You plan to deploy an Azure Bastion Basic SKU host named Bastion1 into VNET1. To allow inbound access to virtual machines through Bastion1, which port must an inbound rule in NSG1 permit?
Choose an answer
Tap an option to check your answer.
Correct answer: 443.
Why this is the answer
Azure Bastion uses port 443 for inbound connectivity from the internet to the Bastion host. This is a secure, standard HTTPS port, making it suitable for web-based access. Once connected to the Bastion host via 443, Bastion then establishes a separate, secure connection to your target virtual machines using their native RDP (3389) or SSH (22) ports. Therefore, for the initial connection to Bastion, NSG1 must allow inbound traffic on port 443. Port 22 is for SSH to Linux VMs, 389 is for LDAP, and 8080 is a common alternative HTTP port, none of which are used for the initial inbound connection to Azure Bastion.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed