Microsoft Cybersecurity Architect (SC-100) practice questions
220 free questions with answers and explanations.
- 201.A global financial services company is designing a Zero Trust architecture for its critical trading platforms, which handle extremely sensitive transaction data. The architecture must ensure that even if an attacker compromises a user's credentials or device, they cannot gain unauthorized access to the trading platform's backend systems or data. Access must be granted only to specific, authorized services and always based on the principle of least privilege. Which Zero Trust principle is being emphasized by this requirement?Design a Zero Trust strategy and architecture
- 202.A multinational corporation is expanding its operations and leveraging multiple cloud providers (Azure, AWS, GCP) in addition to its on-premises data centers. The security team needs a comprehensive solution to gain visibility into the security posture of all these environments, identify misconfigurations, enforce compliance, and provide workload protection across IaaS and PaaS services. Which Microsoft security service is designed to centrally manage and secure this hybrid and multi-cloud estate under a Zero Trust model?Design a Zero Trust strategy and architecture
- 203.A global pharmaceutical company is migrating its research and development (R&D) data to Azure. This data includes highly sensitive genetic sequences and drug compound formulas. The company requires a solution that protects data not only at rest and in transit but also *during processing* in memory, even from privileged administrators or malicious insiders with access to the underlying cloud infrastructure. The data must remain encrypted throughout its entire lifecycle, including computation. Which Azure computing technology should the architect recommend to meet these stringent confidentiality requirements?Design security for applications and data
- 204.A healthcare provider is designing a Zero Trust architecture for its patient data systems, which are highly sensitive and subject to strict regulatory compliance (e.g., HIPAA). The organization requires that access to these systems is continuously re-evaluated based on real-time risk signals, such as changes in user location, device health, or unusual activity patterns, even after initial authentication. Which Azure AD feature provides this continuous, real-time access evaluation?Design a Zero Trust strategy and architecture
- 205.A global conglomerate is designing a Zero Trust architecture for its diverse business units, which operate across various cloud providers and on-premises infrastructure. The security team needs to ensure consistent security policy enforcement, threat protection, and visibility across all these environments for SaaS applications. Which of the following solutions is best suited to address these requirements?Design a Zero Trust strategy and architecture
- 206.A healthcare provider is developing a new patient portal application on Azure App Service. This application will store sensitive patient health information (PHI) in an Azure SQL Database. The security team mandates that the application's connection to the database must be entirely private, preventing any traffic from traversing the public internet, even within the Azure backbone. Furthermore, the database should not be directly accessible from the internet, and network access should be restricted to only the App Service instances. Which networking feature should the architect implement to secure the connection between Azure App Service and Azure SQL Database?Design security for applications and data
- 207.A global software development company is adopting a DevSecOps approach within its Zero Trust architecture. They use GitHub for source code management and Azure DevOps for CI/CD pipelines. The security team needs to integrate security testing early and continuously into the development lifecycle to identify vulnerabilities in both custom code and deployed applications before they reach production. Which two types of security testing are crucial for implementing this strategy?Design a Zero Trust strategy and architecture
- 208.A global financial institution is migrating its on-premises data centers to a hybrid cloud environment, leveraging Azure for new applications and maintaining some critical legacy systems on-premises. They aim to implement a Zero Trust network strategy that provides consistent security policies, optimized traffic routing, and direct, secure access to both cloud and on-premises resources for its globally distributed workforce, without backhauling traffic through a central data center. Which networking solution is best suited for this scenario?Design a Zero Trust strategy and architecture
- 209.A financial institution is designing a new customer-facing web application that will handle sensitive personal and financial data. The application will leverage Azure App Service for hosting and Azure SQL Database for data storage. The security architect needs to implement a solution that ensures all data, both at rest and in transit, within the Azure SQL Database is encrypted, and that the encryption keys are managed outside the database itself, with strict access controls. Furthermore, the solution must minimize changes to the application code for encryption/decryption operations. Which Azure service should the architect recommend to meet these requirements?Design security for applications and data
- 210.A global enterprise is designing its multi-region Azure architecture to host critical web applications. The applications must be protected against common web vulnerabilities, such as SQL injection and cross-site scripting (XSS), and also from large-scale DDoS attacks. The solution needs to provide global traffic routing, caching, and SSL offloading capabilities, with centralized management of web application firewall (WAF) policies across all regions. Which Azure service combination should the architect recommend to meet these requirements comprehensively?Design security for applications and data
