SC-100 Exam Details

  • Exam Code
    :SC-100
  • Exam Name
    :Microsoft Cybersecurity Architect
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :350 Q&As
  • Last Updated
    :Jul 12, 2026

Microsoft SC-100 Online Questions & Answers

  • Question 141:

    You have an Azure subscription that contains virtual machines, storage accounts, and Azure SQL databases.

    All resources are backed up multiple times a day by using Azure Backup.

    You are developing a strategy to protect against ransomware attacks.

    You need to recommend which controls must be enabled to ensure that Azure Backup can be used to restore the resources in the event of a successful ransomware attack.

    Which two controls should you include in the recommendation? Each correct answer presents a complete solution.

    NOTE: Each correct selection is worth one point.

    A. Enable soft delete for backups.
    B. Require PINs for critical operations.
    C. Encrypt backups by using customer-managed keys (CMKs).
    D. Perform offline backups to Azure Data Box.
    E. Use Azure Monitor notifications when backup configurations change.

  • Question 142:

    HOTSPOT

    You have the resources shown in the following table.

    You need to configure multi-user authorization (MUA) for Azure Backup to protect the Recovery Services vaults.

    The solution must maximize the security of the MUA configuration.

    To which location should you deploy Resource Guard, and which role-based access control (RBAC) role should you assign to the team responsible for managing the backup of Resource Guard? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

  • Question 143:

    You have a Microsoft 365 subscription with 1,000 Microsoft Exchange Online mailboxes.

    Incoming email from the internet is currently scanned for security threats by a third-party cloud service.

    You are evaluating the possibility of replacing the third-party service with Microsoft Defender for Office 365.

    What should you modify to ensure that all incoming email is scanned exclusively by Defender for Office 365?

    A. the accepted domains in Exchange Online
    B. the DNS records
    C. the Exchange Online transport rule
    D. the Exchange Online connectors

  • Question 144:

    HOTSPOT

    You need to recommend a multi-tenant and hybrid security solution that meets to the business requirements and the hybrid requirements.

    What should you recommend? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

  • Question 145:

    Your company has a Microsoft 365 E5 subscription.

    The company plans to deploy 45 mobile self-service kiosks that will run Windows 10.

    You need to provide recommendations to secure the kiosks. The solution must meet the following requirements:

    1. Ensure that only authorized applications can run on the kiosks.

    2. Regularly harden the kiosks against new threats.

    Which two actions should you include in the recommendations? Each correct answer presents part of the solution.

    NOTE: Each correct selection is worth one point.

    A. Implement Automated investigation and Remediation (AIR) in Microsoft Defender for Endpoint.
    B. Onboard the kiosks to Microsoft intune and Microsoft Defender for Endpoint.
    C. Implement threat and vulnerability management in Microsoft Defender for Endpoint.
    D. Onboard the kiosks to Azure Monitor.
    E. Implement Privileged Access Workstation (PAW) for the kiosks.

  • Question 146:

    You have an Azure subscription that has Microsoft Defender for Cloud enabled.

    You need to enforce ISO 27001:2013 standards for new resources deployed to the subscription. The solution must ensure that noncompliant resources are automatically detected.

    What should you use?

    A. Azure Policy
    B. Azure Blueprints
    C. the regulatory compliance dashboard in Defender for Cloud
    D. Azure role-based access control (Azure RBAC)

  • Question 147:

    HOTSPOT

    You have 1,000 on-premises servers running Windows Server 2022 and 500 on-premises servers running Linux.

    Your Azure subscription contains the following resources:

    1. A Log Analytics workspace

    2. A Microsoft Defender Cloud Security Posture Management (CSPM) plan

    You need to deploy Update Management for the servers.

    What should you configure? To answer, select the appropriate options in the answer area. Each correct selection is worth one point.

  • Question 148:

    Your company has a hybrid cloud infrastructure.

    The company plans to hire several temporary employees within a brief period. The temporary employees will need to access applications and data on the company' premises network.

    The company's security policy prevents the use of personal devices for accessing company data and applications.

    You need to recommend a solution to provide the temporary employee with access to company resources. The solution must be able to scale on demand.

    What should you include in the recommendation?

    A. Deploy Azure Virtual Desktop, Azure AD Conditional Access, and Microsoft Defender for Cloud Apps.
    B. Redesign the VPN infrastructure by adopting a split tunnel configuration.
    C. Deploy Microsoft Endpoint Manager and Azure AD Conditional Access.
    D. Migrate the on-premises applications to cloud-based applications.

  • Question 149:

    Your company has 10 branch offices, each with a local internet connection that uses a static IP address.

    You have an Azure subscription containing a storage account named storage1 that stores blobs. Users in the branch offices access the blobs via the internet.

    You need to recommend a solution that ensures the data in storage1 is accessible only from the branch office static IP addresses, while minimizing costs.

    What should you include in the recommendation?

    A. Azure Private Link
    B. an Azure Firewall policy
    C. Azure Storage firewall rules
    D. a network security group (NSG)

  • Question 150:

    HOTSPOT

    You have an Azure DevOps organization that is used to manage the development and deployment of internal apps to multiple Azure subscriptions. You need to implement a DevSecOps strategy based on Microsoft Cloud Adoption Framework

    for Azure principles. The solution must meet the following requirements:

    All pull requests must be enforced.

    All deployments to production must be approved.

    What should you include in the solution for each requirement? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SC-100 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.