Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Which TWO Azure services can you use to implement a zero-trust network architecture that verifies identity and device compliance before granting access to on-premises applications? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra Application Proxy

Microsoft Entra Application Proxy (A) is correct because it publishes on-premises web applications to the cloud and enforces Microsoft Entra ID authentication and Conditional Access before any request is forwarded to the internal app, which directly supports verifying identity and device compliance for on-premises access. Microsoft Entra Conditional Access (B) is correct because it is the policy engine that evaluates signals such as user identity, group membership, and device compliance state (via Intune) and then grants, blocks, or challenges access, which is the core of a zero-trust verification step. Azure VPN Gateway (C) only establishes encrypted network tunnels and does not itself verify user identity or device compliance. Azure Firewall (D) is a network-layer traffic filtering and inspection service, not an identity or device-compliance gate. Azure Bastion (E) provides secure RDP/SSH access to Azure VMs over TLS without exposing public IPs, but it does not publish or broker access to on-premises applications based on identity and device compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Entra Application Proxy

    Why this is correct

    Microsoft Entra Application Proxy acts as a reverse proxy for on-premises web applications, intercepting the initial request and pre-authenticating the user against Microsoft Entra ID. It then evaluates Conditional Access policies—like MFA, device compliance, or sign-in risk—before leaving the cloud boundary to reach the on-prem app. This makes it an ideal companion to Conditional Access for enabling zero trust across hybrid application environments.

  • ✓

    Microsoft Entra Conditional Access

    Why this is correct

    Microsoft Entra Conditional Access is an identity-driven policy engine that evaluates signals at each access attempt: user, group, device compliance, location, and risk level. It can require multi-factor authentication, block risky sign-ins, or force device enrollment before granting a session. This aligns directly with zero trust because it continuously verifies identity and device posture rather than assuming trust from a corporate network.

  • ✗

    Azure VPN Gateway

    Why it's wrong here

    Azure VPN Gateway establishes encrypted IPsec/IKE tunnels between on-premises networks or individual clients and Azure. While it can authenticate the VPN peer via certificates or shared security keys, it does not perform user-level identity checks, device compliance validation, or risk-based MFA. It is transport-level connectivity, and zero-trust access decisions belong to the application and identity layers.

  • ✗

    Azure Firewall

    Why it's wrong here

    Azure Firewall is a stateful network firewall that inspects traffic based on IP addresses, ports, and protocols. It can enforce network segmentation and filter malicious traffic, but it does not examine the user's identity or assess whether the endpoint is compliant. In a zero-trust context, it would complement the identity layer, not implement it; identity checks are performed by other services like Conditional Access.

  • ✗

    Azure Bastion

    Why it's wrong here

    Azure Bastion provides browser-based RDP/SSH access to Azure virtual machines but does not expose or protect on-premises applications. It uses the VM's own credentials (local or domain) and cannot enforce Microsoft Entra Conditional Access policies such as MFA or device compliance before the VM session is established. It is primarily a network-management tool, not an application access controller.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.