SC-100 Exam Details

  • Exam Code
    :SC-100
  • Exam Name
    :Microsoft Cybersecurity Architect
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :350 Q&As
  • Last Updated
    :Jul 12, 2026

Microsoft SC-100 Online Questions & Answers

  • Question 101:

    DRAG DROP

    You have a hybrid Azure AD tenant that has pass-through authentication enabled.

    You are designing an identity security strategy.

    You need to minimize the impact of brute force password attacks and leaked credentials of hybrid identities.

    What should you include in the design?

    To answer, drag the appropriate features to the correct requirements. Each feature may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

    NOTE: Each correct selection is worth one point.

    Select and Place:

  • Question 102:

    Your company has a hybrid cloud infrastructure that contains an on-premises Active Directory Domain Services (AD DS) forest, a Microsoft 365 subscription, and an Azure subscription.

    The company's on-premises network contains internal web apps that use Kerberos authentication. Currently, the web apps are accessible only from the network.

    You have remote users who have personal devices that run Windows 11.

    You need to recommend a solution to provide the remote users with the ability to access the web apps. The solution must meet the following requirements:

    1. Prevent the remote users from accessing any other resources on the network.

    2. Support Azure Active Directory (Azure AD) Conditional Access.

    3. Simplify the end-user experience.

    What should you include in the recommendation?

    A. Microsoft Entra Application Proxy
    B. web content filtering in Microsoft Defender for Endpoint
    C. Microsoft Tunnel for Microsoft Intune
    D. Azure Virtual WAN

  • Question 103:

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

    You have an Azure subscription that has Microsoft Defender for Cloud enabled.

    You are evaluating the Azure Security Benchmark V3 report.

    In the Secure management ports controls, you discover that you have 0 out of a potential 8 points.

    You need to recommend configurations to increase the score of the Secure management ports controls.

    Solution: You recommend enabling adaptive network hardening.

    Does this meet the goal?

    A. Yes
    B. No

  • Question 104:

    HOTSPOT

    You have an on-premises datacenter. The datacenter contains a server named Server1 that runs Windows Server 2022 and a firewall that prevents Server1 from connecting to the internet.

    You have an Azure subscription named Sub1.

    You need to recommend a resiliency strategy for Server1 that incorporates a backup plan to transfer the data from Server1 to Sub1.

    What should you include in the recommendation? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

  • Question 105:

    You have a customer that has a Microsoft 365 subscription and an Azure subscription.

    The customer has devices that run either Windows, iOS, Android, or macOS. The Windows devices are deployed on-premises and in Azure.

    You need to design a security solution to assess whether all the devices meet the customer's compliance rules.

    What should you include in the solution?

    A. Microsoft Defender for Endpoint
    B. Microsoft Endpoint Manager
    C. Microsoft Information Protection
    D. Microsoft Sentinel

  • Question 106:

    HOTSPOT

    Your company has an Azure App Service plan that is used to deploy containerized web apps.

    You are designing a secure DevOps strategy for deploying the web apps to the App Service plan.

    You need to recommend a strategy to integrate code scanning tools into a secure software development lifecycle. The code must be scanned during the following two phases:

    1. Uploading the code to repositories

    2. Building containers

    Where should you integrate code scanning for each phase? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

  • Question 107:

    You have a multicloud environment that contains an Azure subscription, an Amazon Web Services (AWS) subscription, and a Google Cloud Platform (GCP) subscription.

    You plan to assess data security and compliance.

    You need to design a Compliance Manager solution that meets the following requirements: Provides recommended improvement actions that include detailed implementation guidance

    Automatically monitors regulatory compliance

    Minimizes administrative effort

    What should you include in the solution?

    A. Microsoft Defender for Cloud
    B. Microsoft Defender for Cloud Apps
    C. Microsoft Sentinel
    D. Compliance Manager connectors

  • Question 108:

    You have 10 Azure subscriptions that contain 100 role-based access control (RBAC) role assignments.

    You plan to consolidate the role assignments.

    You need to recommend a solution to identify which role assignments were NOT used during the last 90 days. The solution must minimize administrative effort.

    What should you include in the recommendation?

    A. Microsoft Defender for Cloud
    B. Microsoft Entra access reviews
    C. Microsoft Entra Privileged Identity Management (PIM)
    D. Microsoft Entra Permissions Management

  • Question 109:

    HOTSPOT

    You have multiple on-premises Hyper-V hosts running virtual machines that use Windows Server 2022.

    You have an Azure subscription and need to recommend a solution to collect Security event logs from the virtual machines using Microsoft Sentinel. The solution must meet the following requirements:

    1. Leverage the Windows Security Events via the Azure Monitor Agent (AMA) data connector.

    2. Ensure that only specific events are collected.

    3. Minimize costs.

    What should you recommend? To answer, select the appropriate options in the answer area.

    Each correct selection is worth one port.

  • Question 110:

    You have an Azure AD tenant that syncs with an Active Directory Domain Services (AD DS) domain.

    You are designing an Azure DevOps solution to deploy applications to an Azure subscription by using continuous integration and continuous deployment (CI/CD) pipelines.

    You need to recommend which types of identities to use for the deployment credentials of the service connection.

    The solution must follow DevSecOps best practices from the Microsoft Cloud Adoption Framework for Azure.

    What should you recommend?

    A. a managed identity in Azure
    B. an Azure AD user account that has role assignments in Azure AD Privileged Identity Management (PIM)
    C. a group managed service account (gMSA)
    D. an Azure AD user account that has a password stored in Azure Key Vault

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SC-100 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.