- 211.A global manufacturing company uses Azure DevOps for its software development lifecycle (SDLC). The security team wants to integrate security best practices directly into the DevOps pipeline, ensuring that security vulnerabilities are identified and remediated early in the development process, before deployment to production. This includes scanning code for vulnerabilities, checking for misconfigurations in infrastructure-as-code (IaC) templates, and scanning container images for known weaknesses. Which Microsoft Defender for Cloud capability should the architect recommend to achieve this 'shift-left' security approach in Azure DevOps?Design security for applications and data
- 212.A software development company is building a new microservices-based application on Azure Kubernetes Service (AKS). Each microservice requires access to various Azure resources, such as Azure Key Vault for secrets and Azure Storage for data. The security team wants to eliminate the need for developers to manage and embed connection strings or secrets directly within the application code or configuration files. The solution must provide secure, automatic authentication for each microservice to its designated Azure resources based on its identity. Which Azure identity feature should the architect recommend for AKS microservices?Design security for applications and data
- 213.A global manufacturing company is designing a Zero Trust architecture for its operational technology (OT) environment. The OT network contains legacy systems that cannot be easily updated or patched and require strict isolation from the enterprise IT network. The company needs to enable secure, one-way data transfer from the OT environment to the IT environment for monitoring and analytics, without allowing any direct inbound connections to OT. Which component is crucial for implementing this secure data flow?Design a Zero Trust strategy and architecture
- 214.A software-as-a-service (SaaS) provider is building a multi-tenant application on Azure Kubernetes Service (AKS). Each tenant's data and workloads must be strictly isolated from one another to meet regulatory compliance and Zero Trust principles. The security architect needs to implement network isolation at the container and pod level within the AKS clusters, ensuring that traffic between tenants is explicitly denied unless absolutely necessary and authorized. Which networking strategy should the architect employ for this level of granular isolation?Design a Zero Trust strategy and architecture
- 215.A global media company uses Azure Blob Storage to store vast amounts of video content, images, and documents. Many of these assets are subject to strict data retention policies and legal hold requirements, mandating that the data cannot be modified or deleted for a specified period, even by administrators. The company needs to implement a solution that ensures data immutability for compliance and legal purposes. Which Azure Blob Storage feature should the architect recommend to meet these requirements?Design security for applications and data
- 216.A global media company is designing a Zero Trust architecture for its content creation and distribution workflows, which involve frequent collaboration with external partners, freelancers, and agencies. The company needs to provide these external users with secure, governed access to specific applications and data within their Azure environment, ensuring that access is granted only after strict identity verification and compliance checks. Which Azure Active Directory capability is essential for managing this external access effectively within a Zero Trust framework?Design a Zero Trust strategy and architecture
- 217.A global enterprise is designing a new data analytics platform on Azure that will consolidate sensitive customer data from various sources, including on-premises databases, Azure SQL Database, and Azure Data Lake Storage Gen2. The company needs a unified data governance solution to discover, classify, map, and manage sensitive data across its entire hybrid data estate. This solution must support automated data classification using sensitivity labels, provide a data catalog for data consumers, and enable data lineage tracking for compliance audits. Which Azure service should the architect recommend for comprehensive data governance?Design security for applications and data
- 218.A global e-commerce company is designing its Zero Trust strategy. They have multiple cloud environments (Azure, AWS) and a large remote workforce accessing various applications, both SaaS and custom-built, from diverse locations and devices. The company needs to provide secure, optimized, and consistent access to all resources, enforce security policies at the edge, and minimize latency for users, without relying on traditional VPNs or centralizing all traffic. Which architectural approach best fits these requirements?Design a Zero Trust strategy and architecture
- 219.A multinational corporation is migrating its on-premises legacy applications to Azure. Many of these applications rely on traditional file shares for storing critical business documents and unstructured data. The security team requires a solution that provides high availability, disaster recovery, and granular, identity-based access control for these file shares directly from Azure, without requiring complex VPN configurations for every user or application. The solution must integrate seamlessly with Azure Active Directory (Azure AD) for authentication. Which Azure storage solution should the architect recommend?Design security for applications and data
- 220.A global e-commerce company uses Azure Cosmos DB to store customer profiles, order history, and payment information. Due to stringent regulatory compliance requirements (e.g., GDPR, PCI DSS), the company must ensure that highly sensitive data, such as credit card numbers and personal identification numbers (PINs), is encrypted at the client application layer before being sent to Cosmos DB. The encryption keys must be managed by the application owners and never exposed to Azure Cosmos DB or Microsoft. Which Azure Cosmos DB feature should the architect recommend to achieve this client-side encryption requirement?Design security for applications and data