AZ-500 Secure networking Practice Question
You are a security engineer for Litware. The company has an Azure virtual network named VNet1 that contains an Azure Bastion host and several VMs. The VMs have public IP addresses, but the security team wants to eliminate all public IP exposure while still allowing administrators to connect via RDP and SSH from the internet. You need to recommend a solution that meets these requirements with the least administrative effort. What should you do?
⚠ Common exam trap
The trap here is thinking that a network security group restricting RDP/SSH to specific source IPs is sufficient, when the requirement explicitly demands eliminating public IP exposure entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remove the public IP addresses from the VMs and configure Azure Bastion in VNet1. Administrators connect to the VMs through the Azure portal using the Bastion host.
Azure Bastion offers secure RDP and SSH access from the Azure portal without public IPs on VMs. Deploying Bastion in VNet1 and removing VM public IPs meets the security requirement with minimal administrative effort, as administrators use the portal directly and no VPN or firewall configuration is needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove the public IP addresses from the VMs and create a site-to-site VPN connection from each administrator's workstation to VNet1.
Why it's wrong here
A site-to-site VPN connects networks, not individual workstations. Configuring a VPN for each administrator would require significant setup and management, and it does not provide the same simple portal-based RDP/SSH access. It also introduces additional cost and complexity that the scenario explicitly seeks to avoid.
- ✗
Keep the public IP addresses but restrict inbound RDP and SSH to the administrators' source IP addresses using a network security group on the VM subnet.
Why it's wrong here
This approach still leaves the VMs with public IP addresses, which violates the requirement to eliminate all public IP exposure. While NSG rules can restrict access, the VMs remain directly reachable from the internet, increasing the attack surface and failing the stated security objective.
- ✓
Remove the public IP addresses from the VMs and configure Azure Bastion in VNet1. Administrators connect to the VMs through the Azure portal using the Bastion host.
Why this is correct
Azure Bastion provides RDP and SSH connectivity over TLS directly from the Azure portal without exposing VM public IPs. Removing the public IPs eliminates internet exposure. Bastion is deployed to a dedicated subnet named AzureBastionSubnet in the same VNet, and no additional client software is required, making it the least-effort solution.
- ✗
Remove the public IP addresses from the VMs and deploy an Azure Firewall with DNAT rules to forward RDP and SSH traffic to the VMs.
Why it's wrong here
Azure Firewall DNAT would still require a public IP on the firewall and would expose RDP/SSH to the internet through that public IP. This does not meet the goal of eliminating public IP exposure for the VMs and adds unnecessary complexity compared to Azure Bastion, which provides secure access without any public IP.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.