Q: 2
You have an Azure subscription that contains multiple network security groups (NSGs), multiple
virtual machines, and an Azure Bastion host named bastion1.
Several NSGs contain rules that allow direct RDP access to the virtual machines by bypassing bastion!
You need to ensure that the virtual machines can be accessed only by using bastion! The solution
must prevent the use of NSG rules to bypass bastion1.
What should you include in the solution?
Options
Discussion
I don’t think it’s B. D makes more sense if the Firewall network rules block all RDP, but the trap is that NSG rules can still be too permissive.
Its D, I think firewall network rules could block direct RDP but trap is that NSG might get around it.
Pretty sure D makes sense, since Azure Firewall network rules could block direct RDP traffic. That should stop users from bypassing bastion1, right? Correct me if I'm missing something here.
B imo. Security admin rules with Azure Virtual Network Manager can override NSG rules, so only bastion1 is used for RDP access.
Be respectful. No spam.