exam questions

Exam SC-100 All Questions

View all questions & answers for the SC-100 exam

Exam SC-100 topic 7 question 3 discussion

Actual exam question from Microsoft's SC-100
Question #: 3
Topic #: 8
[All SC-100 Questions]

You need to recommend a solution to meet the security requirements for the virtual machines.
What should you include in the recommendation?

  • A. just-in-time (JIT) VM access
  • B. an Azure Bastion host
  • C. Azure Virtual Desktop
  • D. a network security group (NSG)
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
PlumpyTumbler
Highly Voted 2 years, 9 months ago
Selected Answer: C
The security requirement this question wants us to meet is "The secure host must be provisioned from a custom operating system image." https://docs.microsoft.com/en-us/azure/virtual-desktop/set-up-golden-image
upvoted 42 times
PeteNZ
2 years, 3 months ago
Just coming back to this. I'd say you're wrong, sorry.\ Reasons: 1. Compliance requirements trumps all others and remote access connections need to be secure to meet HIPAA, so use of Azure Bastion most probably wins. 2. Azure Bastion doesn't support Azure Virtual Desktop: https://learn.microsoft.com/en-us/azure/bastion/bastion-faq#peering 3. You can deploy a custom image without needing AVD - what do you guys think a VM is exactly?
upvoted 4 times
macka2005
11 months, 2 weeks ago
It says "You need to recommend a solution to meet the security requirements for the virtual machines" ignore the other requirements such as HIPAA etc for this question
upvoted 1 times
...
KallMeDan
2 years, 1 month ago
I agree that compliance requirements are the most important, but HIPAA or any compliance for that matter does not mandate use of Azure Bastion. As long as you are able to fulfil the security requirements using AVD, it should fit the bill. I would go for C option here.
upvoted 4 times
...
...
...
JakeCallham
Highly Voted 2 years, 8 months ago
Selected Answer: C
We need custom image so answer C is only correct. A yes, but this is in addition to Azure Virtual Desktop B no because custom image C yes D no, but needed for Jit
upvoted 11 times
adamsca
2 years, 3 months ago
I totally agreed.
upvoted 1 times
...
...
pdnb
Most Recent 6 months, 1 week ago
Selected Answer: B
the requirement to provision the secure host from a custom operating system image can still be met with Azure Bastion. Here's how: Create a Custom Image: You can create a custom operating system image that includes all the necessary configurations and security settings for your secure host. Provision the VM: Use this custom image to provision a virtual machine in Azure. Deploy Azure Bastion: Set up Azure Bastion to provide secure RDP/SSH access to this VM.
upvoted 1 times
...
jetnam
1 year, 3 months ago
I think it's C. Reason: AVD can use custom images, and can host secure PAWs.
upvoted 1 times
...
ayadmawla
1 year, 4 months ago
Selected Answer: B
"Administrators must connect to a "secure host" to perform any remote administration of the virtual machines. The "secure host" must be provisioned from a custom operating system image." It is the "Secure Host" that must be provisioned from a custom operating system = locked down with minimum services = Bastion Host
upvoted 2 times
...
Charly80
1 year, 5 months ago
Not sure that is the question : "Administrators must connect to a secure host to perform any remote administration of the virtual machines. The secure host must be provisioned from a custom operating system image." Is normaly intended to use a PAW station not an VDA station to make administration. Solution is for Dev not admins, so Bastion can respond I think.
upvoted 1 times
...
nExoR
1 year, 6 months ago
Answer: C this is Azure Virtual Desktop Administrators must connect to a secure host to perform any remote administration of the virtual machines. The secure host must be provisioned from a custom operating system image.
upvoted 1 times
...
ConanBarb
1 year, 9 months ago
Selected Answer: B
By all accounts Bastion is for secure connections to host (win and linux) for admin and more purposes. Virtual desktop is not a security solution, but a workforce solution saving money and hassle, so not correct for this purpose. And if a custom VM is needed as the host to connect to other VMs from, then why not set up Bastion to connect to that custom admin VM only.
upvoted 3 times
...
slobav
1 year, 9 months ago
Selected Answer: C "The secure host must be provisioned from a custom operating system image." https://www.youtube.com/watch?v=r-P-2lGzPFQ&list=PLQ2ktTy9rklhzzkSEZvDZT4QSIVUQZD-Y&index=9
upvoted 1 times
...
sherifhamed
1 year, 9 months ago
Selected Answer: B
To meet the security requirements for the virtual machines, including allowing administrators to connect to a secure host for remote administration, you should recommend: B. an Azure Bastion host. Here's how this recommendation aligns with the requirements: Azure Bastion is a secure and managed jump server that allows you to connect to your virtual machines directly through the Azure portal over SSH or RDP. This ensures secure remote administration of the virtual machines. The requirement for administrators to connect to a secure host for remote administration is met by using Azure Bastion.
upvoted 2 times
...
Cock
2 years ago
In the exam 29.05.2023
upvoted 2 times
...
zellck
2 years, 1 month ago
Selected Answer: C
C is the answer. https://learn.microsoft.com/en-us/azure/virtual-desktop/create-custom-image-templates Custom image templates in Azure Virtual Desktop enable you to easily create a custom image that you can use when deploying session host virtual machines (VMs). Using custom images helps you to standardize the configuration of your session host VMs for your organization. Custom image templates are built on Azure Image Builder and tailored for Azure Virtual Desktop.
upvoted 4 times
zellck
2 years ago
Gotten this in May 2023 exam.
upvoted 2 times
...
...
adamsca
2 years, 3 months ago
Selected Answer: C
I totally agree it's AVD because of the need for custom image.
upvoted 3 times
...
TJ001
2 years, 5 months ago
custom image is the key - hence will go for AVD
upvoted 2 times
...
[Removed]
2 years, 6 months ago
Selected Answer: C
Obviously C here. The requirements state that the "jump box" must be running a custom image. Bastion is a fully managed non-customisanle PaaS product. The only answer that supports the requirement for a custom image is AVD.
upvoted 7 times
Gurulee
2 years, 3 months ago
“Administrators must connect to a secure host to perform any remote administration of the virtual machines. The secure host must be provisioned from a custom operating system image.” === Front the requirements, the second sentence would rule out bastion
upvoted 1 times
...
...
Xyz_40
2 years, 7 months ago
I totally agreed with you guys here. AVD
upvoted 1 times
...
Banzaaai
2 years, 8 months ago
Selected Answer: B
we talk about ALL VMs. others comments re customer image is related to secure host ONLY. Therefore, its not applicable
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...