How can you ensure NSG1 permits RDP connections to the virtual machines for no more than 60 minutes when a member of ServerAdmins requests access?
Choose an answer
Tap an option to check your answer.
Correct answer: a just in time (JIT) VM access policy in Microsoft Defender for Cloud.
Why this is the answer
A just-in-time (JIT) VM access policy in Microsoft Defender for Cloud is the correct solution. JIT access allows you to lock down inbound traffic to your Azure VMs, reducing exposure to attacks, while providing easy access when needed. When a user requests access, Defender for Cloud configures the Network Security Group (NSG) to allow inbound traffic from the specified source IP address for a limited time, such as 60 minutes, and then automatically removes the rule. Azure Policy is used for enforcing organizational standards and assessing compliance, not for dynamic, time-limited access to specific ports. Azure AD PIM manages privileged role assignments within Azure AD and Azure resources, but it doesn't directly control NSG rules for VM access. An Azure Bastion host provides secure RDP/SSH connectivity through a browser, but it doesn't inherently enforce time limits on NSG rules for direct VM access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed