Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureEasy

A company is designing an Azure landing zone for its new cloud environment. A critical security requirement is to establish a perimeter network (DMZ) that filters all inbound and outbound traffic to and from the virtual networks hosting application workloads. This DMZ should centralize network security services, including routing, firewalling, and intrusion detection/prevention. Which Azure networking pattern should the security architect recommend?

  1. AHub-and-Spoke topology with Azure Firewall.
  2. BPoint-to-Site VPN connections for all workloads.
  3. CMesh network topology with User Defined Routes (UDRs).
  4. DFlat network topology with Network Security Groups (NSGs).
Show answer & explanation

Correct answer: A. Hub-and-Spoke topology with Azure Firewall.

A Hub-and-Spoke topology is the recommended pattern for creating a secure DMZ in Azure. The 'hub' VNet hosts shared services like Azure Firewall, which centralizes network security, while 'spoke' VNets host workloads and peer with the hub to route all traffic through the centralized firewall.

Why the other options are wrong

  • B. Point-to-Site VPNs are for individual client connections to a VNet, not for establishing a centralized enterprise-wide DMZ for application workloads.
  • C. A mesh network topology is complex to manage and doesn't inherently centralize network security or easily establish a DMZ without significant additional configuration.
  • D. A flat network topology with only NSGs does not provide a centralized perimeter network or advanced firewalling capabilities for an enterprise-grade DMZ.

Hub-and-Spoke Network Topology

A networking model in Azure where a central 'hub' virtual network acts as a core point for connectivity and shared services (like firewalls), and 'spoke' virtual networks peer with the hub to host isolated workloads.

  • Centralizes network security services (e.g., Azure Firewall).
  • Provides isolation for workloads in spoke VNets.
  • Simplifies network management and policy enforcement.
  • Commonly used for enterprise cloud deployments and DMZ implementations.

Memory trick: Hub is the Center, Spoke is the Edge, for secure networks.

More Design security for infrastructure questions