HOTSPOT
You have an Azure subscription containing an Azure Bastion host and 100 virtual machines running Windows Server 2022. The virtual machines have Microsoft Defender for Servers Plan 2 enabled.
You need to recommend a security solution for the virtual machines that meets the following requirements:
1. Administrators must request RDP access to the virtual machines via the Azure portal.
2. Remote Desktop sessions must be limited to a maximum of three hours.
3. Agentless scanning must be scheduled to run on each virtual machine.
What should you recommend using?
To answer, select the appropriate options in the answer area.Each correct selection is worth one point.

Your company plans to apply the Zero Trust Rapid Modernization Plan (RaMP) to its IT environment.
You need to recommend the top three modernization areas to prioritize as part of the plan.
Which three areas should you recommend based on RaMP? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. data, compliance, and governanceDRAG DROP
You have an Azure subscription that contains a resources group named RG1. RG1 contains multiple Azure Files shares.
You need to recommend a solution to deploy a backup solution for the shares. The solution must meet the following requirements:
1. Prevent the deletion of backups and the vault used to store the backups.
2. Prevent privilege escalation attacks against the backup solution.
3. Prevent the modification of the backup retention period.
Which three actions should you recommend be performed in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Select and Place:

You have an Azure subscription that contains the Azure Virtual Machine Scale Sets shown in the following table.

You are evaluating Azure Update Manager and automatic virtual machine guest patching.
Which virtual machine scale sets will automatic guest patching support?
A. VMSS1 onlyYou are designing a ransomware mitigation strategy.
You perform a ransomware risk assessment and identify business-critical assets.
You need to recommend a solution to mitigate ransomware threats. The solution must follow Microsoft security best practices.
Which two actions should you include in the recommendation? Each correct answer presents a complete solution.
NOTE: Each correct answer is worth one point.
A. Enable firewall logging for auditing, without restricting inbound or outbound traffic.HOTSPOT
You are designing security for a runbook in an Azure Automation account. The runbook will copy data to Azure Data Lake Storage Gen2.
You need to recommend a solution to secure the components of the copy process.
What should you include in the recommendation for each component? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You are designing the security standards for a new Azure environment.
You need to design a privileged identity strategy based on the Zero Trust model.
Which framework should you follow to create the design?
A. Enhanced Security Admin Environment (ESAE)You have a Microsoft 365 subscription that contains a group named Group1. The subscription is linked to a Microsoft Entra ID P1 tenant.
You have an external software as a service (SaaS) application named App1. App1 is managed by using a web-based admin portal and supports the use of Microsoft Entra ID credentials.
You need to ensure that only the members of Group1 who sign in from Microsoft Entra joined devices can access the admin portal of App1.
What should you create first in Microsoft Entra?
A. an enterprise applicationHOTSPOT
Your company plans to follow DevSecOps best practices of the Microsoft Cloud Adoption Framework for Azure to integrate DevSecOps processes into continuous integration and continuous deployment (Cl/CD) DevOps pipelines
You need to recommend which security-related tasks to integrate into each stage of the DevOps pipelines.
What should recommend? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You are creating an application lifecycle management process based on the Microsoft Security Development Lifecycle (SDL).
You need to recommend a security standard for onboarding applications to Azure.
The standard will include recommendations for application design, development, and deployment What should you include during the application design phase?
A. static application security testing (SAST) by using SonarQubeNowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SC-100 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.