Microsoft SC-100 Online Practice
Questions and Exam Preparation
SC-100 Exam Details
Exam Code
:SC-100
Exam Name
:Microsoft Cybersecurity Architect
Certification
:Microsoft Certifications
Vendor
:Microsoft
Total Questions
:350 Q&As
Last Updated
:Jul 12, 2026
Microsoft SC-100 Online Questions &
Answers
Question 181:
You need to design a strategy for securing the SharePoint Online and Exchange Online data. The solution must meet the application security requirements.
Which two services should you leverage in the strategy? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. Microsoft Entra Conditional Access B. Microsoft Entra Access Review C. Microsoft Defender for Cloud D. Microsoft Defender for Cloud Apps E. Microsoft Defender for Endpoint
A. Microsoft Entra Conditional Access D. Microsoft Defender for Cloud Apps
Explanation
A. Azure AD Conditional Access: Azure AD Conditional Access allows you to define policies and rules that control access to your applications and services based on specific conditions. You can use it to enforce multi-factor authentication, device compliance, location-based access, and more, providing advanced security controls for your SharePoint Online and Exchange Online resources.
D. Microsoft Defender for Cloud Apps (formerly known as Microsoft Cloud App Security): This service provides advanced security features for cloud applications, including Office 365 apps like SharePoint Online and Exchange Online. It helps you monitor user activities, control access, and detect and respond to threats in these applications, ensuring the security of your data.
You have a Microsoft Entra tenant linked to a Microsoft 365 subscription and an Azure subscription. The tenant contains service principals that are used to access applications in the Azure subscription.
You need to recommend a solution to detect risky sign-ins and other risky activities performed by the service principals in the tenant. The solution must minimize costs.
What should you include in the recommendation?
To answer, select the appropriate options in the answer area. Each correct selection is worth one point.
Question 183:
Your company has on-premises Microsoft SQL Server databases.
The company plans to move the databases to Azure.
You need to recommend a secure architecture for the databases that will minimize operational requirements for patching and protect sensitive data by using dynamic data masking. The solution must minimize costs.
What should you include in the recommendation?
A. SQL Server on Azure Virtual Machines B. Azure Synapse Analytics dedicated SQL pools C. Azure SQL Database
C. Azure SQL Database
Explanation
Azure SQL Database, Azure SQL Managed Instance, and Azure Synapse Analytics support dynamic data masking. Dynamic data masking limits sensitive data exposure by masking it to non-privileged users.
Azure SQL Database is cheaper as its offer DTU's based tier and also vCore based for more intensive workflow.
Hovewer, Managed Instance offers almost ~100% compatibility with on-prem Microsoft SQL Server.
Incorrect:
Not A: SQL Server does not support dynamic data masking.
Not B: Synapse Analytics is more expensive compared to Azure SQL Database.
Your company wants to optimize using Microsoft Defender for Endpoint to protect its resources against ransomware based on Microsoft Security Best Practices.
You need to prepare a post-breach response plan for compromised computers based on the Microsoft Detection and Response Team (DART) approach in Microsoft Security Best Practices.
What should you include in the response plan?
A. controlled folder access B. application isolation C. memory scanning D. machine isolation E. user isolation
D. machine isolation
Explanation
If a ransomware attack is detected the affected entity should immediately activate its security incident response plan, which should include measures to isolate the infected computer systems in order to halt propagation of the attack.
Note: Isolate devices from the network Depending on the severity of the attack and the sensitivity of the device, you might want to isolate the device from the network. This action can help prevent the attacker from controlling the compromised device and performing further activities such as data exfiltration and lateral movement.
1. Set up multi-user authorization (MUA) for Vault1 using a resource guard deployed in Sub2.
2. Enable all available MUA controls for Vault1.
3. In the contoso.com tenant, create a Privileged Identity Management (PIM) assignment called Assignment1.
4. Configure Assignment1 to allow Group1 to activate the Contributor role for Vault1.
For each of the following statements, select Yes if the statements is true. Otherwise, select No.Each correct selection is worth one point.
Box 1: No
No - To enable MUA for Vault1, a resource guard must be deployed to Sub1.
The Backup vault is in Sub1.
You create a Resource Guard in a different tenant than the Backup Fault, to get maximum protection.
Note: The Security admin creates the Resource Guard. We recommend that you create it in a different subscription or a different tenant as the vault. However, it should be in the same region as the vault.
Box 2: Yes
Yes - A user in Group2 must approve changes-made by a user in Group1 to the backup policies of Vault1.
Group1 has administrators who manage Backup for Sub1.
Group2 has administrators who manage security for Sub1 and Sub2.
Note: Select operations to protect using Resource Guard Choose the operations you want to protect using the Resource Guard out of all supported critical operations. By default, all supported critical operations are enabled. However, you (as the security admin) can exempt certain operations from falling under the purview of MUA using Resource Guard.
To exempt operations, follow these steps:
1. In the Resource Guard, go to Properties > Recovery Services vault tab.
2. Select Disable for operations that you want to exclude from being authorized using the Resource Guard.
Note
You can't disable the protected operations - Disable soft delete and Remove MUA protection.
3. Optionally, you can also update the description for the Resource Guard using this blade.
4. Select Save.
Box 3: No
No - A user in Group1 that activates Assignment1 can disable soft for the backups of Vault1, without the approval of a user in Group2.
You can't disable the protected operations - Disable soft delete and Remove MUA protection.
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are designing a security strategy for providing access to Azure App Service web apps through an Azure Front Door instance.
You need to recommend a solution to ensure that the web apps only allow access through the Front Door instance.
Solution: You recommend access restrictions to allow traffic from the backend IP address of the Front Door instance.
Does this meet the goal?
A. Yes B. No
B. No
Explanation
Correct Solution: You recommend access restrictions based on HTTP headers that have the Front Door ID.
Restrict access to a specific Azure Front Door instance.
Traffic from Azure Front Door to your application originates from a well-known set of IP ranges defined in the AzureFrontDoor.Backend service tag. Using a service tag restriction rule, you can restrict traffic to only originate from Azure Front Door. To ensure traffic only originates from your specific instance, you will need to further filter the incoming requests based on the unique http header that Azure Front Door sends.
Your company plans to move all on-premises virtual machines to Azure. A network engineer proposes the Azure virtual network design shown in the following table.
You need to recommend an Azure Bastion deployment to provide secure remote access to all the virtual machines.
Based on the virtual network design, how many Azure Bastion subnets are required?
You enable the Defender Cloud Security Posture Management (CSPM) plan.
You need to optimize the security posture of the subscription by implementing Microsoft Defender for Cloud secure score recommendations.
Which security policy should you enable, and which factors will have a direct impact on the secure score? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Question 189:
You have an operational model based on the Microsoft Cloud Adoption Framework for Azure.
You need to recommend a solution that focuses on cloud-centric control areas to protect resources such as endpoints, databases, files, and storage accounts.
What should you include in the recommendation?
A. business resilience B. modem access control C. network isolation D. security baselines in the Microsoft Cloud Security Benchmark
D. security baselines in the Microsoft Cloud Security Benchmark
Explanation
The Microsoft cloud security benchmark (MCSB) provides prescriptive best practices and recommendations to help improve the security of workloads, data, and services on Azure and your multi-cloud environment. This benchmark focuses on cloud-centric control areas with input from a set of holistic Microsoft and industry security guidance.
Controls include:
* Endpoint Security (ES)
Endpoint Security covers controls in endpoint detection and response, including use of endpoint detection and response (EDR) and anti-malware service for endpoints in cloud environments.
* Data Protection (DP)
Data Protection covers control of data protection at rest, in transit, and via authorized access mechanisms, including discover, classify, protect, and monitor sensitive data assets using access control, encryption, key management and certificate management.
You need to recommend a solution to meet the compliance requirements.
What should you include in the recommendation? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Box 1: A blueprint
Scenario: Requirements. Compliance Requirements
Fabrikam wants to automatically remediate the virtual machines in Sub1 to be compliant with the HIPAA HITRUST standard.
Microsoft releases automation for HIPAA/HITRUST compliance
I am excited to share our new Azure Security and Compliance Blueprint for HIPAA/HITRUST - Health Data & AI. Microsoft's Azure Blueprints are resources to help build and launch cloud-powered applications that comply with stringent regulations and standards. Included in the blueprints are reference architectures, compliance guidance and deployment scripts.
An Azure Blueprint is a package for creating specific sets of standards and requirements that govern the implementation of Azure services, security, and design. Such packages are reusable so that consistency and compliance among resources can be maintained.
Incorrect:
* not Workflow automation
Workflow automation is an approach to making the flow of tasks, documents and information across work-related activities perform independently in accordance with defined business rules.
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Microsoft exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your SC-100 exam preparations
and Microsoft certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.