A global financial institution is migrating its on-premises data centers to a hybrid cloud architecture, leveraging Azure. They need to ensure secure and optimized connectivity between their distributed branch offices, remote users, on-premises data centers, and cloud-based applications. The Zero Trust strategy requires that all network traffic, regardless of its origin or destination, passes through a centralized security inspection point before reaching its target. This must be achieved without backhauling all internet traffic to the corporate data center.
- AImplement a traditional hub-and-spoke VPN architecture with all traffic routed through the central data center.
- BInstall a next-generation firewall (NGFW) at each branch office and cloud perimeter.
- CUtilize Azure ExpressRoute for high-bandwidth, private connectivity to Azure.
- DDeploy a Software-Defined Wide Area Network (SD-WAN) solution with integrated security services.
Show answer & explanationAnswer & explanation
Correct answer: D. Deploy a Software-Defined Wide Area Network (SD-WAN) solution with integrated security services.
An SD-WAN solution with integrated security services (often referred to as Secure Access Service Edge or SASE) allows for dynamic routing and centralized security policy enforcement at the edge, closer to the users and devices. It enables direct and secure access to cloud applications without backhauling all traffic, while ensuring all traffic passes through security inspection, aligning with Zero Trust principles for distributed environments.
Why the other options are wrong
- A. This approach would backhaul all traffic, leading to latency and inefficiency for cloud-bound traffic and failing the 'without backhauling all internet traffic' requirement.
- B. Deploying NGFWs at each location provides local security but lacks the centralized policy enforcement, unified management, and dynamic routing capabilities needed for a distributed Zero Trust network architecture.
- C. ExpressRoute provides private connectivity to Azure but does not address secure connectivity for branch offices or remote users to cloud applications or the centralized security inspection requirement for all traffic.
SD-WAN Integration (Zero Trust for Hybrid/Multi-Cloud)
Integrating Software-Defined Wide Area Network (SD-WAN) with security services to provide secure, optimized, and centrally managed connectivity for distributed environments.
- Optimizes traffic routing for cloud applications.
- Enables centralized security policy enforcement at the network edge.
- Reduces reliance on backhauling all traffic to a central data center.
- Often combined with SASE (Secure Access Service Edge) for comprehensive security.
Memory trick: SD-WAN: Securely Distribute, With Advanced Networking.