SC-100 Exam Details

  • Exam Code
    :SC-100
  • Exam Name
    :Microsoft Cybersecurity Architect
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :350 Q&As
  • Last Updated
    :Jul 12, 2026

Microsoft SC-100 Online Questions & Answers

  • Question 211:

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

    You are designing the encryption standards for data at rest for an Azure resource.

    You need to provide recommendations to ensure that the data at rest is encrypted by using AES-256 keys. The solution must support rotating the encryption keys monthly.

    Solution: For blob containers in Azure Storage, you recommend encryption that uses Microsoft-managed keys within an encryption scope.

    Does this meet the goal?

    A. Yes
    B. No

  • Question 212:

    HOTSPOT

    You have an Azure subscription that contains a Microsoft Sentinel workspace named MWS1 and an Azure Data Lake Storage account named lake1. Firewall log data is ingested into MWS1.

    You plan to export historical firewall log data from MWS1 to lake1.

    You need to ensure that security analysts can perform threat hunting from MWS1. The solution must ensure that the firewall logs stored in lake1 can be included in threat hunting queries.

    What should you configure? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

  • Question 213:

    You have an Azure subscription with several Azure Data Lake Storage accounts.

    You are tasked with recommending a solution to encrypt the contents of these accounts using server-side encryption and customer-managed keys.

    The solution must ensure that encryption keys are applied at the finest level of granularity.

    At which level should you recommend applying the encryption?

    A. file
    B. container
    C. folder
    D. account

  • Question 214:

    You design cloud-based software as a service (SaaS) solutions.

    You need to recommend a recovery solution for ransomware attacks. The solution must follow Microsoft Security Best Practices.

    What should you recommend doing first?

    A. Develop a privileged identity strategy.
    B. Implement data protection.
    C. Develop a privileged access strategy.
    D. Prepare a recovery plan.

  • Question 215:

    HOTSPOT

    You plan to deploy a dynamically scaling, Linux-based Azure Virtual Machine Scale Set that will host jump servers. The jump servers will be used by support staff who connect f personal and kiosk devices via the internet. The subnet of the jump servers will be associated to a network security group (NSG)

    You need to design an access solution for the Azure Virtual Machine Scale Set. The solution must meet the following requirements:

    1. Ensure that each time the support staff connects to a jump server; they must request access to the server.

    2. Ensure that only authorized support staff can initiate SSH connections to the jump servers.

    3. Maximize protection against brute-force attacks from internal networks and the internet.

    4. Ensure that users can only connect to the jump servers from the internet.

    5. Minimize administrative effort

    What should you include in the solution? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

  • Question 216:

    A customer is deploying Docker images to 10 Azure Kubernetes Service (AKS) resources across four Azure subscriptions.

    You are evaluating the security posture of the customer.

    You discover that the AKS resources are excluded from the secure score recommendations.

    You need to produce accurate recommendations and update the secure score.

    Which two actions should you recommend in Microsoft Defender for Cloud? Each correct answer presents part of the solution.

    NOTE: Each correct selection is worth one point.

    A. Enable Defender plans.
    B. Configure auto provisioning.
    C. Add a workflow automation.
    D. Assign regulatory compliance policies.
    E. Review the inventory.

  • Question 217:

    You have a Microsoft Entra tenant named contoso.com.

    You have a partner company that has a multi-tenant application named App1. App1 is registered to a Microsoft Entra tenant named fabnkam.com.

    You need to ensure that the users in contoso.com can authenticate to App1.

    What should you recommend creating in contoso.com?

    A. a service principal
    B. a system-assigned managed identity
    C. an application object
    D. a user-assigned managed identity

  • Question 218:

    HOTSPOT

    You are creating the security recommendations for an Azure App Service web app named App1. App1 has the following specifications:

    1. Users will authenticate by using Azure AD user accounts.

    2. Users will request access to App1 through the My Apps portal. A human resources manager will approve the requests.

    You need to recommend an access security architecture for App1.

    What should you include in the recommendation? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

  • Question 219:

    You have an on-premises server that runs Windows Server and contains a Microsoft SQL Server database named DB1.

    You plan to migrate DB1 to Azure.

    You need to recommend an encrypted Azure database solution that meets the following requirements:

    1. Minimizes the risks of malware that uses elevated privileges to access sensitive data

    2. Prevents database administrators from accessing sensitive data

    3. Enables pattern matching for server-side database operations

    4. Supports Microsoft Azure Attestation

    5. Uses hardware-based encryption

    What should you include in the recommendation?

    A. SQL Server on Azure Virtual Machines with virtualization-based security (VBS) enclaves
    B. Azure SQL Database with virtualization-based security (VBS) enclaves
    C. Azure SQL Managed Instance that has Always Encrypted configured
    D. Azure SQL Database with Intel Software Guard Extensions (Intel SGX) enclaves

  • Question 220:

    HOTSPOT

    You have an Azure subscription. The subscription contains 20 App Service web apps that provide services to external customers.

    Each web app has a unique certificate and key.

    You need to recommend a solution to manage the keys and certificates of the web apps.

    The solution must meet the follow requirements:

    Provide a single tenancy to store the keys and certificates.

    Maintain FIPS 140-2 Level 3 compliance.

    Follow the principle of least privilege.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SC-100 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.