SC-300 Practice Question 3471

Exam: SC-300
Domain: Plan and implement workload identities
Difficulty: hard
When deploying Microsoft Entra Application Proxy for an application that uses Windows Integrated Authentication, which Kerberos mechanism must be configured?

Answer Options

A
Kerberos Constrained Delegation (KCD)
B
Anonymous authentication
C
Basic cleartext authentication over HTTP
D
NTLMv1 legacy negotiation

Correct Answer

A: Kerberos Constrained Delegation (KCD)

Explanation

Kerberos Constrained Delegation (KCD) allows the Application Proxy connector on-premises to impersonate authenticated users and request Kerberos service tickets for internal servers.