Microsoft Cybersecurity Architect Free Sample Questions

20 free sample questions169 in the full practice test

Try simulator

SC-100 Sample Questions

  1. Question 1

    A financial services firm, QuantumLeap Financials, is designing a Zero Trust architecture for its hybrid environment. They have a critical on-premises Active Directory Domain Services (AD DS) infrastructure and a growing footprint in Azure. A key requirement is to protect privileged administrative accounts in AD DS from pass-the-hash and other credential theft attacks originating from compromised workstations. The security architect needs to recommend a solution that isolates administrative tasks from daily user activities like email and web browsing. Which solution best meets this requirement by implementing a tiered access model?

    Answer and explanation

    Correct answer: C

    The core requirement is to isolate administrative tasks from daily user activities to prevent credential theft. Privileged Access Workstations (PAWs) are specifically designed for this purpose. A PAW provides a dedicated, hardened operating system for sensitive tasks, completely separate from the user's standard workstation used for email and browsing. This directly prevents credential theft vectors like phishing and browser exploits from compromising high-privilege accounts. While Defender for Identity is crucial for detection and PIM for just-in-time access, neither provides the required task isolation at the workstation level.

  2. Question 2

    A global logistics company, TerraNova Logistics, is migrating its infrastructure to a multi-cloud environment, using Azure, AWS, and GCP. The CISO is concerned about inconsistent permission management and the risk of privilege escalation across the different cloud platforms. They need a unified solution to discover, remediate, and monitor permissions for all identities and resources across their entire multi-cloud estate. Which Microsoft solution is specifically designed to address this Cloud Infrastructure Entitlement Management (CIEM) challenge?

    Answer and explanation

    Correct answer: C

    Microsoft Entra Permissions Management is the Cloud Infrastructure Entitlement Management (CIEM) solution from Microsoft. It is designed to provide comprehensive visibility and control over permissions for any identity and any resource across multi-cloud infrastructures, including Azure, AWS, and GCP. It helps enforce the principle of least privilege by discovering unused or excessive permissions. Azure Arc extends the Azure control plane, and Defender for Cloud provides posture management, but neither is primarily a CIEM solution for managing granular permissions across clouds.

  3. Question 3

    Multiple answers

    An e-commerce company is building a new application on Azure Kubernetes Service (AKS). As part of their DevSecOps pipeline, they need to ensure that only approved and vulnerability-scanned container images are deployed to their production AKS cluster. The security policy dictates that any attempt to deploy an image that has not passed a security scan or is from an untrusted registry must be blocked. Which combination of Azure services should be used to enforce this policy? (Select TWO)

    Answer and explanation

    Correct answers: A, B

    Microsoft Defender for Containers provides vulnerability scanning for images in Azure Container Registry and real-time threat detection for containerized environments. Azure Policy for Kubernetes can then enforce policies at deployment time, such as blocking the deployment of images that have known vulnerabilities identified by Defender for Containers. This combination directly addresses the requirement to scan images and block non-compliant deployments.

  4. Question 4

    Multiple answers

    A healthcare organization uses Azure to store patient records in Azure SQL Database and Azure Blob Storage. They need to design a security solution that meets the following requirements:

    • Discover and classify sensitive patient data across all Azure data stores.
    • Provide a unified view of data security posture and identify potential threats to the data.
    • Detect anomalous activities, such as unusual data access or potential SQL injection attacks, against the data stores.

    Which two Microsoft Defender plans should be central to this design? (Select TWO)

    Answer and explanation

    Correct answers: A, C

    The requirements specifically call for securing data in Azure SQL Database and Azure Blob Storage. Microsoft Defender for SQL is designed to discover and classify sensitive data, manage vulnerabilities, and detect anomalous activities in SQL databases. Microsoft Defender for Storage provides advanced threat protection for Azure Storage, detecting unusual and potentially harmful attempts to access or exploit storage accounts. Together, these two plans directly address the specified data security needs.

  5. Question 5

    A manufacturing company, Aperture Dynamics, is implementing Microsoft Sentinel as its SIEM. They have a hybrid environment with on-premises servers, Azure VMs, and several Microsoft 365 services. The security operations team needs to automate the initial triage and response to common alerts, such as impossible travel alerts from Azure AD Identity Protection. The automation must post a message in a specific Microsoft Teams channel for the on-duty analyst, temporarily disable the user account, and create a high-priority ticket in ServiceNow. Which Microsoft Sentinel feature should be used to build this automated workflow?

    Answer and explanation

    Correct answer: B

    Microsoft Sentinel Playbooks are collections of procedures that can be run from Microsoft Sentinel in response to an alert or incident. Playbooks are built on Azure Logic Apps, which provide a powerful, customizable, and scalable engine for creating automated workflows. This allows for integration with various services like Microsoft Teams, Azure AD, and ServiceNow to perform the required actions (post message, disable user, create ticket), fulfilling the SOAR (Security Orchestration, Automation, and Response) requirement.

  6. Question 6

    Stellaron Corp is designing a network security architecture for their Azure environment. They want to inspect all outbound internet traffic from their virtual networks to prevent data exfiltration and enforce corporate web policies. Additionally, they need to inspect traffic between spoke virtual networks that are peered to a central hub VNet. The solution must be a managed, cloud-native service that offers advanced threat protection, including TLS inspection and intrusion detection and prevention systems (IDPS). Which Azure service should be deployed in the hub VNet to meet all these requirements?

    Answer and explanation

    Correct answer: C

    Azure Firewall Premium is the ideal choice for this scenario. It is a managed, cloud-native firewall service that can be deployed in a central hub VNet to inspect both east-west (spoke-to-spoke) and north-south (outbound to internet) traffic. The Premium SKU specifically provides advanced capabilities like TLS inspection to decrypt and inspect outbound traffic, a signature-based IDPS to detect and prevent malicious activity, and URL filtering for web policies. NSGs operate at Layer 4 and lack these advanced features, while Application Gateway is primarily for protecting inbound web traffic.

  7. Question 7

    True or False: When designing a resiliency strategy against ransomware, the primary focus should be on implementing advanced threat detection tools like EDR, with backup and recovery solutions being a secondary consideration.

    Answer and explanation

    Correct answer: B

    This statement is false. While detection tools are critical for prevention, a comprehensive ransomware resiliency strategy must prioritize business continuity and disaster recovery (BCDR). The assumption should always be that a preventative control might fail. Therefore, a robust, tested, and secure backup and recovery solution is the ultimate safety net to ensure the business can recover its data and operations without paying a ransom. Microsoft security best practices emphasize a balanced approach but highlight BCDR as a cornerstone of ransomware resilience.

  8. Question 8

    A university needs to provide secure access to on-premises legacy web applications for its researchers, who often work remotely. The university wants to avoid using a traditional VPN and instead adopt a Zero Trust approach. The solution must integrate with their existing Azure Active Directory for authentication, enforce Conditional Access policies like requiring MFA, and not require opening inbound ports on their on-premises firewall. Which service should the university's security architect recommend?

    Answer and explanation

    Correct answer: B

    Microsoft Entra Private Access (which includes the capabilities of the former Azure AD Application Proxy) is the correct solution. It acts as a Zero Trust Network Access (ZTNA) service. It allows publishing on-premises web applications to external users through the Microsoft Entra service. Lightweight connectors are installed on-premises and make outbound connections to the service, meaning no inbound firewall ports need to be opened. It fully integrates with Azure AD, allowing pre-authentication and the application of Conditional Access policies before granting access to the on-premises application, perfectly matching all the requirements.

  9. Question 9

    A retail company is expanding its use of Microsoft 365 and is concerned about data leakage through both managed and unmanaged devices. A security architect must design a solution that provides visibility into cloud app usage, including discovering 'shadow IT' applications. The solution must also enforce granular session controls for sanctioned apps, such as blocking downloads of sensitive files to unmanaged devices. Which Microsoft 365 security service is the primary tool for achieving these Cloud Access Security Broker (CASB) functionalities?

    Answer and explanation

    Correct answer: C

    Microsoft Defender for Cloud Apps is Microsoft's Cloud Access Security Broker (CASB) solution. It directly addresses the requirements by providing capabilities for shadow IT discovery (discovering and assessing cloud apps used by the organization) and by acting as a reverse proxy to apply session controls. These session controls can enforce policies like blocking downloads, uploads, or copy/paste actions for specific users or devices, which is exactly what is needed to prevent data leakage to unmanaged devices.

  10. Question 10

    You are designing a security architecture for a new Azure environment. To align with the Microsoft Cloud Adoption Framework (CAF), you must ensure that all newly deployed resources automatically adhere to corporate security standards, such as enforcing specific NSG rules, enabling encryption, and restricting public IP addresses. What is the most effective way to implement this governance and security requirement at scale for all new subscriptions and resource groups?

    Answer and explanation

    Correct answer: B

    The Cloud Adoption Framework emphasizes establishing governance from the start. The most effective and scalable way to enforce security standards across an entire Azure estate is by using Azure Policy assignments or Azure Blueprints at a high level in the management group hierarchy. This ensures that any new subscription created under that management group automatically inherits the policies, guaranteeing compliance without manual intervention. This approach is a core principle of designing and governing Azure landing zones.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 169 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon