Step2Study
IT & TechnologySC-100100% Free

Microsoft Cybersecurity Architect (SC-100)

Practice bank
220 Qs
Real exam
50 Qs
Time limit
120 min
Passing
A passing score of 700 or greater is required.

Exam blueprint

Design a Zero Trust strategy and architecture
30%
Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies
20%
Design security for infrastructure
20%
Design security for applications and data
30%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 216 min · pass 70% · 220 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Study with friends

Challenge a friend to beat your score.

Microsoft Cybersecurity Architect (SC-100) practice test questions

Sample questions from the 220-question bank, with answers and explanations.

All questions
  1. 1. A global enterprise is expanding its cloud footprint, utilizing multiple cloud providers (Azure, AWS, GCP) and numerous SaaS applications. The cybersecurity architect needs to implement a security operations strategy that provides unified visibility, threat detection, and automated response capabilities across this complex multi-cloud and SaaS environment. Traditional on-premises SIEM/SOAR solutions are proving inadequate. Which strategy should the architect prioritize?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Deploying a cloud-native Extended Detection and Response (XDR) solution.
    • B. Enhancing existing on-premises SIEM with cloud connectors.
    • C. Implementing separate, native security services for each cloud provider.
    • D. Focusing on security awareness training for all cloud users.
    Show answer

    A. Deploying a cloud-native Extended Detection and Response (XDR) solution.

    A cloud-native XDR solution is designed to provide unified visibility, threat detection, and automated response across diverse environments, including multi-cloud, SaaS, endpoints, and identities. This consolidates security data and streamlines operations far more effectively than disparate native services or extended on-premises SIEMs.

  2. 2. A government agency is modernizing its IT infrastructure by adopting a zero-trust architecture. The cybersecurity architect needs to evaluate technical strategies to enforce granular access controls and continuously verify user and device trust for sensitive government data, adhering to NIST frameworks. Which strategy is most aligned with a comprehensive zero-trust implementation?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Assuming all internal network traffic is trustworthy and focusing security efforts only on external threats.
    • B. Granting all authenticated users full access to all internal resources to simplify administration.
    • C. Deploying an Identity and Access Management (IAM) solution with Multi-Factor Authentication (MFA) and a Network Access Control (NAC) system for device posture assessment, integrated with a Policy Decision Point (PDP) for dynamic access policy enforcement.
    • D. Implementing a traditional perimeter-based firewall and VPN for all network access.
    Show answer

    C. Deploying an Identity and Access Management (IAM) solution with Multi-Factor Authentication (MFA) and a Network Access Control (NAC) system for device posture assessment, integrated with a Policy Decision Point (PDP) for dynamic access policy enforcement.

    This strategy fully aligns with zero-trust principles by continuously verifying identity (IAM, MFA), device posture (NAC), and dynamically enforcing granular access policies based on real-time context (PDP), which is a core tenet of NIST zero-trust guidelines.

  3. 3. A multinational financial institution is migrating its core banking applications to a hybrid cloud environment. The cybersecurity architect must ensure that all cloud resources are configured securely and continuously monitored for compliance with internal policies and external regulations (e.g., PCI DSS, GDPR). Which GRC technical strategy provides the MOST effective continuous assessment and enforcement of security configurations across this environment?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Establishing a comprehensive security awareness training program for all employees.
    • B. Deploying a host-based intrusion detection system (HIDS) on all virtual machines.
    • C. Utilizing Cloud Security Posture Management (CSPM) tools.
    • D. Implementing a traditional network vulnerability scanner.
    Show answer

    C. Utilizing Cloud Security Posture Management (CSPM) tools.

    Cloud Security Posture Management (CSPM) tools are specifically designed to continuously monitor and assess the security configuration of cloud resources. They identify misconfigurations and compliance deviations against established benchmarks and regulatory standards, making them ideal for hybrid cloud compliance.

