exam questions

Exam SC-100 All Questions

View all questions & answers for the SC-100 exam

Exam SC-100 topic 3 question 22 discussion

Actual exam question from Microsoft's SC-100
Question #: 22
Topic #: 3
[All SC-100 Questions]

You have an Azure subscription that contains virtual machines.
Port 3389 and port 22 are disabled for outside access.
You need to design a solution to provide administrators with secure remote access to the virtual machines. The solution must meet the following requirements:
✑ Prevent the need to enable ports 3389 and 22 from the internet.
✑ Only provide permission to connect the virtual machines when required.
✑ Ensure that administrators use the Azure portal to connect to the virtual machines.
Which two actions should you include in the solution? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. Configure Azure VPN Gateway.
  • B. Enable Just Enough Administration (JEA).
  • C. Configure Azure Bastion.
  • D. Enable just-in-time (JIT) VM access.
  • E. Enable Azure Active Directory (Azure AD) Privileged Identity Management (PIM) roles as virtual machine contributors.
Show Suggested Answer Hide Answer
Suggested Answer: CD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
CertShooter
Highly Voted 1 year, 10 months ago
Selected Answer: CD
Configure Azure Bastion: Azure Bastion is a service that allows you to securely connect to your Azure virtual machines over Remote Desktop Protocol (RDP) or Secure Shell (SSH) directly from the Azure portal, without the need to enable ports 3389 or 22 on the virtual machines. Azure Bastion uses Remote Desktop Services and Azure AD for authentication, providing a secure and convenient way to access the virtual machines. Enable just-in-time (JIT) VM access: JIT VM access is a feature of Azure Security Center that allows you to control and monitor inbound traffic to your virtual machines. By enabling JIT VM access, you can grant administrators access to the virtual machines only when required, and automatically revoke the access when the session ends. This helps prevent unauthorized access to the virtual machines and ensures that access is granted only to authorized administrators. Other actions, such as configuring Azure VPN Gateway, enabling Just Enough Administration (JEA), or enabling Azure AD Privileged Identity Management (PIM) roles as virtual machine contributors, may not be directly related to providing secure remote access to the virtual machines.
upvoted 6 times
...
zts
Highly Voted 2 years, 2 months ago
Selected Answer: CD
C. Azure Bastion is a fully managed service that provides more secure and seamless Remote Desktop Protocol (RDP) and Secure Shell Protocol (SSH) access to virtual machines (VMs) without any exposure through public IP addresses. Provision the service directly in your local or peered virtual network to get support for all the VMs within it --> https://azure.microsoft.com/en-us/services/azure-bastion/#overview D --> https://docs.microsoft.com/en-us/azure/defender-for-cloud/just-in-time-access-overview?tabs=defender-for-container-arch-aks
upvoted 5 times
...
JAGUDERO
Most Recent 6 months, 4 weeks ago
Here's a trick, B and C are complete solutions in themselves, the question says: "Each correct answer presents part of the solution" So I think the correct thing is: D. Enable just-in-time (JIT) VM access. E. Enable Azure Active Directory (Azure AD) Privileged Identity Management (PIM) roles as virtual machine contributors.
upvoted 1 times
...
imsidrai
1 year, 4 months ago
i believe it should be CDE https://learn.microsoft.com/en-us/azure/architecture/solution-ideas/articles/multilayered-protection-azure-vm
upvoted 2 times
imsidrai
1 year, 4 months ago
oh only two are required , so it should be Bastion & JIT
upvoted 3 times
...
...
zellck
1 year, 5 months ago
Selected Answer: CD
CD is the answer. https://learn.microsoft.com/en-us/azure/architecture/solution-ideas/articles/multilayered-protection-azure-vm#components Azure Bastion provides secure and seamless RDP and SSH connectivity to VMs in a network. In this solution, Azure Bastion connects users who use Microsoft Edge or another internet browser for HTTPS, or secured traffic on port 443. Azure Bastion sets up the RDP connection to the VM. RDP and SSH ports aren't exposed to the internet or the user's origin.
upvoted 5 times
zellck
1 year, 5 months ago
JIT VM access is a feature of Defender for Cloud that provides just-in-time network-based access to VMs. This feature adds a deny rule to the Azure network security group that protects the VM network interface or the subnet that contains the VM network interface. That rule minimizes the attack surface of the VM by blocking unnecessary communication to the VM. When a user requests access to the VM, the service adds a temporary allow rule to the network security group. Because the allow rule has higher priority than the deny rule, the user can connect to the VM. Azure Bastion works best for connecting to the VM. But the user can also use a direct RDP or SSH session.
upvoted 3 times
...
...
uffman
1 year, 6 months ago
Selected Answer: CD
Correct.
upvoted 2 times
...
God2029
1 year, 8 months ago
Going with C and D.
upvoted 1 times
...
yaza85
1 year, 9 months ago
Jit controls access based on nsg not based on identity. Permissions are given in pim
upvoted 1 times
AzureJobsTillRetire
1 year, 8 months ago
PIM is fine but not as virtual machine contributors - too much privileges
upvoted 1 times
AzureJobsTillRetire
1 year, 8 months ago
also virtual machine contributor does not provide connection access
upvoted 1 times
...
...
...
Jt909
1 year, 10 months ago
Selected Answer: CE
Bastion and PIM for "Only provide permission to connect the virtual machines when required"
upvoted 4 times
...
blopfr
2 years ago
Selected Answer: CD
correct link https://learn.microsoft.com/en-us/azure/architecture/solution-ideas/articles/multilayered-protection-azure-vm#architecture
upvoted 4 times
...
monkeybiznex
2 years ago
JIT enables on ports exposed to the internet, not to the Bastion vNET. So... what gives?
upvoted 2 times
...
TheMCT
2 years, 2 months ago
The given answer is correct: C & D
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago