SC-100 Design security solutions for infrastructure Practice Question
Which THREE of the following are best practices for designing a secure hybrid network architecture with Azure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Azure Bastion for secure VM access without public IPs
Option A is correct because Azure Bastion provides RDP/SSH connectivity to VMs directly through the Azure portal over TLS, eliminating the need to expose public IP addresses or open inbound management ports (3389/22) on the VMs, which removes a major attack surface in a hybrid design. Option C is correct because ExpressRoute gives private, dedicated connectivity between on-premises and Azure that bypasses the public internet, and pairing it with Azure Firewall provides centralized, stateful Layer 3–7 traffic inspection and filtering across the hybrid boundary. Option E is correct because forced tunneling routes all internet-bound traffic from Azure subnets back through on-premises (via UDRs with a next hop of the VPN/ExpressRoute gateway), enabling on-premises firewalls, proxies, and DLP to inspect and control that traffic consistently. Option B is wrong because opening all ports to a management subnet violates least-privilege and network segmentation principles, dramatically expanding the attack surface. Option D is wrong because a single VPN gateway is a regional resource and a single point of failure; multi-region designs should use gateways per region (or zone-redundant/active-active configurations) for resiliency and latency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use Azure Bastion for secure VM access without public IPs
Why this is correct
Azure Bastion is a fully PaaS-based service that provides secure RDP/SSH access to Azure VMs over TLS, eliminating the need for any public IP addresses on the VMs themselves. It includes RBAC integration, Microsoft Entra ID authentication, and hybrid AAD join support, while also allowing you to restrict inbound traffic through NSG rules to only the Bastion subnet. This reduces the attack surface for management ports by never exposing them to the internet and supports auditing via Azure Monitor.
- ✗
Open all ports to a management subnet for ease of administration
Why it's wrong here
Opening all ports to a management subnet violates the core security principle of least privilege and creates a massive lateral movement path if the subnet is compromised. It also ignores the need to restrict protocols and source IPs, effectively weakening any network segmentation. A better practice is to allow only specific ports (e.g., RDP/SSH) from designated admin source IPs or through Azure Bastion, and to use just-in-time access whenever possible.
- ✓
Use ExpressRoute with Azure Firewall for traffic inspection
Why this is correct
ExpressRoute creates a private, dedicated connection from your on-premises network into Azure without traversing the public internet, offering higher bandwidth and more predictable latency. Pairing it with Azure Firewall allows you to inspect and filter all traffic entering or leaving that private path, because Azure Firewall provides stateful filtering, threat intelligence-based rules, and centralized logging. This combination ensures that even trusted private connections are governed by consistent security policies, rather than being implicitly trusted due to their private nature.
- ✗
Use a single VPN gateway for all regions
Why it's wrong here
Deploying a single VPN gateway for all regions creates a critical single point of failure: if that gateway fails or undergoes maintenance, all cross-premises connectivity to every region is lost. It also concentrates network egress traffic, which can become a bottleneck and violates availability best practices. For resilient hybrid networking, you should use active-active VPN gateways or deploy redundant gateways in multiple regions to meet per-region SLAs and ensure geo-redundancy.
- ✓
Enable forced tunneling for all internet-bound traffic
Why this is correct
Forced tunneling redirects all internet-bound traffic from Azure VMs through the Azure Firewall or a network virtual appliance before it reaches the internet, ensuring that every egress connection is inspected, logged, and controlled. This is typically configured by creating a user-defined route (UDR) with 0.0.0.0/0 as the destination and the firewall as the next hop, and it prevents VMs from bypassing security policies by using a direct public IP. It also supports regulatory compliance and data loss prevention by explicitly authorizing and auditing outbound traffic.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.