QuestionQ81
Design security operations, identity, and compliance capabilitiesYour company has an on-premises network in Seattle and an Azure subscription. The on-premises network includes a Remote Desktop server.
The company contracts a third-party development firm in France to develop and deploy resources to the virtual machines hosted in the Azure subscription.
Currently, the firm connects by RDP to the Remote Desktop server. From that Remote Desktop connection, the firm accesses the virtual machines hosted in Azure by using custom administrative tools installed on the Remote Desktop server. All traffic to the Remote Desktop server is captured by a firewall, which allows only specific connections from France to the server.
You need to recommend a modern security solution based on the Zero Trust model. The solution must minimize latency for developers.
Which three actions should you recommend? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
- A Configure network security groups (NSGs) to allow access from only specific logical groupings of IP address ranges.
- B Deploy a Remote Desktop server to an Azure region located in France.
- C Migrate from the Remote Desktop server to Azure Virtual Desktop.
- D Implement Azure Firewall to restrict host pool outbound access.
- E Configure Azure Active Directory (Azure AD) Conditional Access with multi-factor authentication (MFA) and named locations.
Community Discussion