Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You manage an Azure subscription with a Windows Server VM named VM1. VM1 uses a public IP and an NSG rule that permits inbound RDP (TCP 3389) from the internet. A new policy requires removing the public IP and allowing administrators to launch RDP sessions to VM1 directly in the Azure portal via a web browser. Which action should you take?
Enable just-in-time VM access for port 3389 on VM1 and restrict allowed source IP ranges.
Deploy an Azure Bastion host in the virtual network and remove the inbound RDP rule from the NSG.
Create an Azure VPN gateway and require administrators to use a Point-to-Site VPN before connecting to VM1's private IP.
Configure a private endpoint for VM1 and enable Private Link Service.
Deploying Azure Bastion places a managed bastion host inside the virtual network and provides browser-based RDP and SSH access over TLS (TCP 443). Because connections are established to the VM's private IP, VM1 no longer needs a public IP address, and the inbound RDP rule can be removed, eliminating direct exposure of port 3389. Just-in-time VM access only controls the exposure window of NSG rules and does not provide browser-based connectivity. Private endpoints cannot be assigned to a VM NIC for RDP, and a VPN gateway still requires a native RDP client rather than portal access.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure Bastion, and how does it facilitate secure RDP access?
Open an interactive chat with Bash
Why is removing the public IP address from a VM important for security?
Open an interactive chat with Bash
How does Azure Bastion differ from just-in-time VM access?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .