AZ-700 exam dumps

AZ-700 practice question 73 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 73

Select 2

You are an Azure network engineer for a company that hosts multiple Windows virtual machines on Azure. Microsoft Defender for Cloud has identified security recommendations in Secure Score indicating that your environment is at risk due to exposed management ports (RDP/SSH) and missing or insufficient Network Security Groups (NSGs) on certain subnets. You need to implement changes to address these recommendations and increase your company� secure score. Which two actions should you take?

  1. A

    Implement NSGs on the relevant subnets with rules that limit inbound traffic to only the required management ports.

  2. B

    Enable Just-in-Time (JIT) VM access for RDP/SSH from Microsoft Defender for Cloud.

  3. C

    Temporarily disable Azure Firewall to observe inbound traffic patterns before creating custom rules.

  4. D

    Replace all existing NSGs with a single Application Gateway WAF configured in detection mode.

  5. E

    Open inbound ports for all network traffic categories to simplify administration and reduce false positive alerts.

Show answer and explanation

Correct answers: A, B

Explanation

To address network-related recommendations from Microsoft Defender for Cloud, you should reduce exposed ports by implementing Network Security Groups and enable Just-in-Time access for any necessary management ports. These measures help close unnecessary inbound paths and detail how and when RDP/SSH ports can be opened. For more information, see Microsoft Defender for Cloud recommendations on restricting management ports (https://learn.microsoft.com/azure/defender-for-cloud/recommendations-reference) and using Just-in-Time VM access (https://learn.microsoft.com/azure/defender-for-cloud/just-in-time-access-overview).

  • A. Correct.

    Correct. Configuring and applying NSGs to subnets or directly to network interfaces, and restricting inbound traffic to only the necessary ports, directly addresses Defender for Cloud's recommendations and improves your secure score.

  • B. Correct.

    Correct. Just-in-Time (JIT) VM access helps secure RDP and SSH by opening those ports only when needed, thereby reducing attack surface and aligning with the recommendations from Defender for Cloud.

  • C. Incorrect.

    Incorrect. Disabling Azure Firewall does not address the recommendation to restrict inbound management ports or properly protect your environment. It would expose your VMs to more threats instead of improving your secure score.

  • D. Incorrect.

    Incorrect. An Application Gateway WAF is beneficial for HTTP/HTTPS workloads but does not replace the need for NSGs to control inbound traffic at the network level. NSGs remain essential for restricting ports at the subnet or NIC level.

  • E. Incorrect.

    Incorrect. Opening all inbound ports increases your attack surface and directly contradicts the recommendation to reduce exposed management ports. This would lower your secure score and overall security posture.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam