Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureMedium
A client is designing an Azure landing zone for a new environment that will host critical applications. A key security requirement is to enforce a consistent network security posture across all subscriptions and to prevent any unauthorized network configurations, such as public IP addresses on VMs or unapproved VNet peering. This enforcement must be automated and applied to new and existing resources. Which Azure service combination is most effective for this requirement?
- AAzure Security Center (Defender for Cloud) and Just-in-Time VM access
- BNetwork Security Groups (NSGs) and Azure DDoS Protection
- CAzure Firewall and Azure Monitor
- DAzure Policy and Management Groups
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Policy and Management Groups
Azure Policy, when applied at the Management Group level, provides the ability to define, assign, and manage standards for resources, enforcing consistent network security configurations across multiple subscriptions and preventing non-compliant deployments.
Why the other options are wrong
- A. Security Center assesses posture and Just-in-Time access secures VM ports, but neither centrally prevents unauthorized network configurations at scale.
- B. NSGs filter traffic, and DDoS Protection mitigates attacks, but neither enforces configuration standards across subscriptions.
- C. Azure Firewall provides centralized network security, and Azure Monitor collects logs, but neither enforces resource configuration compliance.
Azure Policy for Governance
Azure Policy helps to enforce organizational standards and to assess compliance at scale. It provides a centralized way to define rules and apply them to resources, ensuring consistent configurations across environments.
- Enforces organizational standards and assesses compliance.
- Prevents non-compliant resource creation or modification.
- Can be applied at Management Group, subscription, or resource group scope.
- Includes audit, deny, deploy if not exists, and modify effects.
Memory trick: Policy Governs, Management Groups Scope, Compliance Ensured.