AZ-500 exam dumps

AZ-500 practice question 117 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 117

Select 2

You manage several Windows virtual machines (VMs) hosted in Azure that contain sensitive financial data. You need to reduce potential attack exposure, enable advanced threat detection, and ensure compliant security posture for these VMs. Which two actions should you implement as part of an advanced security plan?

  1. A

    Enable Just-in-Time VM Access in Microsoft Defender for Cloud.

  2. B

    Keep default RDP and SSH ports open at all times for immediate troubleshooting.

  3. C

    Install the Log Analytics Agent and enable the Microsoft Defender for servers plan.

  4. D

    Disable Azure Disk Encryption to reduce performance overhead.

Show answer and explanation

Correct answers: A, C

Explanation

A robust compute security plan should include both network-level defenses and host-based threat detection. Just-in-Time VM Access protects against constant port scanning and brute force attacks by opening ports only when needed. Additionally, deploying Microsoft Defender for servers (part of Defender for Cloud) with the Log Analytics Agent delivers crucial threat detection and response capabilities. Refer to official Microsoft documentation on Defender for Cloud (https://learn.microsoft.com/azure/defender-for-cloud/) for detailed guidance on securing your Azure compute resources.

  • A. Correct.

    Correct. Enabling Just-in-Time VM Access in Microsoft Defender for Cloud significantly reduces the attack surface by limiting RDP and SSH access to only pre-approved requests for a specified time window. This approach follows best practices to strengthen compute security.

  • B. Incorrect.

    Incorrect. Leaving RDP and SSH ports open at all times creates a large attack surface. Microsoft’s recommended practice is to only grant remote access when necessary using solutions like Just-in-Time as part of Defender for Cloud.

  • C. Correct.

    Correct. Installing the Log Analytics Agent (or Azure Monitor agent) and enabling the Microsoft Defender for servers plan provides advanced threat detection and security analytics. This solution helps detect anomalous activity, file integrity issues, and other threats in near real-time.

  • D. Incorrect.

    Incorrect. Azure Disk Encryption enhances data protection by encrypting at rest. Disabling disk encryption does not improve security and may violate compliance requirements for sensitive data.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam