Microsoft Cybersecurity Architect (SC-100) practice questions
220 free questions with answers and explanations.
- 101.A company is deploying a new application that uses Azure Key Vault to store cryptographic keys and secrets. The security architect needs to ensure that access to Key Vault is restricted to only authorized Azure resources (e.g., Azure App Service, Azure Functions) and prevents access from the public internet, even if a resource has an incorrect configuration. Which Key Vault networking feature should be configured?Design security for infrastructure
- 102.A global software development company is designing a Zero Trust strategy for its developers who frequently access source code repositories and build servers from various locations, including home offices and co-working spaces. These developers often use high-privilege accounts. The security architect needs to implement a solution that ensures these privileged accounts are only active when explicitly needed and for a limited duration, minimizing the window of opportunity for compromise. Which Zero Trust principle, specifically implemented through a solution like Azure AD PIM, is being addressed here?Design a Zero Trust strategy and architecture
- 103.A large pharmaceutical company is implementing a Zero Trust strategy to protect its intellectual property, which includes highly sensitive research data. The company uses a hybrid cloud model with on-premises data centers and Azure. They need to ensure that data classification and labeling are consistently applied and enforced across all environments, regardless of where the data resides or how it is accessed. Furthermore, access to this sensitive data must be dynamically restricted based on its classification, the user's role, and the device's compliance status.Design a Zero Trust strategy and architecture
- 104.A government agency is designing a Zero Trust architecture for its highly sensitive data and applications, some of which reside in an on-premises private cloud and others in Azure Government. The agency has a strict requirement that all data in transit between these environments, and within each environment, must be protected by cryptographic means, even if the network path is considered 'internal'. This is to comply with the 'assume breach' principle and minimize the impact of a compromised network segment. Which Zero Trust security capability is MOST crucial to meet this requirement?Design a Zero Trust strategy and architecture
- 105.A global financial institution is migrating its on-premises data centers to a hybrid cloud architecture, leveraging Azure. They need to ensure secure and optimized connectivity between their distributed branch offices, remote users, on-premises data centers, and cloud-based applications. The Zero Trust strategy requires that all network traffic, regardless of its origin or destination, passes through a centralized security inspection point before reaching its target. This must be achieved without backhauling all internet traffic to the corporate data center.Design a Zero Trust strategy and architecture
- 106.A manufacturing company is implementing a Zero Trust strategy for its Operational Technology (OT) network, which controls critical machinery. Due to the sensitive nature of OT systems, direct internet connectivity and complex software installations are strictly prohibited. The company needs to provide secure, audited, and isolated remote access for maintenance personnel to specific OT devices without introducing new attack vectors from the IT network. Which solution BEST aligns with these stringent requirements?Design a Zero Trust strategy and architecture
- 107.A company is implementing a zero-trust architecture for its hybrid cloud environment. A critical requirement is to ensure every network access request, regardless of origin, is authenticated, authorized, and encrypted. The company heavily relies on Azure Virtual Networks (VNets) and has on-premises data centers connected via ExpressRoute. Which Azure service combination provides the most robust solution for enforcing these principles across both cloud and on-premises resources?Design security for infrastructure
- 108.A large multinational corporation is migrating its on-premises data centers to Azure. The security architecture team needs to establish a secure and compliant environment. They are particularly concerned about ensuring consistent security policies, centralized management of network security, and isolation between different business units' resources while allowing controlled communication. Which Azure networking service is best suited to meet these requirements?Design security for infrastructure
- 109.A financial institution is migrating a legacy application to Azure. This application processes highly sensitive customer financial data that must remain encrypted at rest and in transit. Additionally, the institution requires a solution that enables cryptographic operations to be performed on the encrypted data without decrypting it in memory, even by the cloud provider. Which Azure compute technology should be recommended to meet these stringent security requirements?Design security for infrastructure
- 110.A global software development company is adopting a DevSecOps approach within its Zero Trust strategy. They use Azure DevOps for their CI/CD pipelines and GitHub for source code management. The security team needs to ensure that security vulnerabilities are identified early in the development lifecycle, specifically within the source code itself and during application runtime, before deployment to production. The solution should be integrated into the existing pipelines to automate security checks.Design a Zero Trust strategy and architecture
- 111.A global financial services company is migrating its on-premises data centers to a hybrid cloud environment, leveraging Azure and AWS. The company handles highly sensitive customer data and must adhere to strict regulatory compliance standards. The security architect needs to design a network segmentation strategy that enforces micro-segmentation across both on-premises and cloud environments, preventing lateral movement of threats. Which Zero Trust architectural concept is MOST relevant for achieving this level of granular network control?Design a Zero Trust strategy and architecture
- 112.A large multinational corporation is designing a Zero Trust strategy for its geographically dispersed workforce. The security architects need to ensure that access to internal resources is granted only after evaluating all available signals, including user identity, device health, location, and behavior patterns. Which core principle of Zero Trust is most directly addressed by this requirement?Design a Zero Trust strategy and architecture
- 113.A government agency is modernizing its IT infrastructure and adopting a Zero Trust architecture. They have a highly sensitive application that processes classified data, residing in an isolated network segment. Access to this application must be strictly controlled, allowing only specific authorized microservices to communicate with it, and blocking all other traffic. This isolation needs to be enforced at the network layer. Which Zero Trust concept is being applied here?Design a Zero Trust strategy and architecture
- 114.A software-as-a-service (SaaS) provider is building a multi-tenant application on Azure Kubernetes Service (AKS). Each tenant's data and application components must be logically isolated from other tenants to meet strict compliance and security requirements. The Zero Trust architecture mandates that communication between pods belonging to different tenants, even within the same AKS cluster, must be strictly controlled and denied by default. Access decisions must be based on the identity of the tenant and the specific application components.Design a Zero Trust strategy and architecture
- 115.A large multinational corporation is designing a Zero Trust architecture for its global operations. The company has a significant number of legacy applications hosted on-premises and a growing number of cloud-native applications in Azure and AWS. Employees access resources from various locations, including corporate offices, remote work environments, and untrusted networks. The security architect needs to ensure that access decisions are made dynamically based on user identity, device health, location, and resource sensitivity, regardless of where the user or resource is located. Which core principle of Zero Trust is MOST critical to address this requirement?Design a Zero Trust strategy and architecture
- 116.A software-as-a-service (SaaS) provider is designing its Zero Trust architecture. They have a multi-tenant application hosted in Azure and need to ensure that each customer's data and application instances are logically separated and inaccessible to other customers, even within the same shared infrastructure. This isolation is critical for compliance and security. Which Zero Trust architectural approach is MOST relevant for achieving this secure logical separation in a multi-tenant cloud environment?Design a Zero Trust strategy and architecture
- 117.A company is designing an Azure landing zone for its new cloud environment. A critical security requirement is to establish a perimeter network (DMZ) that filters all inbound and outbound traffic to and from the virtual networks hosting application workloads. This DMZ should centralize network security services, including routing, firewalling, and intrusion detection/prevention. Which Azure networking pattern should the security architect recommend?Design security for infrastructure
- 118.A multinational corporation is expanding its operations and leveraging multiple cloud providers (Azure, AWS, GCP) for various workloads. They need to establish a unified security posture management solution that provides continuous visibility into configurations, compliance, and threats across all these cloud environments. The solution must also offer automated remediation capabilities and integrate with their existing security information and event management (SIEM) system.Design a Zero Trust strategy and architecture
- 119.A government agency is modernizing its applications and moving them to Azure Kubernetes Service (AKS). Due to strict compliance regulations, all inbound traffic to the AKS cluster must be subject to advanced threat protection, including Layer 7 inspection, SQL injection protection, and bot mitigation. Additionally, the agency requires a centralized point of entry for all applications hosted within AKS. Which Azure service should be deployed in front of the AKS cluster to meet these requirements?Design security for infrastructure
- 120.A financial institution is designing a Zero Trust architecture. They have identified that their on-premises applications, which are critical for daily operations, must be accessible securely by remote employees without exposing the internal network directly to the internet. The security architect needs a solution that acts as a reverse proxy to provide secure remote access to these internal web applications, integrating with Azure AD for authentication and Conditional Access policies. Which Azure AD service is BEST suited for this scenario?Design a Zero Trust strategy and architecture
- 121.A client is designing a data archiving solution in Azure for historical financial records. These records must be stored for a minimum of 7 years and be immutable, meaning they cannot be modified or deleted, even by privileged administrators, for the entire retention period. They also need to be cost-effective for long-term storage with infrequent access. Which Azure storage solution and feature should be used?Design security for infrastructure
- 122.A research institution is designing a Zero Trust strategy for its highly confidential scientific data stored in Azure Blob Storage. The institution requires that access to this data is not only based on user identity and role but also dynamically re-evaluated based on real-time factors like the user's location, device compliance, and even the sensitivity of the specific data being accessed. If any of these factors change during a session, access should be immediately revoked or restricted. Which Azure AD feature is crucial for implementing this dynamic, continuous access evaluation?Design a Zero Trust strategy and architecture
- 123.A company is implementing a Zero Trust strategy and needs to establish a robust identity governance framework. The organization uses Azure Active Directory (Azure AD) for identity management and has several business-critical applications, some of which require highly privileged access. The security architect must ensure that access reviews are regularly conducted for these privileged roles to prevent privilege creep and maintain compliance. Which Azure AD capability is BEST suited for automating and managing these access reviews?Design a Zero Trust strategy and architecture
- 124.A client is designing an Azure landing zone for a new environment that will host critical applications. A key security requirement is to enforce a consistent network security posture across all subscriptions and to prevent any unauthorized network configurations, such as public IP addresses on VMs or unapproved VNet peering. This enforcement must be automated and applied to new and existing resources. Which Azure service combination is most effective for this requirement?Design security for infrastructure
- 125.A global manufacturing company is implementing a Zero Trust strategy. They have recently acquired a smaller company that uses its own on-premises Active Directory and email system. The larger company needs to provide the acquired company's employees with access to certain corporate applications hosted in Azure AD, without migrating their identities or requiring them to create new accounts. Which Azure AD capability should the security architect leverage?Design a Zero Trust strategy and architecture
- 126.A company is implementing a Zero Trust strategy and needs to establish a robust identity governance framework. They want to ensure that privileged access is granted only when necessary, for a limited time, and with proper approval workflows. This approach should also include automated deactivation of elevated privileges after a specific period. Which Azure AD capability is designed to address these requirements?Design a Zero Trust strategy and architecture
- 127.A global conglomerate is designing a Zero Trust architecture for its diverse business units, each operating with significant autonomy and managing their own cloud subscriptions and on-premises infrastructure. The security team needs to implement a solution that centralizes security policy enforcement and visibility across these disparate environments without requiring a complete overhaul of existing identity providers or network configurations within each business unit. The solution must support conditional access based on user, device, application, and location attributes, and enforce policies consistently across SaaS applications, IaaS workloads, and on-premises resources.Design a Zero Trust strategy and architecture
- 128.A security architect is designing an infrastructure security strategy for a highly regulated environment that requires stringent control over network traffic. All outbound connections from Azure Virtual Machines (VMs) to the internet must be inspected, filtered, and logged. Additionally, the solution must support URL filtering, threat intelligence-based filtering, and TLS inspection. Which Azure service should be deployed to meet these requirements?Design security for infrastructure
- 129.A defense contractor is designing a Zero Trust architecture for its highly sensitive research and development environment. The environment contains intellectual property that must be protected with the highest level of assurance. To mitigate the risk of credential theft and malware, administrators accessing this environment must use dedicated, hardened workstations that are isolated from the general corporate network and internet browsing. Which specific Zero Trust security control does this describe?Design a Zero Trust strategy and architecture
- 130.A global software development company uses GitHub for source code management and Azure DevOps for CI/CD pipelines. They are implementing a Zero Trust strategy that extends to their development processes. The security team wants to ensure that all code changes undergo automated security analysis before deployment, identifying vulnerabilities early in the development lifecycle. Which two DevSecOps practices, when combined, would BEST achieve this Zero Trust objective?Design a Zero Trust strategy and architecture
- 131.A global financial institution is designing its cloud architecture in Azure. They require a solution to protect their web applications and APIs from common web exploits and bots, enforce granular access controls based on source IP and geo-location, and provide centralized management across multiple regions. They also need to integrate with Azure Sentinel for security information and event management (SIEM). Which Azure service should be recommended?Design security for infrastructure
- 132.A software development company uses Azure DevOps to manage its CI/CD pipelines. They need to ensure that all build agents, whether hosted or self-hosted, can securely retrieve credentials and configuration settings from Azure Key Vault without exposing these secrets in plaintext during the build process. The solution must adhere to the principle of least privilege and avoid hardcoding credentials. Which authentication method should be configured for the build agents?Design security for infrastructure
- 133.A global enterprise is designing a Zero Trust architecture for its cloud environment, which includes Azure and AWS. The security team wants to ensure that all cloud workloads, regardless of their hosting platform, are continuously monitored for misconfigurations, vulnerabilities, and threats, and that security posture management is unified. Which Microsoft security service is specifically designed to provide this multi-cloud security posture management and workload protection?Design a Zero Trust strategy and architecture
- 134.A security architect is reviewing the data retention policy for an Azure Blob Storage account that stores audit logs. The current policy is set to indefinitely retain all logs. Due to compliance requirements and cost optimization, the architect needs to implement a lifecycle management policy that moves logs older than 90 days to a cooler storage tier and deletes logs older than 365 days. Which storage tier should be used for logs older than 90 days before eventual deletion?Design security for infrastructure
- 135.A global software development company is designing a Zero Trust strategy for its developer environment. Developers require access to various source code repositories, build servers, and testing environments. To minimize the attack surface and prevent unauthorized access, the security architects must ensure that each developer only has the absolute minimum permissions required to perform their current task, and these permissions should be revoked automatically when no longer needed. Which Zero Trust principle is being emphasized here?Design a Zero Trust strategy and architecture
- 136.A global enterprise is migrating its legacy applications to a multi-cloud environment (Azure, AWS, GCP) while adopting a Zero Trust architecture. They need a centralized solution to collect security logs, detect threats across all cloud platforms and on-premises infrastructure, and automate responses to security incidents. Which Microsoft security service is best suited for this requirement?Design a Zero Trust strategy and architecture
- 137.An organization is migrating a financial application that uses a custom database to Azure. The application's security model dictates that database access credentials, API keys, and other secrets must be stored in a highly secure, centralized repository that is isolated from the public internet. The application must connect to this repository over a private, secure channel, and only authorized Azure resources should be able to retrieve secrets. Which Azure service and connectivity method should be used?Design security for infrastructure
- 138.A financial services company is designing a new application in Azure that will process highly sensitive customer financial data. The application will use an Azure SQL Database. Regulatory compliance requires that the data always remains encrypted, even during query processing, to prevent unauthorized access from database administrators or underlying infrastructure. Which Azure SQL Database feature should the architect recommend to meet this requirement?Design security for infrastructure
- 139.A healthcare organization is migrating highly sensitive patient data to Azure. The data will be stored in Azure SQL Database and accessed by applications running in Azure App Service. Regulatory compliance mandates that all data in transit between these services must be encrypted and isolated from the public internet. Which solution should the security architect implement to meet these requirements?Design security for infrastructure
- 140.A global enterprise is designing its Zero Trust architecture and needs to ensure that all devices accessing corporate resources, whether corporate-owned or personal (BYOD), meet specific security standards before being granted access. This includes checking for up-to-date antivirus, operating system patches, and disk encryption. Which type of solution is essential for implementing this control?Design a Zero Trust strategy and architecture
- 141.A global media company is designing a Zero Trust architecture for its content creation and distribution platform. They frequently collaborate with external partners, freelancers, and vendors who need temporary, secure access to specific project files and collaboration tools hosted in Azure. The company requires that these external users authenticate using their existing corporate identities (e.g., from their own Google Workspace or Microsoft 365 tenants) and that their access is governed by the media company's Conditional Access policies. Which Azure AD feature is BEST suited to manage this external collaboration securely within a Zero Trust framework?Design a Zero Trust strategy and architecture
- 142.A multinational corporation is designing a Zero Trust architecture for its global operations. The security team wants to ensure that all user identities, whether employees or external partners, are subject to the same rigorous authentication and authorization policies, regardless of their origin. What identity-centric Zero Trust control should be prioritized to achieve this goal?Design a Zero Trust strategy and architecture
- 143.A global media company is designing a Zero Trust architecture for its content creation and distribution platform. They frequently collaborate with external partners, freelancers, and agencies who require access to specific project files and applications. The company needs a secure and manageable way to grant these external users access without creating full internal accounts or replicating their identities across multiple systems. Access must be governed by conditional access policies.Design a Zero Trust strategy and architecture
- 144.A security architect is designing a strategy to protect sensitive data in Azure Storage accounts from accidental deletion, ransomware attacks, and unauthorized overwrites. The solution must ensure that data remains immutable for a specified retention period, even by administrators. Which Azure Blob Storage feature should be implemented?Design security for infrastructure
- 145.A global enterprise is migrating its legacy applications to a multi-cloud environment (Azure and AWS) while maintaining some critical services on-premises. The security architect is tasked with implementing a unified security operations center (SOC) that can collect security logs and alerts from all these diverse environments, correlate them, and provide a single pane of glass for threat detection and response, crucial for the 'assume breach' principle. Which Microsoft security service is BEST suited to aggregate and analyze security data across this hybrid and multi-cloud landscape?Design a Zero Trust strategy and architecture
- 146.A global manufacturing company is implementing a Zero Trust strategy. They have numerous legacy applications hosted in an on-premises data center that are critical for operations. These applications lack modern authentication capabilities and cannot be directly exposed to the internet. The company needs to securely provide access to these applications for remote employees without using a traditional VPN. Which Microsoft technology would BEST facilitate this requirement in a Zero Trust context?Design a Zero Trust strategy and architecture
- 147.A global manufacturing company is designing a new Azure environment to host its critical production control systems. These systems require extremely low latency, high bandwidth, and a direct, private connection to on-premises operational technology (OT) networks. Security demands isolation from the public internet and other Azure workloads. Which Azure networking service should the architect recommend to meet these requirements?Design security for infrastructure
- 148.A software-as-a-service (SaaS) provider is designing its Zero Trust architecture. They host multiple customer tenants within a shared Azure Kubernetes Service (AKS) cluster. A critical requirement is to ensure that while resources are shared, each customer's data and applications are strictly isolated from other tenants, with no possibility of cross-tenant data leakage or unauthorized access, even in the event of a compromise in an adjacent tenant. Which architectural approach is MOST effective for achieving this stringent isolation in a multi-tenant AKS environment?Design a Zero Trust strategy and architecture
- 149.A global manufacturing company is implementing a Zero Trust architecture. They have numerous legacy applications hosted on-premises that need to be securely accessed by remote employees and partners without exposing them directly to the internet. The company wants to avoid using a traditional VPN for all access. Which Azure service should the company integrate to provide secure, Zero Trust-compliant access to these internal applications?Design a Zero Trust strategy and architecture
- 150.A global manufacturing company is designing a Zero Trust architecture for its operational technology (OT) environment, which includes critical industrial control systems (ICS). The company wants to minimize the attack surface and prevent unauthorized access to these sensitive systems from the corporate IT network, while still allowing necessary data exchange for monitoring and reporting. Direct inbound connections from IT to OT are strictly forbidden. The solution must provide a secure, one-way data flow mechanism.Design a Zero Trust strategy and architecture