Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureMedium
A global financial services company is migrating its on-premises data centers to a hybrid cloud environment, leveraging Azure and AWS. The company handles highly sensitive customer data and must adhere to strict regulatory compliance standards. The security architect needs to design a network segmentation strategy that enforces micro-segmentation across both on-premises and cloud environments, preventing lateral movement of threats. Which Zero Trust architectural concept is MOST relevant for achieving this level of granular network control?
- ADevice health attestation
- BMicro-segmentation
- CDynamic access policies
- DIdentity as the primary security perimeter
Show answer & explanationAnswer & explanation
Correct answer: B. Micro-segmentation
The scenario explicitly mentions the need for 'micro-segmentation across both on-premises and cloud environments' to prevent lateral movement. Micro-segmentation is a core Zero Trust network strategy that achieves this granular control.
Why the other options are wrong
- A. Device health attestation is part of verifying explicitly, ensuring devices meet security standards, but it's not the network segmentation strategy itself.
- C. Dynamic access policies relate to how access is granted based on conditions, not specifically the network segmentation itself.
- D. Identity as the primary security perimeter is a foundational Zero Trust concept but doesn't directly address granular network control or lateral movement prevention through network segmentation.
Micro-segmentation (Zero Trust)
A security technique that divides data centers and cloud environments into small, isolated network segments down to the workload level, enabling granular security policies to be applied to each segment.
- Limits lateral movement of threats.
- Enforces granular security policies.
- Reduces the attack surface by isolating workloads.
Memory trick: Networks need Micro-segmentation and Policy-based access, not just a perimeter.