Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureEasy

A defense contractor is designing a Zero Trust architecture for its highly sensitive research and development environment. Developers work with classified information and require workstations with extremely high security assurances, isolated from general corporate networks and internet browsing. These workstations must prevent data exfiltration, resist malware, and enforce strict application whitelisting. Which type of workstation is BEST suited for this environment?

  1. AStandard Corporate Workstation (SCW)
  2. BBring Your Own Device (BYOD)
  3. CPrivileged Access Workstation (PAW)
  4. DVirtual Desktop Infrastructure (VDI)
Show answer & explanation

Correct answer: C. Privileged Access Workstation (PAW)

Privileged Access Workstations (PAWs) are highly secured, hardened operating systems specifically designed for sensitive tasks and privileged accounts. They enforce strict controls such as application whitelisting, isolation from general networks, and prevention of data exfiltration, making them ideal for handling classified information in a Zero Trust R&D environment.

Why the other options are wrong

  • A. A Standard Corporate Workstation (SCW) has general-purpose access and security, insufficient for classified information and strict isolation requirements.
  • B. Bring Your Own Device (BYOD) introduces significant security risks due to lack of corporate control and is entirely unsuitable for classified environments.
  • D. While VDI can offer some isolation, it typically shares underlying infrastructure and may not provide the same level of dedicated hardening, application whitelisting, and physical/logical isolation from general networks as a purpose-built PAW for extremely sensitive data.

Privileged Access Workstation (PAW)

A dedicated, hardened operating system designed for sensitive tasks and privileged accounts, providing a high level of security against compromise.

  • Isolated from general corporate networks.
  • Enforces strict application whitelisting.
  • Prevents data exfiltration and resists malware.

Memory trick: PAW: Protect All Workstations with high privilege.

More Design a Zero Trust strategy and architecture questions