Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureHard

A global manufacturing company is designing a Zero Trust architecture for its operational technology (OT) environment, which includes critical industrial control systems (ICS). The company wants to minimize the attack surface and prevent unauthorized access to these sensitive systems from the corporate IT network, while still allowing necessary data exchange for monitoring and reporting. Direct inbound connections from IT to OT are strictly forbidden. The solution must provide a secure, one-way data flow mechanism.

  1. AImplement a Software-Defined Wide Area Network (SD-WAN) solution between IT and OT networks.
  2. BUtilize a robust firewall with deep packet inspection (DPI) at the IT/OT boundary.
  3. CDeploy a data diode between the IT and OT networks.
  4. DIsolate the OT network completely with no physical or logical connections to the IT network.
Show answer & explanation

Correct answer: C. Deploy a data diode between the IT and OT networks.

A data diode (or unidirectional gateway) is specifically designed to enforce a physical, one-way data flow, making it impossible for data to flow from the IT network into the OT network. This completely prevents inbound attacks while allowing outbound data for monitoring, aligning perfectly with the strict Zero Trust requirement for critical OT environments where direct inbound connections are forbidden.

Why the other options are wrong

  • A. SD-WAN improves network performance and management but does not inherently enforce one-way data flow or prevent inbound attacks.
  • B. While a robust firewall with DPI is essential, it operates at a logical level and can still be misconfigured or bypassed by sophisticated attacks; it does not physically guarantee one-way flow.
  • D. Complete isolation would prevent necessary monitoring and reporting data exchange, failing the requirement for 'allowing necessary data exchange for monitoring and reporting'.

Data Diode (Unidirectional Gateway)

A cybersecurity device that enforces one-way data transfer, allowing data to flow in only one direction for absolute network separation.

  • Physically prevents data from flowing in the reverse direction.
  • Used for high-security environments like OT/ICS or classified networks.
  • Ensures data integrity and prevents inbound cyberattacks.
  • Allows for secure data export (e.g., logs, sensor data) from sensitive networks.

Memory trick: Diode: Data In, Out, Don't reverse, Ever.

More Design a Zero Trust strategy and architecture questions