An application team wants to securely connect to VMs without exposing public IP addresses. Which service should they deploy?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure Bastion.
Why this is the answer
Azure Bastion is the correct choice because it provides secure and seamless RDP/SSH connectivity to your virtual machines directly through the Azure portal over SSL. This eliminates the need for public IP addresses on your VMs, enhancing security by preventing direct exposure to the internet. Azure Bastion acts as a fully managed PaaS service, simplifying deployment and management. Azure Firewall is incorrect because it's a network security service that protects your Azure Virtual Network resources, but it doesn't provide direct, secure RDP/SSH access to VMs without public IPs in the same way Bastion does. Azure Logic Apps is a serverless platform for building automated workflows and has no relevance to secure VM access. Azure Front Door is a global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications, not for direct VM access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed