You enabled RDP Shortpath for managed networks, but connections still use TCP fallback. Azure Firewall sits between corporate clients and the session host subnet, and NSGs are applied to the subnet. What changes are required to allow Shortpath traffic? (Select two answers.)
Choose an answer
Tap an option to check your answer.
Correct answer: In Azure Firewall, add a network rule collection to allow UDP 3390 from corporate IP ranges to the session host subnet., In the session host subnet NSG, add an inbound rule to allow UDP 3390 from corporate IP ranges..
Why this is the answer
RDP Shortpath for managed networks uses UDP port 3390 for direct connectivity between the client and the session host. To enable this, both Azure Firewall and the Network Security Group (NSG) on the session host subnet must explicitly allow this traffic. Azure Firewall requires a network rule collection to permit UDP 3390 from the corporate network to the session host subnet. Similarly, the session host subnet's NSG needs an inbound rule allowing UDP 3390 from the corporate IP ranges. Without these rules, connections will fall back to TCP. DNAT rules are for external access, not internal managed network traffic. Application rules for HTTPS are for control plane communication, not Shortpath data. Disabling threat intelligence is unrelated to port access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed