SC-100 Exam Details

  • Exam Code
    :SC-100
  • Exam Name
    :Microsoft Cybersecurity Architect
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :350 Q&As
  • Last Updated
    :Jul 12, 2026

Microsoft SC-100 Online Questions & Answers

  • Question 171:

    HOTSPOT

    You are evaluating the security of ClaimsApp.

    For each of the following statements, select Yes if the statement is true. Otherwise, select No.

    NOTE: Each correct selection is worth one point.

  • Question 172:

    Your company is developing an invoicing application that will use Azure Active Directory (Azure AD) B2C. The application will be deployed as an App Service web app.

    You need to recommend a solution to the application development team to secure the application from identity-related attacks.

    Which two configurations should you recommend? Each correct answer presents part of the solution.

    NOTE: Each correct selection is worth one point.

    A. Azure AD workbooks to monitor risk detections
    B. Azure AD Conditional Access integration with user flows and custom policies
    C. smart account lockout in Azure AD B2C
    D. access packages in Identity Governance
    E. custom resource owner password credentials (ROPC) flows in Azure AD B2C

  • Question 173:

    You have an Azure subscription that contains SQL Server on Azure virtual machines located in the West US Azure region. The virtual machines are only accessible by using private IP addresses.

    You plan to deploy a Windows-based Azure App Service web apps in the East US Azure region.

    You need to recommend a solution to provide the web apps access to the SQL Server databases.

    What should you include in the recommendation?

    A. an Azure VPN gateway
    B. a private endpoint
    C. a service endpoint
    D. an Azure Bastion host

  • Question 174:

    HOTSPOT

    You are designing new Azure applications based on security best practices from the Microsoft Cloud Adoption Framework for Azure.

    Each application will be deployed to a dedicated and secure environment that will contain isolated instances of the following key Azure security resources:

    1. Azure Key Vault

    2. Virtual networks

    3. An Azure subscription

    4. Azure Policy assignments

    5. Network security groups (NSGs)

    6. Role-based access control (RBAC) assignments.

    You need to recommend which type of environment and which module to use to deploy the applications.

    The solution must use infrastructure as code (IaC) to deploy each application environment.

    What should you recommend? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

  • Question 175:

    Your on-premises network contains an Active Directory Domain Services (AD DS) domain and a hybrid deployment between a Microsoft Exchange Server 2019 organization and an Exchange Online tenant. The AD DS domain contains a group named Group1. Group1 is a member of the Organization Management role group for the Exchange deployment.

    You have a Microsoft 365 E5 subscription that uses Microsoft Defender.

    You have an Azure subscription that uses Microsoft Sentinel.

    You need to recommend a solution to ensure that Group1 is marked as a sensitive group and that any changes made to Group1 raises an alert in Microsoft Sentinel. The solution must minimize administrative effort.

    What should you include in the recommendation?

    A. Microsoft Entra ID Protection
    B. Microsoft Defender for Identity
    C. Microsoft Defender for Office 365
    D. Microsoft Entra Privileged Identity Management (PIM)

  • Question 176:

    You have an Azure subscription that contains virtual machines.

    Port 3389 and port 22 are disabled for outside access.

    You need to design a solution to provide administrators with secure remote access to the virtual machines. The solution must meet the following requirements:

    1. Prevent the need to enable ports 3389 and 22 from the internet.

    2. Only provide permission to connect the virtual machines when required.

    3. Ensure that administrators use the Azure portal to connect to the virtual machines.

    Which two actions should you include in the solution? Each correct answer presents part of the solution.

    NOTE: Each correct selection is worth one point.

    A. Configure Azure VPN Gateway.
    B. Enable Just Enough Administration (JEA).
    C. Configure Azure Bastion.
    D. Enable just-in-time (JIT) VM access.
    E. Enable Azure AD Privileged Identity Management (PIM) roles as virtual machine contributors.

  • Question 177:

    HOTSPOT

    You have a hybrid cloud infrastructure.

    You plan to deploy the Azure applications shown in the following table.

    What should you use to meet the requirement of each app? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

  • Question 178:

    You have a Microsoft 365 subscription. You have an Azure subscription.

    You need to implement a Microsoft Purview communication compliance solution for Microsoft Teams and Yammer. The solution must meet the following requirements:

    1. Assign compliance policies to Microsoft 365 groups based on custom Microsoft Exchange Online attributes.

    2. Minimize the number of compliance policies

    3. Minimize administrative effort

    What should you include in the solution?

    A. Azure AD Information Protection labels
    B. Microsoft 365 Defender user tags
    C. adaptive scopes
    D. administrative units

  • Question 179:

    You have an Azure subscription that has Microsoft Defender for Cloud enabled. Suspicious authentication activity alerts have been appearing in the Workload protections dashboard.

    You need to recommend a solution to evaluate and remediate the alerts by using workflow automation. The solution must minimize development effort.

    What should you include in the recommendation?

    A. Azure Monitor webhooks
    B. Azure Logics Apps
    C. Azure Event Hubs
    D. Azure Functions apps

  • Question 180:

    HOTSPOT

    You have an Azure subscription that contains the resources shown in the following table.

    You need to recommend a network security solution for App1. The solution must meet the following requirements:

    1. Only the virtual machines that are connected to Subnet1 must be able to connect to D81.

    2. DB1 must be inaccessible from the internet

    3. Costs must be minimized.

    What should you include in the recommendation? To answer, select the options in the answer area. NOTE: Each correct answer is worth one point.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SC-100 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.