SC-300 Practice Question 3471
Exam: SC-300
Domain: Plan and implement workload identities
Difficulty: hard
When deploying Microsoft Entra Application Proxy for an application that uses Windows Integrated Authentication, which Kerberos mechanism must be configured?
Answer Options
A
Kerberos Constrained Delegation (KCD)
B
Anonymous authentication
C
Basic cleartext authentication over HTTP
D
NTLMv1 legacy negotiation
Correct Answer
A: Kerberos Constrained Delegation (KCD)
Explanation
Kerberos Constrained Delegation (KCD) allows the Application Proxy connector on-premises to impersonate authenticated users and request Kerberos service tickets for internal servers.