Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Microsoft Cybersecurity Architect

Last Update 10 hours ago Total Questions : 310

The Microsoft Cybersecurity Architect content is now fully updated, with all current exam questions added 10 hours ago. Deciding to include SC-100 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our SC-100 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these SC-100 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Microsoft Cybersecurity Architect practice test comfortably within the allotted time.

Question # 11

Your company has a main office and a branch office.

The main office contains 20 on-premises servers that run Windows Server and host apps that are published by using Microsoft Entra application proxy. The main office contains 500 on-premises computers that run Windows 11. The branch office contains 100 on-premises computers that run Windows 11.

All the main office computers are enrolled in Microsoft Intune. The branch office computers are NOT enrolled in Intune.

You have a Microsoft 365 E5 subscription.

You have a Microsoft Entra tenant. You have a third-party software as a service (SaaS) app that is registered in the Microsoft Entra tenant.

You plan to implement Global Secure Access.

You are evaluating the use of compliant network check and Conditional Access.

Which two scenarios are supported by compliant network check? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point

A.

connections from the branch office computers

B.

Continuous Access Evaluation for Microsoft Exchange Online

C.

connections to the third-party SaaS app

D.

connections to the on-premises apps

Question # 12

You have an Azure subscription that contains a resources group named RG1. RG1 contains multiple Azure Files shares.

You need to recommend a solution to deploy a backup solution for the shares. The solution must meet the following requirements:

• Prevent the deletion of backups and the vault used to store the backups.

• Prevent privilege escalation attacks against the backup solution.

• Prevent the modification of the backup retention period.

Which three actions should you recommend be performed in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Question # 13

You have an Azure subscription that contains Azure App Service web apps. The apps have the following characteristics:

• The apps are deployed by using continuous integration and continuous deployment (CI/CD) pipelines in Azure DevOps.

• The apps are deployed to a test environment first, and then to a production environment.

• The source code for the apps is stored in Azure Repos.

You plan to implement DevSecOps controls based on the Microsoft Cloud Adoption Framework for Azure. You need to recommend testing controls to meet the following requirements:

• All the source code must be tested for security vulnerabilities in Azure Repos before deploying the apps.

• Once the apps are deployed to the test environment they must be tested for security vulnerabilities.

Which testing method should you recommend for each stage? To answer, select the options in the answer area.

NOTE: Each correct answer is worth one point.

Question # 14

You use Azure Pipelines with Azure Repos to implement continuous integration and continuous deployment (O/CD) workflows for the deployment of applications to Azure. You need to recommend what to include in dynamic application security testing (DAST) based on the principles of the Microsoft Cloud Adoption Framework for Azure. What should you recommend?

A.

unit testing

B.

penetration testing

C.

dependency testing

D.

threat modeling

Question # 15

You have a Microsoft Entra tenant that is linked to a Microsoft 365 subscription and an Azure subscription. The tenant contains service principals that are used to access applications in the Azure subscription.

You need to recommend a solution to detect risky sign-ins and other risky activities performed by the service principals in the tenant. The solution must minimize costs.

What should you include in the recommendation? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 16

You have a Microsoft 365 tenant.

You need to recommend a Microsoft 365 Defender solution to enhance security for the tenant. The solution must meet the following requirements:

• Identify users that are downloading an unusually high number of files from Microsoft SharePoint Online sites and are possibly involved in a data exfiltration attempt.

• Block Microsoft Teams messages that contain potentially malicious content by using zero-hour auto purge (ZAP).

What should you recommend for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Question # 17

You are designing a security strategy for providing access to Azure App Service web apps through an Azure Front Door instance.

You need to recommend a solution to ensure that the web apps only allow access through the Front Door instance.

Solution: You recommend access restrictions to allow traffic from the backend IP address of the Front Door instance.

Does this meet the goal?

A.

Yes

B.

No

Question # 18

You have a Microsoft 365 tenant named contoso.com.

You need to ensure that users can authenticate only to contoso.com. The solution must meet the following requirements:

• Prevent the users from authenticating to other Microsoft 365 tenants.

• Minimize administrative effort.

What should you use?

A.

Microsoft Defender for Endpoint

B.

Microsoft Entra Internet Access

C.

Microsoft Entra Private Access

D.

Microsoft Defender for Cloud Apps

Question # 19

You have a Microsoft 365 E5 subscription.

You plan to deploy Global Secure Access universal tenant restrictions v2.

Which authentication plane resources and which data plane resources will be protected? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 20

You are designing a privileged access strategy for a company named Contoso, Ltd. and its partner company named Fabrikam, Inc. Contoso has a Microsoft Entra tenant named contoso.com. Fabrikam has a Microsoft Entra tenant named fabrikam.com. Users at Fabrikam must access the resources in contoso.com.

You need to provide the Fabrikam users with access to the Contoso resources by using access packages. The solution must meet the following requirements:

• Ensure that the Fabrikam users can use the Contoso access packages without explicitly creating guest accounts in contoso.com.

• Allow non-administrative users in contoso.com to create the access packages.

What should you use for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Go to page: