nerdexam
Microsoft

SC-100 · Question #56

Your company has an on-premise network in Seattle and an Azure subscription. The on-premises network contains a Remote Desktop server. The company contracts a third-party development firm from…

The correct answer is B. Implement Azure Firewall to restrict host pool outbound access. C. Configure Azure Active Directory (Azure AD) Conditional Access with multi-factor authentication D. Migrate from the Remote Desktop server to Azure Virtual Desktop. Migrating to Azure Virtual Desktop (D) replaces the on-premises Remote Desktop server with a cloud-native, Zero Trust-aligned solution-eliminating the need for a jump server architecture. Azure AD Conditional Access with MFA (C) enforces identity verification and access…

Design security solutions for infrastructure

Question

Your company has an on-premise network in Seattle and an Azure subscription. The on-premises network contains a Remote Desktop server. The company contracts a third-party development firm from France to develop and deploy resources to the virtual machines hosted in the Azure subscription. Currently, the firm establishes an RDP connection to the Remote Desktop server. From the Remote Desktop connection, the firm can access the virtual machines hosted in Azure by using custom administrative tools installed on the Remote Desktop server. All the traffic to the Remote Desktop server is captured by a firewall, and the firewall only allows specific connections from France to the server. You need to recommend a modern security solution based on the Zero Trust model. The solution must minimize latency tor developers. Which three actions should you recommend? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • AConfigure network security groups (NSGs) to allow access from only specific logical groupings of
  • BImplement Azure Firewall to restrict host pool outbound access.
  • CConfigure Azure Active Directory (Azure AD) Conditional Access with multi-factor authentication
  • DMigrate from the Remote Desktop server to Azure Virtual Desktop.
  • EDeploy a Remote Desktop server to an Azure region located in France.

How the community answered

(27 responses)
  • A
    19% (5)
  • B
    44% (12)
  • E
    37% (10)

Explanation

Migrating to Azure Virtual Desktop (D) replaces the on-premises Remote Desktop server with a cloud-native, Zero Trust-aligned solution-eliminating the need for a jump server architecture. Azure AD Conditional Access with MFA (C) enforces identity verification and access policies before any session is established, aligning with Zero Trust's 'verify explicitly' principle. Azure Firewall to restrict host pool outbound access (B) controls what the AVD session hosts can reach, minimizing lateral movement risk. Together these three controls modernize the architecture: users authenticate through AVD with MFA, and outbound traffic is governed by Azure Firewall. Option A (NSG groupings) and Option E (Remote Desktop in France) maintain the legacy RDP jump-server model and do not adopt Zero Trust.

Topics

#Zero Trust#Azure Virtual Desktop#Conditional Access#Azure Firewall

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice