AZ-500 · Question #479
SIMULATION Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and click on the username below. To enter your password, place your cursor in…
The correct solution involves enabling Just-in-Time (JIT) VM Access through Microsoft Defender for Cloud, which is the best way to minimize the attack surface while still allowing RDP connections. JIT VM Access locks down inbound traffic to the VM by default and only opens port…
Question
Exhibit
Explanation
The correct solution involves enabling Just-in-Time (JIT) VM Access through Microsoft Defender for Cloud, which is the best way to minimize the attack surface while still allowing RDP connections. JIT VM Access locks down inbound traffic to the VM by default and only opens port 3389 temporarily when explicitly requested by an authorized user, reducing exposure to brute-force and port-scanning attacks. Simply opening port 3389 with a source IP restriction is a secondary approach, but JIT provides dynamic, time-limited access control that truly minimizes the attack surface as the question requires.
Topics
Community Discussion
No community discussion yet for this question.
