A mid-sized financial services company has recently experienced a security incident where an attacker gained access to the internal network through a compromised VPN account. The account belonged to a remote employee who had been granted full network access. The company's security team is now reviewing their security principles to prevent a recurrence. The company has 500 employees, with 50 remote workers. They use a traditional perimeter-based firewall and VPN for remote access. The incident revealed that the compromised account had access to the entire internal network, including sensitive financial databases. The security team is considering implementing a new access control model. They have identified the following requirements: (1) Remote workers should only access specific applications necessary for their roles, (2) Access should be granted based on identity and device posture, (3) Network segmentation should be enforced regardless of location. Which of the following approaches BEST addresses these requirements?
An identity-aware proxy evaluates each request against Microsoft Entra ID identity and device posture before granting access, so a stolen VPN credential alone no longer opens the network. Micro-segmentation then enforces per-application reachability, satisfying the requirement that remote workers reach only role-specific apps and that segmentation holds regardless of location.
Why this answer
A Zero Trust Architecture (ZTA) with an identity-aware proxy and micro-segmentation directly addresses all three requirements: it grants access based on identity and device posture, limits remote workers to specific applications, and enforces segmentation regardless of location. ZTA assumes no implicit trust based on network location, which prevents a compromised VPN account from accessing the entire internal network. This is the most comprehensive and aligned solution.
Exam trap
CC often tests the misconception that MFA or network segmentation alone achieves Zero Trust, but the exam expects recognition that ZTA requires identity-based, context-aware access control with micro-segmentation.
How to eliminate wrong answers
Option A is wrong because MFA and stricter password policies improve authentication but do not limit lateral movement or enforce per-application access; a compromised account would still have full network access. Option C is wrong because VLANs and ACLs provide network segmentation but are location-dependent and do not consider identity or device posture, and they are complex to manage for 50 remote workers. Option D is wrong because least privilege reduces permissions but does not enforce device posture or application-specific access, and it is a principle rather than a technical control that fully meets the requirements.