Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureHard

A global financial institution is migrating its on-premises data centers to a hybrid cloud environment, leveraging Azure for new applications and maintaining some critical legacy systems on-premises. They aim to implement a Zero Trust network strategy that provides consistent security policies, optimized traffic routing, and direct, secure access to both cloud and on-premises resources for its globally distributed workforce, without backhauling traffic through a central data center. Which networking solution is best suited for this scenario?

  1. ATraditional VPN with hub-and-spoke topology
  2. BAzure ExpressRoute for all global traffic
  3. CSoftware-Defined Wide Area Network (SD-WAN) integrated with cloud security services
  4. DAzure Virtual WAN with point-to-site VPNs only
Show answer & explanation

Correct answer: C. Software-Defined Wide Area Network (SD-WAN) integrated with cloud security services

SD-WAN, especially when integrated with cloud security services (forming a SASE-like architecture), provides optimized routing, consistent policy enforcement, and direct secure access to hybrid resources for a distributed workforce, avoiding traffic backhauling and aligning perfectly with Zero Trust principles in a hybrid cloud.

Why the other options are wrong

  • A. Traditional VPNs often backhaul traffic, leading to latency and are complex to manage with consistent Zero Trust policies across hybrid environments.
  • B. Azure ExpressRoute provides private connectivity to Azure but doesn't inherently offer the global routing optimization, distributed security enforcement, or direct access for a globally distributed workforce to both cloud and on-premises resources without backhauling that SD-WAN does.
  • D. Azure Virtual WAN is a Microsoft-managed networking service, but relying solely on point-to-site VPNs for a global workforce without SD-WAN's advanced routing and security integration capabilities would still likely lead to backhauling and less optimized performance compared to an SD-WAN solution.

SD-WAN Integration (Zero Trust for Hybrid/Multi-Cloud)

Integrating Software-Defined Wide Area Network (SD-WAN) with cloud security services (often forming a SASE architecture) provides a unified and optimized network and security framework for hybrid and multi-cloud environments, enforcing Zero Trust principles.

  • Optimizes traffic routing for direct cloud access.
  • Enforces consistent security policies across distributed locations and clouds.
  • Reduces latency and eliminates backhauling of traffic through central data centers.

Memory trick: SD-WAN: 'Smartly Directs Work Across Networks'.

More Design a Zero Trust strategy and architecture questions