SC-100 Exam Questions
236 real SC-100 exam questions with expert-verified answers and explanations. Page 1 of 5.
- Question #1Design security operations, identity, and compliance capabilities
Case Study 1 - Fabrikam, Inc OverView Fabrikam, Inc. is an insurance company that has a main office in New York and a branch office in Paris. Existing Environment On-premises Envir...
Azure RBACCustom RolesIdentity and Access ManagementNetwork Security - Question #2Design security solutions for applications and data
Case Study 1 - Fabrikam, Inc OverView Fabrikam, Inc. is an insurance company that has a main office in New York and a branch office in Paris. Existing Environment On-premises Envir...
Code securityVulnerability scanningSecret managementDevSecOps - Question #3Design security solutions for infrastructure
Case Study 1 - Fabrikam, Inc OverView Fabrikam, Inc. is an insurance company that has a main office in New York and a branch office in Paris. Existing Environment On-premises Envir...
Microsoft Defender for CloudVulnerability ManagementMicrosoft Defender for EndpointAzure VM Security - Question #4Design security solutions for applications and data
Case Study 1 - Fabrikam, Inc OverView Fabrikam, Inc. is an insurance company that has a main office in New York and a branch office in Paris. Existing Environment On-premises Envir...
Azure SQL DatabaseAlways EncryptedData SecurityColumn-level security - Question #5Design security solutions for infrastructure
Case Study 1 - Fabrikam, Inc OverView Fabrikam, Inc. is an insurance company that has a main office in New York and a branch office in Paris. Existing Environment On-premises Envir...
Azure Virtual DesktopRemote AdministrationSecure WorkstationsCustom Images - Question #11Design security solutions for applications and data
Case Study 2 - Litware, inc. Overview Litware, Inc. is a financial services company that has main offices in New York and San Francisco. Litware has 30 branch offices and remote em...
Microsoft Entra Application ProxySingle Sign-On (SSO)Authentication MethodsKerberosSAML - Question #12Design security solutions for infrastructure
Case Study 2 - Litware, inc. Overview Litware, Inc. is a financial services company that has main offices in New York and San Francisco. Litware has 30 branch offices and remote em...
Azure Landing ZonesPrivate DNSNetwork SecurityPrivate Connectivity - Question #19Design security solutions for applications and data
Your company has on-premises Microsoft SQL Server databases. The company plans to move the databases to Azure. You need to recommend a secure architecture for the databases that wi...
Azure SQL DatabasePaaSDynamic Data MaskingDatabase Migration - Question #20Design security solutions for applications and data
You have an Azure subscription that contains several storage accounts. The storage accounts are accessed by legacy applications that are authenticated by using access keys. You nee...
Storage Account SecurityAccess KeysAzure Resource LocksLegacy Applications - Question #21Design security solutions for applications and data
Azure subscription that uses Azure Storage. The company plans to share specific blobs with vendors. You need to recommend a solution to provide the vendors with secure access to sp...
Azure StorageShared Access Signatures (SAS)Access ControlData Security - Question #22Design security operations, identity, and compliance capabilities
You are planning the security requirements for Azure Cosmos DB Core (SQL) API accounts. You need to recommend a solution to audit all users that access the data in the Azure Cosmos...
Azure Cosmos DB securityAuditingAzure AD authenticationSecurity logging - Question #23Design security solutions for infrastructure
You need to design a solution to provide administrators with secure remote access to the virtual machines. The solution must meet the following requirements: - Prevent the need to...
Azure Virtual MachinesRemote AccessJust-in-Time AccessAzure Bastion - Question #24Design security solutions for infrastructure
Your company is designing an application architecture for Azure App Service Environment (ASE) web apps as shown in the exhibit. (Click the Exhibit tab.) Communication between the o...
Azure FirewallHybrid ConnectivityNetwork SecurityApp Service Environment - Question #25Design security solutions for infrastructure
You have Windows 11 devices and Microsoft 365 E5 licenses. You need to recommend a solution to prevent users from accessing websites that contain adult content such as gambling sit...
Web content filteringMicrosoft Defender for EndpointEndpoint securityThreat protection - Question #26Design security solutions for infrastructure
Your company plans to move all on-premises virtual machines to Azure. A network engineer proposes the Azure virtual network design shown in the following table. You need to recomme...
Azure BastionVirtual Network DesignSecure Remote AccessNetwork Security - Question #27Design security operations, identity, and compliance capabilities
You have an Azure subscription that has Microsoft Defender for Cloud enabled. You need to enforce ISO 27001:2013 standards for the subscription. The solution must ensure that nonco...
Azure PolicyRegulatory ComplianceAutomatic RemediationISO 27001 - Question #28Design security operations, identity, and compliance capabilities
You receive a security alert in Microsoft Defender for Cloud as shown in the exhibit. (Click the Exhibit tab.) After remediating the threat which policy definition should you assig...
Azure PolicyStorage Account SecurityShared Key Access - Question #29Design security solutions for infrastructure
Your company is preparing for cloud adoption. You are designing security for Azure landing zones. Which two preventative controls can you implement to increase the secure score? Ea...
Network SecurityAzure FirewallWeb Application Firewall (WAF)Preventative Controls - Question #30Design security solutions for applications and data
You are designing security for an Azure landing zone. Your company identifies the following compliance and privacy requirements: - Encrypt cardholder data by using encryption keys...
Azure data encryptionCustomer-managed keys (CMK)Customer-provided keys (CPK)Data compliance - Question #31Design security operations, identity, and compliance capabilities
Your company finalizes the adoption of Azure and is implementing Microsoft Defender for Cloud. You receive the following recommendations in Defender for Cloud: - Access to storage...
Azure PolicyMicrosoft Defender for CloudStorage Account SecurityCompliance - Question #32Design security operations, identity, and compliance capabilities
You have 50 Azure subscriptions. You need to monitor resource in the subscriptions for compliance with the ISO 27001:2013 standards. The solution must minimize the effort required...
Azure PolicyAzure BlueprintsManagement GroupsCompliance - Question #33Design security solutions for applications and data
Your company has a Microsoft 365 E5 subscription. The company wants to identify and classify data in Microsoft Teams, SharePoint Online, and Exchange Online. You need to recommend...
Microsoft PurviewData ClassificationSensitive InformationContent Explorer - Question #34Design security operations, identity, and compliance capabilities
Your company is developing an invoicing application that will use Azure Active Directory (Azure AD) B2C. The application will be deployed as an App Service web app. You need to rec...
Azure AD B2CConditional AccessIdentity ProtectionApplication Security - Question #35Design security operations, identity, and compliance capabilities
Your company has a Microsoft 365 E5 subscription. Users use Microsoft Teams, Exchange Online, SharePoint Online, and OneDrive for sharing and collaborating. The company identifies...
Data Loss Prevention (DLP)PHIMicrosoft 365 ComplianceInformation Protection - Question #36Design security solutions for infrastructure
You are designing the security standards for containerized applications onboarded to Azure. You are evaluating the use of Microsoft Defender for Containers. In which two environmen...
Microsoft Defender for ContainersContainer SecurityVulnerability ManagementAzure Container Services - Question #37Design security solutions for applications and data
Your company has an on-premises network and an Azure subscription. The company does NOT have a Site-to-Site VPN or an ExpressRoute connection to Azure. You are designing the securi...
Azure App ServiceHybrid ConnectionsOn-premises connectivityNetwork Security - Question #38Design security solutions for applications and data
Your company has a hybrid cloud infrastructure that contains an on-premises Active Directory Domain Services (AD DS) forest, a Microsoft B65 subscription, and an Azure subscription...
Azure AD Application ProxyHybrid IdentityApplication publishingConditional Access - Question #39Design security operations, identity, and compliance capabilities
Your company has a third-party security information and event management (SIEM) solution that uses Splunk and Microsoft Sentinel. You plan to integrate Microsoft Sentinel with Splu...
Microsoft SentinelSIEM integrationAzure Event HubsSecurity operations - Question #40Design security operations, identity, and compliance capabilities
You have an Azure subscription that has Microsoft Defender for Cloud enabled. You have an Amazon Web Services (AWS) implementation. You plan to extend the Azure security strategy t...
Cross-Cloud SecurityIdentity ManagementWorkload SecurityMicrosoft Defender for Cloud - Question #41Design security operations, identity, and compliance capabilities
You have an on-premises network that has several legacy applications. The applications perform LDAP queries against an existing directory service. You are migrating the on-premises...
Azure AD DSLegacy Application IntegrationCloud IdentityManaged Services - Question #42Design security solutions for infrastructure
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Microsoft Defender for CloudAzure Security BenchmarkNetwork SecuritySecure Management Ports - Question #43Design security operations, identity, and compliance capabilities
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Azure Security BenchmarkMicrosoft Defender for CloudVirtual Machine SecurityManagement Port Security - Question #44Design security solutions for infrastructure
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Azure App ServiceAzure Front DoorNetwork SecurityApp Service VNet Integration - Question #45Design security solutions for applications and data
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Azure Front DoorApp ServiceAccess RestrictionsNetwork Security - Question #46Design security solutions for applications and data
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Azure App ServiceAzure Front DoorAccess RestrictionsService Tags - Question #47Design security solutions for applications and data
You are creating an application lifecycle management process based on the Microsoft Security Development Lifecycle (SDL). You need to recommend a security standard for onboarding a...
Security Development Lifecycle (SDL)Threat ModelingApplication DesignApplication Security - Question #48Design security solutions for applications and data
Your company is developing a new Azure App Service web app. You are providing design assistance to verify the security of the web app. You need to recommend a solution to test the...
DASTApplication Security TestingWeb Application SecurityVulnerability Assessment - Question #49Design security solutions for applications and data
Your company plans to deploy several Azure App Service web apps. The web apps will be deployed to the West Europe Azure region. The web apps will be accessed only by customers in E...
Azure Application Gateway WAFWeb Application SecurityBot ProtectionAttack Surface Reduction - Question #50Design security solutions for applications and data
You have a Microsoft 365 E5 subscription. You need to recommend a solution to add a watermark to email attachments that contain sensitive data. What should you include in the recom...
Data ProtectionMicrosoft Information ProtectionWatermarkingSensitive Data - Question #51Design security operations, identity, and compliance capabilities
Your company has a hybrid cloud infrastructure. The company plans to hire several temporary employees within a brief period. The temporary employees will need to access application...
Azure Virtual DesktopConditional AccessHybrid AccessTemporary Workforce - Question #52Design security solutions for infrastructure
You have an Azure subscription that contains virtual machines, storage accounts, and Azure SQL databases. All resources are backed up multiple times a day by using Azure Backup. Yo...
Ransomware protectionAzure BackupData recoverySecurity controls - Question #53Design security operations, identity, and compliance capabilities
Your company develops several applications that are accessed as custom enterprise applications in Azure Active Directory (Azure AD). You need to recommend a solution to prevent use...
Azure AD Conditional AccessGeographical RestrictionsAccess ControlIdentity and Access Management - Question #54Design security operations, identity, and compliance capabilities
Your company has a Microsoft 365 subscription and uses Microsoft Defender for Identity. You are informed about incidents that relate to compromised identities. You need to recommen...
Defender for IdentityHoneypotDeception technologyIdentity protection - Question #55Design security operations, identity, and compliance capabilities
You have a Microsoft 365 E5 subscription and an Azure subscription. You are designing a Microsoft Sentinel deployment. You need to recommend a solution for the security operations...
Microsoft SentinelSecurity OperationsDashboardsWorkbooks - Question #56Design security solutions for infrastructure
Your company has an on-premise network in Seattle and an Azure subscription. The on-premises network contains a Remote Desktop server. The company contracts a third-party developme...
Zero TrustAzure Virtual DesktopConditional AccessAzure Firewall - Question #57Design security operations, identity, and compliance capabilities
Your company is moving all on-premises workloads to Azure and Microsoft 365. Vou need to design a security orchestration, automation, and response (SOAR) strategy in Microsoft Sent...
Microsoft SentinelSOARPlaybooksAutomation - Question #58Design security solutions for infrastructure
Your company plans to provision blob storage by using an Azure Storage account. The blob storage will be accessible from 20 application sewers on the internet. You need to recommen...
Storage account securityNetwork access controlIP firewallBlob storage - Question #59Design security solutions for infrastructure
Your company has a Microsoft 365 E5 subscription. The company plans to deploy 45 mobile self-service kiosks that will run Windows 10. You need to provide recommendations to secure...
Endpoint SecurityDevice ManagementApplication ControlVulnerability Management - Question #60Design security solutions for infrastructure
Your company has an office in Seattle. The company has two Azure virtual machine scale sets hosted on different virtual networks. The company plans to contract developers in India....
Azure BastionVirtual Network PeeringSecure Remote AccessCost Optimization - Question #61Design security solutions for applications and data
Your company is developing a modern application that will run as an Azure App Service web app. You plan to perform threat modeling to identify potential security issues by using th...
Threat ModelingMicrosoft Threat Modeling ToolData Flow DiagramsApplication Security