SC-100 - Design Security Solutions for Infrastructure - Section 3.4

Evaluate solutions for network security and Security Service Edge (SSE).

Evaluate Security Service Edge (SSE) designs that use Microsoft Entra Internet Access as a secure web gateway and Microsoft Entra Private Access to replace legacy VPN for private resource connectivity. Apply Zero Trust network design principles and network segmentation to limit lateral movement and choose between SSE components based on traffic type and protection requirements.

Security Service Edge (SSE)Microsoft Entra Internet AccessMicrosoft Entra Private Accesssecure web gatewaynetwork segmentationZero Trust network design

Practice question for this objective

Free sampleDesign Security Solutions for Infrastructurehard

A multinational is replacing branch firewalls and a hub VPN concentrator with a converged edge so that both wide-area connectivity and security policy are delivered as one service from the cloud. Leadership asks the architect to state, in framework terms, how a Security Service Edge relates to the broader Secure Access Service Edge model so the team scopes the Microsoft components correctly. Which statement most accurately positions Security Service Edge within Secure Access Service Edge?

  • ASecure Access Service Edge is the security half of Security Service Edge, delivering web gateway, private application access and cloud app controls, while wide-area network connectivity such as software-defined networking is the separate networking half.
  • BSecurity Service Edge is the security half of Secure Access Service Edge, delivering secure web gateway, private application access and cloud app controls, while wide-area network connectivity such as software-defined networking is the separate networking half. Correct
  • CSecurity Service Edge is the wide-area networking half of Secure Access Service Edge, providing software-defined connectivity, while the secure web gateway and private application access are delivered by the separate security half.
  • DSecurity Service Edge and Secure Access Service Edge are interchangeable names for the same converged service, each covering software-defined connectivity and the secure web gateway as one indivisible offering.
Security Service Edge is the security subset of Secure Access Service Edge, covering secure web gateway, private access and cloud app controls, not the networking layer. Secure Access Service Edge converges software-defined networking with cloud-delivered security, and Security Service Edge names only that security portion, which is why Microsoft positions Entra Internet Access, Private Access and cloud app security as its Security Service Edge solution rather than as a networking fabric.

Why A is wrong: This inverts the two terms, which is tempting because the acronyms are similar, but Security Service Edge is the subset of Secure Access Service Edge rather than the other way around.

Why B is correct: Secure Access Service Edge converges networking with security, and Security Service Edge is specifically its security stack of secure web gateway, private access and cloud app security, which is the scope Microsoft Entra Internet Access and Private Access deliver.

Why C is wrong: This swaps the responsibilities, which is plausible if the candidate guesses by name, but the security gateway and private access are the defining functions of Security Service Edge, not the networking half.

Why D is wrong: Treating them as identical is a common shortcut, but it ignores that Secure Access Service Edge adds the wide-area networking layer on top of the Security Service Edge security functions, so the scopes are not the same.

See more SC-100 practice questions, answers explained.

More in this domain

Back to all Design Security Solutions for Infrastructure objectives, or the SC-100 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.