Microsoft Cybersecurity Architect — Question 31
Your company has a main office and 10 branch offices. Each branch office contains an on-premises file server that runs Windows Server and multiple devices that run either Windows 11 or macOS. The devices are enrolled in Microsoft Intune.
You have a Microsoft Entra tenant.
You need to deploy Global Secure Access to implement web filtering for device traffic to the internet. The solution must ensure that all the web traffic from the devices in the branch offices is controlled by using Global Secure Access.
What should you do first in each branch office?
Answer options
- A. Configure an Intune policy to onboard Microsoft Defender for Endpoint to each device.
- B. Configure an IPsec tunnel on the router.
- C. Install the Microsoft Entra private network connector on the file server.
- D. Configure an Intune policy to deploy the Global Secure Access client to each device.
Correct answer: D
Explanation
The correct answer is D because deploying the Global Secure Access client to each device is essential for controlling web traffic through this solution. Options A, B, and C do not directly address the need to manage web filtering traffic using Global Secure Access, making them less relevant for this specific requirement.