Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureMedium

A global manufacturing company is migrating its on-premises operational technology (OT) systems to Azure. These systems require highly reliable and low-latency connectivity to various branch offices worldwide, as well as secure segmentation from the corporate IT network. The company needs to manage network policies centrally and ensure consistent security posture across all connections. Which Azure networking service is best suited for this scenario?

  1. AAzure Load Balancer with network security groups
  2. BAzure VPN Gateway with point-to-site connections
  3. CAzure Virtual WAN with secure hub and route management
  4. DAzure ExpressRoute with direct peering
Show answer & explanation

Correct answer: C. Azure Virtual WAN with secure hub and route management

Azure Virtual WAN provides a unified global network architecture that simplifies branch connectivity, offers secure hubs for centralized policy enforcement, and supports both site-to-site VPN and ExpressRoute for high reliability and low latency, making it ideal for a global OT network.

Why the other options are wrong

  • A. Azure Load Balancer distributes traffic and NSGs provide basic network filtering, neither addresses global connectivity, centralized management, or secure segmentation at scale.
  • B. VPN Gateway point-to-site is for individual client connections, not global branch office connectivity.
  • D. ExpressRoute provides private connectivity but lacks the centralized hub and spoke management and security services of Virtual WAN for a global network.

Azure Virtual WAN

Azure Virtual WAN is a networking service that provides optimized, automated, and global branch-to-branch connectivity through Azure. It combines many networking, security, and routing functionalities into a single operational interface.

  • Unified global network architecture.
  • Centralized connectivity for branches, data centers, and remote users.
  • Supports VPN, ExpressRoute, and SD-WAN connectivity.
  • Integrated security services via Secure Hub (Azure Firewall, NVA).

Memory trick: WAN Unifies, Hub Secures, Branches Connect Smoothly.

More Design security for infrastructure questions