SC-100 Exam Details

  • Exam Code
    :SC-100
  • Exam Name
    :Microsoft Cybersecurity Architect
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :350 Q&As
  • Last Updated
    :Jul 12, 2026

Microsoft SC-100 Online Questions & Answers

  • Question 81:

    You have a Microsoft 365 E5 subscription and an Azure subscription.

    You need to recommend a solution to enforce the Zero Trust principle of explicit verification for the subscriptions. The solution must be based on Zero Trust guidance in the Microsoft Cybersecurity Reference Architectures (MCRA).

    What should you include in the recommendation?

    A. Conditional Access
    B. Microsoft Defender for Identity
    C. Microsoft Defender for Cloud
    D. Microsoft Entra ID Identity Governance

  • Question 82:

    HOTSPOT

    You have an Azure subscription that contains two virtual machines named VM1 and VM2, and an Azure App Service Standard app named App1. VM1 is used to upload data to App1, and App1 stores data on VM2.

    You need to secure connectivity between the virtual machines and App1. The solution must minimize the risk of data exfiltration.

    What should you use to manage connectivity for App1?

    To answer, select the options in the answer area..Each correct answer is worth one point.

  • Question 83:

    Your company has a hybrid cloud infrastructure.

    Data and applications are moved regularly between cloud environments.

    The company's on-premises network is managed as shown in the following exhibit.

    You are designing security operations to support the hybrid cloud infrastructure. The solution must meet the following requirements:

    1. Govern virtual machines and servers across multiple environments.

    2. Enforce standards for all the resources across all the environments by using Azure Policy.

    Which two components should you recommend for the on-premises network? Each correct answer presents part of the solution.

    NOTE: Each correct selection is worth one point.

    A. on-premises data gateway
    B. Azure VPN Gateway
    C. guest configuration in Azure Policy
    D. Azure Arc
    E. Azure Bastion

  • Question 84:

    You have an Azure subscription and a Microsoft 365 subscription. All users are assigned Microsoft 365 E5 licenses. All computers run Windows 11 and are Microsoft Entra joined.

    You need to recommend a solution to prevent computers that run early builds of Windows 11 from connecting to Microsoft 365 services.

    Which two types of policies should you include in the recommendation? Each correct answer presents part of the solution.

    A. Microsoft Defender for Cloud regulatory compliance policy
    B. Microsoft Defender for Endpoint endpoint security policy
    C. Microsoft Entra ID Protection sign-in risk policy
    D. Microsoft Entra Conditional Access policy
    E. Microsoft Intune compliance policy

  • Question 85:

    HOTSPOT

    You have an Azure subscription that contains multiple Azure Storage blobs and Azure Files shares.

    You need to recommend a security solution for authorizing access to the blobs and shares. The solution must meet the following requirements:

    1. Support access to the shares using the SMB protocol.

    2. Limit access to the blobs to specific periods of time.

    3. Include authentication support when possible.

    What should you recommend for each resource?

    To answer, select the options in the answer area. Each correct selection is worth one point.

  • Question 86:

    You have a Microsoft 365 tenant that contains 5,000 users and 5,000 Windows 11 devices. All users are assigned Microsoft 365 licenses and the Microsoft Defender Vulnerability Management add-on. The Windows 11 devices are managed using Microsoft Intune and Microsoft Defender for Endpoint. The devices are configured during deployment to comply with the Center for Internet Security (CIS) benchmarks for Windows 11.

    You need to recommend a compliance solution for the Windows 11 devices. The solution must identify devices that were modified and no longer comply with the CIS benchmarks.

    What should you include in the recommendation?

    A. Authenticated scan for Windows in Microsoft Defender Vulnerability Management
    B. Microsoft Secure Score for Devices in Defender for Endpoint
    C. attack surface reduction (ASR) rules in Defender for Endpoint
    D. security baselines assessments in Microsoft Defender Vulnerability Management

  • Question 87:

    HOTSPOT

    You have three on-premises servers that run Windows Server and contain shared folders. The folders contain 10,000 files.

    You have a Microsoft 365 tenant that uses Microsoft Purview and includes custom sensitive information types (SITs).

    You have an Azure subscription that contains five Azure Blob Storage accounts and multiple web apps. The Blob Storage accounts contain data for the web apps.

    You need to recommend a Microsoft Purview solution to scan the storage blobs and the shared folders. The solution must use the custom SITs to identify files that contain specific data.

    What should you use for each type of storage? To answer, select the appropriate options in the answer

    NOTE: Each correct selection is worth one point.

  • Question 88:

    You have an Azure subscription.

    You have an on-premises datacenter that contains Microsoft SQL Server instances. Each instance contains multiple databases.

    You have a Microsoft 365 subscription.

    You plan to implement a solution to scan the databases for vulnerabilities that compromise data security.

    You need to recommend what to configure before the databases can be scanned.

    What should you recommend?

    A. Microsoft Purview data loss prevention (DLP)
    B. Microsoft Purview data governance
    C. Microsoft Defender for Cloud
    D. Microsoft Defender Vulnerability Management

  • Question 89:

    You have an Azure subscription.

    You plan to deploy Azure Kubernetes Service (AKS) clusters to host web services.

    You need to recommend an ingress controller solution that will ensure the security of the hosted web services.

    What should be included in your recommendation?

    A. Azure Load Balancer
    B. Azure Application Gateway
    C. Azure Front Door
    D. Azure Firewall

  • Question 90:

    HOTSPOT

    Your network contains an Active Directory Domain Services (AD DS) domain named Domain1.

    You have a Microsoft Entra tenant.

    Domain1 syncs with the tenant using Microsoft Entra Connect.

    You need to evaluate Microsoft Entra smart lockout by testing the following account lockout considerations:

    1. The number of failed sign-in attempts that trigger a lockout

    2. The duration of the lockout

    What should you use to test each consideration?

    To answer, select the appropriate options in the answer area.

    Each correct selection is worth one point.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SC-100 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.