SC-100 Exam Questions
236 real SC-100 exam questions with expert-verified answers and explanations. Page 2 of 5.
- Question #62Design security solutions for applications and data
Your company is moving a big data solution to Azure. The company plans to use the following storage workloads: - Azure Storage blob containers - Azure Data Lake Storage Gen2 - Azur...
Azure Storage SecurityAzure AD AuthenticationData Lake StorageBlob Storage - Question #63Design security operations, identity, and compliance capabilities
You are evaluating an Azure environment for compliance. You need to design an Azure Policy implementation that can be used to evaluate compliance without changing any resources. Wh...
Azure PolicyCompliance EvaluationPolicy EffectsResource Governance - Question #64Design security operations, identity, and compliance capabilities
Your company has a Microsoft 365 E5 subscription. The Chief Compliance Officer plans to enhance privacy management in the working environment. You need to recommend a solution to e...
Privacy ManagementMicrosoft PrivaData ProtectionCompliance - Question #65Design security operations, identity, and compliance capabilities
You have an Azure subscription that has Microsoft Defender for Cloud enabled. You are evaluating the Azure Security Benchmark V3 report as shown in the following exhibit. You need...
Azure Security BenchmarkMicrosoft Defender for CloudEndpoint SecurityCompliance Management - Question #66Design security solutions for infrastructure
A customer is deploying Docker images to 10 Azure Kubernetes Service (AKS) resources across four Azure subscriptions. You are evaluating the security posture of the customer. You d...
Microsoft Defender for CloudSecure ScoreAzure Kubernetes Service (AKS) SecurityDefender Plans - Question #67Design security operations, identity, and compliance capabilities
You have Microsoft Defender for Cloud assigned to Azure management groups. You have a Microsoft Sentinel deployment. During the triage of alerts, you require additional information...
Microsoft Defender for CloudMicrosoft SentinelThreat IntelligenceSecurity Operations - Question #68Design security solutions for infrastructure
You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled. The Azure subscription contains 50 virtual mac...
Application ControlEndpoint SecurityMicrosoft Defender for EndpointVirtual Machine Security - Question #69Design security operations, identity, and compliance capabilities
Your company has an Azure subscription that has enhanced security enabled for Microsoft Defender for Cloud. The company signs a contract with the United States government. You need...
Microsoft Defender for CloudRegulatory ComplianceNIST 800-53Security Posture Management - Question #70Design security operations, identity, and compliance capabilities
You have an Azure subscription that has Microsoft Defender for Cloud enabled. Suspicious authentication activity alerts have been appearing in the Workload protections dashboard. Y...
Security AutomationWorkflow AutomationMicrosoft Defender for CloudAzure Logic Apps - Question #71Design security solutions for applications and data
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Azure Application GatewayAzure Web Application Firewall (WAF)Database connectivity securityZero Trust - Question #72Design security solutions for infrastructure
Case Study 2 - Litware, inc. Overview Litware, Inc. is a financial services company that has main offices in New York and San Francisco. Litware has 30 branch offices and remote em...
Azure NetworkingAzure FirewallHub-Spoke ArchitectureService Chaining - Question #73Design security solutions for applications and data
Case Study 2 - Litware, inc. Overview Litware, Inc. is a financial services company that has main offices in New York and San Francisco. Litware has 30 branch offices and remote em...
SaaS SecurityData SecurityConditional AccessDefender for Cloud Apps - Question #74Design security operations, identity, and compliance capabilities
Your company has devices that run either Windows 10, Windows 11, or Windows Server. You are in the process of improving the security posture of the devices. You plan to use securit...
Security BaselinesMicrosoft Security Compliance ToolkitPolicy AnalyzerConfiguration Management - Question #75Design security operations, identity, and compliance capabilities
A customer follows the Zero Trust model and explicitly verifies each attempt to access its corporate applications. The customer discovers that several endpoints are infected with m...
Zero TrustConditional AccessDevice ComplianceEndpoint Security - Question #77Design security solutions for applications and data
Your company has the virtual machine infrastructure shown in the following table. The company plans to use Microsoft Azure Backup Server (MABS) to back up the virtual machines to A...
