Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Your company deploys a Windows Server Azure virtual machine in a virtual network that has no public IP address. A new security baseline states that the VM must never receive direct inbound Internet traffic, but administrators working from home still need interactive RDP access over the Internet. Which solution meets the requirements with the least ongoing configuration effort?
Create an inbound NAT rule on an Azure Load Balancer that maps port 443 to port 3389 on the VM.
Deploy Azure Bastion to the virtual network and launch the RDP session through the Azure portal.
Enable just-in-time VM access for port 3389 and allow trusted IP ranges.
Assign a public IP address to the VM and restrict RDP with a Network Security Group source IP filter.
Deploying Azure Bastion in the same virtual network satisfies the requirement. Administrators open an HTML5 RDP session over TCP 443 from the Azure portal to the Bastion host. Bastion then connects to the VM over its private IP on port 3389. You only need an inbound NSG rule that permits TCP 3389 from the Bastion subnet to the VM subnet; no public IP or Internet-facing rule is required. Alternatives such as JIT access, adding a public IP with NSG filtering, or using an inbound NAT rule on a load balancer expose or temporarily open RDP to the Internet, violating the baseline.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure Bastion, and how does it enable secure RDP access?
Open an interactive chat with Bash
Why is just-in-time VM access not ideal in this scenario?
Open an interactive chat with Bash
How does Azure Bastion differ from NSG-based filtering with public IPs?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .