Exam Details

  • Exam Code
    :SC-100
  • Exam Name
    :Microsoft Cybersecurity Architect
  • Certification
    :Microsoft Certified: Cybersecurity Architect Expert
  • Vendor
    :Microsoft
  • Total Questions
    :180 Q&As
  • Last Updated
    :Apr 29, 2024

Microsoft Microsoft Certified: Cybersecurity Architect Expert SC-100 Questions & Answers

  • Question 1:

    You need to recommend a solution to scan the application code. The solution must meet the application development requirements. What should you include in the recommendation?

    A. Azure Key Vault

    B. GitHub Advanced Security

    C. Application Insights in Azure Monitor

    D. Azure DevTest Labs

  • Question 2:

    To meet the application security requirements, which two authentication methods must the applications support? Each correct answer presents a complete solution.

    NOTE: Each correct selection is worth one point.

    A. Security Assertion Markup Language (SAML)

    B. NTLMv2

    C. certificate-based authentication

    D. Kerberos

  • Question 3:

    You need to design a strategy for securing the SharePoint Online and Exchange Online data. The solution must meet the application security requirements.

    Which two services should you leverage in the strategy? Each correct answer presents part of the solution.

    NOTE: Each correct selection is worth one point.

    A. Azure AD Conditional Access

    B. access reviews in Azure AD

    C. Microsoft Defender for Cloud

    D. Microsoft Defender for Cloud Apps

    E. Microsoft Defender for Endpoint

  • Question 4:

    You need to recommend a solution for securing the landing zones. The solution must meet the landing zone requirements and the business requirements. What should you configure for each landing zone?

    A. Azure DDoS Protection Standard

    B. an Azure Private DNS zone

    C. Microsoft Defender for Cloud

    D. an ExpressRoute gateway

  • Question 5:

    You need to recommend a solution to meet the security requirements for the InfraSec group. What should you use to delegate the access?

    A. a subscription

    B. a custom role-based access control (RBAC) role

    C. a resource group

    D. a management group

  • Question 6:

    You need to recommend a solution to meet the security requirements for the virtual machines. What should you include in the recommendation?

    A. an Azure Bastion host

    B. a network security group (NSG)

    C. just-in-time (JIT) VM access

    D. Azure Virtual Desktop

  • Question 7:

    You need to recommend a solution to secure the MedicalHistory data in the ClaimsDetail table. The solution must meet the Contoso developer requirements.

    What should you include in the recommendation?

    A. row-level security (RLS)

    B. Transparent Data Encryption (TDE)

    C. Always Encrypted

    D. data classification

    E. dynamic data masking

  • Question 8:

    You have an on-premises datacenter and an Azure Kubernetes Service (AKS) cluster named AKS1.

    You need to restrict internet access to the public endpoint of AKS1. The solution must ensure that AKS1 can be accessed only from the public IP addresses associated with the on-premises datacenter.

    What should you use?

    A. a private endpoint

    B. a network security group (NSG)

    C. a service endpoint

    D. an authorized IP range

  • Question 9:

    You have an Azure subscription. The subscription contains 50 virtual machines that run Windows Server and 50 virtual machines that run Linux.

    You need to perform vulnerability assessments on the virtual machines. The solution must meet the following requirements:

    Identify missing updates and insecure configurations. Use the Qualys engine.

    What should you use?

    A. Microsoft Defender for Servers

    B. Microsoft Defender Threat Intelligence (Defender TI)

    C. Microsoft Defender for Endpoint

    D. Microsoft Defender External Attack Surface Management (Defender EASM)

  • Question 10:

    You have a Microsoft 365 subscription.

    You need to design a solution to block file downloads from Microsoft SharePoint Online by authenticated users on unmanaged devices.

    Which two services should you include in the solution? Each correct answer presents part of the solution.

    NOTE: Each correct selection is worth one point.

    A. Azure AD Conditional Access

    B. Azure Data Catalog

    C. Microsoft Purview Information Protection

    D. Azure AD Application Proxy

    E. Microsoft Defender for Cloud Apps

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SC-100 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.