Which Azure Resources Can You Associate a Public IP Address To?

Configure and manage virtual networks in Azure Configure name resolution and load balancing
Answer Correct answer: B, C — Associate the public IP IP1 to load balancer LB1's frontend configuration and to network interface NIC1, but not to a VM, VPN gateway, or virtual network.

You have an Azure subscription that contains the resources shown in the following table. You create a public IP address named IP1. Which two resources can you associate to IP1? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point. - image

  1. VM1
  2. LB1 Correct Answer
  3. NIC1 Correct Answer
  4. VPN1
  5. VNet1

Community Votes

BC
100%

100% of anonymous learners picked answer BC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests where Azure public IP addresses can be attached; the trap is assuming a VPN gateway can accept an existing public IP or that a VM itself can be directly associated.

A public IP address in Azure can be associated with a load balancer frontend configuration and a network interface, but not directly with a virtual machine, VPN gateway, or virtual network. The correct selections for IP1 are LB1 and NIC1 (B and C).

Many learners choose VPN1 (D) because VPN gateways require a public IP, but an existing VPN gateway cannot be retrofitted with a new public IP—the address must be assigned at gateway creation.

Community Discussion (9 comments)

RVivek 👍 2 Selected: BC
https://learn.microsoft.com/en-us/azure/virtual-network/ip-services/configure-public-ip-vpn-gateway
Josh219 👍 4 Selected: BC
A public IP address can be associated with resources that require direct internet access, such as virtual machines (via NICs) and load balancers. However, a VPN gateway typically uses its own dedicated public IP address for establishing secure connections between on-premises networks and Azure. VPN1: Uses its own public IP address for secure connections and does not typically share or use a public IP address assigned to other resources. Therefore, the correct resources to associate with IP1 are LB1 and NIC1.
Dankho 👍 3 Selected: BC
why not D? When you create a VPN gateway, you need to associate a public IP address with it. This is done during the configuration of the gateway itself, typically as part of the gateway creation process. The public IP is not managed as a standalone public IP resource after it is associated; it's an integral part of the VPN gateway configuration and is not directly visible as an independent resource in the same way you would see a public IP associated with a NIC or Load Balancer.
CK_Fred 👍 2 Selected: BD
The correct answer should be B & D. Reason behind: LB1 & VPN1 required a public IP address during the creation of resouces. For NIC1, the creation of NIC, don't offer an option to create public IP instead it is asking for private ip with manual / automatic assignment. The public IP association with NIC, only have happen when you have attached the NIC to VM
chucklu 👍 1
should be BCD https://learn.microsoft.com/en-us/azure/virtual-network/ip-services/configure-public-ip-vpn-gateway
DJHASH786 👍 3
VOTE BC
6c05b3d 👍 2 Selected: BC
Answer given is correct.
siheom 👍 4 Selected: BC
VOTE BC
Henrytml 👍 4
LB and NIC are correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The public IP address IP1 can be associated with the load balancer LB1's frontend IP configuration and with the network interface NIC1. Azure allows a public IP to be attached to a NIC at creation or later, and to a load balancer's frontend configuration to expose the service to the internet. These two resources directly accept a standalone public IP resource. Therefore, B and C are the correct choices.

Why the Other Options Are Wrong

VM1 is incorrect because you do not attach a public IP directly to a virtual machine; the association is made through its network interface (NIC). VPN1 is incorrect because a VPN gateway's public IP is assigned during gateway creation and cannot be replaced with an existing public IP resource afterwards. VNet1 is incorrect because virtual networks operate with private IP address spaces and do not consume public IP addresses. Thus, options A, D, and E are invalid.

Community Comment Notes

Many learners in the comments agree with BC, with one noting that a public IP can be associated with resources requiring direct internet access, such as "virtual machines (via NICs) and load balancers." Another commenter pointed out that a VPN gateway "uses its own dedicated public IP address" and does not share a standalone public IP. A few dissenting votes chose BD, arguing that a NIC does not offer public IP creation, but Azure NICs can indeed have public IP configurations, so BC remains correct.

Official Reference

Exam Strategy

Focus on the lifecycle of Azure public IP addresses: they are assigned to a NIC or a load balancer frontend at creation or can be attached later, but a VPN gateway's public IP is fixed at gateway creation and cannot be replaced. When a question asks which resource can be associated with an existing public IP, eliminate resources that require the IP at provisioning time.

Frequently Asked Questions

Why can't IP1 be associated with VPN1?

A VPN gateway's public IP is assigned when the gateway is created and cannot be changed later, so an existing VPN gateway cannot accept a new standalone public IP.

Why is VM1 not correct if a VM can have a public IP?

Azure associates public IP addresses with the VM's network interface (NIC1), not with the virtual machine resource itself, so you must attach IP1 to NIC1.

Related Analysis

Practice All AZ-104 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-104 Practice Test →

← Back to AZ-104 Study Guide