AZ-500 Secure networking Practice Question
You are a security engineer at Fabrikam Inc. The company has an Azure subscription with a single virtual network (VNet1) that contains a production workload. The network is connected to an on-premises data center via a site-to-site VPN. The security team requires that all Remote Desktop Protocol (RDP) and Secure Shell (SSH) access to virtual machines in VNet1 must be brokered through Azure Bastion. Additionally, the team wants to ensure that no public IP addresses are assigned to any virtual machines in the production environment. Currently, there are several VMs with public IPs. You need to implement the requirements with minimal downtime. The solution must also ensure that administrators can access the VMs using Azure Bastion without any additional client software. What should you do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy Azure Bastion in the virtual network and then remove the public IP addresses from all VMs.
Option D is correct because Azure Bastion must be deployed in the same virtual network as the target VMs (or a peered VNet) before public IPs are removed, since Bastion provides RDP/SSH connectivity over TLS port 443 through the Azure portal without requiring any client software or public IPs on the VMs. Deploying Bastion first ensures administrators retain access while the public IPs are disassociated, minimizing downtime. Option A is wrong because a point-to-site VPN does not broker RDP/SSH through Bastion and does not satisfy the no-public-IP requirement by itself. Option B is wrong because JIT VM access is a Microsoft Defender for Cloud feature that reduces exposure but does not replace Bastion or eliminate the need for public IPs. Option C is wrong because removing public IPs before Bastion is deployed would cut off RDP/SSH access and cause downtime.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a point-to-site VPN for administrators and remove public IPs from VMs.
Why it's wrong here
A point-to-site VPN requires installing and configuring VPN client software on each administrator's device and establishing a tunnel to the virtual network, which violates the requirement to avoid additional client software. Even after removing public IPs, the VPN gateway would still need a public endpoint, and ongoing user certificate or RADIUS provisioning adds administrative overhead. Bastion instead delivers browser-based RDP/SSH access with no client-side installation.
- ✗
Deploy Azure Bastion in the virtual network, then configure Just-In-Time (JIT) VM access for all VMs.
Why it's wrong here
Just-In-Time (JIT) access in Microsoft Defender for Cloud is designed to lock down inbound traffic to VMs that have public IP addresses by opening ports on demand; it does not provide a secure HTML5-based bastion host and does not eliminate the need for public IPs. After deploying Bastion, JIT is redundant because Bastion already brokers RDP/SSH sessions over TLS through a private IP connection. Moreover, JIT would require VMs to retain public IPs, directly conflicting with the stated goal of removing them.
- ✗
Disassociate public IPs from all VMs, then deploy Azure Bastion in the same virtual network.
Why it's wrong here
Removing public IPs before Azure Bastion is deployed creates an availability gap during which administrators have no remote connectivity path to the VMs, unless they are on the internal network. If a misconfiguration occurs or the Bastion deployment fails, the team could be locked out entirely, resulting in avoidable downtime. Deploying Bastion first preserves the existing public IP access until the Bastion service is fully provisioned and ready to serve traffic.
- ✓
Deploy Azure Bastion in the virtual network and then remove the public IP addresses from all VMs.
Why this is correct
Deploying Azure Bastion in the same virtual network as the target VMs first establishes a secure, fully managed PaaS service that brokers RDP and SSH sessions over TLS using the HTML5 client, with no additional client software required. Once Bastion reports a healthy status, removing the VMs' public IPs keeps administrative access uninterrupted because Bastion connects to the VMs over their private IP addresses. This ordering ensures zero downtime for administrators and aligns exactly with the requirements to eliminate public exposure and avoid client configuration.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-500
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company has several Azure virtual machines (VMs) in a VNet that host a legacy application. IT support staff need to perform remote administration using RDP. The security team wants to avoid exposing the VMs to the public internet and also enforce Azure Multi-Factor Authentication (MFA) for all RDP sessions. Which Azure service should they deploy to meet these requirements?
medium- A.Just-in-Time (JIT) VM Access from Microsoft Defender for Cloud
- ✓ B.Azure Bastion
- C.Network Security Groups (NSGs) with allow rules for RDP only from a trusted IP
- D.Azure Firewall with DNAT rules to forward RDP traffic
Why B: Azure Bastion provides secure, seamless RDP/SSH connectivity to Azure VMs directly from the Azure portal over TLS, without exposing the VMs to a public IP address. It also integrates with Azure AD and Conditional Access to enforce Azure Multi-Factor Authentication (MFA) for all RDP sessions, meeting both the security and compliance requirements.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.