Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Your organization runs a Windows Server 2022 virtual machine in Azure. Security rules state that no inbound TCP 3389 traffic from the Internet may ever be allowed, yet administrators must be able to initiate ad-hoc RDP sessions directly from a web browser over HTTPS. What is the simplest Azure service configuration to meet the requirement?
Configure Azure Firewall to NAT translate TCP 443 to 3389 for the VM.
Deploy Azure Bastion in the virtual network and remove the VM's public IP.
Enable Just-in-Time VM access on the VM and create a 3389 NSG rule that allows only approved source IPs.
Provision a point-to-site VPN gateway and force administrators to connect before using native Remote Desktop.
Azure Bastion provides browser-based RDP and SSH connectivity to Azure virtual machines over port 443. Because the traffic terminates at the Bastion host inside the virtual network, the target VM no longer needs a public IP address and does not expose TCP 3389 to the Internet. Enabling just-in-time access still relies on temporarily opening the RDP port, a VPN gateway requires additional client configuration, and Azure Firewall NAT would expose the port indirectly. Therefore, deploying Azure Bastion and removing the VM's public IP is the only option that keeps TCP 3389 closed while allowing web-based RDP.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure Bastion, and how does it provide secure RDP access?
Open an interactive chat with Bash
Why is TCP 3389 considered a security risk, and how does removing the VM’s public IP mitigate it?
Open an interactive chat with Bash
How does Azure Bastion differ from other solutions like Just-in-Time access or VPN gateways?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .