CCSP Cloud Security Operations Practice Question
A company uses Microsoft Azure and wants to implement just-in-time (JIT) virtual machine access to reduce the attack surface. They need to ensure that only authorized users can access VMs on specific management ports, and that access is granted for a limited time. Which Azure service should they use?
⚠ Common exam trap
The trap here is assuming that Azure Bastion or NSGs provide just-in-time access, but they do not have the time-bound, request-based access control that JIT VM access offers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Security Center (now Microsoft Defender for Cloud) just-in-time VM access
Microsoft Defender for Cloud's just-in-time VM access is designed to reduce the attack surface by allowing access to VMs only when needed, for a limited time, and on specific ports. It uses Azure RBAC to control who can request access and NSGs to enforce the temporary rules. This meets the requirement for time-limited, authorized access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Bastion
Why it's wrong here
Azure Bastion provides secure RDP/SSH access to VMs without exposing public IPs, but it does not provide just-in-time access with time-limited permissions. It is a persistent jump-host service. While it improves security, it does not meet the requirement for temporary, on-demand access control.
- ✗
Network security groups (NSGs) with service tags
Why it's wrong here
NSGs can restrict traffic based on rules, but they do not provide just-in-time access. Managing NSG rules manually to allow temporary access is error-prone and does not scale. NSGs alone lack the automated request-and-approval workflow and time-bound access that JIT VM access provides.
- ✗
Azure Firewall
Why it's wrong here
Azure Firewall is a managed network security service that can filter traffic, but it does not provide just-in-time access with user-specific, time-bound rules. It requires manual rule configuration and does not integrate with Azure RBAC for temporary access requests.
- ✓
Azure Security Center (now Microsoft Defender for Cloud) just-in-time VM access
Why this is correct
Microsoft Defender for Cloud's just-in-time VM access allows you to lock down inbound traffic to VMs, permitting access only when needed and for a specified duration. It integrates with Azure RBAC and network security groups to grant temporary access on management ports, reducing exposure to attacks.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.