Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureMedium
A global e-commerce company is designing its Zero Trust strategy. They have multiple cloud environments (Azure, AWS) and a large remote workforce accessing various applications, both SaaS and custom-built, from diverse locations and devices. The company needs to provide secure, optimized, and consistent access to all resources, enforce security policies at the edge, and minimize latency for users, without relying on traditional VPNs or centralizing all traffic. Which architectural approach best fits these requirements?
- AImplementing a Secure Access Service Edge (SASE) model.
- BUtilizing only Azure Virtual Network peering for inter-cloud connectivity.
- CDeploying a traditional perimeter firewall in each cloud environment.
- DMandating a site-to-site VPN connection for every remote user.
Show answer & explanationAnswer & explanation
Correct answer: A. Implementing a Secure Access Service Edge (SASE) model.
SASE converges networking (SD-WAN) and security services (SWG, CASB, ZTNA, FWaaS) into a single, cloud-delivered platform, providing secure, optimized, and consistent access for a distributed workforce to multi-cloud resources, enforcing policies at the edge, and eliminating backhauling.
Why the other options are wrong
- B. Azure Virtual Network peering is for connecting virtual networks within Azure, not for providing secure, optimized access for a global remote workforce to multi-cloud and SaaS applications.
- C. Traditional perimeter firewalls are insufficient for a distributed workforce and multi-cloud environment, as they don't provide consistent edge security or optimized access.
- D. Mandating site-to-site VPNs for every remote user would be complex, inefficient, and would likely lead to traffic backhauling, contradicting the goal of minimizing latency and avoiding centralization.
Secure Access Service Edge (SASE)
SASE (pronounced 'sassy') is a cloud-native architecture that converges wide area networking (WAN) and network security services into a single, cloud-delivered service model to protect users, applications, and data.
- Combines SD-WAN, Zero Trust Network Access (ZTNA), CASB, SWG, and Firewall-as-a-Service (FWaaS).
- Delivers security functions closer to the user/device, reducing latency.
- Provides consistent policy enforcement for a distributed workforce accessing hybrid/multi-cloud resources.
Memory trick: SASE: 'Secure Access, Simple Everywhere'.