Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureHard
A defense contractor is designing a Zero Trust architecture for its highly secure development environment. They are implementing a policy where access to critical build servers and source code repositories is only granted from specialized, hardened workstations that are strictly controlled and continuously monitored for security posture. These workstations are isolated from the general corporate network. This approach directly supports the Zero Trust principle of 'assume breach' by limiting the potential impact of a compromised user account or general-purpose endpoint. What is the industry term for such specialized workstations?
- ABring Your Own Device (BYOD)
- BPrivileged Access Workstations (PAWs)
- CVirtual Desktop Infrastructure (VDI)
- DThin Clients
Show answer & explanationAnswer & explanation
Correct answer: B. Privileged Access Workstations (PAWs)
The scenario describes 'specialized, hardened workstations... isolated from the general corporate network' used for accessing 'critical build servers and source code repositories' with high-privilege accounts. This perfectly defines a Privileged Access Workstation (PAW), a key control in Zero Trust and 'assume breach' strategies for protecting administrative access.
Why the other options are wrong
- A. BYOD is about allowing personal devices, which is the opposite of a strictly controlled, hardened workstation.
- C. VDI provides virtual desktops but doesn't inherently imply hardening or isolation for privileged access.
- D. Thin Clients are low-power computers that rely heavily on a central server, not necessarily hardened for privileged access.
Privileged Access Workstations (PAWs)
Dedicated, hardened, and isolated computing devices used exclusively for sensitive administrative tasks and accessing critical systems, significantly reducing the risk of credential theft and lateral movement.
- Isolated from general user networks and internet browsing.
- Strictly controlled and monitored.
- Crucial for protecting privileged accounts and 'assume breach' strategies.
Memory trick: PAWs Protect Privileged Access, Always.