A finance team at Mercury Systems wants to use Just-in-Time (JIT) VM Access for a set of Windows VMs. They require that RDP (TCP 3389) is only opened for approved engineer public IPs for a maximum of 2 hours per access request, and that only port 3389 is ever opened. How should JIT be configured in Azure Security Center (Defender) to meet these constraints?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable JIT on the selected VMs, set allowed source IP ranges to the engineers' public IP addresses, configure allowed ports to TCP 3389 with maximum request time of 2 hours, and require approval workflow for requests..
Why this is the answer
The correct option directly describes the configuration steps for Azure Security Center's Just-in-Time (JIT) VM access feature to meet all specified requirements. JIT allows you to restrict inbound traffic to your Azure VMs, reducing exposure to attacks. You can define allowed source IP ranges, specific ports (like TCP 3389), and the maximum time a port can be open. The approval workflow ensures requests are reviewed. The incorrect options fail to meet the requirements: Using NSG rules with Azure Automation is a manual workaround that doesn't leverage JIT's security benefits and dynamic port opening/closing. Enabling JIT with a wildcard source (0.0.0.0/0) would expose the VM to all public IPs, violating the requirement for approved engineer IPs. Azure Bastion is a secure connectivity solution, but the question specifically asks for JIT configuration, and Bastion doesn't inherently enforce time-limited access in the same way JIT does for direct VM access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed