AZ-500 exam dumps

AZ-500 practice question 49 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 49

Single answer

Your organization manages multiple virtual networks across Development, Test, and Production subscriptions. You plan to use Azure Virtual Network Manager to ensure traffic control among these environments. Specifically, you need to block RDP access from the Development virtual networks to the Production virtual networks for enhanced security. Which solution should you implement in Azure Virtual Network Manager to accomplish this?

  1. A

    Create one connectivity configuration and place all Development and Production virtual networks in the same network group, then deny RDP at the subnet level in each virtual network.

  2. B

    Enable service endpoints on Development subnets to block RDP traffic to Production subnets through Azure Virtual Network Manager.

  3. C

    Create separate network groups for Development and Production, create a security admin configuration with a Deny RDP rule between these groups, then deploy the configuration.

  4. D

    Configure Azure Firewall within a shared services subscription to block RDP traffic and synchronize its settings directly in Azure Virtual Network Manager.

Show answer and explanation

Correct answer: C

Explanation

To block RDP traffic between Development and Production virtual networks with Azure Virtual Network Manager, you must group the VNets according to their environment and apply a security admin configuration to deny RDP traffic between those groups. Configuring security via Azure Virtual Network Manager centralizes policy enforcement and simplifies administration. For more details, refer to the Azure Virtual Network Manager documentation on creating network groups and deploying security admin configurations.

  • A. Incorrect.

    Option 1 is incorrect because a single network group for both Development and Production doesn't allow you to selectively block RDP from Development to Production. Placing them in one group and then denying RDP at the subnet level would require multiple manual NSG rules rather than leveraging Azure Virtual Network Manager’s centralized security admin configuration.

  • B. Incorrect.

    Option 2 is incorrect because service endpoints do not provide a mechanism to deny RDP traffic between virtual networks. Service endpoints are primarily used to secure access to Azure services, not to block traffic between VNets.

  • C. Correct.

    Option 3 is correct. By creating separate network groups for Development and Production, you can define a security admin configuration in Azure Virtual Network Manager that specifically denies RDP traffic between those groups. This is the recommended and centralized approach for granular cross-VNet traffic control.

  • D. Incorrect.

    Option 4 is incorrect because Azure Virtual Network Manager does not synchronize firewall policy settings directly from an Azure Firewall. While Azure Firewall can block traffic at a network boundary, it is not managed automatically within Azure Virtual Network Manager, and separate configuration is needed.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam