Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You manage an Azure subscription with a Windows Server VM named VM1. VM1 uses a public IP and an NSG rule that permits inbound RDP (TCP 3389) from the internet. A new policy requires removing the public IP and allowing administrators to launch RDP sessions to VM1 directly in the Azure portal via a web browser. Which action should you take?
Configure a private endpoint for VM1 and enable Private Link Service.
Create an Azure VPN gateway and require administrators to use a Point-to-Site VPN before connecting to VM1's private IP.
Deploy an Azure Bastion host in the virtual network and remove the inbound RDP rule from the NSG.
Enable just-in-time VM access for port 3389 on VM1 and restrict allowed source IP ranges.
Deploying Azure Bastion places a managed bastion host inside the virtual network and provides browser-based RDP and SSH access over TLS (TCP 443). Because connections are established to the VM's private IP, VM1 no longer needs a public IP address, and the inbound RDP rule can be removed, eliminating direct exposure of port 3389. Just-in-time VM access only controls the exposure window of NSG rules and does not provide browser-based connectivity. Private endpoints cannot be assigned to a VM NIC for RDP, and a VPN gateway still requires a native RDP client rather than portal access.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure Bastion, and how does it facilitate secure RDP access?
Open an interactive chat with Bash
Why is removing the public IP address from a VM important for security?
Open an interactive chat with Bash
How does Azure Bastion differ from just-in-time VM access?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .