nerdexam
Microsoft

AZ-140 · Question #23

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…

The correct answer is B. No. Modifying the IP configuration of each session host to block internet access would also prevent the hosts from accessing required Microsoft services, failing to meet the complete requirements.

Submitted by ravi_2018· Apr 18, 2026Plan and implement an Azure Virtual Desktop infrastructure

Question

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Azure Virtual Desktop host pool that contains five session hosts. The session hosts run Windows 10 Enterprise multi-session. You need to prevent users from accessing the internet from Azure Virtual Desktop sessions. The session hosts must be allowed to access all the required Microsoft services. Solution: You modify the IP configuration of each session host. Does that meet the goal?

Options

  • AYes
  • BNo

How the community answered

(36 responses)
  • A
    33% (12)
  • B
    67% (24)

Why each option

Modifying the IP configuration of each session host to block internet access would also prevent the hosts from accessing required Microsoft services, failing to meet the complete requirements.

AYes

This solution is incorrect because simply altering the IP configuration on the session hosts would likely block all outbound network traffic, including the legitimate Microsoft services the hosts need to function, rather than selectively blocking user internet access.

BNoCorrect

No. Directly modifying the IP configuration on each session host, for instance by removing the default gateway, would prevent all outbound internet access, including the necessary communication with Microsoft services, thus failing to meet the requirement to allow required services. Granular network control for user vs. system traffic requires Network Security Groups or Azure Firewall.

Concept tested: Azure Virtual Desktop network egress filtering.

Source: https://learn.microsoft.com/en-us/azure/virtual-desktop/network-connectivity-url-list

Topics

#Azure Virtual Desktop networking#Outbound internet access control#Session host configuration#Network security

Community Discussion

No community discussion yet for this question.

Full AZ-140 Practice