AZ-104 exam dumps

AZ-104 practice question 224 of 289

Microsoft Certified: Azure Administrator Associate. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-104 Question 224

Single answer

You are administering a new deployment in Azure where multiple Windows and Linux virtual machines need to be accessed via RDP and SSH. Your primary requirement is to avoid exposing public IP addresses on these VMs and to allow administrators to connect through the Azure portal. Which of the following actions is essential for implementing Azure Bastion in this scenario?

  1. A

    Enable the RDP and SSH ports on the virtual machine’s Network Security Group (NSG) and associate a public IP with each VM

  2. B

    Create an Azure Bastion subnet named 'AzureBastionSubnet' and provision a Bastion host in that subnet

  3. C

    Assign a public IP address to the Azure Load Balancer and forward RDP/SSH connections to the VMs

  4. D

    Configure Just-In-Time (JIT) VM Access policies on all Azure VMs

Show answer and explanation

Correct answer: B

Explanation

To implement Azure Bastion, you must create a dedicated subnet named 'AzureBastionSubnet' and deploy the Bastion host within that subnet. This approach allows you to connect to your VMs securely from the Azure portal without allocating public IP addresses to the VMs.

  • A. Incorrect.

    Opening RDP and SSH ports on the NSG and assigning public IP addresses to each VM would expose them to the public internet, which contradicts the requirement to avoid direct public IP exposure.

  • B. Correct.

    Deploying Azure Bastion requires creating a special subnet named 'AzureBastionSubnet' (with at least a /27 address space) and provisioning the Bastion service in it, enabling secure RDP/SSH access from the Azure portal without the need for public IPs on the VMs.

  • C. Incorrect.

    Setting up a public IP address on a Load Balancer and forwarding RDP/SSH requests would still expose these services externally, defeating the purpose of hiding them behind Bastion.

  • D. Incorrect.

    While JIT can help reduce exposure for management ports, it does not replace Azure Bastion, which provides secure browser-based RDP/SSH connections without directly exposing public IP addresses.

Timed practice exam

Take a AZ-104 practice test under exam conditions

60 questions in 60 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam