nerdexam
Microsoft

SC-100 · Question #90

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…

The correct answer is A. Yes. The answer is Yes. To improve the 'Secure management ports' score in the Azure Security Benchmark V3 within Microsoft Defender for Cloud, enabling Just-In-Time (JIT) VM access is the correct recommendation. JIT VM access locks down inbound traffic to management ports (RDP port…

Design security solutions for infrastructure

Question

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure subscription that has Microsoft Defender for Cloud enabled. You are evaluating the Azure Security Benchmark V3 report. In the Secure management ports controls, you discover that you have 0 out of a potential 8 points. You need to recommend configurations to increase the score of the Secure management ports controls. Solution: You recommend enabling just-in-time (JIT) VM access on all virtual machines. Does this meet the goal?

Options

  • AYes
  • BNo

How the community answered

(52 responses)
  • A
    71% (37)
  • B
    29% (15)

Explanation

The answer is Yes. To improve the 'Secure management ports' score in the Azure Security Benchmark V3 within Microsoft Defender for Cloud, enabling Just-In-Time (JIT) VM access is the correct recommendation. JIT VM access locks down inbound traffic to management ports (RDP port 3389 and SSH port 22) by default, only opening them temporarily and only to approved source IPs when a user explicitly requests access. This directly addresses the secure management ports control, which penalizes VMs that leave RDP/SSH ports permanently open. JIT access is a built-in feature of Microsoft Defender for Servers and is the primary mechanism for scoring points in this control category.

Topics

#Just-in-Time VM Access#Microsoft Defender for Cloud#Azure Security Benchmark#Network Security

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice