exam questions

Exam AZ-800 All Questions

View all questions & answers for the AZ-800 exam

Exam AZ-800 topic 4 question 7 discussion

Actual exam question from Microsoft's AZ-800
Question #: 7
Topic #: 4
[All AZ-800 Questions]

You have an Azure virtual machine named VM1 that runs Windows Server.
You need to configure the management of VM1 to meet the following requirements:
✑ Require administrators to request access to VM1 before establishing a Remote Desktop connection.
✑ Limit access to VM1 from specific source IP addresses.
✑ Limit access to VM1 to a specific management port.
What should you configure?

  • A. a network security group (NSG)
  • B. Azure Active Directory (Azure AD) Privileged Identity Management (PIM)
  • C. Microsoft Defender for Cloud
  • D. Azure Front Door
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
syu31svc
Highly Voted 2 years, 1 month ago
Selected Answer: C
JIT lets you allow access to your VMs only when the access is needed, on the ports needed, and for the period of time needed C is correct
upvoted 5 times
...
jpcapobianco
Most Recent 1 month, 4 weeks ago
Selected Answer: C
both A (NSG) and C (Defender for Cloud) could be considered correct, depending on the perspective taken to address the requirements. Why both could be correct: A. Network Security Group (NSG): The NSG is a direct solution for limiting access from specific IP addresses and restricting access to a specific management port. However, it cannot independently require administrators to request access (the first requirement). In this case, it lacks the "Just-In-Time Access" functionality. C. Microsoft Defender for Cloud: Defender for Cloud, with its Just-In-Time (JIT) VM Access feature, fulfills the requirement of requiring administrators to request access before connecting. However, Defender for Cloud also relies on NSGs to limit traffic from specific IP addresses and to specific ports. Therefore, it indirectly covers the other two requirements.
upvoted 1 times
...
formacaotismic
5 months, 2 weeks ago
Selected Answer: C
Microsoft Defender for Cloud (formerly known as Azure Security Center) indeed provides a comprehensive solution that can meet all three requirements: Just-In-Time (JIT) VM Access: This feature allows you to require administrators to request access before establishing a Remote Desktop connection, enhancing security by reducing the attack surface. Network Security Group (NSG) Management: Defender for Cloud can help you manage NSGs to limit access to specific source IP addresses and ports, ensuring that only authorized traffic can reach your VM. So, the correct choice is: C. Microsoft Defender for Cloud This option effectively combines JIT access with NSG management to provide a robust security solution for your VM.
upvoted 2 times
...
Ksk08
6 months ago
C. Microsoft Defender for Cloud This choice effectively meets all three requirements by allowing you to implement JIT access (requiring requests for RDP connections), manage IP restrictions through NSGs, and limit management port access securely.
upvoted 1 times
...
Krayzr
9 months, 3 weeks ago
Selected Answer: C
Microsoft Defender for Cloud’s Just-in-Time (JIT) VM access feature1 indeed meets all the requirements listed: It requires administrators to request access to VM1 before establishing a Remote Desktop connection. It allows you to limit access to VM1 from specific source IP addresses. It enables you to limit access to VM1 to a specific management port. So, the correct answer should be: C. Microsoft Defender for Cloud https://learn.microsoft.com/en-us/azure/defender-for-cloud/just-in-time-access-usage
upvoted 3 times
...
gabmancuso
11 months, 2 weeks ago
A&C? Not a double? Strange... None of them, alone, help us to achieve the goal. If forced to choose one opion only, I'd say C, but port? IP?
upvoted 1 times
...
SIAMIANJI
1 year ago
Selected Answer: A
To meet the specified requirements, you should configure a network security group (NSG). NSGs allow you to filter network traffic to and from Azure resources, including virtual machines (VMs). You can define rules within the NSG to control inbound and outbound traffic based on source and destination IP addresses, as well as specific ports. Option A. a network security group (NSG) is the correct choice as it allows you to:
upvoted 1 times
...
skycrap
1 year, 10 months ago
Selected Answer: C
C is correct. Jit
upvoted 2 times
...
Telekon
2 years, 2 months ago
Selected Answer: B
https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure
upvoted 3 times
Telekon
2 years, 2 months ago
I am wrong , C in this case is correct
upvoted 1 times
...
...
BryRob
2 years, 4 months ago
Selected Answer: C
Given answer is correct
upvoted 2 times
...
johosofat
2 years, 5 months ago
Its C - look at the link Just in time access request is for Defender for the cloud - https://learn.microsoft.com/en-us/azure/defender-for-cloud/just-in-time-access-usage?tabs=jit-config-asc%2Cjit-request-asc
upvoted 3 times
...
kijken
2 years, 6 months ago
I would say B
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago