Microsoft Azure Security Engineer Associate AZ-500 Practice Question

Your organization runs a Windows Server 2022 virtual machine in Azure. Security rules state that no inbound TCP 3389 traffic from the Internet may ever be allowed, yet administrators must be able to initiate ad-hoc RDP sessions directly from a web browser over HTTPS. What is the simplest Azure service configuration to meet the requirement?

  • Configure Azure Firewall to NAT translate TCP 443 to 3389 for the VM.

  • Deploy Azure Bastion in the virtual network and remove the VM's public IP.

  • Enable Just-in-Time VM access on the VM and create a 3389 NSG rule that allows only approved source IPs.

  • Provision a point-to-site VPN gateway and force administrators to connect before using native Remote Desktop.

Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot