
Answer-first summary for fast verification
Answer: Implement a distributed network design with local internet breakouts at each remote site, utilizing Microsoft Entra Internet Access as a secure web gateway for direct and secure access to Microsoft 365 services, while applying consistent security policies across all sites.
Option B is the most appropriate solution as it aligns with security best practices and the requirements outlined. By implementing a distributed network design with local internet breakouts and using Microsoft Entra Internet Access as a secure web gateway, the enterprise ensures secure, direct access to Microsoft 365 services. This approach minimizes latency for remote users, reduces the risk of data breaches by avoiding unnecessary routing through the headquarters, and provides scalability and cost-effectiveness. It also allows for the application of consistent security policies across all sites, ensuring compliance with industry standards.
Author: LeetQuiz Editorial Team
Ultimate access to all questions.
No comments yet.
As a Cybersecurity Architect for a large enterprise with multiple remote sites, you are tasked with designing a network that ensures secure access to Microsoft 365 services. The design must comply with industry standards, provide robust data protection, and enforce strict access control. Additionally, the solution should be cost-effective, scalable, and minimize latency for remote users. Which of the following solutions BEST meets these requirements? (Choose one option)
A
Deploy a single VPN concentrator at the headquarters and establish site-to-site VPNs to all remote sites, ensuring all traffic to Microsoft 365 services is routed through the headquarters.
B
Implement a distributed network design with local internet breakouts at each remote site, utilizing Microsoft Entra Internet Access as a secure web gateway for direct and secure access to Microsoft 365 services, while applying consistent security policies across all sites.
C
Adopt a cloud-based security solution that offers a unified management console for security policies across all sites, without specifying the use of local internet breakouts or direct access to Microsoft 365 services.
D
Deploy a dedicated MPLS network connecting all remote sites to the headquarters, ensuring all Microsoft 365 traffic is securely routed through the MPLS network to the headquarters before accessing the internet.