow direction described in the question. A deployment prerequisite is different from a network traffic path; the same arrow shape can represent either when the legend says so.

Read a rule table against the complete flow

For an NSG exhibit, write down the flow before reading rules: direction, source, destination, protocol, and destination port.

For example, a backend application may listen on TCP 8443 while clients connect to a load-balancer frontend on TCP 443. A probe can also use TCP 8443. A rule that permits the intended client subnet does not by itself establish that probe traffic is permitted.

Inspect the probe’s actual source and port, then evaluate all relevant custom and default rules. Use the same method separately for client traffic. Microsoft documents NSG matching and the default load-balancer probe rule in its NSG overview .

Reading habit: do not apply a frontend port or client source address to every leg of the connection.

Read monitoring evidence on a timeline

Suppose guest log collection begins at 14:00, but the question asks about an incident at 13:30. A correctly written query cannot retrieve records that were never collected into that destination.

Check the data source, collection configuration, destination, and relevant time range before changing the query. For VM guest telemetry, inspect Azure Monitor Agent and the associated data collection rule. Resource diagnostic settings are a separate path for resource logs and supported platform telemetry. See data collection rules and diagnostic settings .

Reading habit: an empty result has several possible explanations. Use the supplied evidence to distinguish no matching events from missing or misdirected collection.

Check selections and explanation together

For a Select TWO item, verify two independently supported statements and honour the requested count. Do not choose a second answer just because it uses the same vocabulary as the first. Focus on what each resource name, command, diagram or statement means.

After any question, write one sentence: “This answer fits because the exhibit shows ___.” Then explain why the nearest alternative fails. If you cannot identify that evidence, revisit the cheat sheet and try a different scenario.