An Azure subscription contains several virtual machines across peered virtual networks. Azure Bastion is deployed to VNET2. Which virtual machines can be protected by the Bastion host?
Choose an answer
Tap an option to check your answer.
Correct answer: VM1, VM2, VM3, and VM4.
Why this is the answer
Azure Bastion can connect to virtual machines in the virtual network where it is deployed (VNET2, protecting VM2 and VM4) and to virtual machines in peered virtual networks (VNET1, protecting VM1 and VM3). This is because network peering allows resources in different virtual networks to communicate with each other as if they were in the same network. Therefore, the Bastion host in VNET2 can establish connections to all VMs across both VNET1 and VNET2. The options suggesting only a subset of VMs are incorrect because they fail to account for Bastion's ability to reach peered networks.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed