You are securing a tiered web application that handles customer PII. In phase one, you must minimize blast radius, restrict privileged access, and assume breach. A formal data classification rollout will start next quarter. Which two design decisions should you implement now?
Choose an answer
Tap an option to check your answer.
Correct answer: Enforce defense in depth: place Azure Application Gateway WAF in front, use Azure Firewall Premium and NSGs/ASGs for segmentation, and use Private Endpoints to remove public exposure of data services., Implement least privilege with Azure AD RBAC and PIM for just-in-time elevation; use managed identities and store secrets in Azure Key Vault with RBAC-enabled access..
Why this is the answer
The correct options directly address minimizing blast radius, restricting privileged access, and assuming breach. Defense in depth with WAF, Firewall, NSGs/ASGs, and Private Endpoints creates multiple layers of protection and limits network exposure, reducing the impact of a breach. Implementing least privilege with RBAC, PIM, managed identities, and Key Vault ensures that access is granted only when necessary, for the shortest duration, and through secure means, directly restricting privileged access and supporting the "assume breach" principle by limiting potential damage. Granting the Owner role to all engineers violates the principle of least privilege and increases the blast radius. Using a single generic data label and relying solely on encryption-at-rest is insufficient for robust data classification and protection, especially with PII. Immediately enforcing DLP without stakeholder input or discovery is impractical and likely to cause operational disruption, as a formal data classification rollout is planned for the next quarter.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed