nerdexam
Microsoft

SC-100 · Question #38

Your company has a hybrid cloud infrastructure that contains an on-premises Active Directory Domain Services (AD DS) forest, a Microsoft B65 subscription, and an Azure subscription. The company's…

The correct answer is A. Azure AD Application Proxy. The correct answer is A: Azure AD Application Proxy. Application Proxy is purpose-built for this scenario: it publishes internal, on-premises web applications to external users via Azure AD without exposing the applications directly to the internet or requiring a VPN client on…

Design security solutions for applications and data

Question

Your company has a hybrid cloud infrastructure that contains an on-premises Active Directory Domain Services (AD DS) forest, a Microsoft B65 subscription, and an Azure subscription. The company's on-premises network contains internal web apps that use Kerberos authentication. Currently, the web apps are accessible only from the network. You have remote users who have personal devices that run Windows 11. You need to recommend a solution to provide the remote users with the ability to access the web apps. The solution must meet the following requirements:

  • Prevent the remote users from accessing any other resources on the network.
  • Support Azure Active Directory (Azure AD) Conditional Access.
  • Simplify the end-user experience.

What should you include in the recommendation?

Options

  • AAzure AD Application Proxy
  • BAzure Virtual WAN
  • CMicrosoft Tunnel
  • Dweb content filtering in Microsoft Defender for Endpoint

How the community answered

(18 responses)
  • A
    72% (13)
  • B
    6% (1)
  • C
    17% (3)
  • D
    6% (1)

Explanation

The correct answer is A: Azure AD Application Proxy. Application Proxy is purpose-built for this scenario: it publishes internal, on-premises web applications to external users via Azure AD without exposing the applications directly to the internet or requiring a VPN client on personal devices. It supports Kerberos Constrained Delegation (KCD) to handle Kerberos authentication on behalf of remote users. It natively integrates with Azure AD Conditional Access for policy enforcement, and users access apps through a simple browser URL (simplifying the experience). It also enforces access only to the published applications, satisfying the requirement to prevent access to other network resources. Azure Virtual WAN (B) is a wide-area networking solution. Microsoft Tunnel (C) is a VPN gateway for mobile devices (iOS/Android) managed by Intune, not for general Windows access. Web content filtering (D) is a Defender for Endpoint feature that controls web browsing categories, not app access.

Topics

#Azure AD Application Proxy#Hybrid Identity#Application publishing#Conditional Access

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice