Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureHard

A multinational corporation is designing a Zero Trust architecture for its global operations. The company has identified that its employees frequently access corporate resources from unmanaged personal devices and public Wi-Fi networks. They need to ensure that regardless of the device ownership or network location, access to corporate applications is always secured, monitored, and compliant with corporate policies, without requiring full device enrollment. Which Zero Trust capability is BEST suited for this scenario?

  1. ACloud Access Security Broker (CASB)
  2. BEndpoint Detection and Response (EDR)
  3. CSecurity Information and Event Management (SIEM)
  4. DPrivileged Access Management (PAM)
Show answer & explanation

Correct answer: A. Cloud Access Security Broker (CASB)

A Cloud Access Security Broker (CASB) provides visibility and control over cloud applications. It can enforce access policies, detect shadow IT, and apply granular controls (e.g., block downloads, restrict copy/paste) even when users access cloud apps from unmanaged devices or untrusted networks, making it ideal for securing access to corporate applications in a Zero Trust model without full device enrollment.

Why the other options are wrong

  • B. EDR focuses on detecting and responding to threats on managed endpoints. It's not designed for securing access from unmanaged devices without enrollment.
  • C. SIEM aggregates and analyzes security logs for threat detection and compliance. It's a logging and monitoring tool, not an access enforcement point for unmanaged devices.
  • D. PAM manages and secures privileged accounts. While important for Zero Trust, it doesn't directly address securing access to corporate applications from unmanaged devices.

Cloud Access Security Broker (CASB)

A security policy enforcement point placed between cloud service consumers and cloud service providers to combine and interject enterprise security policies as cloud resources are accessed.

  • Provides visibility into cloud app usage.
  • Enforces data protection and access policies.
  • Can apply granular controls (e.g., block downloads) for unmanaged devices.

Memory trick: CASB: Control All Cloud Access, Secure the Boundary.

More Design a Zero Trust strategy and architecture questions