To enable just-in-time (JIT) VM access for all session hosts in the deployment, what should you do first?
Choose an answer
Tap an option to check your answer.
Correct answer: Assign a network security group (NSG) to Subnet1..
Why this is the answer
Just-in-time (JIT) VM access in Azure Security Center requires that the virtual machines are protected by a Network Security Group (NSG). Applying an NSG to Subnet1 ensures that all current and future session hosts within that subnet are covered by an NSG, which is a prerequisite for enabling JIT. While assigning NSGs directly to individual network interfaces (NICs) would also work, applying it at the subnet level is more scalable and manageable for multiple session hosts. Deploying Azure Bastion is for secure RDP/SSH access, not a prerequisite for JIT itself. Configuring Access Control (IAM) for the host pool manages permissions for the host pool resource, not network security for JIT.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed