nerdexam
Microsoft

AZ-140 · Question #87

You are one of the security personnel in your organization. Your organization is using Azure Virtual Desktop. While using Azure Virtual Desktop, some components are already secured for your…

The correct answer is A. App security B. Network controls E. Session host OS. In an Azure Virtual Desktop deployment, customers are responsible for securing application access, managing network controls, and maintaining the security of the session host operating systems.

Submitted by jakub_pl· Apr 18, 2026Plan and implement identity and security

Question

You are one of the security personnel in your organization. Your organization is using Azure Virtual Desktop. While using Azure Virtual Desktop, some components are already secured for your environment. You or your team will need to configure other components/areas yourself to fit the security needs of your organization. From the below list of security needs, choose the ones your team or you are responsible for in your Azure virtual desktop deployment. (Select THREE)

Options

  • AApp security
  • BNetwork controls
  • CVirtualization control plane
  • DPhysical datacenter
  • ESession host OS

How the community answered

(21 responses)
  • A
    86% (18)
  • C
    5% (1)
  • D
    10% (2)

Why each option

In an Azure Virtual Desktop deployment, customers are responsible for securing application access, managing network controls, and maintaining the security of the session host operating systems.

AApp securityCorrect

Customers are responsible for the security of applications installed and used within their AVD environment, including application configuration, updates, and access control.

BNetwork controlsCorrect

Customers are responsible for configuring and maintaining network controls, such as virtual networks, subnets, network security groups (NSGs), and firewall rules, to secure communication to and from AVD session hosts.

CVirtualization control plane

The virtualization control plane for Azure Virtual Desktop is a service managed and secured by Microsoft as part of the shared responsibility model.

DPhysical datacenter

The physical datacenter infrastructure where Azure services run is entirely managed and secured by Microsoft, not the customer.

ESession host OSCorrect

Customers are responsible for the security of the session host operating system, including patching, configuration, antivirus, and compliance.

Concept tested: Azure Virtual Desktop shared responsibility model

Source: https://learn.microsoft.com/en-us/azure/virtual-desktop/security-guide?tabs=fslogix

Topics

#Azure Virtual Desktop#Shared Responsibility Model#Security#Cloud Security

Community Discussion

No community discussion yet for this question.

Full AZ-140 Practice