How can you ensure the virtual machines in resource group RG1 have their Remote Desktop port closed until an authorized user requests temporary access?
Choose an answer
Tap an option to check your answer.
Correct answer: just in time (JIT) VM access.
Why this is the answer
Just-in-time (JIT) VM access is the correct solution. It allows you to lock down inbound traffic to your Azure VMs, reducing exposure to attacks. When a user needs access, they can request it through the Azure portal, and JIT will temporarily open the specified ports (like RDP) for a limited time and from approved source IPs. Azure AD Privileged Identity Management (PIM) manages elevated access to Azure resources and Azure AD roles, but it doesn't directly control network port access. An application security group (ASG) groups VMs and defines network security rules based on those groups, but it doesn't provide temporary, on-demand access. Azure AD conditional access enforces policies based on user, device, and location, but it doesn't directly manage the opening and closing of VM ports for temporary access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed