AZ-500 Secure networking Practice Question
Which THREE are best practices for securing network traffic in Azure? (Choose three.)
⚠ Common exam trap
It's easy for candidates to confuse 'just-in-time VM access' (which controls RDP/SSH access) with network traffic security, but it is indeed a best practice for reducing the attack surface of management ports, so it is correct; the real distractors are the obviously insecure options B and C that test your understanding of exposure minimization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use private endpoints for Azure services
Option A is correct because private endpoints assign a private IP address from your VNet to an Azure PaaS service via Azure Private Link, keeping traffic on the Microsoft backbone and eliminating exposure to the public internet. Option D is correct because just-in-time (JIT) VM access in Microsoft Defender for Cloud opens NSG rules only on demand for a limited time and from approved source IPs, reducing the attack surface of management ports like RDP 3389 and SSH 22. Option E is correct because service tags in NSG rules let you allow or deny traffic to specific Azure services (for example, Storage or Sql) by Microsoft-managed IP ranges, avoiding broad 0.0.0.0/0 or Internet rules and simplifying maintenance. Option B is not a best practice because assigning public IP addresses to every VM directly exposes them to internet scanning and brute-force attacks; VMs should generally be reached via Bastion, VPN, or private endpoints. Option C is not a best practice because allowing direct outbound internet access from VMs bypasses inspection and enables data exfiltration and command-and-control traffic; outbound traffic should be routed through Azure Firewall, NAT Gateway, or a user-defined route to a controlled egress point.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use private endpoints for Azure services
Why this is correct
Azure Private Endpoints use a network interface with a private IP from your VNet to connect to PaaS services (e.g., Storage, SQL DB), so traffic flows entirely over the Microsoft backbone and never reaches the public internet. This eliminates data exposure to the internet and enables secure connections from on-premises via ExpressRoute or VPN, while also helping prevent data exfiltration by keeping service communication inside your virtual network.
- ✗
Assign public IP addresses to every VM
Why it's wrong here
Attaching a public IP address to every VM means each instance exposes its network interfaces directly to the internet, including management ports, which significantly expands the attack surface and makes NSG rule sets harder to manage. For most workloads, inbound connections should go through a public load balancer or a NAT Gateway for outbound traffic only, while VMs themselves remain private and are reached via a jump box or private endpoints.
- ✗
Allow direct outbound internet access from VMs
Why it's wrong here
Allowing VMs to reach the internet directly lets traffic bypass centralized security checkpoints, so malicious requests, malware callbacks, or data exfiltration go uninspected and unlogged. Instead, route outbound traffic through Azure Firewall or an NVA using a user-defined route, enabling application-level policy enforcement like FQDN filtering, and only permit known egress patterns through NSG rules and service tags.
- ✓
Implement just-in-time (JIT) VM access
Why this is correct
Just-in-Time (JIT) access, offered by Microsoft Defender for Cloud, automatically creates NSG or ASG rules that deny inbound traffic to RDP/SSH ports until a user with the right Microsoft Entra ID role requests access for a specified IP and time window. After the approved period expires, the rules revert to their blocking state, which drastically reduces the window attackers have to scan and exploit management endpoints.
- ✓
Use service tags in NSG rules
Why this is correct
Service tags are logical groupings of IP prefixes for Azure services, such as 'Storage' or 'AzureCosmosDB', that you can reference directly in NSG and firewall rules rather than maintaining a hard-coded list of changing IP ranges. Because Microsoft updates these tags automatically as underlying prefixes change, your rules become both more accurate and easier to maintain, eliminating common errors from stale IP entries.
Visual reference
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.