SC-100 Exam Details

  • Exam Code
    :SC-100
  • Exam Name
    :Microsoft Cybersecurity Architect
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :350 Q&As
  • Last Updated
    :Jul 12, 2026

Microsoft SC-100 Online Questions & Answers

  • Question 221:

    You are designing the security standards for containerized applications onboarded to Azure.

    You are evaluating the use of Microsoft Defender for Containers.

    In which two environments can you use Defender for Containers to scan for known vulnerabilities?

    Each correct answer presents a complete solution.

    NOTE: Each correct selection is worth one point.

    A. Linux containers deployed to Azure Container Instances
    B. Windows containers deployed to Azure Kubernetes Service (AKS)
    C. Windows containers deployed to Azure Container Registry
    D. Linux containers deployed to Azure Container Registry
    E. Linux containers deployed to Azure Kubernetes Service (AKS)

  • Question 222:

    You have a Microsoft 365 tenant.

    You have an Azure subscription that contains Azure App Service web apps. The apps have the following characteristics:

    1. The apps use third-party and open-source components.

    2. The apps were developed by using C#, Python, and Java.

    3. The app deployment process is managed by using Azure DevOps.

    4. The source code for the apps is stored in GitHub Enterprise Cloud repositories and protected by using GitHub Advanced Security.

    You need to reduce the risk of supply chain attacks during the application lifecycle.

    What should you implement?

    A. secret scanning
    B. Dependabot alerts
    C. app governance in Microsoft Defender for Cloud Apps
    D. NuGet Audit

  • Question 223:

    HOTSPOT

    You open Microsoft Defender for Cloud as shown in the following exhibit.

    Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

    NOTE: Each correct selection is worth one point.

  • Question 224:

    You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.

    The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019.

    You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application.

    Which security control should you recommend?

    A. Azure Active Directory (Azure AD) Conditional Access App Control policies
    B. OAuth app policies in Microsoft Defender for Cloud Apps
    C. app protection policies in Microsoft Endpoint Manager
    D. application control policies in Microsoft Defender for Endpoint

  • Question 225:

    You have an on-premises network that has several legacy applications. The applications perform LDAP queries against an existing directory service.

    You are migrating the on-premises infrastructure to a cloud-only infrastructure.

    You need to recommend an identity solution for the infrastructure that supports the legacy applications. The solution must minimize the administrative effort to maintain the infrastructure.

    Which identity service should you include in the recommendation?

    A. Microsoft Entra External ID
    B. Azure Active Directory Domain Services (Azure AD DS)
    C. Microsoft Entra ID
    D. Active Directory Domain Services (AD DS)

  • Question 226:

    HOTSPOT

    Your company, named Contoso. Ltd... has an Azure AD tenant namedcontoso.com. Contoso has a partner company named Fabrikam. Inc. that has an Azure AD tenant named fabrikam.com. You need to ensure that helpdesk users at Fabrikam can reset passwords for specific users at Contoso. The solution must meet the following requirements:

    1. Follow the principle of least privilege.

    2. Minimize administrative effort.

    What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

  • Question 227:

    You have an Azure AD tenant that contains 10 Windows 11 devices and two groups named Group1 and Group2. The Windows 11 devices are joined to the Azure AD tenant and are managed by using Microsoft Intune.

    You are designing a privileged access strategy based on the rapid modernization plan (RaMP).

    The strategy will include the following configurations:

    1. Each user in Group1 will be assigned a Windows 11 device that will be configured as a privileged access device.

    2. The Security Administrator role will be mapped to the privileged access security level.

    3. The users in Group1 will be assigned the Security Administrator role.

    4. The users in Group2 will manage the privileged access devices.

    You need to configure the local Administrators group for each privileged access device. The solution must follow the principle of least privilege.

    What should you include in the solution?

    A. Only add Group2 to the local Administrators group.
    B. Configure Windows Local Administrator Password Solution (Windows LAPS) in legacy Microsoft LAPS emulation mode.
    C. Add Group2 to the local Administrators group. Add the user that is assigned the Security Administrator role to the local Administrators group of the user's assigned privileged access device.

  • Question 228:

    DRAG DROP

    Your company wants to optimize ransomware incident investigations.

    You need to recommend a plan to investigate ransomware incidents based on the Microsoft Detection and Response Team (DART) approach.

    Which three actions should you recommend performing in sequence in the plan? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    Select and Place:

  • Question 229:

    You have a Microsoft Entra tenant with 500 Windows devices that have the Global Secure Access client deployed.

    You are planning to implement Global Secure Access to manage access to a third-party Software as a Service (SaaS) app named App1.

    You need to recommend a solution to manage connections to App1, ensuring that users authenticate using their Microsoft Entra credentials before they can access App1.

    What should you include in the recommendation?

    A. a Global Secure Access app
    B. a private access traffic forwarding profile
    C. an internet access traffic forwarding profile
    D. a Quick Access app

  • Question 230:

    Your company is moving a big data solution to Azure.

    The company plans to use the following storage workloads:

    1. Azure Storage blob containers

    2. Azure Data Lake Storage Gen2

    3. Azure Storage file shares

    4. Azure Disk Storage

    Which two storage workloads support authentication by using Azure AD? Each correct answer presents a complete solution.

    NOTE: Each correct selection is worth one point.

    A. Azure Storage file shares
    B. Azure Disk Storage
    C. Azure Storage blob containers
    D. Azure Data Lake Storage Gen2

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SC-100 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.