MS-900 · Question #416
Hotspot Question A company plans to migrate to Microsoft 365. You need to identify the Microsoft 365 products that the company can use for each Zero Trust model pillar. Which products should you…
This hotspot question tests knowledge of Microsoft 365 product mapping to Zero Trust model pillars, requiring candidates to identify which Microsoft 365 products align with each of the six Zero Trust pillars: Identity, Endpoints, Applications, Network, Infrastructure, and Data.
Question
Exhibit
Answer Area
- InfrastructureAzure FirewallJust-in-time (JIT) accessMicrosoft Defender for EndpointMicrosoft Defender for Cloud Apps
- DataAzure FirewallMicrosoft SentinelMicrosoft Defender for Cloud AppsMicrosoft Purview Information Protection
- Visibility, Automation, OrchestrationAzure FirewallJust-in-time (JIT) accessMicrosoft Defender for EndpointMicrosoft Purview Information Protection
Explanation
This hotspot question tests knowledge of Microsoft 365 product mapping to Zero Trust model pillars, requiring candidates to identify which Microsoft 365 products align with each of the six Zero Trust pillars: Identity, Endpoints, Applications, Network, Infrastructure, and Data.
Approach. The Zero Trust model pillars map to Microsoft 365 products as follows: Identity pillar uses Azure Active Directory (Azure AD / Microsoft Entra ID) for identity verification and conditional access; Endpoints pillar uses Microsoft Intune and Microsoft Defender for Endpoint for device compliance and management; Applications pillar uses Microsoft Defender for Cloud Apps (formerly MCAS) for app visibility and control; Network pillar uses Azure Firewall, Azure VPN Gateway, and Microsoft Defender for Identity for network security; Infrastructure pillar uses Microsoft Defender for Cloud for workload protection and security posture; and Data pillar uses Microsoft Purview (Information Protection, DLP, Compliance) to classify, label, and protect sensitive data. Each product directly addresses the security controls and visibility requirements defined for its respective pillar in Microsoft's Zero Trust framework.
Concept tested. Microsoft Zero Trust model pillars and their corresponding Microsoft 365/Azure product mappings, including Identity (Azure AD/Entra ID), Endpoints (Intune/Defender for Endpoint), Applications (Defender for Cloud Apps), Network (Azure networking/Defender for Identity), Infrastructure (Defender for Cloud), and Data (Microsoft Purview).
Reference. Microsoft Zero Trust Guidance Center: https://docs.microsoft.com/en-us/security/zero-trust/ and Microsoft 365 Zero Trust deployment plan documentation.
Topics
Community Discussion
No community discussion yet for this question.
