Microsoft Cybersecurity Architect (SC-100) practice questions

220 free questions with answers and explanations.

Practice test
  1. 151.A software development company uses Azure DevOps to manage its CI/CD pipelines. They need to ensure that the pipelines can securely access Azure Key Vault to retrieve secrets for application deployments without embedding credentials directly in the pipeline definitions or scripts. The solution must adhere to the principle of least privilege and be easy to manage across multiple projects. Which Azure identity feature should be implemented?Design security for infrastructure
  2. 152.An organization uses Azure Key Vault to store cryptographic keys, secrets, and certificates for its applications. Compliance requirements state that all access to Key Vault must originate from within a specific Azure Virtual Network and must not traverse the public internet. This applies to both applications and administrative access. Which networking feature should the architect implement to enforce this requirement?Design security for infrastructure
  3. 153.A manufacturing company is implementing a Zero Trust strategy for its operational technology (OT) environment, which includes industrial control systems (ICS). Due to the sensitivity and proprietary nature of these systems, direct internet access is strictly prohibited. However, the security team needs to collect telemetry and security logs from these isolated OT systems for centralized monitoring and threat detection in Microsoft Sentinel. Which architectural pattern should be used to securely bridge the air-gapped OT network to Azure while adhering to Zero Trust principles?Design a Zero Trust strategy and architecture
  4. 154.A multinational corporation is designing a Zero Trust architecture for its global operations. The company has identified that its employees frequently access corporate resources from unmanaged personal devices and public Wi-Fi networks. They need to ensure that regardless of the device ownership or network location, access to corporate applications is always secured, monitored, and compliant with corporate policies, without requiring full device enrollment. Which Zero Trust capability is BEST suited for this scenario?Design a Zero Trust strategy and architecture
  5. 155.A global e-commerce company is migrating its public-facing web applications to Azure. These applications experience frequent DDoS attacks and require advanced web application firewall (WAF) capabilities, including custom rules, bot protection, and geo-filtering, to protect against common web vulnerabilities. They also need global traffic routing with SSL/TLS termination at the edge to improve performance and security. Which Azure service combination should the architect recommend?Design security for infrastructure
  6. 156.A global retailer is designing a Zero Trust architecture for its e-commerce platform hosted across Azure and AWS. The platform processes sensitive customer data, including payment information. The security architects must ensure that data remains confidential and unalterable during transit between microservices, across cloud boundaries, and when stored at rest. Which security capability is paramount for meeting these requirements?Design a Zero Trust strategy and architecture
  7. 157.A software-as-a-service (SaaS) provider is designing its Zero Trust architecture. They host multiple customer tenants within a shared infrastructure, and strict isolation between each tenant's data and resources is paramount. The provider needs a mechanism to ensure that even if one tenant's environment is compromised, the breach cannot propagate to another tenant. Which Zero Trust architectural concept directly addresses this need for isolation?Design a Zero Trust strategy and architecture
  8. 158.A global enterprise is designing a Zero Trust architecture for its cloud environment, which includes Azure, AWS, and SaaS applications. The security team needs a unified platform to continuously assess the security posture of cloud resources, identify misconfigurations, track compliance against industry benchmarks (e.g., CIS, NIST), and provide recommendations for remediation across all these diverse cloud platforms. Which Microsoft service is BEST suited for this comprehensive multi-cloud security posture management?Design a Zero Trust strategy and architecture
  9. 159.A startup is deploying a new microservices-based application in Azure. Each microservice needs to communicate with other services securely over a private network, and all outbound traffic from the microservices must be inspected and filtered. The startup operates on a tight budget and needs a cost-effective solution that is easy to deploy and manage. Which network architecture pattern is most appropriate for this scenario?Design security for infrastructure
  10. 160.A global e-commerce company is migrating its public-facing web applications to Azure. These applications handle sensitive customer payment information and are frequently targeted by web-based attacks. The company requires a solution that provides advanced threat protection, content delivery network (CDN) capabilities, and centralized management for all its web applications globally, with minimal latency for users worldwide. Which Azure service should the architect recommend?Design security for infrastructure
  11. 161.A large healthcare organization is designing a Zero Trust architecture for its patient data systems. The organization needs to ensure that access to sensitive patient records is granted only after evaluating the user's identity, device health, location, and the sensitivity of the data being accessed. Which core principle of Zero Trust does this scenario primarily emphasize?Design a Zero Trust strategy and architecture
  12. 162.A financial institution is implementing a Zero Trust architecture. They have identified that privileged users (e.g., system administrators, security engineers) pose a significant risk due to their extensive access. To mitigate this, they want to enforce a secure, isolated environment for all privileged administrative tasks, preventing these tasks from being performed on standard user workstations. Which security control should be prioritized?Design a Zero Trust strategy and architecture
  13. 163.A company is designing a new cloud-native application that will process highly sensitive customer data. The application will use Azure Cosmos DB for its database. Due to regulatory requirements, all data in Cosmos DB must be encrypted at rest with keys that are owned and managed solely by the customer, including key generation and lifecycle management. Which Cosmos DB encryption option should be chosen?Design security for infrastructure
  14. 164.A global manufacturing company is migrating its on-premises operational technology (OT) systems to Azure. These systems require highly reliable and low-latency connectivity to various branch offices worldwide, as well as secure segmentation from the corporate IT network. The company needs to manage network policies centrally and ensure consistent security posture across all connections. Which Azure networking service is best suited for this scenario?Design security for infrastructure
  15. 165.A large pharmaceutical company is implementing a Zero Trust strategy. They have a complex environment with numerous applications, some of which are legacy and lack modern authentication protocols. The security architect needs to ensure that all access to these legacy applications is protected by multi-factor authentication (MFA) and Conditional Access policies, even though the applications themselves cannot directly integrate with Azure AD. Which component of a Zero Trust architecture acts as an intermediary to enforce these modern security controls for legacy applications?Design a Zero Trust strategy and architecture
  16. 166.A global manufacturing company is implementing a Zero Trust strategy. They need to integrate existing on-premises applications that use Integrated Windows Authentication (IWA) into their Azure AD-centric identity model without exposing them directly to the internet. The solution must provide secure remote access for employees and partners. Which Azure AD component should the security architect recommend?Design a Zero Trust strategy and architecture
  17. 167.A financial services company is designing a new application in Azure that will process highly sensitive customer financial data. Regulatory compliance dictates that all data, both at rest and in transit, must be encrypted with keys managed by the customer. Furthermore, the application must be able to perform computations on encrypted data without decrypting it in memory, even to the cloud provider. Which Azure security feature best meets these stringent requirements?Design security for infrastructure
  18. 168.A company is adopting a Zero Trust model and needs to ensure that all devices accessing corporate resources, whether corporate-owned or personal (BYOD), meet specific security standards before being granted access. This includes checking for up-to-date antivirus definitions, operating system patches, and disk encryption. The security architect must integrate this device posture assessment into the access decision process. Which component of a Zero Trust architecture is responsible for evaluating and reporting device health and compliance?Design a Zero Trust strategy and architecture
  19. 169.A healthcare organization is migrating its patient portal application to Azure. The application's web front end is exposed to the internet and requires protection against common web vulnerabilities, such as SQL injection, cross-site scripting (XSS), and bot attacks. Additionally, the organization needs to ensure high availability and global routing for optimal user experience. Which Azure service combination provides the most suitable solution?Design security for infrastructure
  20. 170.A global media company is designing a Zero Trust architecture for its content creation and distribution workflows, which involve numerous third-party contractors and freelancers. The company needs to ensure that these external users can securely access specific applications and data in Azure, but their identities are managed by their respective organizations, not by the media company's Azure AD. Which Azure AD capability is crucial for enabling this secure, identity-federated access?Design a Zero Trust strategy and architecture
  21. 171.A medium-sized enterprise is deploying several business-critical applications into Azure. The security architect needs to ensure that all virtual machines (VMs) are configured with a baseline set of security settings, including specific operating system hardening, antivirus software installation, and regular patch management. These configurations must be consistently applied and continuously monitored for drift. Which Azure service combination provides the most effective solution for this scenario?Design security for infrastructure
  22. 172.A client is designing a data protection strategy for highly sensitive medical records stored in Azure Blob Storage. These records must meet stringent compliance requirements, including immutable storage for auditing purposes for a fixed period and legal hold capabilities. The solution must prevent any deletion or modification of the data, even by privileged administrators, until the retention period expires or the legal hold is released. Which Azure Blob Storage feature should be implemented?Design security for infrastructure
  23. 173.A large pharmaceutical company is implementing a Zero Trust strategy. They have a complex environment with numerous applications and resources, each with specific access requirements. To enforce granular access control policies based on user identity, device compliance, location, and application sensitivity, which component is primarily responsible for performing the access decision and granting or denying access in real-time?Design a Zero Trust strategy and architecture
  24. 174.A company is designing a new cloud-native application that will process highly sensitive customer data. The application will leverage Azure Kubernetes Service (AKS) for container orchestration and Azure SQL Database for data storage. The security architect needs to ensure that data at rest in the Azure SQL Database is protected against unauthorized access, even if the underlying storage is compromised. Which encryption strategy should be recommended?Design security for infrastructure
  25. 175.A defense contractor is migrating a highly classified application to Azure. The application processes sensitive government data that requires strict isolation and assurance that no other customer's workloads can run on the same physical server. The solution must ensure that the underlying hardware is dedicated solely to their organization. Which Azure compute option should the architect recommend?Design security for infrastructure
  26. 176.A large e-commerce company is designing its Zero Trust strategy. They have multiple cloud environments (Azure, AWS, GCP) and numerous SaaS applications. The security team needs a unified solution to enforce consistent security policies, detect threats, and manage access across all these disparate environments, treating every access request as untrusted. Which overarching security model is best suited to achieve this comprehensive, cloud-native approach?Design a Zero Trust strategy and architecture
  27. 177.A global manufacturing company is implementing a Zero Trust strategy. They have recently acquired a smaller company with its own separate Azure AD tenant and on-premises infrastructure. The security architect needs to design a solution that allows employees from both companies to seamlessly access shared applications and resources, while maintaining the Zero Trust principle of 'verify explicitly' and ensuring consistent policy enforcement across tenants. Which Azure AD capability should be used to facilitate this cross-tenant collaboration securely?Design a Zero Trust strategy and architecture
  28. 178.A global consulting firm is implementing a Zero Trust strategy. They want to ensure that all sensitive documents stored in Microsoft 365, Azure Storage, and their on-premises file shares are protected from unauthorized access, even if they are downloaded or shared outside the corporate network. The protection must travel with the data itself. Which technology best addresses this requirement?Design a Zero Trust strategy and architecture
  29. 179.A large enterprise is designing its Azure landing zone. They need to ensure that all virtual machines (VMs) deployed in the environment automatically conform to security baselines, including specific OS configurations, patch levels, and software installations. Furthermore, any deviation from these baselines must be automatically remediated. Which Azure service combination is most effective for achieving this continuous compliance and automated remediation for VMs?Design security for infrastructure
  30. 180.A software-as-a-service (SaaS) provider is designing its Zero Trust architecture. They host multiple customer environments (tenants) within the same underlying infrastructure. To meet strict compliance requirements and ensure data isolation, the architecture must prevent any unauthorized cross-tenant communication or data leakage, even in the event of a security compromise within one tenant. Which design principle is critical for this scenario?Design a Zero Trust strategy and architecture
  31. 181.A global enterprise is designing a Zero Trust architecture for its cloud environment, which includes Azure and AWS. The security team needs to ensure that all cloud resources (VMs, storage accounts, databases, etc.) are continuously monitored for misconfigurations, vulnerabilities, and threats. Furthermore, they require automated responses to detected threats and compliance with industry standards. The solution must provide a unified view across both cloud providers.Design a Zero Trust strategy and architecture
  32. 182.A healthcare organization is designing a new cloud application that will process Protected Health Information (PHI) in Azure. The application's database will use Azure SQL Database. Regulatory compliance mandates that the data must be encrypted at rest using customer-managed keys (CMK) that are stored in a highly secure, FIPS 140-2 Level 3 validated hardware security module (HSM). Which Azure service should be used to store and manage these keys?Design security for infrastructure
  33. 183.A global financial services company is designing a Zero Trust architecture for its critical applications and data. They need to ensure that access decisions are made in real-time, considering user behavior, device posture, and environmental factors, and that these decisions can adapt dynamically to changing conditions. Which Zero Trust principle is MOST directly addressed by this requirement?Design a Zero Trust strategy and architecture
  34. 184.A defense contractor is migrating a highly classified application to Azure. The application requires dedicated, isolated compute resources that ensure complete separation from other tenants and provide hardware-level assurance of resource allocation. Standard virtual machines are deemed insufficient due to multi-tenancy concerns. Which Azure compute option provides the highest level of physical isolation and dedicated hardware resources?Design security for infrastructure
  35. 185.A global healthcare provider is designing a Zero Trust architecture for its patient data systems, which are hosted across Azure and an on-premises data center. The organization needs to ensure that data access policies are consistently applied, audited, and enforced, regardless of where the data resides or how it is accessed. Which Azure service is BEST suited to provide a centralized and consistent policy engine for this hybrid environment?Design a Zero Trust strategy and architecture
  36. 186.A financial services company is designing an Azure environment to host highly sensitive customer data, including credit card numbers and personal financial records. Compliance regulations dictate that this data must be protected against unauthorized access, even by privileged administrators of the cloud provider. The solution must ensure that the data is never exposed in plaintext during processing within the virtual machines. Which advanced security technology should the architect prioritize for this scenario?Design security for infrastructure
  37. 187.A global financial institution is migrating its on-premises data centers to a hybrid cloud environment, leveraging Azure. A critical requirement for their Zero Trust strategy is to ensure that all network communication between their on-premises network, Azure Virtual Networks, and other cloud providers is encrypted and inspected for threats, without relying solely on traditional perimeter firewalls. Which architectural component is essential for establishing secure, inspected network pathways across these diverse environments?Design a Zero Trust strategy and architecture
  38. 188.A defense contractor is designing a Zero Trust architecture for its highly sensitive research and development environment. Developers work with classified information and require workstations with extremely high security assurances, isolated from general corporate networks and internet browsing. These workstations must prevent data exfiltration, resist malware, and enforce strict application whitelisting. Which type of workstation is BEST suited for this environment?Design a Zero Trust strategy and architecture
  39. 189.A research institution is designing a Zero Trust strategy for its highly confidential scientific data. The data is stored in Azure Blob Storage and accessed by researchers from various locations. The institution requires that access to this data is not only authenticated but also continuously re-evaluated based on changes in user behavior, device posture, and potential environmental risks, even during an active session. Which Zero Trust concept does this continuous re-evaluation during a session primarily represent?Design a Zero Trust strategy and architecture
  40. 190.A multinational corporation is migrating its legacy applications to Azure. These applications still rely on traditional network-based security controls and require deep packet inspection, intrusion detection/prevention (IDPS), and URL filtering for internet-bound traffic. The security team needs a centralized solution that can scale globally and integrate with their existing security operations center (SOC) tools. Which Azure security service should be recommended?Design security for infrastructure
  41. 191.A large enterprise is migrating its data warehouse to Azure Synapse Analytics. The data contains highly sensitive customer information, and compliance regulations require that all data in the data warehouse be encrypted at rest using customer-managed encryption keys (CMK) stored in a hardware security module (HSM). The solution must also ensure that the encryption keys are never exposed to Azure's control plane. Which Azure Key Vault feature, combined with Synapse Analytics, meets these requirements?Design security for infrastructure
  42. 192.A multinational corporation is implementing a Zero Trust architecture across its hybrid cloud environment. They need to ensure that all access requests, regardless of origin (on-premises or cloud), are rigorously authenticated, authorized, and continuously verified. The solution must integrate with existing on-premises identity providers and provide granular access control to Azure resources. Which Azure identity and access management service is foundational to achieving this Zero Trust principle?Design security for infrastructure
  43. 193.A security architect is designing a data protection strategy for highly sensitive data stored in Azure Blob Storage. The data needs to be encrypted at rest, and the encryption keys must be managed by the customer to meet stringent regulatory requirements. The solution should also allow for key rotation and revocation. Which encryption method should be used?Design security for infrastructure
  44. 194.A global e-commerce company is designing its Zero Trust strategy. They have multiple cloud environments (Azure, AWS, GCP) and a significant remote workforce. The company wants to consolidate network security functions like firewall-as-a-service, secure web gateway, cloud access security broker (CASB), and Zero Trust Network Access (ZTNA) into a single, integrated offering. Which architecture model BEST fits this requirement?Design a Zero Trust strategy and architecture
  45. 195.A defense contractor is designing a Zero Trust architecture for its highly secure development environment. They are implementing a policy where access to critical build servers and source code repositories is only granted from specialized, hardened workstations that are strictly controlled and continuously monitored for security posture. These workstations are isolated from the general corporate network. This approach directly supports the Zero Trust principle of 'assume breach' by limiting the potential impact of a compromised user account or general-purpose endpoint. What is the industry term for such specialized workstations?Design a Zero Trust strategy and architecture
  46. 196.A global enterprise needs to secure its Azure environment, which hosts various applications and data across multiple subscriptions and management groups. They require a centralized security solution that can provide unified security management, advanced threat protection, and security posture management across hybrid cloud workloads, including on-premises servers. The solution must also offer regulatory compliance assistance. Which Azure service is designed to address these comprehensive security needs?Design security for infrastructure
  47. 197.A global software development company uses GitHub for source code management and Azure DevOps for CI/CD pipelines. They are implementing a Zero Trust strategy and need to ensure that all code pushed to repositories is scanned for secrets, vulnerabilities, and misconfigurations before it can be integrated into the main branch. This scanning must be automated and integrated directly into the development workflow. Which type of security control is essential for implementing this continuous security validation in the DevOps pipeline?Design a Zero Trust strategy and architecture
  48. 198.A healthcare provider is designing a Zero Trust architecture for its patient data systems, which are hosted in a hybrid environment (on-premises and Azure). They need to ensure that access to sensitive patient records is continuously evaluated and re-authorized, even after an initial access decision has been made. If a user's risk profile changes (e.g., due to a sign-in from an unusual location) or a device becomes non-compliant during an active session, access must be immediately revoked without waiting for the session to expire. This is critical for maintaining compliance with strict healthcare regulations.Design a Zero Trust strategy and architecture
  49. 199.A security architect is designing a strategy for securing virtual machines (VMs) in Azure. The organization has a strict policy that all VMs must have a baseline security configuration applied automatically upon deployment and continuously monitored for drift. Additionally, any non-compliant configurations must be remediated without manual intervention. Which Azure service combination should be used to achieve this?Design security for infrastructure
  50. 200.A global consulting firm is implementing a Zero Trust strategy. They want to ensure that all sensitive client data, regardless of where it is stored or shared (e.g., SharePoint, Teams, email, local drives), is classified, protected, and its usage is monitored. The solution must allow for automatic labeling and encryption based on content, and provide persistent protection even when data leaves the organizational boundary. Which Microsoft technology best addresses these requirements?Design a Zero Trust strategy and architecture