AZ-500 · Question #301
Case Study 3 - Fabrikam, Inc General Overview Fabrikam, Inc. is a consulting company that has a main office in Montreal and branch offices in Seattle and New York. Fabrikam has IT, human resources…
The correct answer is C. VM2, VM3, and VM4 only. Explanation Why C is correct: Just-in-Time (JIT) VM access in Microsoft Defender for Cloud (formerly Azure Security Center) requires VMs to be associated with a Network Security Group (NSG). Based on the scenario's VM table, VM2, VM3, and VM4 have NSGs associated with them…
Question
Options
- AVM1 and VM3 only
- BVM1, VM2, VM3, and VM4
- CVM2, VM3, and VM4 only
- DVM1 only
How the community answered
(44 responses)- A18% (8)
- B11% (5)
- C66% (29)
- D5% (2)
Explanation
Explanation
Why C is correct: Just-in-Time (JIT) VM access in Microsoft Defender for Cloud (formerly Azure Security Center) requires VMs to be associated with a Network Security Group (NSG). Based on the scenario's VM table, VM2, VM3, and VM4 have NSGs associated with them, making them eligible for JIT VM access, while VM1 does not have an NSG association in its current configuration.
Why the distractors are wrong:
- A (VM1 and VM3 only) is incorrect because VM1 lacks the required NSG association needed for JIT, and VM4 is also supported.
- B (VM1, VM2, VM3, and VM4) is incorrect because VM1 is not eligible without an NSG - the planned change to associate VM1 with ASG1 does not substitute for an NSG requirement.
- D (VM1 only) is incorrect for the same reason - VM1 cannot support JIT without an NSG, and it incorrectly excludes the other eligible VMs.
Memory Tip: Think of JIT as a "gatekeeper" - it needs an NSG to act as the gate. No NSG = No JIT. When reviewing VM eligibility for JIT, always check for NSG association first, and remember that Application Security Groups (ASGs) alone are not a substitute for NSGs in enabling JIT access.
Topics
Community Discussion
No community discussion yet for this question.