SC-100 · Question #90
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…
The correct answer is A. Yes. The answer is Yes. To improve the 'Secure management ports' score in the Azure Security Benchmark V3 within Microsoft Defender for Cloud, enabling Just-In-Time (JIT) VM access is the correct recommendation. JIT VM access locks down inbound traffic to management ports (RDP port…
Question
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure subscription that has Microsoft Defender for Cloud enabled. You are evaluating the Azure Security Benchmark V3 report. In the Secure management ports controls, you discover that you have 0 out of a potential 8 points. You need to recommend configurations to increase the score of the Secure management ports controls. Solution: You recommend enabling just-in-time (JIT) VM access on all virtual machines. Does this meet the goal?
Options
- AYes
- BNo
How the community answered
(52 responses)- A71% (37)
- B29% (15)
Explanation
The answer is Yes. To improve the 'Secure management ports' score in the Azure Security Benchmark V3 within Microsoft Defender for Cloud, enabling Just-In-Time (JIT) VM access is the correct recommendation. JIT VM access locks down inbound traffic to management ports (RDP port 3389 and SSH port 22) by default, only opening them temporarily and only to approved source IPs when a user explicitly requests access. This directly addresses the secure management ports control, which penalizes VMs that leave RDP/SSH ports permanently open. JIT access is a built-in feature of Microsoft Defender for Servers and is the primary mechanism for scoring points in this control category.
Topics
Community Discussion
No community discussion yet for this question.