AZ-900 Describe Azure architecture and services Practice Question
A company has deployed several Azure virtual machines in a VNet. The security policy requires that no VM has a public IP address. However, administrators need to connect to the VMs using RDP and SSH for management. The administrators currently use the Azure portal and must not install any additional client software on their local workstations. Which Azure service should they use to meet these requirements?
⚠ Common exam trap
Candidates often confuse Azure Bastion with Azure VPN Gateway, thinking a VPN provides direct browser-based RDP/SSH without client software, but VPN Gateway requires a VPN client and does not offer portal-based connectivity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Bastion
Azure Bastion provides secure, seamless RDP and SSH connectivity to Azure VMs directly from the Azure portal over TLS, without exposing any public IP addresses on the VMs. It uses a browser-based HTML5 client, so administrators do not need to install any additional client software on their local workstations, meeting all stated requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Bastion
Why this is correct
Azure Bastion is the correct choice because it is a platform-managed PaaS service that provides secure, browser-based RDP and SSH access to Azure VMs directly from the Azure portal. It connects to a VM's private IP over TLS without requiring a public IP, an agent, or a VPN client on the user's workstation. The service also integrates with Microsoft Entra ID for additional authentication and even supports conditional access policies, making it the ideal secure remote access tool for this scenario.
- ✗
Azure VPN Gateway
Why it's wrong here
Azure VPN Gateway is not correct for this scenario because it is primarily a network connectivity service that creates site-to-site or point-to-site IPsec tunnels. While a point-to-site VPN would allow an administrator to reach the VNet, it still requires installing and configuring a VPN client on the administrator's workstation and does not provide browser-based RDP/SSH connectivity. The gateway only encapsulates network packets, leaving remote desktop or SSH session handling to separate client software, so it does not satisfy the stated security requirement.
When this WOULD be correct
A company needs to connect its on-premises network to Azure VNets securely over the internet, using IPsec tunnels, and administrators are allowed to install VPN client software on their local workstations.
- ✗
Azure Firewall
Why it's wrong here
Azure Firewall is incorrect because it is a stateful, managed network security service that filters and logs traffic at the network edge, not a remote connectivity tool. It can inspect and block traffic destined for VMs, but it does not masquerade as a jump host or support native RDP/SSH session initiation from a browser. Using Azure Firewall would not remove the need for a public IP or a VPN client for secure VM access; it only enforces north-south and east-west security rules, so it cannot replace the functionality of Azure Bastion.
When this WOULD be correct
A company needs to centrally control and log outbound/inbound traffic to and from Azure VMs, with requirements for threat intelligence-based filtering and high availability. Azure Firewall would be the correct service to deploy as a perimeter firewall.
- ✗
Azure ExpressRoute
Why it's wrong here
Azure ExpressRoute is wrong because it is a dedicated, private WAN connection from an on-premises network to Azure, established through an MPLS or similar carrier provider. It extends the corporate network into Azure at Layer 2/Layer 3 but offers no interactive remote access functionality, so an administrator would still need to deploy a separate remote desktop or SSH solution. Additionally, ExpressRoute is meant for consistent low-latency bandwidth and requires additional configuration like a virtual network gateway, making it unsuitable as a direct jump-server alternative for browser-based access.
When this WOULD be correct
A company needs a private, high-bandwidth, low-latency connection between their on-premises data center and Azure, with no traffic traversing the internet, and they require a service-level agreement for availability. ExpressRoute would be the correct choice.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Azure BastionCorrect answer▾
Why this is correct
Azure Bastion is the correct choice because it is a platform-managed PaaS service that provides secure, browser-based RDP and SSH access to Azure VMs directly from the Azure portal. It connects to a VM's private IP over TLS without requiring a public IP, an agent, or a VPN client on the user's workstation. The service also integrates with Microsoft Entra ID for additional authentication and even supports conditional access policies, making it the ideal secure remote access tool for this scenario.
✗Azure VPN GatewayWrong answer — click to see why▾
Why this is wrong here
Azure VPN Gateway provides site-to-site or point-to-site connectivity from on-premises networks to Azure VNets, but it does not provide direct RDP/SSH access to VMs without public IPs and requires client software for point-to-site connections.
★ When this WOULD be the correct answer
A company needs to connect its on-premises network to Azure VNets securely over the internet, using IPsec tunnels, and administrators are allowed to install VPN client software on their local workstations.
Why candidates choose this
Candidates may think VPN Gateway can be used to remotely access VMs, confusing it with a jump box or remote access solution, and overlook the requirement to avoid installing additional client software.
✗Azure FirewallWrong answer — click to see why▾
Why this is wrong here
Azure Firewall is a managed network security service that filters traffic, but it does not provide RDP/SSH connectivity without public IPs. It cannot replace Bastion's purpose of enabling secure remote access to VMs without exposing them to the internet.
★ When this WOULD be the correct answer
A company needs to centrally control and log outbound/inbound traffic to and from Azure VMs, with requirements for threat intelligence-based filtering and high availability. Azure Firewall would be the correct service to deploy as a perimeter firewall.
Why candidates choose this
Candidates may think Azure Firewall can be used as a jump box or proxy for RDP/SSH, confusing its traffic filtering role with secure remote access capabilities.
✗Azure ExpressRouteWrong answer — click to see why▾
Why this is wrong here
Azure ExpressRoute provides a private, dedicated network connection from on-premises to Azure, but it does not provide RDP/SSH access to VMs without public IPs. It requires additional client software and does not offer browser-based connectivity.
★ When this WOULD be the correct answer
A company needs a private, high-bandwidth, low-latency connection between their on-premises data center and Azure, with no traffic traversing the internet, and they require a service-level agreement for availability. ExpressRoute would be the correct choice.
Why candidates choose this
Candidates may think ExpressRoute provides secure remote access because it is a private connection, but it is designed for site-to-site connectivity, not for individual VM management sessions without additional components.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Azure Regions and Geographies
Key term
Azure portal
The Azure portal is a web-based, unified console that lets you build, manage, and monitor everything from simple web apps to complex cloud deployments using a graphical user interface.
Key term
Azure Bastion
Azure Bastion is a fully managed PaaS service that provides secure and seamless RDP and SSH connectivity to virtual machines directly through the Azure portal without exposing public IP addresses.
About these practice questions
This AZ-900 question is part of Courseiva's 981-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.