What's changed: Created SC-100 Chapter 4 (Domain 3 "Infrastructure security": Defender for Cloud (CSPM/CWPP)/Secure Score/MCSB/Azure Arc/multicloud posture; Security Exposure Management (attack paths/attack-surface reduction/initiatives)/Defender EASM; servers/endpoints (baselines/Defender for Endpoint/Intune/Windows LAPS)/OT-ICS-IoT (Defender for IoT)/containers (Defender for Containers)/Azure AI services security; network (microsegmentation/Private Link/Azure Bastion)/SSE (Entra Internet Access/Entra Private Access/Global Secure Access)).
4.4Network security and Security Service Edge (SSE)
Understand evaluating network designs for security alignment, Security Service Edge (SSE) including Microsoft Entra Internet Access (secure web gateway) and Microsoft Entra Private Access, and Zero Trust networking.
Network still matters in Zero Trust—but the mindset shifts from "defend at the perimeter" to "verify by identity and conditions while connecting minimally." The new shape of this is SSE (Security Service Edge).
4.4.1Evaluating network design and segmentation
Architects evaluate whether the network design aligns with security requirements: microsegmentation (limit lateral movement on compromise), private connectivity (Private Link/private endpoints to avoid exposure), isolated management access (Azure Bastion for jumpbox-less RDP/SSH), and L7 defense (WAF/Front Door from the next chapter). Network controls are supplementary to identity controls but essential to "minimize blast radius" under assume-breach.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

