A multinational is replacing branch firewalls and a hub VPN concentrator with a converged edge so that both wide-area connectivity and security policy are delivered as one service from the cloud. Leadership asks the architect to state, in framework terms, how a Security Service Edge relates to the broader Secure Access Service Edge model so the team scopes the Microsoft components correctly. Which statement most accurately positions Security Service Edge within Secure Access Service Edge?
- ASecure Access Service Edge is the security half of Security Service Edge, delivering web gateway, private application access and cloud app controls, while wide-area network connectivity such as software-defined networking is the separate networking half.
- BSecurity Service Edge is the security half of Secure Access Service Edge, delivering secure web gateway, private application access and cloud app controls, while wide-area network connectivity such as software-defined networking is the separate networking half. Correct
- CSecurity Service Edge is the wide-area networking half of Secure Access Service Edge, providing software-defined connectivity, while the secure web gateway and private application access are delivered by the separate security half.
- DSecurity Service Edge and Secure Access Service Edge are interchangeable names for the same converged service, each covering software-defined connectivity and the secure web gateway as one indivisible offering.
Why A is wrong: This inverts the two terms, which is tempting because the acronyms are similar, but Security Service Edge is the subset of Secure Access Service Edge rather than the other way around.
Why B is correct: Secure Access Service Edge converges networking with security, and Security Service Edge is specifically its security stack of secure web gateway, private access and cloud app security, which is the scope Microsoft Entra Internet Access and Private Access deliver.
Why C is wrong: This swaps the responsibilities, which is plausible if the candidate guesses by name, but the security gateway and private access are the defining functions of Security Service Edge, not the networking half.
Why D is wrong: Treating them as identical is a common shortcut, but it ignores that Secure Access Service Edge adds the wide-area networking layer on top of the Security Service Edge security functions, so the scopes are not the same.