Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureHard
A government agency is designing a Zero Trust architecture for its highly sensitive data and applications, some of which reside in an on-premises private cloud and others in Azure Government. The agency has a strict requirement that all data in transit between these environments, and within each environment, must be protected by cryptographic means, even if the network path is considered 'internal'. This is to comply with the 'assume breach' principle and minimize the impact of a compromised network segment. Which Zero Trust security capability is MOST crucial to meet this requirement?
- AConditional Access policies
- BPrivileged Access Workstations (PAWs)
- CMicro-segmentation
- DEnd-to-end encryption
Show answer & explanationAnswer & explanation
Correct answer: D. End-to-end encryption
The scenario explicitly states that 'all data in transit... must be protected by cryptographic means, even if the network path is considered 'internal''. This directly points to 'End-to-end encryption', a fundamental Zero Trust control that ensures data confidentiality regardless of network location or perceived trust.
Why the other options are wrong
- A. Conditional Access policies enforce access decisions but don't inherently encrypt data in transit.
- B. Privileged Access Workstations (PAWs) are hardened endpoints for administrative tasks, protecting the source of privileged access, not the data in transit across the network.
- C. Micro-segmentation limits lateral movement and applies granular network policies, but it doesn't automatically encrypt all traffic within or between segments.
End-to-End Encryption (Zero Trust)
A Zero Trust security capability that ensures all data in transit, regardless of its network location or internal/external status, is cryptographically protected from the source to the destination.
- Protects data even if the network is compromised.
- Supports the 'assume breach' principle.
- Applies to communication within and between network segments.
Memory trick: Encrypt All Data, Everywhere, Always.