Courseiva

SC-100 Design security solutions for infrastructure Practice Question

You are designing a secure remote access solution for on-premises web applications using Microsoft Entra ID. The solution must support multifactor authentication (MFA) and conditional access. Which service should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra application proxy

Microsoft Entra application proxy (option A) is correct because it is the service designed to publish on-premises web applications for secure remote access through Microsoft Entra ID, and it natively supports Entra ID authentication, multifactor authentication (MFA), and conditional access policies. It works via a lightweight connector on the on-premises network, so users authenticate to Entra ID before reaching the internal web app, satisfying the MFA and conditional access requirements. Windows Server DirectAccess (B) provides seamless intranet connectivity for domain-joined Windows clients but does not integrate with Entra ID conditional access for publishing web apps. A VPN gateway with RADIUS authentication (C) provides network-level access and can use MFA via RADIUS, but it does not natively enforce Entra ID conditional access for individual web applications. Microsoft Entra ID (D) is the identity provider itself, not the remote-access publishing service, so it alone cannot expose on-premises web applications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Entra application proxy

    Why this is correct

    Microsoft Entra Application Proxy publishes internal web applications through an outbound connector, so remote users access the app via an external URL without opening inbound firewall ports. It relies on Entra ID for pre-authentication, which lets you enforce MFA, Conditional Access, and device compliance before a session is established, and it supports Kerberos Constrained Delegation for seamless SSO to the backend app. This is the only option that delivers identity-aware, application-level access control specifically for on-premises web apps.

  • ✗

    Windows Server DirectAccess

    Why it's wrong here

    Windows Server DirectAccess uses IPsec with IPv6 to create an always-on, transparent tunnel for domain-joined client computers, making it effectively an automatic VPN at the network layer. It does not integrate natively with Microsoft Entra ID for MFA or Conditional Access; classic DirectAccess relies on NLA and PKI, so enforcing Entra ID MFA requires complex workarounds or third-party NPS extensions. Additionally, it is a legacy technology that Microsoft no longer actively develops, and it grants network-wide access rather than scoped application-level publishing.

  • ✗

    VPN gateway with RADIUS authentication

    Why it's wrong here

    A VPN gateway with RADIUS authentication validates credentials only at the network boundary, allowing the user to join the corpnet's IP space and reach many internal resources. RADIUS itself does not provide application-layer awareness, interactive MFA prompts, or Conditional Access policies that can be tailored per on-premises app; even if you add MFA via NPS, the VPN inherently grants broad network access rather than selective application access. This makes it unsuitable when the requirement is precise, app-centric remote access with Entra ID policies.

  • ✗

    Microsoft Entra ID (Azure AD)

    Why it's wrong here

    Microsoft Entra ID (Azure AD) by itself is an identity provider and directory service; it can authenticate users and issue tokens, but it has no built-in reverse-proxy or forwarding component to reach on-premises applications. Without a connector-based proxy like Application Proxy or a similar gateway, Entra ID cannot bridge the network boundary to an internal web server, so it cannot publish or mediate access to on-premises apps. It is the underlying authentication and policy authority, not the access delivery mechanism, and thus insufficient on its own for this scenario.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.