Which Azure Resources Can You Associate a Public IP Address To?
You have an Azure subscription that contains the resources shown in the following table. You create a public IP address named IP1. Which two resources can you associate to IP1? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point. - 
Community Votes
100% of anonymous learners picked answer BC. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests where Azure public IP addresses can be attached; the trap is assuming a VPN gateway can accept an existing public IP or that a VM itself can be directly associated.
A public IP address in Azure can be associated with a load balancer frontend configuration and a network interface, but not directly with a virtual machine, VPN gateway, or virtual network. The correct selections for IP1 are LB1 and NIC1 (B and C).
Many learners choose VPN1 (D) because VPN gateways require a public IP, but an existing VPN gateway cannot be retrofitted with a new public IP—the address must be assigned at gateway creation.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The public IP address IP1 can be associated with the load balancer LB1's frontend IP configuration and with the network interface NIC1. Azure allows a public IP to be attached to a NIC at creation or later, and to a load balancer's frontend configuration to expose the service to the internet. These two resources directly accept a standalone public IP resource. Therefore, B and C are the correct choices.
Why the Other Options Are Wrong
VM1 is incorrect because you do not attach a public IP directly to a virtual machine; the association is made through its network interface (NIC). VPN1 is incorrect because a VPN gateway's public IP is assigned during gateway creation and cannot be replaced with an existing public IP resource afterwards. VNet1 is incorrect because virtual networks operate with private IP address spaces and do not consume public IP addresses. Thus, options A, D, and E are invalid.
Community Comment Notes
Many learners in the comments agree with BC, with one noting that a public IP can be associated with resources requiring direct internet access, such as "virtual machines (via NICs) and load balancers." Another commenter pointed out that a VPN gateway "uses its own dedicated public IP address" and does not share a standalone public IP. A few dissenting votes chose BD, arguing that a NIC does not offer public IP creation, but Azure NICs can indeed have public IP configurations, so BC remains correct.
Official Reference
Exam Strategy
Focus on the lifecycle of Azure public IP addresses: they are assigned to a NIC or a load balancer frontend at creation or can be attached later, but a VPN gateway's public IP is fixed at gateway creation and cannot be replaced. When a question asks which resource can be associated with an existing public IP, eliminate resources that require the IP at provisioning time.
Frequently Asked Questions
Why can't IP1 be associated with VPN1?
A VPN gateway's public IP is assigned when the gateway is created and cannot be changed later, so an existing VPN gateway cannot accept a new standalone public IP.
Why is VM1 not correct if a VM can have a public IP?
Azure associates public IP addresses with the VM's network interface (NIC1), not with the virtual machine resource itself, so you must attach IP1 to NIC1.
Related Analysis
Practice All AZ-104 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-104 Practice Test →