Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureHard

A defense contractor is migrating a highly classified application to Azure. The application requires dedicated, isolated compute resources that ensure complete separation from other tenants and provide hardware-level assurance of resource allocation. Standard virtual machines are deemed insufficient due to multi-tenancy concerns. Which Azure compute option provides the highest level of physical isolation and dedicated hardware resources?

  1. AAzure Kubernetes Service (AKS) with dedicated node pools
  2. BAzure Dedicated Hosts
  3. CAzure VMware Solution
  4. DAzure Isolated Virtual Machines
Show answer & explanation

Correct answer: B. Azure Dedicated Hosts

Azure Dedicated Hosts provide single-tenant physical servers that are dedicated to a single customer. This offers the highest level of physical isolation and hardware-level assurance, ensuring complete separation from other tenants, which is crucial for highly classified workloads.

Why the other options are wrong

  • A. AKS with dedicated node pools still runs on shared underlying infrastructure, not dedicated physical servers.
  • C. Azure VMware Solution provides a VMware-native environment but the underlying hardware infrastructure is still managed and potentially shared at a higher level than Dedicated Hosts.
  • D. Azure Isolated Virtual Machines run on specific hardware types but are still in a multi-tenant environment, though logically isolated.

Azure Dedicated Hosts

A service that provides physical servers dedicated to a single Azure customer, offering hardware isolation for highly sensitive workloads.

  • Single-tenant physical servers for maximum isolation.
  • Allows control over server maintenance events and patching.
  • Ideal for compliance, licensing, and high-security requirements.

Memory trick: Dedicated Hosts are your own PRIVATE island in the cloud.

More Design security for infrastructure questions