  4. 4. A large pharmaceutical company is conducting extensive research and development (R&D) on new drug formulations. This R&D data is highly sensitive, proprietary, and subject to strict intellectual property (IP) protection laws. The cybersecurity architect needs to implement a technical strategy that ensures the integrity and confidentiality of this data throughout its lifecycle, from creation to archiving, and provides strong audit trails for regulatory compliance and IP protection. Which strategy is MOST crucial for this scenario?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Establishing an advanced Data Classification and Protection (DCP) framework with encryption and access controls.
    • B. Utilizing an advanced Security Information and Event Management (SIEM) system with custom R&D data rules.
    • C. Deploying a comprehensive Data Loss Prevention (DLP) solution across all data egress points.
    • D. Implementing a robust Cloud Access Security Broker (CASB) for all cloud services.
    Show answer

    A. Establishing an advanced Data Classification and Protection (DCP) framework with encryption and access controls.

    An advanced Data Classification and Protection (DCP) framework directly addresses the need to categorize sensitive R&D data, apply appropriate encryption and granular access controls throughout its lifecycle, and provide audit trails for IP protection and regulatory compliance.

  5. 5. A large e-commerce company processes millions of transactions daily and stores vast amounts of customer data. Due to increasing regulatory scrutiny (e.g., GDPR, CCPA) and a rise in sophisticated cyberattacks, the company needs to enhance its ability to identify, protect, and report on sensitive data across its hybrid cloud environment. The existing tools are siloed and provide an incomplete picture of data risk. Which strategy would provide the most comprehensive solution for continuous data discovery, classification, and protection across the enterprise?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Implementing an advanced Endpoint Detection and Response (EDR) solution.
    • B. Enhancing network segmentation and firewall rules.
    • C. Deploying a unified Data Security Posture Management (DSPM) platform.
    • D. Utilizing a Security Orchestration, Automation, and Response (SOAR) platform.
    Show answer

    C. Deploying a unified Data Security Posture Management (DSPM) platform.

    A Data Security Posture Management (DSPM) platform is designed to provide continuous, real-time visibility into sensitive data across hybrid and multi-cloud environments. It automates data discovery, classification, and risk assessment, identifying misconfigurations, access risks, and compliance gaps specific to data. This directly addresses the need for comprehensive data protection, regulatory compliance, and reporting in a complex data landscape.

  6. 6. A global pharmaceutical company is conducting extensive research and development (R&D) on new drug formulations. This involves highly sensitive intellectual property (IP) that must be protected from both external threats and insider risks. The company operates a hybrid IT environment, and the cybersecurity architect needs a GRC technical strategy that ensures the integrity and confidentiality of this IP across all data states (at rest, in transit, in use). Which approach is MOST comprehensive for this scenario?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Deploying a robust Data Loss Prevention (DLP) system integrated with Information Rights Management (IRM).
    • B. Implementing endpoint detection and response (EDR) solutions across all workstations.
    • C. Establishing a comprehensive Security Information and Event Management (SIEM) system.
    • D. Utilizing advanced persistent threat (APT) protection at the network perimeter.
    Show answer

    A. Deploying a robust Data Loss Prevention (DLP) system integrated with Information Rights Management (IRM).

    The combination of Data Loss Prevention (DLP) and Information Rights Management (IRM) offers the most comprehensive protection for sensitive IP across all data states. DLP prevents unauthorized exfiltration, while IRM controls access and usage of the data itself, even after it leaves the organization's direct control.

  7. 7. A global financial institution is implementing a new cloud-based trading platform. The platform must adhere to stringent regulatory requirements, including data residency and privacy laws across multiple jurisdictions. The cybersecurity architect is tasked with evaluating technical strategies to ensure compliance while maintaining operational efficiency. Which of the following strategies best addresses the need for consistent security controls and regulatory adherence across diverse global regions?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Implementing separate, region-specific security policies and configurations for each cloud deployment.
    • B. Relying on the cloud provider's default security services and shared responsibility model for all compliance needs.
    • C. Utilizing a centralized cloud security posture management (CSPM) solution with policy as code and regional enforcement capabilities.
    • D. Deploying a decentralized security information and event management (SIEM) system with local data storage in each region.
    Show answer

    C. Utilizing a centralized cloud security posture management (CSPM) solution with policy as code and regional enforcement capabilities.

