Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureMedium

A global financial services company is migrating its on-premises data centers to a hybrid cloud environment, leveraging Azure and AWS. The company handles highly sensitive customer data and must adhere to strict regulatory compliance standards. The security architect needs to design a network segmentation strategy that enforces micro-segmentation across both on-premises and cloud environments, preventing lateral movement of threats. Which Zero Trust architectural concept is MOST relevant for achieving this level of granular network control?

  1. ADevice health attestation
  2. BMicro-segmentation
  3. CDynamic access policies
  4. DIdentity as the primary security perimeter
Show answer & explanation

Correct answer: B. Micro-segmentation

The scenario explicitly mentions the need for 'micro-segmentation across both on-premises and cloud environments' to prevent lateral movement. Micro-segmentation is a core Zero Trust network strategy that achieves this granular control.

Why the other options are wrong

  • A. Device health attestation is part of verifying explicitly, ensuring devices meet security standards, but it's not the network segmentation strategy itself.
  • C. Dynamic access policies relate to how access is granted based on conditions, not specifically the network segmentation itself.
  • D. Identity as the primary security perimeter is a foundational Zero Trust concept but doesn't directly address granular network control or lateral movement prevention through network segmentation.

Micro-segmentation (Zero Trust)

A security technique that divides data centers and cloud environments into small, isolated network segments down to the workload level, enabling granular security policies to be applied to each segment.

  • Limits lateral movement of threats.
  • Enforces granular security policies.
  • Reduces the attack surface by isolating workloads.

Memory trick: Networks need Micro-segmentation and Policy-based access, not just a perimeter.

More Design a Zero Trust strategy and architecture questions