exam questions

Exam SC-100 All Questions

View all questions & answers for the SC-100 exam

Exam SC-100 topic 2 question 6 discussion

Actual exam question from Microsoft's SC-100
Question #: 6
Topic #: 2
[All SC-100 Questions]

Your company has on-premises network in Seattle and an Azure subscription. The on-premises network contains a Remote Desktop server.
The company contracts a third-party development firm from France to develop and deploy resources to the virtual machines hosted in the Azure subscription.
Currently, the firm establishes an RDP connection to the Remote Desktop server. From the Remote Desktop connection, the firm can access the virtual machines hosted in Azure by using custom administrative tools installed on the Remote Desktop server. All the traffic to the Remote Desktop server is captured by a firewall, and the firewall only allows specific connections from France to the server.
You need to recommend a modern security solution based on the Zero Trust model. The solution must minimize latency for developers.
Which three actions should you recommend? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. Configure network security groups (NSGs) to allow access from only specific logical groupings of IP address ranges.
  • B. Deploy a Remote Desktop server to an Azure region located in France.
  • C. Migrate from the Remote Desktop server to Azure Virtual Desktop.
  • D. Implement Azure Firewall to restrict host pool outbound access.
  • E. Configure Azure Active Directory (Azure AD) Conditional Access with multi-factor authentication (MFA) and named locations.
Show Suggested Answer Hide Answer
Suggested Answer: CDE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
zellck
Highly Voted 1 year, 5 months ago
Selected Answer: CDE
CDE is the answer. https://learn.microsoft.com/en-us/azure/firewall/protect-azure-virtual-desktop?tabs=azure Azure Virtual Desktop is a desktop and app virtualization service that runs on Azure. When an end user connects to an Azure Virtual Desktop environment, their session is run by a host pool. A host pool is a collection of Azure virtual machines that register to Azure Virtual Desktop as session hosts. These virtual machines run in your virtual network and are subject to the virtual network security controls. They need outbound Internet access to the Azure Virtual Desktop service to operate properly and might also need outbound Internet access for end users. Azure Firewall can help you lock down your environment and filter outbound traffic.
upvoted 10 times
zellck
1 year, 5 months ago
https://learn.microsoft.com/en-us/azure/virtual-desktop/set-up-mfa Users can sign into Azure Virtual Desktop from anywhere using different devices and clients. However, there are certain measures you should take to help keep yourself and your users safe. Using Azure Active Directory (Azure AD) Multi-Factor Authentication (MFA) with Azure Virtual Desktop prompts users during the sign-in process for another form of identification in addition to their username and password. You can enforce MFA for Azure Virtual Desktop using Conditional Access, and can also configure whether it applies to the web client, mobile apps, desktop clients, or all clients.
upvoted 5 times
...
...
Ramye
Highly Voted 9 months, 2 weeks ago
Why D over A? A seems to be better choice but most choosing D. Can someone explain pls?
upvoted 5 times
...
RabbitB
Most Recent 2 months, 2 weeks ago
Selected Answer: CDE
Because A, B does not make sense at all.
upvoted 1 times
...
Jacek_
9 months, 1 week ago
I'm wondering Azure Active directory is now Entra ID on exam we see old naming convention or new one ?
upvoted 1 times
...
Ario
1 year, 3 months ago
ACE are correct answers here
upvoted 2 times
...
Holii
1 year, 3 months ago
This question is terrible. B could work to solve the latency issue...and MFA is explicitly stated as a requirement to migrate their existing firewall, but in the context of Zero Trust > latency I would go with E over B. CDE.
upvoted 1 times
Holii
1 year, 3 months ago
is not stated as a requirement to migrate their existing firewall*
upvoted 1 times
...
...
uffman
1 year, 6 months ago
Selected Answer: CDE
Correct.
upvoted 2 times
...
Gurulee
1 year, 6 months ago
Selected Answer: CDE
This is a tricky one… Based on zero trust, minimizing latency, and keeping the existing firewall requirement in place; I’d go with C,D,E
upvoted 4 times
Holii
1 year, 3 months ago
How exactly does CDE do anything to minimizing latency?
upvoted 2 times
...
...
Fal991l
1 year, 7 months ago
Selected Answer: ABE
A. Configure network security groups (NSGs) to allow access from only specific logical groupings of IP address ranges: This action will restrict access to the on-premises network and the Azure subscription to only specific logical groupings of IP address ranges. This helps ensure that only authorized traffic is allowed to access the resources. B. Deploy a Remote Desktop server to an Azure region located in France: This action will help reduce latency for developers by ensuring that they have a closer connection to the Remote Desktop server. This can be achieved by deploying the Remote Desktop server in an Azure region located in France. E. Configure Azure Active Directory (Azure AD) Conditional Access with multi-factor authentication (MFA) and named locations: This action will help ensure that only authorized users are allowed to access the resources. Azure AD Conditional Access can be used to enforce MFA and restrict access based on named locations. This helps ensure that only authorized users are accessing the resources.
upvoted 4 times
...
Fal991l
1 year, 7 months ago
Selected Answer: BCE
AI: To implement a modern security solution based on the Zero Trust model and minimize latency for developers, the following actions should be recommended: Migrate from the Remote Desktop server to Azure Virtual Desktop: Azure Virtual Desktop is a modern solution that allows users to securely access their virtual desktops and applications from any device, anywhere. By migrating from the on-premises Remote Desktop server to Azure Virtual Desktop, you can provide secure remote access to the virtual machines hosted in Azure without compromising on security.
upvoted 1 times
Fal991l
1 year, 7 months ago
ChatGPT: I apologize for the confusion. My previous response was incorrect. The recommended actions for a modern security solution based on the Zero Trust model that minimizes latency for developers and allows access to Azure virtual machines hosted in the Azure subscription by a third-party development firm from France are: A. Configure network security groups (NSGs) to allow access from only specific logical groupings of IP address ranges. B. Deploy a Remote Desktop server to an Azure region located in France. E. Configure Azure Active Directory (Azure AD) Conditional Access with multi-factor authentication (MFA) and named locations. I hope this clears up any confusion.
upvoted 1 times
jasscomp
1 year, 1 month ago
ChatGPT isn't always right and you need to feed it more info to for more contect. option B isn't a modern 'security' feature
upvoted 3 times
...
Rowanomaly
6 months ago
All you need to do to change ChatGPTs mind is to drop a paragraph from one of the other option. Then it'll apologize again and change it to the answer you "suggested"
upvoted 1 times
...
...
Fal991l
1 year, 7 months ago
Deploy a Remote Desktop server to an Azure region located in France: To minimize latency for developers, you can deploy a Remote Desktop server in an Azure region located in France. This will ensure that developers can access the resources they need quickly and efficiently.
upvoted 1 times
Fal991l
1 year, 7 months ago
Configure Azure Active Directory (Azure AD) Conditional Access with multi-factor authentication (MFA) and named locations: Azure AD Conditional Access allows you to control access to resources based on user identity, device health, and location. By configuring Azure AD Conditional Access with MFA and named locations, you can ensure that only authorized users are able to access the resources they need, from trusted locations.
upvoted 1 times
Fal991l
1 year, 7 months ago
Therefore, the correct answers are C. Migrate from the Remote Desktop server to Azure Virtual Desktop, B. Deploy a Remote Desktop server to an Azure region located in France, and E. Configure Azure Active Directory (Azure AD) Conditional Access with multi-factor authentication (MFA) and named locations.
upvoted 2 times
jasscomp
1 year, 1 month ago
Don't use ChatGPT for answers to Microsoft exam questions - I tested it on my renewal exam and it got 50% wrong!
upvoted 1 times
...
...
...
...
...
TJ001
1 year, 10 months ago
CDE is perfect
upvoted 4 times
...
Bill831231
2 years ago
why there is no option for bastion host?
upvoted 2 times
mistralst
1 year, 10 months ago
Because: "by using custom administrative tools installed on the Remote Desktop server."
upvoted 2 times
PeteNZ
1 year, 7 months ago
The real reason is that they are replacing an RDS environment, so the Azure version of this is AVD. Bastion doesn't support connections to AVD, so it wouldn't be useful in this respect.
upvoted 2 times
...
...
nicknamedude
1 year, 10 months ago
Bastion for OBM
upvoted 2 times
...
...
JCkD4Ni3L
2 years ago
Selected Answer: CDE
CDE is appropriate
upvoted 2 times
...
tester18128075
2 years, 1 month ago
CDE IS CORRECT
upvoted 3 times
...
InformationOverload
2 years, 1 month ago
Selected Answer: CDE
CDE looks fine to me
upvoted 3 times
...
zts
2 years, 1 month ago
Selected Answer: CDE
same here.
upvoted 2 times
...
HardcodedCloud
2 years, 1 month ago
Selected Answer: CDE
Correct answer
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago