AZ-700 exam dumps

AZ-700 practice question 74 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 74

Select 2

You are managing an Azure environment where multiple virtual machines are exposed to the internet via RDP and SSH, and Defender for Cloud� Secure Score reports that these VMs lack Network Security Groups (NSGs) and Just-In-Time (JIT) VM Access. You want to remediate these issues to align with Defender for Cloud� recommendations and improve your organization� Secure Score. Which two actions should you take?

  1. A

    Create NSGs and apply them to the subnets hosting the VMs, restricting inbound traffic to only required ports and source IP addresses.

  2. B

    Enable Just-in-Time VM Access for each of the publicly accessible VMs to limit exposure time for RDP and SSH ports.

  3. C

    Disable the public IP addresses of all VMs and rely exclusively on site-to-site VPN connections for any remote management.

  4. D

    Ignore the recommendations, as they do not significantly affect compliance or overall security.

Show answer and explanation

Correct answers: A, B

Explanation

Microsoft Defender for Cloud recommends implementing baseline network protections�such as NSGs and Just-in-Time VM Access�to reduce external exposure and improve Secure Score. Subnet-level NSGs effectively control traffic flow, and JIT Access for RDP/SSH further minimizes the attack surface by restricting management ports to authorized users and time windows. Refer to the Microsoft Defender for Cloud documentation for detailed guidance on addressing similar recommendations (https://docs.microsoft.com/azure/defender-for-cloud).

  • A. Correct.

    Option 1 is correct. Creating and applying NSGs to each subnet hosting these VMs enforces granular control over inbound and outbound traffic, which is a best practice recommended by Defender for Cloud to help reduce the attack surface.

  • B. Correct.

    Option 2 is correct. Enabling Just-in-Time VM Access allows administrators to open RDP or SSH ports only when needed and for a limited duration. This reduces the risk of malicious network scans and brute-force attacks.

  • C. Incorrect.

    Option 3 is incorrect. While removing public IPs and using a private-only approach can be a valid security measure in some scenarios, it may not be feasible for all business cases. Furthermore, this step alone does not address the specific Defender for Cloud recommendations regarding NSGs and JIT access for exposed VMs.

  • D. Incorrect.

    Option 4 is incorrect. The recommendations made by Defender for Cloud help improve both your Secure Score and the overall security posture. Ignoring them can leave your environment unnecessarily exposed and undermine compliance efforts.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam