Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureMedium

A global conglomerate is designing a Zero Trust architecture for its diverse business units, each operating with significant autonomy and managing their own cloud subscriptions and on-premises infrastructure. The security team needs to implement a solution that centralizes security policy enforcement and visibility across these disparate environments without requiring a complete overhaul of existing identity providers or network configurations within each business unit. The solution must support conditional access based on user, device, application, and location attributes, and enforce policies consistently across SaaS applications, IaaS workloads, and on-premises resources.

  1. ADeploy Azure AD Conditional Access policies exclusively within each business unit's Azure tenant.
  2. BMandate the migration of all business unit applications to a single, centralized Azure subscription.
  3. CImplement a Cloud Access Security Broker (CASB) solution integrated with existing identity providers.
  4. DInstall a host-based firewall and Endpoint Detection and Response (EDR) solution on all endpoints.
Show answer & explanation

Correct answer: C. Implement a Cloud Access Security Broker (CASB) solution integrated with existing identity providers.

A Cloud Access Security Broker (CASB) provides the necessary visibility and control over cloud applications and resources, allowing for centralized policy enforcement across diverse environments and integrating with existing identity solutions without requiring a complete infrastructure overhaul. It can enforce conditional access based on various attributes.

Why the other options are wrong

  • A. This approach would not centralize policy enforcement or visibility across disparate environments and on-premises resources effectively.
  • B. This is a radical and often impractical solution that does not address the immediate need for centralized policy enforcement across existing diverse environments.
  • D. While important for endpoint security, host-based firewalls and EDRs do not provide centralized policy enforcement or visibility across diverse cloud and on-premises applications.

Cloud Access Security Broker (CASB)

A software tool or service that acts as an intermediary between users and cloud service providers, ensuring security policies are enforced.

  • Provides visibility into cloud application usage.
  • Enforces data security policies (e.g., DLP, encryption).
  • Protects against threats and ensures compliance.
  • Can integrate with various identity providers and environments.

Memory trick: CASB: Centralizing Access Security for Broad Reach.

More Design a Zero Trust strategy and architecture questions