Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureEasy

A defense contractor is migrating a highly classified application to Azure. The application processes sensitive government data that requires strict isolation and assurance that no other customer's workloads can run on the same physical server. The solution must ensure that the underlying hardware is dedicated solely to their organization. Which Azure compute option should the architect recommend?

  1. AAzure App Service
  2. BAzure Dedicated Hosts
  3. CAzure Kubernetes Service (AKS)
  4. DAzure Virtual Machines (VMs)
Show answer & explanation

Correct answer: B. Azure Dedicated Hosts

Azure Dedicated Hosts provide physical servers dedicated to a single customer, ensuring complete isolation and meeting stringent compliance requirements for sensitive workloads by preventing other tenants from sharing hardware.

Why the other options are wrong

  • A. Azure App Service is a PaaS offering, abstracting the underlying infrastructure and typically running on shared resources.
  • C. AKS deploys containers on VMs, which by default are on shared infrastructure, not dedicated physical servers.
  • D. Azure VMs run on shared infrastructure, meaning other customers' VMs could be on the same physical host.

Azure Dedicated Hosts

A service that provides physical servers dedicated to a single Azure subscription, allowing customers to deploy Azure Virtual Machines onto isolated hardware.

  • Ensures physical isolation and dedicated hardware.
  • Provides control over maintenance events for VMs.
  • Helps meet strict compliance and regulatory requirements.

Memory trick: Dedicated Hosts are like your own private server room in Azure.

More Design security for infrastructure questions