Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureHard

A company is implementing a zero-trust architecture for its hybrid cloud environment. A critical requirement is to ensure every network access request, regardless of origin, is authenticated, authorized, and encrypted. The company heavily relies on Azure Virtual Networks (VNets) and has on-premises data centers connected via ExpressRoute. Which Azure service combination provides the most robust solution for enforcing these principles across both cloud and on-premises resources?

  1. AAzure Active Directory (Azure AD) Identity Protection and Azure VPN Gateway.
  2. BAzure Firewall Premium with IDPS and Azure Private Link.
  3. CAzure Active Directory B2B Collaboration and Azure DDoS Protection.
  4. DAzure Active Directory (Azure AD) with Conditional Access and Azure Network Security Groups (NSGs).
Show answer & explanation

Correct answer: B. Azure Firewall Premium with IDPS and Azure Private Link.

Azure Firewall Premium with IDPS provides deep packet inspection and L7 filtering for all network traffic, enforcing granular security policies. Azure Private Link ensures that traffic to Azure PaaS services traverses the Microsoft backbone privately, never exposed to the public internet, fulfilling the 'encrypted' and 'authorized' aspects of zero trust for PaaS access.

Why the other options are wrong

  • A. Azure AD Identity Protection focuses on user risk detection. Azure VPN Gateway is for connecting networks, not for enforcing granular, deep-packet-inspected zero-trust policies across all traffic.
  • C. Azure AD B2B is for external user collaboration. Azure DDoS Protection protects against DDoS attacks. Neither directly addresses the core requirements of authenticating, authorizing, and encrypting every network access request for a zero-trust network architecture across hybrid resources.
  • D. Azure AD and Conditional Access primarily handle identity and access management for users/devices, but NSGs are basic L3/L4 firewalls and don't provide deep packet inspection or enforce zero-trust network principles effectively across all traffic.

Zero Trust Network Enforcement

A security model where no user, device, or application is implicitly trusted, regardless of their location. Every access request is authenticated, authorized, and constantly validated, with encryption applied to traffic.

  • Verify explicitly, always authenticate and authorize.
  • Assume breach, minimize blast radius.
  • Least privilege access.
  • Encrypt all traffic, inspect all traffic.

Memory trick: Never Trust, Always Verify, Firewall and Private Link make it fly.

More Design security for infrastructure questions