AZ-500 · Question #164
You have an Azure subscription that contains a virtual network. The virtual network contains the subnets shown in the following table. The subscription contains the virtual machines shown in the…
The correct answer is C. VM1, VM3 and VM4 only. Explanation Option C is correct because JIT VM Access in Microsoft Defender for Cloud only protects virtual machines that have a Network Security Group (NSG) associated with their subnet or network interface - VM1, VM3, and VM4 meet this requirement, while VM2 does not (its…
Question
Exhibits
Options
- AVM4 only
- BVM1 and VM3 only
- CVM1, VM3 and VM4 only
- DVM1, VM2, VM3, and VM4
How the community answered
(20 responses)- A5% (1)
- B10% (2)
- C85% (17)
Explanation
Explanation
Option C is correct because JIT VM Access in Microsoft Defender for Cloud only protects virtual machines that have a Network Security Group (NSG) associated with their subnet or network interface - VM1, VM3, and VM4 meet this requirement, while VM2 does not (its subnet lacks an NSG, making JIT unable to enforce time-based access rules).
- Option A is wrong because VM4 alone is insufficient - VM1 and VM3 also satisfy JIT requirements by having NSGs applied.
- Option B is wrong because it excludes VM4, which also has a qualifying NSG and is therefore protected by JIT.
- Option D is wrong because VM2 resides on a subnet without an NSG, so JIT cannot create the necessary inbound port rules to protect it.
Memory Tip: Think of JIT as a bouncer that needs a door (NSG) to work - if there's no NSG on the subnet or NIC, JIT has nowhere to enforce its rules, and the VM cannot be protected. Always check for NSG presence when identifying JIT-eligible VMs.
Topics
Community Discussion
No community discussion yet for this question.



