Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Microsoft Cybersecurity Architect SC-100 Exam Questions

Page: 1 / 21 Total 310 questions

Want more questions? Get Premium Access.

Question 1

Your company has devices that run either Windows 10, Windows 11, or Windows Server.

You are in the process of improving the security posture of the devices.

You plan to use security baselines from the Microsoft Security Compliance Toolkit.

What should you recommend using to compare the baselines to the current device configurations?

Question 2

Your company has a Microsoft 365 E5 subscription.

The Chief Compliance Officer plans to enhance privacy management in the working environment. You need to recommend a solution to enhance the privacy management. The solution must meet the following requirements:

* Identify unused personal data and empower users to make smart data handling decisions.

* Provide users with notifications and guidance when a user sends personal data in Microsoft Teams.

* Provide users with recommendations to mitigate privacy risks.

What should you include in the recommendation?

Correct Answer: C. Privacy Risk Management in Microsoft Priva
Explanation:

Privacy Risk Management in Microsoft Priva gives you the capability to set up policies that identify privacy risks in your Microsoft 365 environment and enable easy remediation. Privacy Risk Management policies are meant to be internal guides and can help you: Detect overexposed personal data so that users can secure it. Spot and limit transfers of personal data across departments or regional borders. Help users identify and reduce the amount of unused personal data that you store.

https://www.microsoft.com/en-us/security/business/privacy/microsoft-priva-risk-management


Question 3

You have a customer that has a Microsoft 365 subscription and uses the Free edition of Azure Active Directory (Azure AD)

The customer plans to obtain an Azure subscription and provision several Azure resources.

You need to evaluate the customer's security environment.

What will necessitate an upgrade from the Azure AD Free edition to the Premium edition?

Question 4

You have an Azure subscription that contains virtual machines, storage accounts, and Azure SQL databases. All resources are backed up multiple times a day by using Azure Backup. You are developing a strategy to protect against ransomware attacks.

You need to recommend which controls must be enabled to ensure that Azure Backup can be used to restore the resources in the event of a successful ransomware attack.

Which two controls should you include in the recommendation? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Correct Answer: A. Use Azure Monitor notifications when backup configurations change.; B. Require PINs for critical operations.
Explanation:

https://docs.microsoft.com/en-us/azure/security/fundamentals/backup-plan-to-protect-against-ransomware

'You need to recommend which CONTROLS must be enabled to ENSURE that Azure Backup can be used to RESTORE the resources in the event of a successful ransomware attack.' Whilst helpful for auditing purposes and detection of a malicious attack, monitoring configuration changes and alerting after a change is made does not represent a CONTROL which ENSURES Azure Backup can be used to RESTORE the resources.


Question 5

Your company has the virtual machine infrastructure shown in the following table.

The company plans to use Microsoft Azure Backup Server (MABS) to back up the virtual machines to Azure.

You need to provide recommendations to increase the resiliency of the backup strategy to mitigate attacks such as ransomware.

What should you include in the recommendation?

Question 6

You are designing the encryption standards for data at rest for an Azure resource

You need to provide recommendations to ensure that the data at rest is encrypted by using AES-256 keys. The solution must support rotating the encryption keys monthly.

Solution: For blob containers in Azure Storage, you recommend encryption that uses Microsoft-managed keys within an encryption scope.

Does this meet the goal?

Question 7

You have a Microsoft 365 subscription that contains a group named Group1. The subscription contains 1,000 Windows devices that are joined to a Microsoft Entra tenant and managed by using Microsoft Intune. All users sign in to the devices by using standard user accounts.

You plan to deploy a new app named App1 to the members of Group1. The Group1 members must have administrative rights to install new versions of App1.

You need to ensure that the Group1 members can install new versions of App1. The solution must follow the principles of Zero Trust.

What should you implement?

Correct Answer: B. Endpoint Privilege Management (EPM)

Question 8

You have an Azure subscription that contains multiple network security groups (NSGs), multiple virtual machines, and an Azure Bastion host named bastion1.

Several NSGs contain rules that allow direct RDP access to the virtual machines by bypassing bastion!

You need to ensure that the virtual machines can be accessed only by using bastion! The solution must prevent the use of NSG rules to bypass bastion1.

What should you include in the solution?

Correct Answer: B. Azure Virtual Network Manager security admin rules
Explanation:

To ensure virtual machines can only be accessed through Azure Bastion and prevent NSG rule bypass:

  • Azure Bastion Standard tier: The Standard tier of Azure Bastion provides enhanced security features including the ability to enforce Bastion-only access and restrict direct RDP connections.
  • Native client support: Enables secure access while preventing RDP port (3389) exposure directly from NSGs. This feature allows only Bastion to access VMs regardless of NSG rules.
  • NSG remediation: Configure NSGs to deny direct RDP access (port 3389) from all sources except Azure Bastion's internal subnet. Bastion communicates with VMs over private channels that bypass traditional NSG RDP rules.
  • Enforcement mechanism: Bastion Standard provides built-in enforcement that any VM connected to Bastion cannot be accessed except through Bastion, preventing NSG rules from circumventing this control.
  • Alternative approach: Ensure NSG rules are configured to deny port 3389 from all external sources and allow only Bastion's subnet. However, Standard tier enforcement is the robust solution.

Deploy Azure Bastion in Standard tier with native client support and configure NSG rules to deny direct RDP access, ensuring all VM access routes through Bastion regardless of other NSG configurations.

Question 9

Your company has an Azure subscription that has enhanced security enabled for Microsoft Defender for Cloud.

The company signs a contract with the United States government.

You need to review the current subscription for NIST 800-53 compliance.

What should you do first?

Question 10

Your company is developing a serverless application in Azure that will have the architecture shown in the following exhibit.

You need to recommend a solution to isolate the compute components on an Azure virtual network. What should you include in the recommendation?

Correct Answer: B. an Azure App Service Environment (ASE)
Explanation:

App Service environments (ASEs) are appropriate for application workloads that require:

Very high scale,Isolation and secure network access,High memory utilization.This capability can host your:

Windows web apps,Linux web apps

Docker containers,Mobile apps

Functions

https://docs.microsoft.com/en-us/azure/app-service/environment/overview


Question 11

Your company finalizes the adoption of Azure and is implementing Microsoft Defender for Cloud.

You receive the following recommendations in Defender for Cloud

* Access to storage accounts with firewall and virtual network configurations should be restricted,

* Storage accounts should restrict network access using virtual network rules.

* Storage account should use a private link connection.

* Storage account public access should be disallowed.

You need to recommend a service to mitigate identified risks that relate to the recommendations. What should you recommend?

Question 12

Your company plans to deploy several Azure App Service web apps. The web apps will be deployed to the West Europe Azure region. The web apps will be accessed only by customers in Europe and the United States.

You need to recommend a solution to prevent malicious bots from scanning the web apps for vulnerabilities. The solution must minimize the attach surface.

What should you include in the recommendation?

Correct Answer: D. Azure Traffic Manager and application security groups

Question 13

Your company has a hybrid cloud infrastructure.

The company plans to hire several temporary employees within a brief period. The temporary employees will need to access applications and data on the company' premises network.

The company's security policy prevents the use of personal devices for accessing company data and applications.

You need to recommend a solution to provide the temporary employee with access to company resources. The solution must be able to scale on demand.

What should you include in the recommendation?

Question 14

You have an Azure AD tenant that syncs with an Active Directory Domain Services (AD DS) domain.

You have an on-premises datacenter that contains 100 servers. The servers run Windows Server and are backed up by using Microsoft Azure Backup Server (MABS).

You are designing a recovery solution for ransomware attacks. The solution follows Microsoft Security Best Practices.

You need to ensure that a compromised administrator account cannot be used to delete the backups

What should you do?

Correct Answer: A. From a Recovery Services vault generate a security PIN for critical operations.
Explanation:

To ensure a compromised administrator account cannot delete backups, you should: Implement Azure Backup immutability features through retention lock settings that prevent deletion or modification of backup data, even by administrators with full permissions. Additionally: (1) Use Azure Role-Based Access Control (RBAC) to restrict backup deletion permissions to a separate administrative role, (2) Configure backup data to be stored in a separate subscription or resource group with restricted access, and (3) Enable Multi-User Authorization (MUA) in MABS to require approval from multiple administrators for critical backup operations. The immutability setting is the primary technical control that prevents ransomware operators from destroying recovery options.

Question 15

You have an Azure subscription that has Microsoft Defender for Cloud enabled. You need to enforce ISO 2700V2013 standards for the subscription. The solution must ensure that noncompliant resources are remediated automatically

What should you use?