Ransomware MitigationAzure Backup SecurityData ResiliencyBackup Protection - Question #78Design security operations, identity, and compliance capabilities
You have a customer that has a Microsoft 365 subscription and an Azure subscription. The customer has devices that run either Windows, iOS, Android, or macOS. The Windows devices a...
Device complianceEndpoint managementMicrosoft IntuneCross-platform management - Question #79Design security operations, identity, and compliance capabilities
Your company has a hybrid cloud infrastructure. Data and applications are moved regularly between cloud environments. The company's on-premises network is managed as shown in the f...
Azure ArcAzure PolicyHybrid Cloud SecurityServer Governance - Question #80Design security operations, identity, and compliance capabilities
You are designing the security standards for a new Azure environment. You need to design a privileged identity strategy based on the Zero Trust model. Which framework should you fo...
Zero TrustPrivileged Identity ManagementSecurity FrameworksRapid Modernization Plan (RaMP) - Question #81Design security operations, identity, and compliance capabilities
You have a customer that has a Microsoft 365 subscription and uses the Free edition of Microsoft Entra ID. The customer plans to obtain an Azure subscription and provision several...
Microsoft Entra IDEntra ID LicensingPrivileged Identity Management (PIM) - Question #82Design security operations, identity, and compliance capabilities
A customer uses Azure to develop a mobile app that will be consumed by external users as shown in the following exhibit. You need to design an identity strategy for the app. The so...
Azure AD B2CExternal IdentitiesCIAMApplication Identity - Question #83Design security operations, identity, and compliance capabilities
A customer has a Microsoft 365 E5 subscription and an Azure subscription. The customer wants to centrally manage security incidents, analyze log, audit activity, and hunt for poten...
Microsoft SentinelSecurity OperationsSIEMThreat Hunting - Question #84Design security operations, identity, and compliance capabilities
You have an Azure subscription that is used as an Azure landing zone for an application. You need to evaluate the security posture of all the workloads in the landing zone. What sh...
Azure Defender for CloudSecurity Posture ManagementCloud Workload ProtectionSecurity Operations - Question #85Design security solutions for infrastructure
Your company is developing a serverless application in Azure that will have the architecture shown in the following exhibit. You need to recommend a solution to isolate the compute...
Azure App Service Environment (ASE)Virtual Network IntegrationPaaS SecurityCompute Isolation - Question #86Design security operations, identity, and compliance capabilities
You have a Microsoft 365 E5 subscription. You are designing a solution to protect confidential data in Microsoft SharePoint Online sites that contain more than one million document...
DLPSensitivity LabelsPII ProtectionSharePoint Online Security - Question #87Design security solutions for applications and data
Your company has an on-premises network, an Azure subscription, and a Microsoft 365 E5 subscription. The company uses the following devices: - Computers that run either Windows 10...
Microsoft Information ProtectionData classificationData encryptionSensitivity labels - Question #88Design security solutions for applications and data
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Azure Front DoorAzure App ServiceAccess RestrictionsWeb Application Security - Question #89Design security solutions for applications and data
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Azure Private LinkNetwork SecurityZero TrustDatabase Security - Question #90Design security solutions for infrastructure
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Just-in-Time VM AccessMicrosoft Defender for CloudAzure Security BenchmarkNetwork Security - Question #91Design security solutions for applications and data
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Azure Front DoorWeb Application Firewall (WAF)Database ConnectivityZero Trust - Question #96Design security operations, identity, and compliance capabilities
Drag and Drop Question You have a Microsoft 365 subscription You need to recommend a security solution to monitor the following activities: - User accounts that were potentially co...
Cloud Application SecurityIdentity ProtectionThreat DetectionMicrosoft 365 Security - Question #99Design security operations, identity, and compliance capabilities
Drag and Drop Question Your company has Microsoft 365 E5 licenses and Azure subscriptions. The company plans to automatically label sensitive data stored in the following locations...
Sensitivity LabelsInformation ProtectionMicrosoft 365 ComplianceAuto-labeling - Question #106Design security solutions for infrastructure
You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled. The Azure subscription contains 50 virtual mac...
Application ControlMicrosoft Defender for CloudVirtual Machine SecurityServer Protection - Question #107Design security operations, identity, and compliance capabilities
A customer has a hybrid cloud infrastructure that contains a Microsoft 365 E5 subscription and an Azure subscription. All the on-premises servers in the perimeter network are preve...
Microsoft SentinelLog CollectionRole-Based Access Control (RBAC)Hybrid Cloud Security - Question #108Design security solutions for applications and data
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Azure Key VaultZero TrustApplication SecurityDatabase Security - Question #109Design security solutions for applications and data
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Azure SQL DatabaseData Encryption at RestCustomer-Managed KeysKey Rotation - Question #110Design security solutions for applications and data
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Azure Storage EncryptionCustomer-Managed Keys (CMK)Key RotationData at Rest Encryption - Question #111Design security solutions for applications and data
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Azure Storage EncryptionData at Rest EncryptionKey ManagementKey Rotation Policies - Question #112Design security solutions for infrastructure
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Azure Security BenchmarkVM SecurityNetwork Access ControlDefender for Cloud - Question #113Design security operations, identity, and compliance capabilities
Your company has an Azure subscription that has enhanced security enabled for Microsoft Defender for Cloud. The company signs a contract with the United States government. You need...
Azure PolicyCompliance ManagementNIST 800-53Regulatory Compliance - Question #114Design security solutions for infrastructure
You have been hired to help an organization secure their Azure landing zone design. The current design includes implementation plans for both compute and storage services. You have...
Azure Key VaultPKIConfidentialityNon-repudiation - Question #115Design security solutions for infrastructure
Your company uses loT flow valves at remote water treatment facilities. The devices are monitored by network sensors that are supplied by different vendors. Each vendor uses differ...
Azure ExpressRouteMulti-cloud ConnectivityIoT SecurityNetwork Performance - Question #117Design security operations, identity, and compliance capabilities
Draga and Drop Question Your client has implemented Microsoft Sentinel as its cloud-based Security Information and Event Management (SIEM). The client wants to maximize the value o...
Microsoft SentinelIncident ManagementThreat DetectionSecurity Operations - Question #119Design security solutions for applications and data
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Data at rest encryptionAzure SQL DatabaseTransparent Data Encryption (TDE)Key managementKey rotation - Question #120Design security operations, identity, and compliance capabilities
You are designing a ransomware response plan that follows Microsoft Security Best Practices. You need to recommend a solution to limit the scope of damage of ransomware attacks wit...
Ransomware protectionPrivileged Access WorkstationsDamage containmentSecurity best practices - Question #121Design security solutions for applications and data
You use Azure Pipelines with Azure Repos to implement continuous integration and continuous deployment (CI/CD) workflows for the deployment of applications to Azure. You need to re...
DASTPenetration TestingApplication Security TestingCI/CD Security - Question #124Design solutions that align with security best practices and priorities
Your company plans to apply the Zero Trust Rapid Modernization Plan (RaMP) to its IT environment. You need to recommend the top three modernization areas to prioritize as part of t...
Zero TrustRapid Modernization PlanSecurity StrategySecurity Modernization - Question #126Design security operations, identity, and compliance capabilities
For an Azure deployment, you are designing a security architecture based on the Microsoft Cloud Security Benchmark. You need to recommend a best practice for implementing service a...
Azure ADApplication IdentityService AccountsAPI Management - Question #127Design security operations, identity, and compliance capabilities
You have a Microsoft Entra tenant that syncs with an Active Directory Domain Services (AD DS) domain. Client computers run Windows and are hybrid-joined to Microsoft Entra. You are...
Endpoint SecurityPrivileged Access Management (PAM)Lateral Movement PreventionLocal Administrator Password Solution (LAPS) - Question #128Design solutions that align with security best practices
Drag and Drop Question For a Microsoft cloud environment, you need to recommend a security architecture that follows the Zero Trust principles of the Microsoft Cybersecurity Refere...
Zero TrustMCRASecurity ArchitectureCloud Security - Question #129Design solutions that align with security best practices and priorities
You have legacy operational technology (OT) devices and IoT devices. You need to recommend best practices for applying Zero Trust principles to the OT and IoT devices based on the...
Zero TrustOT/IoT SecuritySecurity MonitoringMCRA