You must restrict RDP access to an Azure VM to on‑demand requests for up to 3 hours and only from the requester’s public IP. You also need an auditable record of all access requests retained in Log Analytics. What should you do? (Choose two)
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Just‑in‑time VM access for the VM in Microsoft Defender for Cloud, allowing TCP 3389 for a maximum of 3 hours and source set to Requestor’s IP., Stream the subscription Activity Log to a Log Analytics workspace to retain JIT access request events..
Why this is the answer
Just-in-time (JIT) VM access in Microsoft Defender for Cloud is the correct solution for restricting RDP access to on-demand requests for a limited time and from a specific IP. It dynamically opens the RDP port (TCP 3389) only when requested, for a specified duration (up to 3 hours), and from the requester's public IP, then automatically closes it, fulfilling all access requirements. To retain an auditable record of these JIT access requests, streaming the subscription's Activity Log to a Log Analytics workspace is necessary. JIT access events are recorded in the Activity Log, and sending them to Log Analytics ensures their long-term storage and queryability. Adding a permanent NSG rule is incorrect because it does not provide on-demand access or time-based restrictions. Azure Bastion provides secure RDP access but doesn't inherently limit access duration or source IP dynamically in the way JIT does, nor does it automatically close ports. Azure AD Privileged Identity Management (PIM) manages role assignments, not direct network access to VMs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed