SC-100: Microsoft Cybersecurity Architect Microsoft Practice Exam
QuestionQ1
Design security operations, identity, and compliance capabilities
Save question
You are designing a privileged-access strategy for Contoso, Ltd. and its partner, Fabrikam, Inc. Contoso has an Azure AD tenant named contoso.com, and Fabrikam has an Azure AD tenant named fabrikam.com. Fabrikam users must access resources in contoso.com.
You need to give Fabrikam users access to Contoso resources by using access packages. What should you use for each requirement?
Select
Ensure that the Fabrikam users can use the access packages without explicitly creating guest accounts in contoso.com:
Allow non-administrative users in contoso.com to create the access packages by creating:
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Design security operations, identity, and compliance capabilities
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Design security operations, identity, and compliance capabilities
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Design security solutions for applications and data
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Design security solutions for applications and data
0
Community Discussion
No comments yet. Be the first to start the discussion!
It's free
100% of the questions are free for all users. No strings attached.
Design solutions that align with security best practices and prioritiesDesign security operations, identity, and compliance capabilitiesDesign security solutions for infrastructureDesign security solutions for applications and data
You have an Azure subscription that includes a Microsoft Sentinel workspace.
Your on-premises network includes firewalls that can forward event logs in the Common Event Format (CEF). No built-in Microsoft Sentinel connector exists for the firewalls.
You need to recommend a solution to ingest firewall events into Microsoft Sentinel.
What should you include in the recommendation?
Aan Azure logic app
Ban on-premises Syslog server
Can on-premises data gateway
DAzure Data Factory
You need to recommend a SIEM and SOAR strategy that meets the hybrid requirements, the Microsoft Sentinel requirements, and the regulatory compliance requirements.
What should you recommend?
Select
Segment Microsoft Sentinel workspaces by:
Integrate Azure subscriptions by using:
You have several on-premises Hyper-V hosts containing virtual machines that run Windows Server 2022, along with an Azure subscription.
Recommend a solution for collecting Security event logs from the virtual machines by using Microsoft Sentinel. The solution must:
Use the Windows Security Events via AMA data connector.
Collect only specified events.
Minimize costs.
What should you recommend?
Select
In Azure, deploy:
On the virtual machines, install:
Your company intends to provision blob storage by using an Azure Storage account. The blob storage will be available to 20 application servers on the internet.
You need to recommend a solution that ensures only the application servers can access the storage account.
What should you recommend to secure the blob storage?
Amanaged rule sets in Azure Web Application Firewall (WAF) policies
Binbound rules in network security groups (NSGs)
Cfirewall rules for the storage account
Dinbound rules in Azure Firewall
Eservice tags in network security groups (NSGs)
QuestionQ6
Design security solutions for applications and data
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Design security solutions for applications and data
QuestionQ8
Design security operations, identity, and compliance capabilities
QuestionQ9
Design security solutions for applications and data
QuestionQ10
Design security solutions for applications and data
QuestionQ11
Design solutions that align with security best practices and priorities
QuestionQ12
Design security solutions for applications and data
QuestionQ13
Design security solutions for infrastructure
QuestionQ14
Design solutions that align with security best practices and priorities
QuestionQ15
Design solutions that align with security best practices and priorities
QuestionQ16
Design security operations, identity, and compliance capabilities
QuestionQ17
Design security solutions for infrastructure
QuestionQ18
Design security solutions for applications and data
QuestionQ19
Design security solutions for applications and data
QuestionQ20
Design security solutions for applications and data
QuestionQ21
Design security solutions for infrastructure
QuestionQ22
Design security solutions for infrastructure
QuestionQ23
Design security solutions for infrastructure
QuestionQ24
Design security solutions for infrastructure
QuestionQ25
Design security operations, identity, and compliance capabilities
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
You are designing the encryption standards for data at rest for an Azure resource.
You need to provide recommendations to ensure that the data at rest is encrypted by using AES-256 keys. The solution must support rotating the encryption keys monthly.
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
You are designing the encryption standards for data at rest for an Azure resource.
You need to provide recommendations to ensure that the data at rest is encrypted by using AES-256 keys. The solution must support rotating the encryption keys monthly.
