Question 1
A financial services firm, QuantumLeap Financials, is designing a Zero Trust architecture for its hybrid environment. They have a critical on-premises Active Directory Domain Services (AD DS) infrastructure and a growing footprint in Azure. A key requirement is to protect privileged administrative accounts in AD DS from pass-the-hash and other credential theft attacks originating from compromised workstations. The security architect needs to recommend a solution that isolates administrative tasks from daily user activities like email and web browsing. Which solution best meets this requirement by implementing a tiered access model?
Answer and explanation
Correct answer: C
The core requirement is to isolate administrative tasks from daily user activities to prevent credential theft. Privileged Access Workstations (PAWs) are specifically designed for this purpose. A PAW provides a dedicated, hardened operating system for sensitive tasks, completely separate from the user's standard workstation used for email and browsing. This directly prevents credential theft vectors like phishing and browser exploits from compromising high-privilege accounts. While Defender for Identity is crucial for detection and PIM for just-in-time access, neither provides the required task isolation at the workstation level.