    A centralized CSPM solution with policy as code allows for consistent definition and automated enforcement of security policies across all cloud environments, adapting to regional nuances while maintaining a unified compliance posture. This approach directly addresses the challenge of diverse global regulations.

  8. 8. A multinational financial services organization operates in numerous jurisdictions, each with distinct data residency, privacy, and industry-specific compliance requirements (e.g., GDPR, CCPA, PCI DSS, SOX). The cybersecurity architect needs to implement a technical strategy that can consistently apply and enforce these varied regulatory controls across its global cloud infrastructure while providing a centralized view of compliance posture. Which strategy would BEST address these complex requirements?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Deploying a global Security Information and Event Management (SIEM) system with custom correlation rules.
    • B. Establishing a federated Privileged Access Management (PAM) system for all critical cloud resources.
    • C. Implementing a unified Cloud Security Posture Management (CSPM) solution with policy-as-code capabilities.
    • D. Utilizing a Distributed Ledger Technology (DLT) for immutable audit trails across regions.
    Show answer

    C. Implementing a unified Cloud Security Posture Management (CSPM) solution with policy-as-code capabilities.

    A unified CSPM solution with policy-as-code allows for the centralized definition and automated enforcement of security policies, including compliance with various regulations, across diverse cloud environments. This provides a consistent approach and a centralized view of compliance.

  9. 9. A global technology company is developing a new suite of microservices-based applications deployed on Kubernetes in a multi-cloud environment. The company needs to enforce consistent security policies, manage secrets, and ensure compliance across all development, staging, and production environments, while maintaining rapid development cycles. The cybersecurity architect must choose a GRC technical strategy that integrates seamlessly into their CI/CD pipelines. Which strategy is MOST effective in this scenario?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Establishing a traditional Vulnerability Management (VM) program with quarterly scans.
    • B. Implementing a centralized Security Information and Event Management (SIEM) system.
    • C. Utilizing a Data Loss Prevention (DLP) system for monitoring data exfiltration from containers.
    • D. Deploying a cloud-native secrets management solution and policy-as-code for infrastructure.
    Show answer

    D. Deploying a cloud-native secrets management solution and policy-as-code for infrastructure.

    For microservices and Kubernetes in multi-cloud, a cloud-native secrets management solution handles sensitive data, while policy-as-code ensures consistent security and compliance enforcement directly within CI/CD pipelines, supporting rapid development.

  10. 10. A large enterprise is facing increasing cyber threats and needs to improve its ability to predict and prevent attacks, rather than merely react to them. The cybersecurity architect is evaluating strategies to enhance security operations by leveraging external intelligence. Which strategy would be most effective for proactive threat intelligence integration and operationalization?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Implementing a Threat Intelligence Platform (TIP) that aggregates multiple commercial and open-source feeds, normalizes data, and integrates with SIEM, SOAR, and endpoint security solutions for automated correlation and enforcement.
    • B. Subscribing to a free public threat intelligence feed and manually updating firewall rules.
    • C. Relying on internal security team's ad-hoc research for threat intelligence.
    • D. Monitoring industry news and forums for reports of new vulnerabilities.
    Show answer

    A. Implementing a Threat Intelligence Platform (TIP) that aggregates multiple commercial and open-source feeds, normalizes data, and integrates with SIEM, SOAR, and endpoint security solutions for automated correlation and enforcement.

    A TIP that aggregates, normalizes, and integrates threat intelligence with existing security tools enables automated correlation, proactive detection, and rapid enforcement of defenses, moving beyond reactive measures to predictive and preventive security operations.

