exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 3 question 30 discussion

Actual exam question from Microsoft's AZ-500
Question #: 30
Topic #: 3
[All AZ-500 Questions]

You have an Azure subscription that contains a virtual network. The virtual network contains the subnets shown in the following table.

The subscription contains the virtual machines shown in the following table.

You enable just in time (JIT) VM access for all the virtual machines.
You need to identify which virtual machines are protected by JIT.
Which virtual machines should you identify?

  • A. VM4 only
  • B. VM1 and VM3 only
  • C. VM1, VM3 and VM4 only
  • D. VM1, VM2, VM3, and VM4
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
A365
Highly Voted 4 years, 2 months ago
answer is correct: The service will detect where the temporary exceptions need to be created and act accordingly. The only requirement is that there IS an NSG either on the vmNIC or the subnet to which the required exceptions can be added as required. If there is no NSG then a warning is surfaced via Azure Security Center. https://www.itprotoday.com/iaaspaas/faqs-closer-look-requirements-and-functions-just-time-vm-access-azure
upvoted 41 times
...
dadageer
Highly Voted 4 years, 2 months ago
correct answer
upvoted 9 times
...
Jimmy500
Most Recent 11 months, 2 weeks ago
Answer is correct , please note that besides NSG , firewall can also come to this question. Either NSG or Azure Firewall integrated can be protected by JIT
upvoted 1 times
...
yonie
1 year, 5 months ago
Selected Answer: C
VMs that don't support JIT because: Missing network security group (NSG) https://learn.microsoft.com/en-us/azure/defender-for-cloud/just-in-time-access-usage#work-with-jit-vm-access-using-microsoft-defender-for-cloud
upvoted 2 times
...
Obama_boy
1 year, 5 months ago
Selected Answer: C
because these VMs have NSGs protecting them
upvoted 1 times
...
ESAJRR
1 year, 9 months ago
Selected Answer: C
C. VM1, VM3 and VM4 only
upvoted 1 times
...
majstor86
2 years, 3 months ago
Selected Answer: C
VM1, VM3 and VM4 only
upvoted 2 times
...
ligu
2 years, 3 months ago
Answer is correct. JIT works only when NSW associated at subnet or VM
upvoted 1 times
...
NinjaSchoolProfessor
2 years, 10 months ago
Selected Answer: C
In exam 15-July-2022
upvoted 5 times
...
NinjaSchoolProfessor
2 years, 10 months ago
In exam 15-July-2022
upvoted 5 times
...
Alessandro365
2 years, 11 months ago
Selected Answer: C
C is correct answer.
upvoted 2 times
...
salmantarik
2 years, 11 months ago
Answer is correct. JIT works only when NSW associated at subnet or VM
upvoted 3 times
...
ishin999
3 years, 4 months ago
answer is correct...NSG at either the subnet or VM interface level
upvoted 3 times
...
HananS
3 years, 6 months ago
The answer is correct A network security group (NSG) contains a list of security rules that allow or deny network traffic to resources connected to Azure Virtual Networks (VNet). NSGs can be associated to subnets or individual network interfaces (NIC) attached to VMs.
upvoted 1 times
...
mhzayt
3 years, 6 months ago
To get JIT working you need an NSG either on the subnet level or VM. VM1, VM2, and VM3 have an NSG on the subnet level. VM4 has an NSG on the NIC, so JIT is also working for VM4? What do I see wrong here?
upvoted 2 times
palantony
3 years, 6 months ago
VM1 & VM3 has NSG @ subnet level (Subnet1) VM4 has NSG @ VM VM2 which is connected to Subnet2 doesn't have NSG at Subnet level neither on VM
upvoted 10 times
...
...
Scryptre
3 years, 7 months ago
Correct!
upvoted 1 times
...
Cyberbug2021
4 years, 1 month ago
A NSG required for JIT
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...