exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 4 question 22 discussion

Actual exam question from Microsoft's AZ-500
Question #: 22
Topic #: 4
[All AZ-500 Questions]

You have an Azure subscription that contains a user named Admin1 and a virtual machine named VM1. VM1 runs Windows Server 2019 and was deployed by using an Azure Resource Manager template. VM1 is the member of a backend pool of a public Azure Basic Load Balancer.
Admin1 reports that VM1 is listed as Unsupported on the Just in time VM access blade of Azure Security Center.
You need to ensure that Admin1 can enable just in time (JIT) VM access for VM1.
What should you do?

  • A. Create and configure a network security group (NSG).
  • B. Create and configure an additional public IP address for VM1.
  • C. Replace the Basic Load Balancer with an Azure Standard Load Balancer.
  • D. Assign an Azure Active Directory Premium Plan 1 license to Admin1.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
gills
Highly Voted 3 years, 11 months ago
A is correct. https://docs.microsoft.com/en-us/azure/security-center/security-center-just-in-time?tabs=jit-config-asc%2Cjit-request-asc Unsupported - VMs without JIT enabled and which don't support the feature. Your VM might be in this tab for the following reasons: Missing network security group (NSG) - JIT requires an NSG to be configured Classic VM - JIT supports VMs that are deployed through Azure Resource Manager, not 'classic deployment'. Learn more about classic vs Azure Resource Manager deployment models. Other - Your VM might be in this tab if the JIT solution is disabled in the security policy of the subscription or the resource group. Unsupported - VMs without JIT enabled and which don't support the feature. Your VM might be in this tab for the following reasons: Missing network security group (NSG) - JIT requires an NSG to be configured Classic VM - JIT supports VMs that are deployed through Azure Resource Manager, not 'classic deployment'. Learn more about classic vs Azure Resource Manager deployment models. Other - Your VM might be in this tab if the JIT solution is disabled in the security policy of the subscription or the resource group.
upvoted 31 times
Thi
3 years, 9 months ago
Thanks A is correct
upvoted 4 times
...
...
epic13131
Highly Voted 3 years, 3 months ago
I love Bill Gates
upvoted 21 times
Mcgood
3 years, 3 months ago
hahhahah
upvoted 3 times
...
...
mrt007
Most Recent 7 months, 1 week ago
To enable Just-In-Time (JIT) VM access for VM1, you should replace the Basic Load Balancer with an Azure Standard Load Balancer. JIT operates with network resources in Azure and ensures “deny all inbound traffic” rules exist for your selected ports in the network security group (NSG) and Azure Firewall rules. However, these rules are not supported by Azure Basic Load Balancer, hence the need to upgrade to a Standard Load Balancer. So, the correct answer is C. Replace the Basic Load Balancer with an Azure Standard Load Balancer.
upvoted 3 times
...
Ivan80
9 months, 2 weeks ago
In exam 1/28/24
upvoted 2 times
...
fahrulnizam
1 year, 6 months ago
Selected Answer: A
A is correct , JIT requires NSG to be configured
upvoted 1 times
...
majstor86
1 year, 8 months ago
Selected Answer: A
A. Create and configure a network security group (NSG).
upvoted 3 times
...
ligu
1 year, 8 months ago
The answer is correct: JIT requires an NSG to be configured or a Firewall configuration (or both)
upvoted 1 times
...
OrangeSG
1 year, 9 months ago
Selected Answer: A
This question seems outdated. If there is Azure Firewall, NSG no longer mandatory. New Microsoft document on VMs that don't support JIT because: • Missing network security group (NSG) or Azure Firewall - JIT requires an NSG to be configured or a Firewall configuration (or both) Old Microsoft document on VMs that don't support JIT because: • Missing network security group (NSG) - JIT requires an NSG to be configured
upvoted 3 times
Fal991l
1 year, 8 months ago
So the correct answer is D. The question didn't specify Admin1 has licensed Premium Plan 1 yet.
upvoted 1 times
...
...
Amit3
2 years, 4 months ago
A: NSG group is correct
upvoted 1 times
...
tnagy
2 years, 4 months ago
Selected Answer: A
A is correct
upvoted 2 times
...
Eltooth
2 years, 7 months ago
Selected Answer: A
A is correct answer.
upvoted 2 times
...
zioggs
3 years ago
Exam - 4/11/21
upvoted 2 times
...
Simon_Leung
3 years ago
Load balancer is misleading. NSG is the key component for JIT. you can always remote to backend server IP directly without pass thru load balancer without enforcing UDR to firewall (hub environment).
upvoted 1 times
...
poplovic
3 years, 2 months ago
A is correct. either NSG or FireWall is required. see https://docs.microsoft.com/en-us/azure/security-center/just-in-time-explained
upvoted 1 times
...
kumax
3 years, 4 months ago
On exam, May 2021.
upvoted 3 times
...
roy9889
3 years, 6 months ago
This is an important question and correct answer Load balancers connect directly to VM's NIC (not a subnet) so we cannot just assume in this question that an NSG has been created yet. 2nd piece of important info is JIT can only be enabled for an NSG - an NSG can only be applied for VM or Subnet (not the entire Vnet)
upvoted 2 times
Mcgood
3 years, 3 months ago
Great Statement
upvoted 1 times
...
...
glowglow
3 years, 7 months ago
Enable JIT on your VMs - You can enable JIT with your own custom options for one or more VMs using Security Center, PowerShell, or the REST API. Alternatively, you can enable JIT with default, hard-coded parameters, from Azure virtual machines. When enabled, JIT locks down inbound traffic to your Azure VMs by creating a rule in your network security group.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago