SC-100 Design security solutions for infrastructure Practice Question
You are designing a secure access strategy for a manufacturing plant using Azure IoT Hub and Azure Defender for IoT. The plant has unpatched legacy PLCs that cannot be updated. What is the best approach to prevent these devices from being compromised and used as an entry point into the corporate network?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement network micro-segmentation using Azure Firewall and NSGs to isolate the PLCs from the corporate network.
The correct option is B: implementing network micro-segmentation with Azure Firewall and NSGs to isolate the PLCs from the corporate network. Since the legacy PLCs cannot be patched, the most effective mitigation is to limit their attack surface and blast radius by placing them in a segmented network zone with strict allow-list rules, so a compromised PLC cannot pivot laterally into corporate systems. Azure Firewall provides centralized Layer 3–7 filtering and NSGs enforce subnet/NIC-level traffic control, which directly addresses the unpatched-device risk. Option A is wrong because a VPN gateway only provides encrypted connectivity, not isolation or traffic restriction. Option C is wrong because the Defender for IoT micro-agent requires installation and support on the device, which unpatched legacy PLCs typically cannot accommodate. Option D is wrong because TLS 1.2 only protects data in transit and does not prevent compromise or lateral movement from an unpatched PLC.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Azure VPN Gateway to connect PLCs to the virtual network.
Why it's wrong here
A VPN Gateway only creates an encrypted tunnel for connectivity; it does not restrict which resources a compromised PLC can reach once attached to the virtual network. Because the PLCs remain on the same network plane as corporate workloads, unpatched vulnerabilities can still be exploited and used for lateral movement. VPN also lacks stateful inspection and identity-based rule enforcement, so it provides no compensating security control for legacy devices.
- ✓
Implement network micro-segmentation using Azure Firewall and NSGs to isolate the PLCs from the corporate network.
Why this is correct
Micro-segmentation with Azure Firewall and NSGs is a compensating control that works even when PLCs cannot be patched or updated. By placing PLCs in a dedicated subnet, applying NSG rules to deny inbound/outbound traffic except allowed industrial protocols, and centralizing policy in Azure Firewall, you enforce least-privilege communication. This containment limits the blast radius so a compromised PLC cannot reach corporate systems or other OT zones.
- ✗
Install the Microsoft Defender for IoT micro-agent on each PLC.
Why it's wrong here
The Defender for IoT micro-agent requires a supported OS and runtime environment to be installed and executed. Legacy PLCs often run proprietary real-time operating systems that do not allow third-party agents, and they cannot be modified without disrupting production. Even if the agent could run, it primarily provides monitoring and threat detection, not network isolation or exploit prevention, so it does not address the unpatched vulnerability risk.
- ✗
Enforce TLS 1.2 for all PLC communications.
Why it's wrong here
TLS 1.2 enforcement assumes the PLCs support modern cryptographic stacks, which many legacy industrial devices do not. Forcing TLS 1.2 could cause loss of connectivity or require replacement of the devices, defeating the purpose of a quick security improvement. Moreover, TLS only protects data in transit; it does nothing to block an attacker from exploiting a listening service or moving laterally once on the network.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.