AZ-500 Secure networking Practice Question
You need to provide secure remote administration access to Azure virtual machines in a production environment. You want to eliminate public RDP/SSH endpoints and provide just-in-time access. Which Azure service should you use?
⚠ Common exam trap
Many candidates confuse Azure Bastion's 'no public IP' secure access with just-in-time access, but Bastion provides persistent, always-on connectivity, whereas JIT VM access enforces time-limited, approval-based access with automatic port closure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Just-in-time VM access in Microsoft Defender for Cloud
Just-in-time (JIT) VM access in Microsoft Defender for Cloud is the correct choice because it specifically provides time-bound, policy-controlled access to Azure VMs via RDP/SSH while eliminating permanent public endpoints. JIT dynamically opens NSG rules for a specified duration only when an authorized user requests access, then automatically closes them, enforcing the principle of least privilege for remote administration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network Security Groups (NSGs)
Why it's wrong here
Network Security Groups (NSGs) are stateful packet filters for subnets and network interfaces, but they lack any time-based, just-in-time access workflow. Manually modifying NSG rules to allow RDP or SSH requires creating permanent inbound rules, which persist until someone remembers to remove them, and there is no approval or audit process built in. Thus, an NSG on its own cannot grant or revoke access for a limited window as requested.
- ✗
Azure Firewall
Why it's wrong here
Azure Firewall is a managed, cloud-native firewall that performs L3-L7 filtering and can use DNAT to forward inbound RDP/SSH traffic to VMs, but it is not an access control service for administrative sessions. It does not provide time-limited, workflow-based access with automated approval or expiration; its rules are static and intended for persistent network security policy. Therefore, using Azure Firewall does not satisfy the requirement for just-in-time administrative access.
- ✓
Just-in-time VM access in Microsoft Defender for Cloud
Why this is correct
Just-in-time (JIT) VM access in Microsoft Defender for Cloud is a workload-protection feature that deliberately denies inbound RDP/SSH traffic to Azure VMs using automatically configured NSG rules. When an authenticated user with the appropriate Microsoft Entra ID identity requests access, Defender for Cloud applies targeted NSG rules for a limited, configurable time window and then reverts them automatically after expiration. It supports approval workflows, can enforce MFA, and produces audit logs, making it the only option here that directly delivers time-bound administrative access.
- ✗
Azure Bastion
Why it's wrong here
Azure Bastion is a fully managed service that offers secure, TLS-encrypted RDP and SSH access to VMs directly through the Azure portal, eliminating the need for public IP addresses. It allows authorized users to connect anytime as long as they have the appropriate permissions, but it has no built-in time-limited, just-in-time access workflow or automatic port closing. So while Bastion enhances the security of the remote session itself, it does not control or restrict the access window as required.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.