Q: 15
A network security engineer needs to implement segmentation but is under strict compliance
requirements to place security enforcement as close as possible to the private applications hosted in
Azure. Which deployment style is valid and meets the requirements in this scenario?
Options
Discussion
I don’t think it’s A. C makes more sense since the VM-Series is designed for Azure and Layer 3 zones are required for proper segmentation with routing between subnets. Layer 2 isn’t really supported in Azure like in physical networks, so I think A and B might be traps here. Not totally confident but leaning C.
Don't think A or B work since Layer 2 isn't supported by VM-Series in Azure, that's a common trap. C is the one that fits-VM-Series for Azure with Layer 3 zones gives you segmentation and meets compliance rules. If anyone thinks Layer 2 works natively in cloud, I'd double-check that, pretty sure it's unsupported.
C
A
I figured Layer 2 zones on the VM-Series could handle segmentation in Azure since it lets you isolate traffic without complex routing. Maybe I’m missing something with the compliance part but A looked fine to me.
I figured Layer 2 zones on the VM-Series could handle segmentation in Azure since it lets you isolate traffic without complex routing. Maybe I’m missing something with the compliance part but A looked fine to me.
Its C. VM-Series is made for Azure and only Layer 3 segmentation is actually supported there, not Layer 2.
A or B seem possible here, since both set up Layer 2 zones for logical segmentation and that's sometimes enough for isolating traffic close to apps. Pretty sure VM-Series is good in Azure but the guides can be confusing-I'd check the official doc or lab it if possible.
Nah, pretty sure it's B since PA-Series is for physical appliances and Layer 2 zones seem like a trap here. Option B.
I think A makes sense here because Layer 2 segmentation should work for logically separating the network within Azure. VM-Series can be used in cloud, and Layer 2 zones let you isolate traffic. Not totally sure if Layer 3 is needed for this specific compliance ask, but A seems valid to me. Agree?
Be respectful. No spam.