You need to provide administrators SSH access to Arc-enabled Linux servers located on a private network with no public IPs or inbound firewall holes. Access must use Azure AD authentication with short-lived credentials. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Deploy the Azure Arc SSH extension to the Linux servers, ensure OpenSSH is running, grant users the Azure Connected Machine SSH role, and have them connect using az ssh arc..
Why this is the answer
The correct solution leverages Azure Arc's SSH capabilities. The Azure Arc SSH extension enables secure SSH access to Arc-enabled Linux servers over a private network without requiring public IPs or inbound firewall rules. It integrates with Azure AD for authentication, and the az ssh arc command facilitates the connection using short-lived credentials, enhancing security. The "Azure Connected Machine SSH Login" role grants necessary permissions. Configuring a site-to-site VPN and exposing port 22 is less secure as it requires inbound firewall rules and doesn't inherently use Azure AD for authentication or short-lived credentials. Just-In-Time (JIT) VM access in Microsoft Defender for Cloud is for Azure VMs, not directly for on-premises Arc-enabled servers in this manner. Azure Bastion is for Azure VMs and cannot be directly attached to an on-premises network to provide SSH access to Arc-enabled servers without additional complex networking and proxying.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed