SC-100 Exam Details

  • Exam Code
    :SC-100
  • Exam Name
    :Microsoft Cybersecurity Architect
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :350 Q&As
  • Last Updated
    :Jul 12, 2026

Microsoft SC-100 Online Questions & Answers

  • Question 191:

    You have a Microsoft 365 subscription.

    You have a Conditional Access policy that has the following settings:

    1. Name: Policy 1

    2. Assignments o Users:

    3. Include: All users o Target resources

    4. Include: Select apps; Office

    365. o Network

    5. Include: Any network or location.

    6. Exclude: Selected networks and locations; Site1. o Access controls

    7. Grant: Require multifactor authentication, Require Hybrid Microsoft Entra joined device.

    You plan to implement Zero Trust Rapid Modernization Plan (RaMP).

    You need to ensure that Policy1 aligns with best practice recommendations in RaMP.

    Which setting should you change?

    A. Include: Any network or location
    B. Exclude: Selected networks and locations; Site1
    C. Grant Require Hybrid Microsoft Entra joined device
    D. Grant: Require multifactor authentication

  • Question 192:

    You have 50 Azure subscriptions.

    You need to monitor the resource in the subscriptions for compliance with the ISO 27001:2013 standards. The solution must minimize the effort required to modify the list of monitored policy definitions for the subscriptions.

    What are two ways to achieve the goal? Each correct answer presents a complete solution.

    NOTE: Each correct selection is worth one point.

    A. Assign an initiative to a management group.
    B. Assign a policy to each subscription.
    C. Assign a policy to a management group.
    D. Assign an initiative to each subscription.
    E. Assign a blueprint to each subscription.
    F. Assign a blueprint to a management group.

  • Question 193:

    HOTSPOT

    Your company has a multi-cloud environment that contains a Microsoft 365 subscription, an Azure subscription, and Amazon Web Services (AWS) implementation.

    You need to recommend a security posture management solution for the following components:

    1. Azure IoT Edge devices

    2. AWS EC2 instances

    Which services should you include in the recommendation? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

  • Question 194:

    You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.

    The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019.

    You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application.

    Which security control should you recommend?

    A. adaptive application controls in Defender for Cloud
    B. app protection policies in Microsoft Endpoint Manager
    C. app discovery anomaly detection policies in Microsoft Defender for Cloud Apps
    D. Azure Security Benchmark compliance controls in Defender for Cloud

  • Question 195:

    You have a Microsoft 365 subscription that includes 1,000 users, each assigned a Microsoft 365 E5 license.

    The subscription utilizes sensitivity labels to classify corporate documents. All users have Windows 11 devices, which are onboarded to Microsoft Defender for Endpoint, and are configured to sync files to Microsoft OneDrive.

    You need to prevent users from uploading documents from OneDrive to external websites.

    What should you include in the solution?

    A. Microsoft Purview Information Protection
    B. Microsoft Purview data loss prevention (DLP)
    C. web content filtering in Defender for Endpoint
    D. an endpoint security policy

  • Question 196:

    DRAG DROP

    You need to design a solution to accelerate a Zero Trust security implementation. The solution must be based on the Zero Trust Rapid Modernization Plan (RaMP).

    Which three initiatives should you include in the solution, and in which order should you implement the initiatives?

    Each correct answer presents part of the solution. Each correct selection is worth one point.

    Select and Place:

  • Question 197:

    Your company has a main office and 10 branch offices. Each branch office contains an on-premises file server that runs Windows Server and multiple devices that run either Windows 11 or macOS. The devices are enrolled in Microsoft Intune.

    You have a Microsoft Entra tenant.

    You need to deploy Global Secure Access to implement web filtering for device traffic to the internet.

    The solution must ensure that all the web traffic from the devices in the branch offices is controlled by using Global Secure Access.

    What should you do first in each branch office?

    A. Configure an Intune policy to deploy the Global Secure Access client to each device.
    B. Configure an IPsec tunnel on the router.
    C. Install the Microsoft Entra private network connector on the file server.
    D. Configure an Intune policy to onboard Microsoft Defender for Endpoint to each device.

  • Question 198:

    Your company is developing a serverless application in Azure that will have the architecture shown in the following exhibit.

    You need to recommend a solution to isolate the compute components on an Azure virtual network.

    What should you include in the recommendation?

    A. Microsoft Entra enterprise applications
    B. an Azure App Service Environment (ASE)
    C. Azure service endpoints
    D. an Azure Active Directory (Azure AD) application proxy

  • Question 199:

    HOTSPOT

    You have an Azure subscription that contains an Azure Kubernetes Service (AKS) cluster named AKS1.

    AKS1 hosts a Windows node pool named Pool1 and a Linux node pool named Pool2.

    You are designing a pool update strategy for AKS1.

    You need to recommend how often to replace the operating system images deployed to the nodes.

    The solution must meet the following requirements:

    1. Minimize how long it takes to apply operating system updates once the updates are released.

    2. Minimize administrative effort.

    What should you recommend for each pool? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

  • Question 200:

    You have an Azure subscription that contains a web app named App1. App1 uses a Microsoft Entra user account named SRV1 as a service account to authenticate to an Azure SQL database named DB1.

    You discover that a developer accessed DB1 directly by using SRV1.

    You need to recommend a secure authentication method that will prevent credential misuse outside of App1. The solution must minimize administrative effort.

    What should you recommend?

    A. a managed identity
    B. a group managed service account (gMSA)
    C. a delegated managed service account (dMSA)
    D. a federated identity credential

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SC-100 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.