Created by Rick Schoenman
over 2 years ago
|
||
Question | Answer |
What is Just-In-Time (JIT) administration? | The denial of inbound traffic to a VM for certain ports, up until an administrative task has to be done. The port will then be open for a specified amount of time. |
Where can JIT administration be configured? | In the Azure Security Center. You can define the network ports that are to be secured for inbound communication. |
How does Security Center implement the inbound communication restriction? | Set a deny all inbound traffic rule for the selected ports, by using Network Security Groups and Azure Firewall. |
How does Security Center classify a VM as healthy? | - By checking if JIT is enabled - Check if there is a NSG or Firewall rule that doesn't allow traffic from ports 22, 3389, 5985 and 5986 |
What does Security Center do automatically considering JIT? | Recommend that a VM can benefit from JIT |
What happens when you connect to a VM that is JIT enabled? | Azure instructs you to request access |
Want to create your own Flashcards for free with GoConqr? Learn more.