nerdexam
Microsoft

AZ-500 · Question #479

SIMULATION Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and click on the username below. To enter your password, place your cursor in…

The correct solution involves enabling Just-in-Time (JIT) VM Access through Microsoft Defender for Cloud, which is the best way to minimize the attack surface while still allowing RDP connections. JIT VM Access locks down inbound traffic to the VM by default and only opens port…

Submitted by eva_at· Mar 6, 2026Implement and manage Azure security - specifically securing compute resources and managing network access to virtual machines using Microsoft Defender for Cloud and NSG configurations (AZ-500 / SC-900 domain: Manage security operations and implement platform protection).

Question

SIMULATION Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and click on the username below. To enter your password, place your cursor in the Enter password box and click on the password below. Azure Username: [email protected] Azure Password: Gp0Ae4@!Dg If the Azure portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab. The following information is for technical support purposes only: Lab Instance: 28681041 You need to configure Azure to allow RDP connections from the Internet to a virtual machine named VM1. The solution must minimize the attack surface of VM1. To complete this task, sign in to the Azure portal. Answer:

Exhibit

AZ-500 question #479 exhibit

Explanation

The correct solution involves enabling Just-in-Time (JIT) VM Access through Microsoft Defender for Cloud, which is the best way to minimize the attack surface while still allowing RDP connections. JIT VM Access locks down inbound traffic to the VM by default and only opens port 3389 temporarily when explicitly requested by an authorized user, reducing exposure to brute-force and port-scanning attacks. Simply opening port 3389 with a source IP restriction is a secondary approach, but JIT provides dynamic, time-limited access control that truly minimizes the attack surface as the question requires.

Topics

#Just-in-Time VM Access#Microsoft Defender for Cloud#Network Security Groups#Azure Virtual Machines Security

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice