QuestionQ14

Secure storage, databases, and networking

You use Azure Virtual Network Manager to manage multiple virtual networks in a network group called Group1.

You find that the virtual machines in Group1 can be reached from the internet over TCP port 3389.

You need to block inbound TCP port 3389 traffic from the internet across every virtual network in Group1. The solution must minimize administrative effort.

What should you use?

Explanation

A security admin configuration in Azure Virtual Network Manager centrally applies security admin rules to all virtual networks in a target network group. A rule configured to deny inbound TCP port 3389 from the Internet blocks RDP exposure across Group1 with a single scalable policy.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!