Microsoft Cybersecurity Architect (SC-100) practice questions

220 free questions with answers and explanations.

Practice test
  1. 51.A healthcare organization is migrating its patient records database from an on-premises SQL Server to Azure SQL Database. Compliance regulations mandate that all sensitive patient health information (PHI) must be encrypted at the column level within the database, and the encryption keys must be managed externally by the organization, not by Microsoft. This ensures that even database administrators cannot view unencrypted PHI. Which Azure SQL Database feature should be implemented?Design security for applications and data
  2. 52.A global manufacturing company uses Azure Data Factory to ingest and transform sensitive customer data from various on-premises and cloud sources. The transformed data is stored in Azure Data Lake Storage Gen2. The company needs to enforce strict access controls based on user roles and data classifications, ensuring that only authorized personnel can access specific data sets, even at the file or folder level within the Data Lake. Which security mechanism should be primarily used to achieve this granular access control?Design security for applications and data
  3. 53.A startup is building a new mobile application that stores user profiles and preferences in an Azure Cosmos DB database. The application developers want to implement encryption for specific sensitive fields within the JSON documents, such as email addresses and phone numbers, before the data is sent to Cosmos DB. This encryption should be handled by the client application, and the database should only ever receive and store the encrypted values. Keys for this encryption will be managed in Azure Key Vault. Which encryption approach should the security architect recommend?Design security for applications and data
  4. 54.A global e-commerce company uses Azure Blob Storage to store customer images, product catalogs, and order history. Due to regulatory requirements and legal hold policies, certain critical data, specifically archived order history, must be retained for a fixed period and cannot be modified or deleted, even by administrators. Which Azure Blob Storage feature should the company implement for this specific data?Design security for applications and data
  5. 55.A global manufacturing company uses Azure DevOps for its software development lifecycle (SDLC). The security team wants to integrate security checks early into the development process for all new applications. This includes scanning source code for vulnerabilities, checking open-source components for known issues, and ensuring secure configuration of Azure resources deployed by CI/CD pipelines. The goal is to identify and remediate security flaws before they reach production. Which Azure service should the security architect integrate with Azure DevOps to achieve this 'shift-left' security approach?Design security for applications and data
  6. 56.A financial institution is designing a new customer-facing web application that will handle sensitive transaction data. The application will be hosted on Azure App Service. The security architect needs to implement a solution to protect the application from common web vulnerabilities such as SQL injection and cross-site scripting (XSS) at the network edge. The solution must also provide centralized management and logging. Which Azure service should the architect recommend?Design security for applications and data
  7. 57.A global manufacturing company uses Azure DevOps for its software development lifecycle (SDLC). They are concerned about vulnerabilities in container images used in their CI/CD pipelines and misconfigurations in their ARM templates. They need a solution that can automatically scan these artifacts for security issues early in the development process. Which Microsoft Defender for Cloud capability should they leverage?Design security for applications and data
  8. 58.A multinational corporation is developing a new customer relationship management (CRM) application that will collect and process customer data across various regions. The application must comply with local data privacy regulations, such as GDPR in Europe and CCPA in California. The security architect needs to implement a data classification and labeling strategy that automatically identifies sensitive data, applies appropriate protection, and enforces access policies based on the data's sensitivity and regulatory requirements. Which Azure service combination provides the most comprehensive solution?Design security for applications and data
  9. 59.A global enterprise is designing a new customer relationship management (CRM) application that will process and store highly sensitive customer data, including financial and health information. The company has a strict data classification policy that requires all sensitive documents and emails generated by the CRM to be automatically labeled, encrypted, and have access restricted based on user roles and the sensitivity of the content. This protection needs to persist even when documents are shared externally. Which Microsoft technology should the security architect leverage to meet these comprehensive data protection requirements?Design security for applications and data
  10. 60.A global enterprise is designing its multi-region Azure architecture to host critical web applications. The security team requires a highly scalable, cloud-native firewall solution that can provide advanced threat protection capabilities, including TLS/SSL inspection, URL filtering, and IDPS (Intrusion Detection and Prevention System), for outbound traffic from Azure Virtual Networks. Which Azure service should the architect recommend?Design security for applications and data
  11. 61.A large enterprise is designing a new data analytics platform on Azure that will consolidate various data sources, including on-premises databases, SaaS applications, and IoT devices. The platform will use Azure Data Lake Storage Gen2 as its central data repository. The security architect needs to ensure that all data ingested into Data Lake Storage Gen2 is automatically scanned for sensitive information (e.g., PII, financial data) and that data owners are notified of any findings to apply appropriate governance policies. Which Azure service is best suited for this automated data discovery and classification within the data lake?Design security for applications and data
  12. 62.A large enterprise is designing a new data analytics platform on Azure that will consolidate data from various departments, including HR, finance, and operations. This platform will contain highly sensitive personal identifiable information (PII) and financial records. The company needs a unified solution to discover, classify, map, and govern all its data assets across hybrid and multi-cloud environments, ensuring compliance with data privacy regulations. Which Azure service is best suited for this comprehensive data governance requirement?Design security for applications and data
  13. 63.A global e-commerce company uses Azure Blob Storage to store customer images, product catalogs, and order fulfillment documents. Some of this data contains PII and is subject to GDPR regulations. The security architect needs to implement a data retention policy that automatically deletes data after a specified period, encrypts all data at rest, and prevents accidental deletion or modification of critical historical records for a certain duration. Which combination of Azure Blob Storage features should be used?Design security for applications and data
  14. 64.A research institution is developing a new data analytics platform on Azure that will consolidate sensitive genomic data from various sources. The platform needs to ensure that data access permissions are granular, allowing different research teams to access specific datasets within the data lake, while ensuring that access to the underlying storage is not granted directly to users. The solution must support both identity-based access control and POSIX-like permissions for fine-grained control over files and directories. Which security model should the architect recommend for Azure Data Lake Storage Gen2?Design security for applications and data
  15. 65.A global financial institution is migrating its core banking applications to Azure. These applications rely heavily on stored procedures and parameterized queries to interact with sensitive customer account data in Azure SQL Database. The institution requires that sensitive columns, such as account numbers and balances, are encrypted within the database and can only be decrypted by the client application, without exposing the encryption keys to the database engine. The solution must also support computations (e.g., comparisons, arithmetic operations) on the encrypted data directly within the database, without requiring decryption server-side. Which Azure SQL Database feature should the architect recommend?Design security for applications and data
  16. 66.A software development company is building a new microservices-based application on Azure. Each microservice needs to securely access other Azure resources, such as Azure Key Vault for secrets and Azure Storage for data. These microservices are deployed as Azure App Services. The security architect wants to eliminate the need for developers to manage credentials or connection strings in code for these interactions. Which security mechanism should be implemented?Design security for applications and data
  17. 67.A global e-commerce company is migrating its entire product catalog and customer order history, including credit card details, to Azure Blob Storage. The company has a strict regulatory requirement to retain all data for a minimum of seven years and ensure that the data cannot be altered or deleted during this period, even by administrators. Which Azure Blob Storage feature should the security architect recommend to meet this specific immutability requirement?Design security for applications and data
  18. 68.A company uses Azure Data Factory to ingest and transform sensitive customer data from various sources into an Azure Data Lake Storage Gen2 account. The transformed data is then used by Azure Synapse Analytics for reporting. The security architect needs to ensure that data in Data Lake Storage Gen2 is always encrypted at rest and that access is strictly controlled based on the principle of least privilege, using Azure Active Directory (AAD) identities. Which encryption and access control mechanisms should be prioritized?Design security for applications and data
  19. 69.A healthcare provider is deploying a new patient portal application to Azure App Service. The application will store patient health records (PHR) in Azure Cosmos DB and images in Azure Blob Storage. The security architect needs to ensure that all data access from the App Service to these backend services is secured using private networking, eliminating exposure to the public internet, to comply with HIPAA regulations. Which Azure networking feature is most appropriate for achieving this private connectivity?Design security for applications and data
  20. 70.A multinational corporation is designing a new customer relationship management (CRM) application on Azure. The application will handle highly sensitive customer data, including personally identifiable information (PII) and financial details. The company requires that data classification and protection policies are consistently applied across all data stored in Azure, on-premises, and in SaaS applications. Furthermore, these policies must allow for automated encryption, access restrictions, and visual marking based on the sensitivity of the data. Which Microsoft solution should the architect recommend?Design security for applications and data
  21. 71.A global retail company is deploying a new e-commerce platform on Azure Kubernetes Service (AKS). The application processes payment card industry (PCI) data and requires a high level of isolation and security for its containerized workloads. Specifically, the company needs to ensure that containers are run in a highly isolated environment with a strong hardware-backed boundary, preventing any unauthorized access or compromise of the host kernel. Which AKS feature should the security architect recommend?Design security for applications and data
  22. 72.A global financial institution is designing a new high-transaction online banking application. The application will use Azure Kubernetes Service (AKS) for container orchestration. To ensure the highest level of workload isolation and prevent potential container escape vulnerabilities, the security architect needs to recommend a container runtime that provides a strong isolation boundary, similar to a virtual machine, for sensitive workloads. Which AKS container runtime should the architect recommend?Design security for applications and data
  23. 73.A healthcare provider is deploying a new patient portal application to Azure App Service. The application needs to securely connect to an Azure SQL Database instance that hosts sensitive patient health information (PHI). To enhance security and restrict network access, the database should not be accessible over the public internet, and all traffic between the App Service and SQL Database must remain within the Azure backbone network. Which networking solution should the architect implement?Design security for applications and data
  24. 74.A company is developing a new serverless application using Azure Functions. The application will process sensitive customer data and store it in an Azure SQL Database. The security architect needs to ensure that the Azure Functions can securely connect to the Azure SQL Database without exposing credentials in the function code or configuration. Which method should the architect recommend for secure database connectivity?Design security for applications and data
  25. 75.A global pharmaceutical company is designing a new research data platform on Azure. The platform will store highly sensitive genomic data and clinical trial results. The company requires a solution that ensures data remains encrypted during processing, even from the cloud provider's administrators. Which Azure technology should the company prioritize to meet this requirement?Design security for applications and data
  26. 76.A global pharmaceutical company is migrating its research and development (R&D) data to Azure. This data includes highly sensitive intellectual property (IP) and patient trial results. The company requires that data remains encrypted even while being processed in memory to prevent unauthorized access from privileged administrators or malicious insiders, known as 'in-use' encryption. Which Azure technology should the architect recommend to meet this stringent requirement?Design security for applications and data
  27. 77.A global financial institution is migrating its core banking applications to Azure. These applications use highly sensitive customer account data, which must be encrypted at rest, in transit, and during processing. The institution requires a solution that provides cryptographic separation between the application and the database owner, ensuring that the database administrator cannot view decrypted sensitive data. Which encryption technology should be used for the Azure SQL Database?Design security for applications and data
  28. 78.A startup is building a new mobile application that stores user profiles and preferences in Azure Cosmos DB. To protect user privacy, the company wants to ensure that all sensitive user data is encrypted within the application before being sent to Cosmos DB, and that the encryption keys are never exposed to Azure Cosmos DB itself. Which encryption approach should the startup use?Design security for applications and data
  29. 79.A global pharmaceutical company is migrating its research and development data to Azure. This data includes highly sensitive clinical trial results and intellectual property. The company requires a solution that ensures data remains encrypted both at rest and in transit, and also offers the ability to perform computations on encrypted data without decrypting it, thereby minimizing the risk of exposure during processing. Which Azure data security technology should the company prioritize?Design security for applications and data
  30. 80.A global enterprise is designing its multi-region Azure architecture to host critical web applications. The security architect needs to ensure robust network segmentation, centralized traffic inspection, and advanced threat protection for all outbound and inbound traffic, including URL filtering and IDPS (Intrusion Detection and Prevention System) capabilities. This solution must operate at the network layer and apply across multiple virtual networks and subscriptions. Which Azure service should be deployed?Design security for applications and data
  31. 81.A financial services organization is building a new customer-facing web application on Azure App Service. The application will frequently access customer financial data stored in an Azure SQL Database. The security architect needs to implement a comprehensive strategy to protect the application from common web vulnerabilities, specifically SQL injection and cross-site scripting (XSS), and ensure consistent security policies are applied across all application instances. Which Azure service should be deployed in front of the App Service to meet these requirements?Design security for applications and data
  32. 82.A financial services organization is building a new customer-facing web application on Azure. The application will be exposed to the public internet and must be protected against common web vulnerabilities such as SQL injection, cross-site scripting (XSS), and cross-site request forgery (CSRF). Additionally, the solution needs to provide SSL/TLS termination, centralized certificate management, and load balancing for the backend web servers. Which Azure service should the security architect deploy to meet these requirements?Design security for applications and data
  33. 83.A financial institution is migrating its legacy on-premises applications to Azure. These applications handle sensitive customer financial data and require highly secure, FIPS 140-2 Level 3 validated cryptographic key storage. Which Azure Key Vault offering should the institution choose to meet this compliance requirement?Design security for applications and data
  34. 84.A financial institution is designing a new customer-facing web application that will handle sensitive personal identifiable information (PII) and financial transaction data. The application will be hosted on Azure App Service. The security architect needs to ensure that all data in transit between the client browser and the application, and between the application and backend services, is encrypted. Additionally, the application must enforce strict access controls based on user roles and ensure that only authenticated users can access their own data. Which Azure service should be primarily used to manage and rotate the digital certificates required for secure communication (TLS/SSL) for the web application?Design security for applications and data
  35. 85.A software development company is building a new microservices-based application on Azure. Each microservice is deployed as an Azure Function or Azure Container Instance. These microservices need to securely access other Azure services like Azure Key Vault and Azure Cosmos DB without using hardcoded credentials or secrets in their code. The security architect needs a solution that provides an automatically managed identity for each microservice, authenticated by Azure AD, to access other resources. Which Azure service or feature should be implemented?Design security for applications and data
  36. 86.A software development company is building a new microservices-based application on Azure Kubernetes Service (AKS). The application processes customer orders and integrates with several third-party APIs. The security architect needs to design a strategy to manage secrets (API keys, database connection strings) for the microservices securely and to ensure that only authorized services can access these secrets. The solution must also support automatic secret rotation and provide an audit trail of secret access. Which Azure service is the most appropriate for this requirement?Design security for applications and data
  37. 87.A global manufacturing company is migrating its legacy on-premises applications to Azure. One critical application relies on hardware security modules (HSMs) for cryptographic key storage and operations, requiring FIPS 140-2 Level 3 validated protection. The security architect needs to ensure that the migrated application can continue to use HSM-backed keys in Azure with equivalent or stronger security guarantees. Which Azure Key Vault tier should the architect recommend?Design security for applications and data
  38. 88.A global e-commerce company uses Azure Cosmos DB to store customer profiles and order history. To comply with GDPR and other data privacy regulations, the company needs to ensure that personally identifiable information (PII) within Cosmos DB documents is encrypted before it leaves the client application, and only authorized client applications can decrypt it. Which data encryption strategy should they implement?Design security for applications and data
  39. 89.A healthcare provider is deploying a new patient portal application to Azure App Service. The application needs to securely access a PostgreSQL database hosted in an Azure Virtual Network (VNet) that is not exposed to the public internet. The security architect must ensure that all traffic between the App Service and the PostgreSQL database remains entirely within the Azure backbone network and does not traverse the public internet, while also simplifying network configuration. Which networking feature should the architect recommend?Design security for applications and data
  40. 90.A global financial institution is migrating its core banking applications to Azure. These applications handle highly sensitive customer financial data and require the highest level of data confidentiality. The architect needs to ensure that sensitive columns in the Azure SQL Database, such as account numbers and credit card details, are encrypted at rest and in transit, and that the encryption keys are never exposed to the database engine. This encryption must also support complex operations like joins and aggregations on encrypted data without decrypting the entire dataset. Which Azure SQL Database feature should be implemented?Design security for applications and data
  41. 91.A startup is building a new mobile application that stores user profiles and preferences in Azure Cosmos DB. The application is designed with a 'zero-trust' principle, meaning that even the application backend should not have direct access to unencrypted sensitive user data. The security architect needs to ensure that sensitive user attributes, such as email addresses and phone numbers, are encrypted by the client application before being sent to Cosmos DB and remain encrypted at rest and in transit, with decryption only possible by the client application. Which data protection approach should the architect recommend?Design security for applications and data
  42. 92.A startup is building a new mobile application that stores user profiles and preferences in Azure Table Storage. They are concerned about data breaches and want to ensure that even if the storage account is compromised, the sensitive user data (e.g., email addresses) remains unreadable to unauthorized parties. The security architect needs to implement encryption for specific sensitive columns within the Azure Table Storage, without requiring a full client-side encryption solution for the entire table. Which approach should be taken?Design security for applications and data
  43. 93.A global manufacturing company uses Azure DevOps for its software development lifecycle (SDLC). The security team wants to integrate security best practices directly into the CI/CD pipelines to identify and remediate vulnerabilities early in the development process, including Infrastructure as Code (IaC) misconfigurations and insecure container images. Which Microsoft Defender for Cloud capability should the architect recommend?Design security for applications and data
  44. 94.A financial services organization is designing a new customer-facing web application that will handle sensitive personal and financial information. The security architect needs to ensure that all data exchanged between the application and the client browsers is encrypted using TLS/SSL certificates managed securely. The certificates must be automatically renewed and centrally managed with robust access control. Which Azure service should be used to manage these certificates?Design security for applications and data
  45. 95.A global manufacturing company is migrating its legacy on-premises applications to Azure. One critical application uses hardware security modules (HSMs) to protect cryptographic keys. The company requires a cloud solution that provides FIPS 140-2 Level 3 validated HSMs for key protection, ensuring that keys are never exposed outside the HSM boundary, even to Azure administrators. Which tier of Azure Key Vault should be recommended?Design security for applications and data
  46. 96.A global manufacturing company uses Azure DevOps for its software development lifecycle (SDLC). The security architect needs to implement a 'shift-left' security strategy for their applications, ensuring that security vulnerabilities are identified and remediated as early as possible in the development process, ideally before code is even deployed to production. This includes scanning code for vulnerabilities, checking for misconfigurations in Infrastructure-as-Code (IaC) templates, and scanning container images. Which Azure service is central to implementing this strategy within Azure DevOps?Design security for applications and data
  47. 97.A healthcare organization is deploying a new patient portal application to Azure App Service. The application needs to securely connect to a backend Azure SQL Database that contains sensitive patient health information (PHI). To comply with HIPAA regulations, all traffic between the App Service and the SQL Database must remain entirely within the Azure backbone network and not traverse the public internet. The security architect also needs to ensure that the SQL Database is not publicly accessible. Which networking service should be used to establish this secure and private connection?Design security for applications and data
  48. 98.A multinational corporation is designing a new customer relationship management (CRM) application on Azure. The application will store customer data across various Azure services, including Azure SQL Database and Azure Blob Storage. The company needs to classify and protect this data based on its sensitivity (e.g., 'Confidential', 'Highly Confidential'). This classification must be integrated with existing Microsoft 365 data governance policies and allow for consistent labeling and protection across both structured and unstructured data. Which Microsoft Purview capability should the architect recommend?Design security for applications and data
  49. 99.A global e-commerce company uses Azure Blob Storage to store customer images, product catalogs, and historical order data. Due to regulatory compliance (e.g., GDPR, PCI DSS), the company must ensure that certain critical data, once written, cannot be modified or deleted for a specified retention period. This is crucial for audit trails and legal hold requirements. Which Azure Blob Storage feature should be configured?Design security for applications and data
  50. 100.A large pharmaceutical company is implementing a Zero Trust strategy. They have a complex network infrastructure with numerous internal applications and services, some of which are legacy and lack modern authorization mechanisms. The company needs to enforce granular access policies to these internal resources based on user identity, device posture, and application context, without modifying the legacy applications themselves. Which Zero Trust component acts as the critical enforcement point to achieve this?Design a Zero Trust strategy and architecture