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
You are designing the encryption standards for data at rest for an Azure resource.
You need to provide recommendations to ensure that the data at rest is encrypted by using AES-256 keys. The solution must support rotating the encryption keys monthly.
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
You are designing the encryption standards for data at rest for an Azure resource.
You need to provide recommendations to ensure that the data at rest is encrypted by using AES-256 keys. The solution must support rotating the encryption keys monthly.
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
You must recommend a solution to protect the MedicalHistory data in the ClaimsDetail table. The solution must satisfy the Contoso developer requirements.
What should the recommendation include?
Arow-level security (RLS)
BTransparent Data Encryption (TDE)
CAlways Encrypted
Ddata classification
Edynamic data masking
You have a Microsoft 365 E5 subscription.
You are designing a solution to protect confidential data in Microsoft SharePoint Online sites containing more than one million documents.
You need to recommend a solution that prevents Personally Identifiable Information (PII) from being shared.
Which two components should you include in the recommendation? Each correct answer represents part of the solution.
NOTE: Each correct selection is worth one point.
Choose two
Adata loss prevention (DLP) policies
Bretention label policies
CeDiscovery cases
Dsensitivity label policies
Your company has a Microsoft 365 subscription and uses Microsoft Defender for Identity.
You receive information about incidents related to compromised identities. You need to recommend a solution that exposes several accounts for attackers to exploit. When attackers try to exploit these accounts, an alert must be triggered.
Which Defender for Identity feature should you recommend?
Asensitivity labels
Bcustom user tags
Cstandalone sensors
Dhoneytoken entity tags
You have an Azure subscription containing a Microsoft Sentinel workspace named MWS1 and an Azure Data Lake Storage account named lake1. Firewall log data is ingested into MWS1.
You plan to export historical firewall log data from MWS1 to lake1.
You need to make sure that security analysts can perform threat hunting from MWS1, including the firewall logs stored in lake1 in threat-hunting queries.
What should you configure?
Select
Microsoft Sentinel feature:
Azure resource:
You have an Azure subscription.
You plan to deploy a storage account named storage1 to hold confidential data, and you will apply tags to that confidential data.
You must ensure that access to storage1 can be defined by using the assigned tags.
Which authorization mechanism should you enable, and which resource type should store the data?
Select
Authorization mechanism:
Resource type:
You design cloud-based software-as-a-service (SaaS) solutions.
You need to recommend a recovery solution for ransomware attacks. The solution must adhere to Microsoft Security Best Practices.
What should you recommend doing first?
ADevelop a privileged identity strategy.
BImplement data protection.
CDevelop a privileged access strategy.
DPrepare a recovery plan.
You have a Microsoft 365 tenant.
Recommend a Microsoft 365 Defender solution that improves tenant security and meets these requirements:
Identify users downloading an unusually large number of files from Microsoft SharePoint Online sites who could be attempting data exfiltration.
Block Microsoft Teams messages containing potentially malicious content by using zero-hour auto purge (ZAP).
What should you recommend for each requirement?
Select
Identify data exfiltration attempts:
Block Teams messages:
You plan to implement an Azure environment based on Microsoft Cloud Adoption Framework enterprise-scale landing zone architecture principles. The environment will host three apps with these characteristics:
Each app will have development, test, and production environments.
A separate team will manage each environment.
Each app will store its secrets in Azure Key Vault.
Recommend the number of Azure subscriptions and key vaults to deploy to the application landing zones.
Select
Subscriptions:
Key vaults:
You are developing a ransomware response plan that adheres to Microsoft Security Best Practices.
You need to recommend a solution that minimizes the risk that a ransomware attack will encrypt local user files.
What should you include in the recommendation?
AWindows Defender Device Guard
BMicrosoft Defender for Endpoint
CAzure Files
DBitLocker Drive Encryption (BitLocker)
Eprotected folders
Your company uses an Azure App Service plan to deploy containerized web apps.
You are designing a secure DevOps approach for deploying the web apps to that App Service plan. Recommend how to integrate code-scanning tools into a secure software development lifecycle. Scan the code during these two phases:
Uploading code to repositories
Building containers
Where should code scanning be integrated for each phase?
