Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You manage Azure resources for your company. Security policy states that no inbound public port may remain open directly to any production virtual machine. However, administrators occasionally need to initiate RDP sessions to troubleshoot Windows Server VMs from anywhere on the Internet. Each connection must be limited to a maximum of three hours, and every access request must be logged automatically. Which Azure capability meets all of these requirements with the least administrative effort?

  • Configure just-in-time VM access in Microsoft Defender for Cloud.

  • Deploy Azure Bastion Standard and disable public IP addresses on the VMs.

  • Enable point-to-site VPN connectivity by using Azure VPN Gateway.

  • Publish the RDP endpoint through Microsoft Entra Application Proxy.

Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot