Microsoft SC-100 Online Practice
Questions and Exam Preparation
SC-100 Exam Details
Exam Code
:SC-100
Exam Name
:Microsoft Cybersecurity Architect
Certification
:Microsoft Certifications
Vendor
:Microsoft
Total Questions
:350 Q&As
Last Updated
:Jul 12, 2026
Microsoft SC-100 Online Questions &
Answers
Question 91:
You manage multiple Azure subscriptions, each containing several resource groups.
You need to identify the privileged role assignments in each subscription and assess any associated security risks.
The solution should minimize administrative effort.
What tool or service should you use?
A. access reviews in Privileged Identity Management (PIM) B. access reviews in Microsoft Entra ID Identity Governance C. Microsoft Defender External Attack Surface Management (Defender EASM) discovery D. the Analytics dashboard in Microsoft Entra Permissions Management
A. access reviews in Privileged Identity Management (PIM)
Explanation
Azure role assignment integration with Privileged Identity Management is currently in PREVIEW.
Follow these steps:
1. In the Azure portal, click All services and then select the scope. For example, you can select Management groups, Subscriptions, Resource groups, or a resource.
2. Click the specific resource.
3. Click Access control (IAM).
4. Click the Role assignments tab to view the role assignments at this scope.
If you have a Microsoft Entra ID Free or Microsoft Entra ID P1 license, your Role assignments tab is similar to the following screenshot.
You have a Microsoft 365 tenant containing two groups: Group1 and Group2.
You use Microsoft Defender XDR to manage the tenants of your company's customers.
You need to ensure that users in Group1 can perform security tasks within each customer's tenant while meeting the following requirements:
1. Users in Group1 must only be assigned the Security Operator role for the customer tenants.
2. Users in Group2 must have the ability to assign the Security Operator role to Group1 users for the customer tenants.
3. The use of guest accounts must be minimized.
4. Administrative effort must be minimized.
What should you include in the solution?
A. multi-user authorization (MUA) B. Azure Lighthouse C. Privileged Identity Management (PIM) D. Microsoft Entra B2B collaboration
B. Azure Lighthouse
Explanation
Azure Lighthouse includes multiple ways to help streamline engagement and management:
* Azure delegated resource management: Manage your customers' Azure resources securely from within your own tenant, without having to switch context and control planes. Customer subscriptions and resource groups can be delegated to specified users and roles in the managing tenant, with the ability to remove access as needed.
* Etc.
Incorrect:
Not A: Multi-Factor Authentication for Email and Office 365. Multi-Factor authentication (a.k.a. MFA) is a method to help better secure email accounts and Office 365 access. This additional security comes from having to Approve the sign-ins to your account using a mobile device.
You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.
The Azure subscription contains a Microsoft Sentinel workspace. Microsoft Sentinel data connectors are configured for Microsoft 365, Microsoft 365 Defender, Defender for Cloud, and Azure.
You plan to deploy Azure virtual machines that will run Windows Server.
You need to enable extended detection and response (EDR) and security orchestration, automation, and response (SOAR) capabilities for Microsoft Sentinel.
How should you recommend enabling each capability? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Box 1: Onboard the servers to Defender for Cloud.
Extended detection and response (XDR) is a new approach defined by industry analysts that are designed to deliver intelligent, automated, and integrated security across domains to help defenders connect seemingly disparate alerts and get ahead of attackers.
As part of this announcement, we are unifying all XDR technologies under the Microsoft Defender brand. The new Microsoft Defender is the most comprehensive XDR in the market today and prevents, detects, and responds to threats across identities, endpoints, applications, email, IoT, infrastructure, and cloud platforms.
Box 2: Configure Microsoft Sentinel playbooks.
As a SOAR platform, its primary purposes are to automate any recurring and predictable enrichment, response and remediation tasks that are the responsibility of Security Operations Centers (SOC/SecOps). Leveraging SOAR frees up time and resources for more in-depth investigation of and hunting for advanced threats. Automation takes a few different forms in Microsoft Sentinel, from automation rules that centrally manage the automation of incident handling and response to playbooks that run predetermined sequences of actions to provide robust and flexible advanced automation to your threat response tasks.
The company plans to share specific blobs with vendors. You need to recommend a solution to provide the vendors with secure access to specific blobs without exposing the blobs publicly. The access must be time-limited.
What should you include in the recommendation?
A. Create shared access signatures (SAS). B. Share the connection string of the access key. C. Configure private link connections. D. Configure encryption by using customer-managed keys (CMKs)
D. Configure encryption by using customer-managed keys (CMKs)
Question 95:
HOTSPOT
You have a Microsoft 365 subscription containing 1,000 users and two groups: Group1 and Group2. All users have devices onboarded to Microsoft Intune and Microsoft Defender for Endpoint. Group1 manages Microsoft Entra and Microsoft 365 services, while Group2 manages Intune and Defender for Endpoint.
You need to recommend a solution to prevent users from connecting to Microsoft 365 services from devices that have encryption disabled.
What should you recommend implementing for each group?
To answer, select the options in the answer area.Each correct answer is worth one point.
Box 1: A Conditional Access policy Group1 manages Microsoft Entra and Microsoft 365 services.
Microsoft Entra ID, Conditional Access, Common Conditional Access policy: Require a compliant device, Microsoft Entra hybrid joined device, or multifactor authentication for all users Organizations who deploy Microsoft Intune can use the information returned from their devices to identify devices that meet compliance requirements such as:
Requiring a PIN to unlock
*-> Requiring device encryption
Requiring a minimum or maximum operating system version Requiring a device isn't jailbroken or rooted
Box 2: A compliance policy in Intune Group2 manages Intune and Defender for Endpoint.
Device Compliance settings for Windows 10/11 in Intune includes:
* Encryption
Encryption of data storage on a device: This setting applies to all drives on a device.
Not configured (default)
Require - Use Require to encrypt data storage on your devices. DeviceStatus CSP - DeviceStatus/Compliance/EncryptionCompliance
A customer has a hybrid cloud infrastructure that contains a Microsoft 365 E5 subscription and an Azure subscription.
All on-premises servers in the perimeter network are prevented from connecting directly to the internet.
The customer recently recovered from a ransomware attack.
The customer plans to deploy Microsoft Sentinel.
You need to recommend solutions to meet the following requirements:
1. Ensure that the security operations team can access the security logs and the operation logs.
2. Ensure that the IT operations team can access only the operations logs, including the event logs of the servers in the perimeter network.
Which two solutions should you include in the recommendation? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A. Create a custom collector that uses the Log Analytics agent. B. Use the Azure Monitor agent with the multi-homing configuration. C. Implement resource-based role-based access control (RBAC) in Microsoft Sentinel. D. Configure Azure Active Directory (Azure AD) Conditional Access policies.
B. Use the Azure Monitor agent with the multi-homing configuration. C. Implement resource-based role-based access control (RBAC) in Microsoft Sentinel.
Explanation
A: You can collect data in custom log formats to Microsoft Sentinel with the Log Analytics agent.
Note: You can use the Log Analytics agent to collect data in text files of nonstandard formats from both Windows and Linux computers. Once collected, you can either parse the data into individual fields in your queries or extract the data during collection to individual fields.
You can connect your data sources to Microsoft Sentinel using custom log formats.
C: Microsoft Sentinel uses Azure role-based access control (Azure RBAC) to provide built-in roles that can be assigned to users, groups, and services in Azure.
Use Azure RBAC to create and assign roles within your security operations team to grant appropriate access to Microsoft Sentinel. The different roles give you fine-grained control over what Microsoft Sentinel users can see and do. Azure roles can be assigned in the Microsoft Sentinel workspace directly (see note below), or in a subscription or resource group that the workspace belongs to, which Microsoft Sentinel inherits.
Incorrect:
A: You can collect data in custom log formats to Microsoft Sentinel with the Log Analytics agent.
Note: You can use the Log Analytics agent to collect data in text files of nonstandard formats from both Windows and Linux computers. Once collected, you can either parse the data into individual fields in your queries or extract the data during collection to individual fields.
You can connect your data sources to Microsoft Sentinel using custom log formats.
You have a Microsoft 365 subscription that uses Microsoft Defender XDR and Microsoft Purview.
On a Microsoft SharePoint Online site, you have a file named File1 that has a sensitivity label applied.
You need to recommend a solution that will reevaluate Conditional Access policies when a user downloads Filel from the SharePoint site.
What should you include in the recommendation?
A. Microsoft Defender for Cloud Apps B. Microsoft Defender for Cloud C. Microsoft Defender for Office 365 D. Microsoft Entra application proxy
A. Microsoft Defender for Cloud Apps
Question 98:
HOTSPOT
You have an Azure subscription that contains multiple apps, which are managed using continuous integration and continuous deployment (CI/CD) pipelines in Azure DevOps.
You need to recommend DevSecOps controls for the Commit code and Build and test CI/CD process stages, following the Microsoft Cloud Adoption Framework for Azure.
Which testing method should you recommend for each stage? To answer, select the appropriate options in the answer area.
Each correct selection is worth one point.
Box 1: Static application security testing (SAST) Commit the code
Box 2: Dynamic application security testing (DAST) Build and test
"Content explorer. This tab provides visibility into the amount and types of sensitive data in an organization. It also enables users to filter by label or sensitivity type. Doing so displays a detailed view of locations where the sensitive data is stored. It provides admins with the ability to: index the sensitive documents that are stored within supported Microsoft 365 workloads. identify the sensitive information they're storing."
Question 100:
You have an Azure subscription. The subscription contains 100 virtual machines that run Linux on Windows Server.
The subscription uses Microsoft Defender for Servers Plan 1.
You need to recommend a solution to identify and remediate virtual machines that have the following characteristics:
1. Are NOT onboarded to Defender for Servers.
2. Are missing critical updates.
3. Have risky apps installed.
The solution must minimize administrative effort.
What should you include in the recommendation?
A. Microsoft Defender External Attack Surface Management (Defender EASM) B. Microsoft Defender Vulnerability Management C. Microsoft Defender Threat Intelligence (Defender TI) D. Microsoft Intune Advanced Analytics
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Microsoft exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your SC-100 exam preparations
and Microsoft certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.