Free Microsoft Cybersecurity SC-100 Actual Exam Questions - Question 5 Discussion

Question No. 5
You have an Azure subscription that has Microsoft Defender for Cloud enabled.
You are evaluating the Azure Security Benchmark V3 report.
In the Secure management ports controls, you discover that you have 0 out of a potential 8 points.
You need to recommend configurations to increase the score of the Secure management ports
controls.
Solution: You recommend enabling just-in-time (JIT) VM access on all virtual machines.
Does this meet the goal?
Select one option, then reveal solution.
US
WU
Will U.
2026-02-15

It’s A. Enabling just-in-time VM access directly targets the risk of having management ports open and accessible all the time, which is exactly what the Secure management ports control is about. Other controls like NSGs or MFA are good too, but JIT alone already scores points in this area because it reduces the attack surface by only opening ports when needed. So this solution fits the requirement perfectly.

0
WU
Will U.
2026-02-14

A. JIT VM access limits open management ports to when needed, which directly improves security for these ports according to the benchmark. It’s the main recommendation here.

0
WU
Will U.
2026-02-11

A/B? JIT definitely restricts access, but the benchmark might also expect things like NSG rules or MFA for management ports. So maybe JIT alone isn’t enough?

0
ZG
Zain G.
2026-02-10

Makes sense to me. JIT VM access restricts management ports from being open all the time, so it definitely helps improve the Secure management ports score. So yeah, A sounds right here.

0
ZG
Zain G.
2026-01-15

A

0