Courseiva

AZ-305 Design infrastructure solutions Practice Question

A company needs to provide secure remote administration access to Azure virtual machines for their IT team. The VMs are in a virtual network with no public IP addresses. The IT team uses browsers to connect. The solution should not require any custom software on the client machines. Which Azure service should they use?

⚠ Common exam trap

It's easy for candidates to confuse Just-in-Time VM access (which still requires a public IP and a client) with Bastion's fully browser-based, no-public-IP solution, or they mistakenly think a VPN gateway provides browser-based RDP/SSH without client software.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Bastion

Azure Bastion provides secure, seamless RDP/SSH connectivity to Azure virtual machines directly in the Azure portal over TLS. Because the VMs have no public IP addresses, Bastion acts as a jump server that is deployed inside the virtual network, eliminating the need for any public exposure. Since the IT team uses browsers and cannot install custom software, Bastion's native browser-based HTML5 client meets the requirement perfectly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure Bastion

    Why this is correct

    Azure Bastion is a fully managed PaaS service that provides browser-based RDP and SSH connectivity to virtual machines directly through the Azure portal over TLS. It is deployed inside a virtual network and brokers the connection from the portal to the VM, so the VMs do not need public IP addresses and no client software is required on the user's machine. The management ports (RDP 3389 and SSH 22) are never exposed to the public internet, and the session is rendered securely over SSL, fully satisfying the requirements for secure remote administration.

  • ✗

    Just-in-Time VM access

    Why it's wrong here

    Just-in-Time (JIT) VM access, part of Microsoft Defender for Cloud, temporarily opens the configured management ports (RDP/SSH) via network security group rules to a specific allowed source IP address for a limited time after user approval. While this is more secure than permanently open ports, the VM still needs a public IP address or a public-facing load balancer to receive the incoming connection, and the user must use an RDP/SSH client on their machine. Because the scenario explicitly prohibits public IP exposure and requires no client software, JIT VM access does not meet the stated constraints and is therefore incorrect.

  • ✗

    Azure VPN Gateway

    Why it's wrong here

    Azure VPN Gateway establishes an encrypted IPsec/IKE site-to-site or point-to-site tunnel between on-premises networks and an Azure virtual network. However, for a remote user to connect, the device typically must run a VPN client (such as IKEv2, OpenVPN, or SSTP) and be configured with certificates or authentication details. This requirement conflicts directly with the scenario's need to avoid installing client software on user machines, so although it provides secure connectivity, it is not the appropriate solution for secure remote administration in this case.

  • ✗

    Microsoft Entra ID Domain Services

    Why it's wrong here

    Microsoft Entra ID Domain Services (formerly Azure AD DS) provides managed domain services such as LDAP, Kerberos, NTLM, and Group Policy to Azure virtual machines via domain join, addressing identity and authentication needs. It does not, however, offer any remote administration or connectivity features—it is not a proxy for RDP/SSH sessions and cannot deliver a browser-based console. Even if a VM is domain-joined to Entra DS, users are still forced to use separate RDP or SSH clients over a network path; therefore, it fails to meet the requirement for secure remote access without client software.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.