nerdexam
Microsoft

SC-100 · Question #51

Your company has a hybrid cloud infrastructure. The company plans to hire several temporary employees within a brief period. The temporary employees will need to access applications and data on the…

The correct answer is D. Deploy Azure Virtual Desktop, Azure Active Directory (Azure AD) Conditional Access, and. Azure Virtual Desktop (AVD) combined with Azure AD Conditional Access (and likely Microsoft Intune/Endpoint Manager) satisfies all requirements. AVD provides managed virtual desktops that temporary employees access via a browser or thin client-no personal device installs…

Design security operations, identity, and compliance capabilities

Question

Your company has a hybrid cloud infrastructure. The company plans to hire several temporary employees within a brief period. The temporary employees will need to access applications and data on the company' premises network. The company's security policy prevents the use of personal devices for accessing company data and applications. You need to recommend a solution to provide the temporary employee with access to company resources. The solution must be able to scale on demand. What should you include in the recommendation?

Options

  • AMigrate the on-premises applications to cloud-based applications.
  • BRedesign the VPN infrastructure by adopting a split tunnel configuration.
  • CDeploy Microsoft Endpoint Manager and Azure Active Directory (Azure AD) Conditional Access.
  • DDeploy Azure Virtual Desktop, Azure Active Directory (Azure AD) Conditional Access, and

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    11% (2)
  • C
    5% (1)
  • D
    79% (15)

Explanation

Azure Virtual Desktop (AVD) combined with Azure AD Conditional Access (and likely Microsoft Intune/Endpoint Manager) satisfies all requirements. AVD provides managed virtual desktops that temporary employees access via a browser or thin client-no personal device installs company data or applications, complying with the security policy. AVD scales on demand by adding session hosts. Conditional Access enforces access policies (MFA, compliant device, location) before granting access. Option A (migrating to cloud apps) doesn't address the on-premises data requirement. Option B (split tunnel VPN) still requires personal-device VPN clients, violating policy. Option C alone (Endpoint Manager + Conditional Access) enforces policy on existing devices but doesn't provide the virtual desktop mechanism needed to keep data off personal devices.

Topics

#Azure Virtual Desktop#Conditional Access#Hybrid Access#Temporary Workforce

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice