Courseiva
easyMultiple Choice

SC-200 Practice Question: Protect Azure virtual machines from brute force…

A company wants to protect Azure virtual machines from brute force attacks by allowing remote desktop protocol (RDP) access only when explicitly requested and approved. Which Microsoft Defender for Cloud feature should they enable?

⚠ Common exam trap

Watch out — candidates often confuse Adaptive network hardening (which also involves NSG rules) with JIT VM access, but Adaptive network hardening only recommends permanent rule changes based on traffic patterns, not temporary, approval-based port openings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Just-in-time VM access

Just-in-time (JIT) VM access in Microsoft Defender for Cloud locks down inbound traffic to Azure VMs by default, opening RDP (port 3389) only when a user requests access and is approved via Microsoft Entra ID and Azure Policy. This directly addresses the requirement to allow RDP only on explicit request and approval, mitigating brute force attacks by reducing the attack surface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Adaptive network hardening

    Why it's wrong here

    Adaptive network hardening uses machine learning to profile real internet traffic and recommend hardening rules for existing network security groups, but it never creates time-limited, on-demand access grants. Because it only suggests static changes to be applied manually, it cannot respond to a user's request to open a port for a specific interval during a brute-force incident.

  • ✓

    Just-in-time VM access

    Why this is correct

    Just-in-time VM access in Microsoft Defender for Cloud eliminates standing inbound exposure by locking down management ports with deny rules, and only transiently adds an allow rule when an authenticated, authorized request is made for a defined source IP, protocol, and time window. This reduced attack surface directly mitigates brute-force attempts because SSH/RDP ports remain closed to the public internet until a legitimate user specifically requests access.

  • ✗

    File integrity monitoring

    Why it's wrong here

    File integrity monitoring continuously hashes and compares critical operating system files, registry keys, and software to detect unauthorized changes after they occur, but it provides no network-layer filtering that would stop authentication attempts from reaching the VM. It is an audit and detection control, not a preventive access-control mechanism, and therefore cannot reduce the exposure of management endpoints to brute force.

  • ✗

    Security recommendations

    Why it's wrong here

    Security recommendations are a reporting feature that surfaces misconfigurations, missing patches, or Microsoft Defender for Cloud scoring gaps, and they often suggest enabling JIT or adjusting firewall rules, but merely viewing a recommendation has no runtime effect on inbound traffic. They are advisory rather than enforced controls, so they cannot automatically shut down brute-force attempts unless an administrator takes manual action based on that guidance.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.