SC-300 · Question #394
You have a Microsoft 365 subscription. You have an Azure subscription that contains an Azure App Service web app named App1. You have multiple devices that run Windows and are enrolled in Microsoft…
The correct answer is B. Configure a traffic forwarding profile. Configuring a traffic forwarding profile is the correct next step because, after deploying the Global Secure Access client to devices, you must enable and configure the Private Access traffic forwarding profile to direct private network traffic through Microsoft Entra Private…
Question
You have a Microsoft 365 subscription. You have an Azure subscription that contains an Azure App Service web app named App1. You have multiple devices that run Windows and are enrolled in Microsoft Intune. You deploy the Global Secure Access client to the devices by using Intune. You need to configure private access to App1. What should you do next?
Options
- ACreate a remote network.
- BConfigure a traffic forwarding profile.
- CDeploy a private network connector.
- DCreate an application security group.
How the community answered
(19 responses)- A5% (1)
- B74% (14)
- C16% (3)
- D5% (1)
Explanation
Configuring a traffic forwarding profile is the correct next step because, after deploying the Global Secure Access client to devices, you must enable and configure the Private Access traffic forwarding profile to direct private network traffic through Microsoft Entra Private Access - without this profile, the client has no instructions on what traffic to forward or how to route it to App1.
Why the distractors are wrong:
- A (Remote network): Remote networks are used to connect branch offices or physical locations via CPE devices - not for configuring access to a specific Azure web app via the Global Secure Access client.
- C (Private network connector): While a private network connector will eventually be needed to connect App1 to Microsoft Entra Private Access, the immediate next step after deploying the client is enabling the traffic forwarding profile; the connector comes later in the configuration sequence.
- D (Application security group): Application security groups are an Azure networking construct used to group VMs for NSG rules - they have no role in Global Secure Access private access configuration.
Memory tip: Think of the traffic forwarding profile as the "on switch" - you've installed the Global Secure Access client (the hardware), but without flipping the profile on, nothing moves. Always ask: "What tells the client where to send traffic?" - that's the forwarding profile.
Topics
Community Discussion
No community discussion yet for this question.