ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 117 - AZ-720 discussion

Report
Export

HOTSPOT

A company deploys just-in-time (JIT) virtual machine (VM) access.

A user reports that they are unable to request access to a JIT VM.

You need to determine the permission operations that are required for the user to request JIT access.

The solution should use the principle of least privilege.

Which permission operations are required? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 117
Correct answer: Question 117

Explanation:

Permission: JIT Network Access Policies permission

Operation: Microsoft.Security/locations/jitNetworkAccessPolicies/initiate/action

Explanation: To request JIT access to a VM, the user needs the

Microsoft.Security/locations/jitNetworkAccessPolicies/initiate/action permission. This permission allows the user to initiate a JIT request on a specific VM1. The other permissions are not sufficient for

requesting JIT access.

Permission: Virtual machine permission Operation: Microsoft.Compute/virtualMachines/read Explanation: To request JIT access to a VM, the user also needs the

Microsoft.Compute/virtualMachines/read permission. This permission allows the user to view the details of the VM, such as its name, location, and status2. The other permissions are not necessary

for requesting JIT access.

1: Enable just-in-time access on VMs - Microsoft Defender for Cloud 2: Built-in roles for Azure

resources - Azure RBAC

asked 02/10/2024
Riaan Cilliers
32 questions
User
0 comments
Sorted by

Leave a comment first