exam questions

Exam AZ-720 All Questions

View all questions & answers for the AZ-720 exam

Exam AZ-720 topic 6 question 58 discussion

Actual exam question from Microsoft's AZ-720
Question #: 8
Topic #: 6
[All AZ-720 Questions]

A company enables just-in-time (JIT) virtual machine (VM) access in Azure.

An administrator observes a list of VMs on the Unsupported tab of the JIT VM access page in the Microsoft Defender for Cloud portal.

You need to determine why some VMs are not supported for JIT VM access.

What should you conclude?

  • A. The client firewall does not allow port 3389 on the VMs.
  • B. The administrator is using the Microsoft Defender for Cloud free tier.
  • C. A network security group is not associated with the VMs.
  • D. The client firewall does not allow port 22 on the VMs.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
cris_exam
2 years, 2 months ago
Selected Answer: C
C is the answer. For any JIT rule access to work it needs to be added into an associated NSG to the VM subnet/NIC OR if there is an AZFW active in the environment, that also works, but in our case it's the NSG. https://learn.microsoft.com/en-us/azure/defender-for-cloud/just-in-time-access-usage#work-with-jit-vm-access-using-microsoft-defender-for-cloud
upvoted 2 times
...
MarshalLaw
2 years, 2 months ago
A and D can't because Bastion / JiT works on Port 443. B is a stupid answer so the answer would be C.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...