Courseiva
Secure networking →easyMultiple Choice

AZ-500 Secure networking Practice Question

You need to provide secure remote administration access to Azure virtual machines in a production environment. You want to eliminate public RDP/SSH endpoints and provide just-in-time access. Which Azure service should you use?

⚠ Common exam trap

Many candidates confuse Azure Bastion's 'no public IP' secure access with just-in-time access, but Bastion provides persistent, always-on connectivity, whereas JIT VM access enforces time-limited, approval-based access with automatic port closure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Just-in-time VM access in Microsoft Defender for Cloud

Just-in-time (JIT) VM access in Microsoft Defender for Cloud is the correct choice because it specifically provides time-bound, policy-controlled access to Azure VMs via RDP/SSH while eliminating permanent public endpoints. JIT dynamically opens NSG rules for a specified duration only when an authorized user requests access, then automatically closes them, enforcing the principle of least privilege for remote administration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Network Security Groups (NSGs)

    Why it's wrong here

    Network Security Groups (NSGs) are stateful packet filters for subnets and network interfaces, but they lack any time-based, just-in-time access workflow. Manually modifying NSG rules to allow RDP or SSH requires creating permanent inbound rules, which persist until someone remembers to remove them, and there is no approval or audit process built in. Thus, an NSG on its own cannot grant or revoke access for a limited window as requested.

  • ✗

    Azure Firewall

    Why it's wrong here

    Azure Firewall is a managed, cloud-native firewall that performs L3-L7 filtering and can use DNAT to forward inbound RDP/SSH traffic to VMs, but it is not an access control service for administrative sessions. It does not provide time-limited, workflow-based access with automated approval or expiration; its rules are static and intended for persistent network security policy. Therefore, using Azure Firewall does not satisfy the requirement for just-in-time administrative access.

  • ✓

    Just-in-time VM access in Microsoft Defender for Cloud

    Why this is correct

    Just-in-time (JIT) VM access in Microsoft Defender for Cloud is a workload-protection feature that deliberately denies inbound RDP/SSH traffic to Azure VMs using automatically configured NSG rules. When an authenticated user with the appropriate Microsoft Entra ID identity requests access, Defender for Cloud applies targeted NSG rules for a limited, configurable time window and then reverts them automatically after expiration. It supports approval workflows, can enforce MFA, and produces audit logs, making it the only option here that directly delivers time-bound administrative access.

  • ✗

    Azure Bastion

    Why it's wrong here

    Azure Bastion is a fully managed service that offers secure, TLS-encrypted RDP and SSH access to VMs directly through the Azure portal, eliminating the need for public IP addresses. It allows authorized users to connect anytime as long as they have the appropriate permissions, but it has no built-in time-limited, just-in-time access workflow or automatic port closing. So while Bastion enhances the security of the remote session itself, it does not control or restrict the access window as required.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.