Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureHard
A financial institution is implementing a Zero Trust architecture. They have identified that privileged users (e.g., system administrators, security engineers) pose a significant risk due to their extensive access. To mitigate this, they want to enforce a secure, isolated environment for all privileged administrative tasks, preventing these tasks from being performed on standard user workstations. Which security control should be prioritized?
- AMulti-factor Authentication (MFA) for all privileged accounts
- BRegular security awareness training for privileged users
- CPrivileged Access Workstations (PAWs)
- DJust-In-Time (JIT) access for administrative roles
Show answer & explanationAnswer & explanation
Correct answer: C. Privileged Access Workstations (PAWs)
Privileged Access Workstations (PAWs) are dedicated, hardened devices used exclusively for sensitive administrative tasks. They provide a highly secure environment, isolated from general user activities, to prevent credential theft and malware infection that could compromise privileged accounts.
Why the other options are wrong
- A. MFA is crucial but doesn't isolate the administrative environment from potential compromises on a standard workstation.
- B. Training is important for user behavior but doesn't provide a technical control for workstation isolation.
- D. JIT access limits the duration of elevated privileges but doesn't address the security posture of the workstation itself.
Privileged Access Workstations (PAWs)
Dedicated, hardened client devices used exclusively for sensitive administrative tasks, providing a highly secure and isolated environment.
- Isolated from general user activities and internet browsing.
- Minimizes exposure to malware and phishing attacks.
- Enforces strong security configurations and monitoring.
- Essential for protecting privileged credentials and critical systems.
Memory trick: PAW-some protection for your admin's paws.