Select
Uploading code to repositories:
Building containers:
You have two Azure subscriptions, Sub1 and Sub2, that contain the vaults shown in the following table.
You need to design a multi-user authorization (MUA) solution for security operations on the vaults. The solution must meet these requirements:
RSVault1 and RSVault2 must require MUA to disable soft delete, remove MUA protection, and disable immutability.
BackupVault1 and BackupVault2 must require MUA to disable soft delete and remove MUA protection.
What is the minimum number of Resource Guard resources required?
A1
B2
C3
D4
You have a Microsoft 365 E5 subscription and an Azure subscription.
You need to assess the existing environment to improve the overall security posture of these components:
Windows 11 devices managed by Microsoft Intune
Azure Storage accounts
Azure virtual machines
What should you use to evaluate the components?
Select
Windows 11 devices:
Azure virtual machines:
Azure Storage accounts:
You have an Azure subscription that includes multiple Azure Data Lake Storage accounts.
You need to recommend a solution that encrypts the accounts’ content by using service-side encryption and customer-managed keys. The solution must ensure that individual encryption keys are applied at the finest-grained level.
At what level should you recommend applying the encryption?
Afile
Bcontainer
Cfolder
Daccount
Solution: For Azure SQL databases, recommend Transparent Data Encryption (TDE) that uses customer-managed keys (CMKs).
Does this satisfy the goal?
AYes
BNo
Solution: For blob containers in Azure Storage, you recommend encryption that uses Microsoft-managed keys in an encryption scope.
Does this meet the goal?
AYes
BNo
Solution: For Azure SQL databases, recommend Transparent Data Encryption (TDE) using Microsoft-managed keys.
Does this solution meet the goal?
AYes
BNo
Solution: For Azure Storage blob containers, recommend encryption using customer-managed keys (CMKs).
Does this satisfy the goal?
AYes
BNo
Your company has an office in Seattle.
The company has two Azure virtual machine scale sets hosted on separate virtual networks. The company plans to hire contract developers in India.
You need to recommend a solution that gives the developers the ability to connect to the virtual machines over SSL from the Azure portal. The solution must meet the following requirements:
Prevent the virtual machines’ public IP addresses from being exposed.
Provide the ability to connect without using a VPN.
Minimize costs.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
Choose two
ACreate a hub and spoke network by using virtual network peering.
BDeploy Azure Bastion to each virtual network.
CDeploy Azure Bastion to one virtual network.
DCreate NAT rules and network rules in Azure Firewall.
EEnable just-in-time VM access on the virtual machines.
Your company has a main office and 10 branch offices. Each branch office has an on-premises file server running Windows Server and multiple devices running either Windows 11 or macOS. The devices are enrolled in Microsoft Intune.
You have a Microsoft Entra tenant.
You need to deploy Global Secure Access to provide web filtering for device traffic to the internet. The solution must ensure that all web traffic from devices in the branch offices is controlled by using Global Secure Access.
What should you do first at each branch office?
AConfigure an Intune policy to onboard Microsoft Defender for Endpoint to each device.
BConfigure an IPsec tunnel on the router.
CInstall the Microsoft Entra private network connector on the file server.
DConfigure an Intune policy to deploy the Global Secure Access client to each device.
You have a Microsoft Entra tenant containing 10 Windows 11 devices and two groups named Group1 and Group2. The Windows 11 devices are joined to the Microsoft Entra tenant and managed by using Microsoft Intune.
You are designing a privileged-access strategy based on the rapid modernization plan (RaMP). The strategy will include these configurations:
Each user in Group1 will be assigned a Windows 11 device configured as a privileged access device.
The Security Administrator role will be mapped to the privileged access security level.
Users in Group1 will be assigned the Security Administrator role.
Users in Group2 will manage the privileged access devices.
You need to configure the local Administrators group on each privileged access device. The solution must adhere to the principle of least privilege.
What should you include in the solution?
AOnly add Group2 to the local Administrators group.
BConfigure Windows Local Administrator Password Solution (Windows LAPS) in legacy Microsoft LAPS emulation mode.
CAdd Group2 to the local Administrators group. Add the user that is assigned the Security Administrator role to the local Administrators group of the user's assigned privileged access device.
Community Discussion