Courseiva
Secure networking →easyMultiple Choice

AZ-500 Secure networking Practice Question

You need to provide secure remote access to Azure virtual machines for developers without exposing public IP addresses. The solution must authenticate users via Microsoft Entra ID and support multifactor authentication. Which service should you use?

⚠ Common exam trap

Watch out — candidates often confuse Azure Bastion with Azure VPN Gateway, assuming a VPN is required for secure remote access, but Bastion is the correct choice when the goal is to avoid public IPs and integrate directly with Microsoft Entra ID for authentication and MFA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Bastion

Azure Bastion provides secure RDP/SSH connectivity to Azure virtual machines directly from the Azure portal over TLS, without exposing public IP addresses. It integrates with Microsoft Entra ID for authentication and supports multifactor authentication (MFA) when combined with Conditional Access policies, meeting all requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Front Door

    Why it's wrong here

    Azure Front Door is a global Layer 7 load balancer and CDN designed exclusively for HTTP/HTTPS web applications. It terminates web traffic at Microsoft's edge and routes it to backends, but it cannot carry RDP or SSH protocol sessions, so it provides no interactive administrative access to a VM. Even when used with Private Link, Front Door remains a web-delivery service, not a remote-management plane.

  • ✗

    Azure VPN Gateway

    Why it's wrong here

    Azure VPN Gateway creates an encrypted IPsec/IKE tunnel between a client or on-premises network and your Azure VNet, but it requires a public IP on the gateway and a properly configured VPN client or device. After the tunnel is up, you still need a separate RDP/SSH client and the VM's private IP address, adding management overhead and potentially leaving the VPN gateway's public endpoint vulnerable. It also does not provide an identity-aware, portal-based session like Azure Bastion does.

  • ✓

    Azure Bastion

    Why this is correct

    Azure Bastion is a fully managed, agentless PaaS service that provides secure, seamless RDP and SSH connectivity to Azure VMs directly through the Azure portal over TLS. It is deployed in a dedicated subnet (AzureBastionSubnet) and lets users connect to VMs without any public IP, NSG rule allowing inbound RDP/SSH, or additional client software. Bastion integrates with Microsoft Entra ID authentication, MFA, and RBAC, making it the ideal answer for secure browser-based remote access to Azure VMs.

  • ✗

    Azure Firewall

    Why it's wrong here

    Azure Firewall is a stateful network firewall that filters traffic between virtual networks and the internet at Layers 3-7, using rules and threat intelligence. While it can be configured with DNAT rules to forward RDP/SSH from a firewall public IP to a VM, that still exposes an inbound management port and does not provide identity-based authentication, encryption, or a portal-based session. As a security boundary rather than a remote-access mechanism, it cannot substitute for Azure Bastion.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on AZ-500

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You need to provide secure remote access to Azure virtual machines without assigning them public IP addresses. Which Azure service should you use?

easy
  • A.Azure VPN Gateway
  • B.Azure Firewall
  • ✓ C.Azure Bastion
  • D.Azure Front Door

Why C: Azure Bastion provides secure, seamless RDP/SSH connectivity to Azure virtual machines directly in the Azure portal over TLS, without exposing public IP addresses. It uses a hardened, fully managed platform as a service (PaaS) that sits inside your virtual network, eliminating the need for a jump box or public-facing endpoints.

Variation 2. You need to provide secure remote access to Azure virtual machines for administrators without exposing them to the public internet. The solution must use a single entry point and support Azure Active Directory (now Microsoft Entra ID) authentication. Which Azure service should you use?

easy
  • ✓ A.Azure Bastion.
  • B.Just-in-time (JIT) VM access with Microsoft Defender for Cloud.
  • C.Azure Front Door with private endpoints.
  • D.Azure VPN Gateway with point-to-site VPN.

Why A: Azure Bastion provides secure, seamless RDP/SSH connectivity to Azure VMs directly from the Azure portal over TLS, without exposing public IP addresses. It uses a single entry point (the Bastion host) and supports Azure AD authentication for login, meeting both requirements.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.