Official Bank 0/269

Microsoft Cybersecurity Architect Exam (SC-100) - Microsoft Exam Questions

Last updated on June 22, 2026

97% Exam Compliance
269 Total Questions
1
Question
You receive a security alert in Microsoft Defender for Cloud as shown in the exhibit. (Click the Exhibit tab.)

Exhibit

After remediating the threat which policy definition should you assign to prevent the threat from reoccurring?
Options
A Azure Key Vault Managed HSM should have purge protection enabled
B Storage accounts should prevent shared key access
C Storage account public access should be disallowed
D Storage account keys should not be expired
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
You have a Microsoft Entra tenant named contoso.com and use Microsoft Intune. Each user in contoso.com has a Microsoft Entra ID P1 license and a Windows 11 device that has the Global Secure Access client deployed.

You plan to deploy the following configuration of Microsoft Entra Internet Access:

• Enable a baseline profile.

• Create a security profile named Profile` that has a priority of 300 and contains a single web
content filtering policy named WCFPolicy configure WCFPolicy1 as follows: o Set Action to allow. o Include a single rule that has a fully qualified domain name (FQDN) destination of ‘. adatum.com.

• Link Profile1 to a Conditional Access policy named CAPolicy1, apply CAPolicy1 to all users, and
grant access unless a user's device is noncompliant

You need to evaluate the impact of the planned deployment on traffic to the following resources:

• https://www.adatum.com:8433

• https://www.fabrikam.com

Which two traffic scenarios will occur? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point
Select 2
Options
A Traffic to https://www.adatum.com:8433 will be blocked from all the devices.
B Traffic to https://www.fabrikam.com will be blocked from noncompliant devices only.
C Traffic to https://www.adatumxom:8433 will be allowed from all the devices.
D Traffic to https://www.adatum.com:8433 will be allowed from compliant devices only.
E Traffic to https://www.fabrikam.com will be allowed from all the devices.
F Traffic to https://www.fabrikam.com will be allowed from compliant devices only.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
You have a Microsoft 365 subscription that syncs with Active Directory Domain Services (AD DS). You need to define the recovery steps for a ransomware attack that encrypted data in the subscription The solution must follow Microsoft Security Best Practices.

What is the first step in the recovery plan?
Options
A Recover files to a cleaned computer or device.
B Contact law enforcement.
C Disable Microsoft OneDnve sync and Exchange ActiveSync.
D From Microsoft Defender for Endpoint perform a security scan.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
You are evaluating an Azure environment for compliance. You need to design an Azure Policy implementation that can be used to evaluate compliance without changing any resources.

Which effect should you use in Azure Policy?
Options
A Disabled
B Modify
C Deny
D Append
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
You are designing a security strategy for providing access to Azure App Service web apps through an Azure Front Door instance. You need to recommend a solution to ensure that the web apps only allow access through the Front Door instance. Solution: You recommend access restrictions based on HTTP headers that have the Front Door ID. Does this meet the goal?
Options
A No
B Yes
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.