AZ-140 · Question #22
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…
The correct answer is B. No. Configuring address space settings of a virtual network or subnet does not provide the granular control needed to block user internet access while allowing session hosts to reach specific Microsoft services.
Question
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Azure Virtual Desktop host pool that contains five session hosts. The session hosts run Windows 10 Enterprise multi-session. You need to prevent users from accessing the internet from Azure Virtual Desktop sessions. The session hosts must be allowed to access all the required Microsoft services. Solution: You configure the Address space settings of the virtual network that contains the session hosts. Does that meet the goal?
Options
- AYes
- BNo
How the community answered
(24 responses)- A29% (7)
- B71% (17)
Why each option
Configuring address space settings of a virtual network or subnet does not provide the granular control needed to block user internet access while allowing session hosts to reach specific Microsoft services.
This solution is incorrect because changing address space settings alone does not function as a security mechanism to filter outbound internet traffic or distinguish between user access and necessary service access.
No. Modifying VNet or subnet address space settings only defines the IP ranges available within your network; it does not implement firewall-like rules or proxies to control outbound internet access for users or permit specific services for hosts. Network Security Groups or Azure Firewall are required for such traffic control.
Concept tested: Azure Virtual Desktop network access control.
Source: https://learn.microsoft.com/en-us/azure/virtual-desktop/network-connectivity-url-list
Topics
Community Discussion
No community discussion yet for this question.