AZ-303 Exam QuestionsBrowse all questions from this exam

AZ-303 Exam - Question 33


HOTSPOT -

You have an Azure subscription that contains a resource group named RG1.

You have a group named Group1 that is assigned the Contributor role for RG1.

You need to enhance security for the virtual machines in RG1 to meet the following requirements:

✑ Prevent Group1 from assigning external IP addresses to the virtual machines.

✑ Ensure that Group1 can establish a Remote Desktop connection to the virtual machines through a shared external IP address.

What should you use to meet each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

Exam AZ-303 Question 33
Show Answer
Correct Answer:
Exam AZ-303 Question 33

Box 1: Azure Policy -

There is a built-in policy in the Azure Policy service that allows you to block public IPs on all NICs of a VM.

Note: Azure Policy is a powerful tool in your Azure toolbox. It allows you to enforce specific governance principals you want to see implemented in your environment. Some key examples of what Azure Policy allows you to do is:

Automatically tag resources -

Exam AZ-303 Question 33

✑ Block VMs from having a public IP

✑ Enforce specific regions

✑ Enforce VM size

Box 2: Azure Bastion -

Azure Bastion is a fully managed PaaS service that provides secure and seamless RDP and SSH access to your virtual machines directly through the Azure

Portal.

Azure Bastion is provisioned directly in your Virtual Network (VNet) and supports all VMs in your Virtual Network (VNet) using SSL without any exposure through public IP addresses.

Incorrect Answers:

Virtual Network (VNet) service endpoint provides secure and direct connectivity to Azure services over an optimized route over the Azure backbone network.

Endpoints allow you to secure your critical Azure service resources to only your virtual networks. Service Endpoints enables private IP addresses in the VNet to reach the endpoint of an Azure service without needing a public IP address on the VNet.

Reference:

https://blog.nillsf.com/index.php/2019/11/02/using-azure-policy-to-deny-public-ips-on-specific-vnets/ https://azure.microsoft.com/en-us/services/azure-bastion/

Discussion

11 comments
Sign in to comment
Chuck_Strut
Jun 4, 2021

the second box in my exam was load balancer not bastion

TSMRE
Jun 8, 2021

Load Balancers work too with NAT rules

17Master
Dec 24, 2021

But there is no such option

sanketh123
Jul 31, 2021

Does bastion provide an external IP address?

mpellizzon
Sep 19, 2021

No it does not. It provides private IP Address. WAF should be the correct one.

17Master
Dec 24, 2021

Check Azure Bastion values: https://docs.microsoft.com/en-us/azure/bastion/quickstart-host-portal

JayBee65
Jan 31, 2022

WAF is most definitely not the correct answer. I think it most have been April Fools Day when you answered!

17Master
Dec 24, 2021

Azure Bastion values: https://docs.microsoft.com/en-us/azure/bastion/quickstart-host-portal

17Master
Dec 24, 2021

Check Azure Bastion values: https://docs.microsoft.com/en-us/azure/bastion/quickstart-host-portal

JayBee65
Jan 31, 2022

WAF is most definitely not the correct answer. I think it most have been April Fools Day when you answered!

JayBee65
Jan 31, 2022

It uses an external address.

syu31svc
Aug 30, 2021

Answer is correct Policy to prevent assignment and Bastion for RDP

Rens19991
Jul 26, 2021

Load balancer or Azure WAF for Box 2

chris009
Oct 10, 2021

Wrong answer. should be Azure policy and WAF

JayBee65
Jan 31, 2022

WAF??? For RDP. That makes no sense, please explain.

poplovic
Oct 17, 2021

Bastion is the correct answer for (2). The shared external IP address is the public IP address of Bastion.

resq4u
Nov 20, 2021

The answer is correct. For second part, Bastion is the correct answer as although the VMs don't require public IPs but Bastion server does require a public IP to which clients can connect.

sreejit4u2003
May 31, 2021

Answer is Correct

goTEXANS
Jul 15, 2021

https://docs.microsoft.com/en-us/azure/bastion/vnet-peering Azure Bastion works with the following types of peering: Virtual network peering: Connect virtual networks within the same Azure region. Global virtual network peering: Connecting virtual networks across Azure regions.

quantumray
Dec 8, 2021

Question appeared On AZ-303 exam on 08/12/2021 - 49 questions, 4Q - Fabrikan case study

Suwani
Dec 21, 2021

Answer is correct