Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureMedium
A large pharmaceutical company is implementing a Zero Trust strategy to protect its intellectual property, which includes highly sensitive research data. The company uses a hybrid cloud model with on-premises data centers and Azure. They need to ensure that data classification and labeling are consistently applied and enforced across all environments, regardless of where the data resides or how it is accessed. Furthermore, access to this sensitive data must be dynamically restricted based on its classification, the user's role, and the device's compliance status.
- ADeploy a dedicated Data Loss Prevention (DLP) solution for each cloud and on-premises environment.
- BRequire all users to access sensitive data only from Privileged Access Workstations (PAWs).
- CUtilize Azure Information Protection (AIP) integrated with Microsoft Purview for data classification and protection.
- DImplement network-level access control lists (ACLs) on all file shares and Azure storage accounts.
Show answer & explanationAnswer & explanation
Correct answer: C. Utilize Azure Information Protection (AIP) integrated with Microsoft Purview for data classification and protection.
Azure Information Protection (AIP), now largely integrated with Microsoft Purview Information Protection, provides a unified solution for classifying, labeling, and protecting sensitive data across on-premises, cloud, and endpoints. It allows for dynamic access restrictions based on data classification and user attributes, which aligns perfectly with the Zero Trust principles for data protection.
Why the other options are wrong
- A. Deploying separate DLP solutions for each environment would lead to inconsistent policies and management overhead, failing the 'consistently applied and enforced' requirement.
- B. While PAWs are good for privileged users, requiring them for all access to sensitive data is impractical and does not directly address data classification or dynamic access based on data sensitivity.
- D. ACLs are static and difficult to manage consistently across hybrid environments, and do not provide dynamic classification-based access.
Azure Information Protection (AIP) / Microsoft Purview Information Protection
A cloud-based solution that helps organizations discover, classify, and protect sensitive documents and emails by applying labels.
- Provides persistent data protection regardless of location.
- Enables manual, recommended, or automatic classification and labeling.
- Supports encryption, visual markings, and usage rights restrictions.
- Integrates with Microsoft 365 services and on-premises solutions.
Memory trick: AIP/Purview: Always Insist on Protecting via Labels.