Courseiva

SC-100 Design security solutions for infrastructure Practice Question

You are the security architect for a company that has a hybrid identity infrastructure with Microsoft Entra ID (formerly Azure AD) and an on-premises Active Directory Domain Services (AD DS) forest. The company is planning to migrate several line-of-business (LOB) applications to Azure Virtual Machines. The applications currently use Windows Integrated Authentication (WIA) and rely on Kerberos delegation. You need to design a solution that allows the Azure VMs to authenticate on-premises users and access on-premises resources using Kerberos constrained delegation (KCD) without exposing on-premises-domain controllers to the internet. The solution must minimize latency and administrative overhead. You have configured Azure ExpressRoute for connectivity between the on-premises network and Azure. What should you do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy domain controllers as Azure VMs in the same virtual network as the application VMs. Configure the application VMs to use these domain controllers for authentication and KCD.

Option A is correct because deploying replica domain controllers as Azure VMs in the same virtual network as the application VMs keeps Kerberos authentication and KCD traffic local to Azure, minimizing latency while avoiding any internet exposure of on-premises domain controllers; the VMs join the on-premises AD DS domain and use these in-Azure DCs for authentication and delegation. Option D would work functionally over ExpressRoute but adds WAN latency and dependency on the on-premises DCs for every Kerberos exchange, so it does not minimize latency. Option C is wrong because Microsoft Entra Domain Services (Microsoft Entra Domain Services) is a managed domain that does not support Kerberos constrained delegation to on-premises resources or joining an existing on-premises AD DS forest. Option B is wrong because Microsoft Entra application proxy publishes web apps for remote access and uses Entra ID authentication, which does not provide Kerberos KCD for LOB applications running on Azure VMs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deploy domain controllers as Azure VMs in the same virtual network as the application VMs. Configure the application VMs to use these domain controllers for authentication and KCD.

    Why this is correct

    Deploying domain controllers as Azure VMs in the same virtual network as the application VMs provides a low-latency and fully compatible Active Directory presence for authentication and Kerberos Constrained Delegation (KCD). These Azure-based domain controllers are full replicas of the on-premises domain, so they can issue Kerberos tickets, perform KCD with protocol transition, and handle all directory operations exactly like on-premises DCs, satisfying stringent application requirements. Because the DCs reside in the same virtual network, authentication traffic never traverses the WAN, reducing latency and avoiding timeouts; this design also prevents direct exposure of on-premises domain controllers to Azure or internet traffic while maintaining identity consistency through Active Directory replication over ExpressRoute or S2S VPN. This is the recommended pattern for hybrid applications that require fast, full-featured directory access and KCD.

  • ✗

    Implement Microsoft Entra application proxy to publish the applications and use Microsoft Entra ID for authentication.

    Why it's wrong here

    Microsoft Entra application proxy is a reverse proxy designed to publish on-premises web applications for external remote access, not to enable server-to-server authentication delegation between Azure VMs and Active Directory. It terminates pre-authentication in Microsoft Entra ID and forwards the request to the published app, but it does not perform Kerberos Constrained Delegation (KCD) or protocol transition for multi-hop scenarios where an application must act on behalf of a user to access another backend service. Additionally, Application Proxy relies on a connector installed on-premises and is irrelevant for internal hybrid workloads that need low-latency KCD inside an Azure virtual network.

  • ✗

    Use Microsoft Entra Domain Services to provide domain join and KCD capabilities for the Azure VMs.

    Why it's wrong here

    Microsoft Entra Domain Services (AAD DS) provides a managed domain that can authenticate users via Kerberos or NTLM, but it does not fully support Kerberos Constrained Delegation (KCD) for scenarios requiring protocol transition, service ticket issuance for on-premises resources, or resource-based constrained delegation. Even though AAD DS synchronizes from Microsoft Entra ID, it does not maintain a direct trust relationship with your on-premises Active Directory domain, so applications cannot delegate credentials to on-premises services through KCD. Moreover, AAD DS is a simplified managed domain that lacks many enterprise features such as custom schema extensions, complete Group Policy, and flexible service account management, which are often prerequisites for real-world line-of-business applications. As a result, using AAD DS would not meet the full KCD requirements and could cause application failures or security misconfigurations.

  • ✗

    Configure the application VMs to use the on-premises domain controllers over ExpressRoute for authentication and KCD.

    Why it's wrong here

    This is wrong because using only ExpressRoute means the VMs would have to communicate with on-premises DCs over the WAN, potentially increasing latency; additionally, this would expose on-premises DCs to the internet if not properly secured.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.