nerdexam
Microsoft

AZ-500 · Question #164

You have an Azure subscription that contains a virtual network. The virtual network contains the subnets shown in the following table. The subscription contains the virtual machines shown in the…

The correct answer is C. VM1, VM3 and VM4 only. Explanation Option C is correct because JIT VM Access in Microsoft Defender for Cloud only protects virtual machines that have a Network Security Group (NSG) associated with their subnet or network interface - VM1, VM3, and VM4 meet this requirement, while VM2 does not (its…

Submitted by the_admin· Mar 6, 2026Secure compute, storage, and databases

Question

You have an Azure subscription that contains a virtual network. The virtual network contains the subnets shown in the following table. The subscription contains the virtual machines shown in the following table. You enable just in time (JIT) VM access for all the virtual machines. You need to identify which virtual machines are protected by JIT. Which virtual machines should you identify?

Exhibits

AZ-500 question #164 exhibit 1
AZ-500 question #164 exhibit 2
AZ-500 question #164 exhibit 3
AZ-500 question #164 exhibit 4

Options

  • AVM4 only
  • BVM1 and VM3 only
  • CVM1, VM3 and VM4 only
  • DVM1, VM2, VM3, and VM4

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    10% (2)
  • C
    85% (17)

Explanation

Explanation

Option C is correct because JIT VM Access in Microsoft Defender for Cloud only protects virtual machines that have a Network Security Group (NSG) associated with their subnet or network interface - VM1, VM3, and VM4 meet this requirement, while VM2 does not (its subnet lacks an NSG, making JIT unable to enforce time-based access rules).

  • Option A is wrong because VM4 alone is insufficient - VM1 and VM3 also satisfy JIT requirements by having NSGs applied.
  • Option B is wrong because it excludes VM4, which also has a qualifying NSG and is therefore protected by JIT.
  • Option D is wrong because VM2 resides on a subnet without an NSG, so JIT cannot create the necessary inbound port rules to protect it.

Memory Tip: Think of JIT as a bouncer that needs a door (NSG) to work - if there's no NSG on the subnet or NIC, JIT has nowhere to enforce its rules, and the VM cannot be protected. Always check for NSG presence when identifying JIT-eligible VMs.

Topics

#Just-in-Time (JIT) VM access#Network Security Groups (NSG)#Virtual machine security#Azure Defender for Cloud

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice