SC-100 Exam Details

  • Exam Code
    :SC-100
  • Exam Name
    :Microsoft Cybersecurity Architect
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :350 Q&As
  • Last Updated
    :Jul 12, 2026

Microsoft SC-100 Online Questions & Answers

  • Question 91:

    You manage multiple Azure subscriptions, each containing several resource groups.

    You need to identify the privileged role assignments in each subscription and assess any associated security risks.

    The solution should minimize administrative effort.

    What tool or service should you use?

    A. access reviews in Privileged Identity Management (PIM)
    B. access reviews in Microsoft Entra ID Identity Governance
    C. Microsoft Defender External Attack Surface Management (Defender EASM) discovery
    D. the Analytics dashboard in Microsoft Entra Permissions Management

  • Question 92:

    You have a Microsoft 365 tenant containing two groups: Group1 and Group2.

    You use Microsoft Defender XDR to manage the tenants of your company's customers.

    You need to ensure that users in Group1 can perform security tasks within each customer's tenant while meeting the following requirements:

    1. Users in Group1 must only be assigned the Security Operator role for the customer tenants.

    2. Users in Group2 must have the ability to assign the Security Operator role to Group1 users for the customer tenants.

    3. The use of guest accounts must be minimized.

    4. Administrative effort must be minimized.

    What should you include in the solution?

    A. multi-user authorization (MUA)
    B. Azure Lighthouse
    C. Privileged Identity Management (PIM)
    D. Microsoft Entra B2B collaboration

  • Question 93:

    HOTSPOT

    You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.

    The Azure subscription contains a Microsoft Sentinel workspace. Microsoft Sentinel data connectors are configured for Microsoft 365, Microsoft 365 Defender, Defender for Cloud, and Azure.

    You plan to deploy Azure virtual machines that will run Windows Server.

    You need to enable extended detection and response (EDR) and security orchestration, automation, and response (SOAR) capabilities for Microsoft Sentinel.

    How should you recommend enabling each capability? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

  • Question 94:

    Azure subscription that uses Azure Storage.

    The company plans to share specific blobs with vendors. You need to recommend a solution to provide the vendors with secure access to specific blobs without exposing the blobs publicly. The access must be time-limited.

    What should you include in the recommendation?

    A. Create shared access signatures (SAS).
    B. Share the connection string of the access key.
    C. Configure private link connections.
    D. Configure encryption by using customer-managed keys (CMKs)

  • Question 95:

    HOTSPOT

    You have a Microsoft 365 subscription containing 1,000 users and two groups: Group1 and Group2. All users have devices onboarded to Microsoft Intune and Microsoft Defender for Endpoint. Group1 manages Microsoft Entra and Microsoft 365 services, while Group2 manages Intune and Defender for Endpoint.

    You need to recommend a solution to prevent users from connecting to Microsoft 365 services from devices that have encryption disabled.

    What should you recommend implementing for each group?

    To answer, select the options in the answer area.Each correct answer is worth one point.

  • Question 96:

    A customer has a hybrid cloud infrastructure that contains a Microsoft 365 E5 subscription and an Azure subscription.

    All on-premises servers in the perimeter network are prevented from connecting directly to the internet.

    The customer recently recovered from a ransomware attack.

    The customer plans to deploy Microsoft Sentinel.

    You need to recommend solutions to meet the following requirements:

    1. Ensure that the security operations team can access the security logs and the operation logs.

    2. Ensure that the IT operations team can access only the operations logs, including the event logs of the servers in the perimeter network.

    Which two solutions should you include in the recommendation? Each correct answer presents a complete solution.

    NOTE: Each correct selection is worth one point.

    A. Create a custom collector that uses the Log Analytics agent.
    B. Use the Azure Monitor agent with the multi-homing configuration.
    C. Implement resource-based role-based access control (RBAC) in Microsoft Sentinel.
    D. Configure Azure Active Directory (Azure AD) Conditional Access policies.

  • Question 97:

    You have a Microsoft 365 subscription that uses Microsoft Defender XDR and Microsoft Purview.

    On a Microsoft SharePoint Online site, you have a file named File1 that has a sensitivity label applied.

    You need to recommend a solution that will reevaluate Conditional Access policies when a user downloads Filel from the SharePoint site.

    What should you include in the recommendation?

    A. Microsoft Defender for Cloud Apps
    B. Microsoft Defender for Cloud
    C. Microsoft Defender for Office 365
    D. Microsoft Entra application proxy

  • Question 98:

    HOTSPOT

    You have an Azure subscription that contains multiple apps, which are managed using continuous integration and continuous deployment (CI/CD) pipelines in Azure DevOps.

    You need to recommend DevSecOps controls for the Commit code and Build and test CI/CD process stages, following the Microsoft Cloud Adoption Framework for Azure.

    Which testing method should you recommend for each stage? To answer, select the appropriate options in the answer area.

    Each correct selection is worth one point.

  • Question 99:

    Your company has a Microsoft 365 E5 subscription.

    The company wants to identify and classify data in Microsoft Teams, SharePoint Online, and Exchange Online.

    You need to recommend a solution to identify documents that contain sensitive information.

    What should you include in the recommendation?

    A. data classification content explorer
    B. data loss prevention (DLP)
    C. eDiscovery
    D. Information Governance

  • Question 100:

    You have an Azure subscription. The subscription contains 100 virtual machines that run Linux on Windows Server.

    The subscription uses Microsoft Defender for Servers Plan 1.

    You need to recommend a solution to identify and remediate virtual machines that have the following characteristics:

    1. Are NOT onboarded to Defender for Servers.

    2. Are missing critical updates.

    3. Have risky apps installed.

    The solution must minimize administrative effort.

    What should you include in the recommendation?

    A. Microsoft Defender External Attack Surface Management (Defender EASM)
    B. Microsoft Defender Vulnerability Management
    C. Microsoft Defender Threat Intelligence (Defender TI)
    D. Microsoft Intune Advanced Analytics

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SC-100 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.