AZ-140 · Question #23
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…
The correct answer is B. No. Modifying the IP configuration of each session host to block internet access would also prevent the hosts from accessing required Microsoft services, failing to meet the complete requirements.
Question
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Azure Virtual Desktop host pool that contains five session hosts. The session hosts run Windows 10 Enterprise multi-session. You need to prevent users from accessing the internet from Azure Virtual Desktop sessions. The session hosts must be allowed to access all the required Microsoft services. Solution: You modify the IP configuration of each session host. Does that meet the goal?
Options
- AYes
- BNo
How the community answered
(36 responses)- A33% (12)
- B67% (24)
Why each option
Modifying the IP configuration of each session host to block internet access would also prevent the hosts from accessing required Microsoft services, failing to meet the complete requirements.
This solution is incorrect because simply altering the IP configuration on the session hosts would likely block all outbound network traffic, including the legitimate Microsoft services the hosts need to function, rather than selectively blocking user internet access.
No. Directly modifying the IP configuration on each session host, for instance by removing the default gateway, would prevent all outbound internet access, including the necessary communication with Microsoft services, thus failing to meet the requirement to allow required services. Granular network control for user vs. system traffic requires Network Security Groups or Azure Firewall.
Concept tested: Azure Virtual Desktop network egress filtering.
Source: https://learn.microsoft.com/en-us/azure/virtual-desktop/network-connectivity-url-list
Topics
Community Discussion
No community discussion yet for this question.