Microsoft Azure Administrator Associate AZ-104 Practice Question
An organization has deployed multiple virtual machines (VMs) within an Azure virtual network. The VMs do not have public IP addresses, and network security group (NSG) rules prevent inbound internet traffic. Administrators need a secure method to manage these VMs remotely over the internet without modifying NSG rules or assigning public IPs to the VMs. What should the administrators implement to achieve this requirement?
Configure a point-to-site VPN connection to the virtual network.
Enable just-in-time (JIT) VM access for the VMs.
Add a public load balancer to provide access to the VMs.
Deploy an Azure Bastion host in the virtual network.
Deploying an Azure Bastion host in the virtual network allows administrators to securely access the VMs using Remote Desktop Protocol (RDP) or Secure Shell (SSH) directly through the Azure portal over HTTPS. This method does not require public IP addresses on the VMs or changes to NSG rules, as Azure Bastion provides secure connectivity over TLS.
Configuring a point-to-site VPN (Option 1) would require setting up VPN clients on administrator workstations and maintaining VPN infrastructure. While this provides secure access, it adds complexity and requires VPN connectivity. Enabling just-in-time VM access (Option 2) still necessitates opening inbound NSG ports and possibly assigning public IPs, which the scenario aims to avoid. Adding a public load balancer (Option 4) would expose the VMs to the internet, conflicting with the security requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure Bastion and how does it work?
Open an interactive chat with Bash
What are network security groups (NSGs) and their role in Azure?
Open an interactive chat with Bash
What is the Remote Desktop Protocol (RDP) and how is it secured?
Open an interactive chat with Bash
Microsoft Azure Administrator Associate AZ-104
Configure and manage virtual networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access