Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Your company hosts several Windows Server VMs in a single Azure virtual network. Each VM currently has a public IP that allows direct RDP traffic on TCP 3389. The security team insists the RDP port must never be reachable from the internet, yet administrators must still start remote sessions from the Azure portal from any location. Which solution meets these requirements?
Configure an Azure Application Gateway with web application firewall (WAF) and route RDP traffic through the gateway.
Enable just-in-time VM access for the virtual machines in Microsoft Defender for Cloud.
Deploy Azure Bastion to the virtual network and remove the public IP addresses from the virtual machines.
Deploy Azure Firewall and create DNAT rules that forward port 3389 only from approved administrator public IP addresses.
Azure Bastion provides browser-based RDP and SSH connectivity over TLS (port 443) directly in the Azure portal. Because Bastion is deployed inside the virtual network, the virtual machines no longer need public IP addresses and their RDP ports remain closed to the internet at all times. Just-in-time (JIT) access reduces exposure but still creates a temporary inbound rule for port 3389, so the port can be reachable during the allowed window. Application Gateway and Azure Firewall DNAT still require the RDP port to be exposed, albeit through a different endpoint, so they do not satisfy the requirement that the port must never be reachable from the internet.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure Bastion and how does it ensure secure RDP access?
Open an interactive chat with Bash
How is Azure Bastion different from enabling just-in-time (JIT) VM access?
Open an interactive chat with Bash
Why are Azure Firewall and Application Gateway not suitable for securing the RDP port?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .