AZ-500 exam dumps

AZ-500 practice question 118 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 118

Select 2

Your organization hosts multiple Linux and Windows virtual machines in Azure. These VMs currently have public IP addresses assigned for remote administrative access (SSH and RDP). The security team wants to eliminate direct public connectivity, only allowing administrators to connect over a secure web-based session. They also require that any additional network access to these VMs be granted on a time-limited basis. Which two approaches should you implement to meet these requirements?

  1. A

    Enable Just-In-Time VM access in Microsoft Defender for Cloud and enforce request-based access to open SSH/RDP ports only as needed.

  2. B

    Deploy Azure Bastion in the same virtual network where the VMs reside, removing the need for direct public IP addresses on each VM.

  3. C

    Configure inbound NAT rules on a public load balancer that directs SSH and RDP traffic to each VM's internal IP address.

  4. D

    Expose the VMs' SSH and RDP ports directly to the internet but restrict access to administrators' IP addresses only.

Show answer and explanation

Correct answers: A, B

Explanation

Combining Azure Bastion with Just-In-Time access offers a strong security posture. Azure Bastion removes the need for a public IP on each VM and tunnels RDP/SSH connections over a secure web client, while Just-In-Time access (configured in Microsoft Defender for Cloud) additionally restricts the timeframe and source for remote connections. For more details, refer to Microsoft documentation on Azure Bastion (https://learn.microsoft.com/azure/bastion/bastion-overview) and Just-In-Time VM access (https://learn.microsoft.com/azure/defender-for-cloud/just-in-time-access-overview).

  • A. Correct.

    Option 1 is correct. Just-In-Time VM access in Microsoft Defender for Cloud provides time-limited access to SSH or RDP ports, reducing the attack window by keeping them closed unless an approved request is made.

  • B. Correct.

    Option 2 is correct. Azure Bastion provides a secure, browser-based connection to VMs without exposing them through public IP addresses. Administrators connect over HTTPS, eliminating the need for direct inbound RDP/SSH ports.

  • C. Incorrect.

    Option 3 is incorrect. Configuring inbound NAT rules on a public load balancer still exposes VMs to the internet, even if it’s a single IP address. This does not meet the requirement for isolating the VMs from direct public connectivity.

  • D. Incorrect.

    Option 4 is incorrect. Restricting access to known IP addresses is better than open access, but it still relies on public endpoints for SSH or RDP, which the scenario specifically aims to avoid.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam