A global financial institution is migrating its on-premises data centers to a hybrid cloud environment, leveraging Azure for new applications and maintaining some critical legacy systems on-premises. They aim to implement a Zero Trust network strategy that provides consistent security policies, optimized traffic routing, and direct, secure access to both cloud and on-premises resources for its globally distributed workforce, without backhauling traffic through a central data center. Which networking solution is best suited for this scenario?
- ATraditional VPN with hub-and-spoke topology
- BAzure ExpressRoute for all global traffic
- CSoftware-Defined Wide Area Network (SD-WAN) integrated with cloud security services
- DAzure Virtual WAN with point-to-site VPNs only
Show answer & explanationAnswer & explanation
Correct answer: C. Software-Defined Wide Area Network (SD-WAN) integrated with cloud security services
SD-WAN, especially when integrated with cloud security services (forming a SASE-like architecture), provides optimized routing, consistent policy enforcement, and direct secure access to hybrid resources for a distributed workforce, avoiding traffic backhauling and aligning perfectly with Zero Trust principles in a hybrid cloud.
Why the other options are wrong
- A. Traditional VPNs often backhaul traffic, leading to latency and are complex to manage with consistent Zero Trust policies across hybrid environments.
- B. Azure ExpressRoute provides private connectivity to Azure but doesn't inherently offer the global routing optimization, distributed security enforcement, or direct access for a globally distributed workforce to both cloud and on-premises resources without backhauling that SD-WAN does.
- D. Azure Virtual WAN is a Microsoft-managed networking service, but relying solely on point-to-site VPNs for a global workforce without SD-WAN's advanced routing and security integration capabilities would still likely lead to backhauling and less optimized performance compared to an SD-WAN solution.
SD-WAN Integration (Zero Trust for Hybrid/Multi-Cloud)
Integrating Software-Defined Wide Area Network (SD-WAN) with cloud security services (often forming a SASE architecture) provides a unified and optimized network and security framework for hybrid and multi-cloud environments, enforcing Zero Trust principles.
- Optimizes traffic routing for direct cloud access.
- Enforces consistent security policies across distributed locations and clouds.
- Reduces latency and eliminates backhauling of traffic through central data centers.
Memory trick: SD-WAN: 'Smartly Directs Work Across Networks'.