Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudHard
A security engineer is investigating a high-severity alert in Microsoft Defender for Cloud indicating 'Suspicious RDP activity from an unusual location' on an Azure VM. The VM is critical for a production application. After initial investigation, the engineer suspects the RDP port (3389) might be exposed to the internet. Which immediate action should the engineer take within Defender for Cloud to mitigate the potential threat while minimizing disruption to legitimate users who occasionally need RDP access?
- ADisable the RDP port 3389 in the Network Security Group (NSG) for the VM.
- BDelete the virtual machine immediately to prevent further compromise.
- CImplement Just-in-Time (JIT) VM access for the RDP port 3389.
- DBlock the source IP address identified in the alert using an Azure Firewall rule.
Show answer & explanationAnswer & explanation
Correct answer: C. Implement Just-in-Time (JIT) VM access for the RDP port 3389.
Implementing JIT VM access allows RDP port 3389 to be closed by default and only opened for a limited time when explicitly requested by authorized users, significantly reducing the attack surface while still allowing legitimate access. This directly addresses the 'unusual location' and minimizes disruption.
Why the other options are wrong
- A. Disabling RDP entirely would disrupt legitimate users, which goes against the 'minimizing disruption' requirement.
- B. Deleting a production VM is an extreme measure that would cause significant disruption and data loss, not a primary mitigation for suspicious RDP activity.
- D. Blocking a single source IP is a reactive measure and doesn't address the underlying vulnerability of an open RDP port to the internet from other potential attackers. The 'unusual location' implies the port is broadly accessible.
Just-in-Time (JIT) VM Access
A feature in Microsoft Defender for Cloud that hardens network access to virtual machines by locking down inbound traffic to management ports, only opening them on demand for a limited time and from approved source IPs.
- Reduces attack surface by restricting port exposure.
- Allows legitimate access only when needed.
- Integrates with Azure Active Directory for authorization.
- Automatically closes ports after a defined time.
Memory trick: To close the RDP door, but still allow a knock, JIT access is your clock.