  11. 11. An organization is migrating sensitive patient health information (PHI) to a new cloud-based electronic health record (EHR) system. The cybersecurity architect needs to ensure that the cloud environment adheres to HIPAA regulations, specifically regarding data encryption, access logging, and incident reporting. The architect also needs to demonstrate compliance to auditors. Which GRC technical strategy should be prioritized to provide continuous assurance and evidence of compliance for the cloud EHR system?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Establishing a Security Information and Event Management (SIEM) system with custom HIPAA correlation rules.
    • B. Deploying a comprehensive Cloud Security Posture Management (CSPM) platform.
    • C. Utilizing a Web Application Firewall (WAF) to protect the EHR application.
    • D. Implementing a robust Data Loss Prevention (DLP) solution for all endpoints.
    Show answer

    B. Deploying a comprehensive Cloud Security Posture Management (CSPM) platform.

    A CSPM platform continuously monitors the cloud environment for misconfigurations and compliance violations against frameworks like HIPAA, providing continuous assurance and audit evidence regarding encryption, access logging, and other controls.

  12. 12. A large healthcare provider is expanding its telehealth services, requiring secure communication and data exchange with remote patients and external specialists. The organization must comply with HIPAA regulations, which mandate strict data privacy and security controls. The cybersecurity architect needs to select a GRC technical strategy that ensures compliance while facilitating secure collaboration. Which strategy is MOST appropriate?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Deploying a comprehensive secure messaging and file sharing platform with audit capabilities.
    • B. Utilizing a network intrusion detection system (NIDS) to monitor perimeter traffic.
    • C. Implementing a robust patch management system for all endpoints.
    • D. Establishing a bring-your-own-device (BYOD) policy with basic security guidelines.
    Show answer

    A. Deploying a comprehensive secure messaging and file sharing platform with audit capabilities.

    A secure messaging and file sharing platform with audit capabilities directly addresses the need for secure communication and data exchange, which are critical for telehealth and HIPAA compliance. Audit capabilities ensure accountability and demonstrate compliance.

  13. 13. A large e-commerce company processes millions of transactions daily and is subject to PCI DSS compliance. The company is adopting a microservices architecture and uses containers extensively. The cybersecurity architect needs to implement a security operations strategy that provides real-time threat detection and response specifically for containerized applications within the Payment Card Industry (PCI) environment. Which strategy would be MOST effective?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Relying solely on static application security testing (SAST) during the CI/CD pipeline.
    • B. Deploying a dedicated Container Security Platform with runtime protection and compliance scanning.
    • C. Utilizing a perimeter-based firewall to protect the entire microservices cluster.
    • D. Implementing traditional host-based antivirus software on container hosts.
    Show answer

    B. Deploying a dedicated Container Security Platform with runtime protection and compliance scanning.

    A dedicated Container Security Platform provides specialized runtime protection for containerized applications, including threat detection, vulnerability scanning of images, and compliance checks tailored for container environments. This is crucial for real-time security and PCI DSS compliance in a microservices architecture.

  14. 14. A global manufacturing company is implementing a new enterprise resource planning (ERP) system that will process sensitive financial and operational data across multiple geopolitical regions. The cybersecurity architect needs to ensure that data residency requirements are met for each region while maintaining a unified security posture. Which GRC technical strategy is BEST suited to address this challenge?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Deploying a global Security Information and Event Management (SIEM) system.
    • B. Utilizing data loss prevention (DLP) solutions with regional policy enforcement.
    • C. Establishing a centralized identity and access management (IAM) system.
    • D. Implementing a distributed ledger technology for data integrity.
    Show answer

    B. Utilizing data loss prevention (DLP) solutions with regional policy enforcement.

    Data Loss Prevention (DLP) solutions are designed to prevent sensitive data from leaving defined boundaries. With regional policy enforcement, DLP can ensure that data stays within its required geopolitical region, directly addressing data residency while supporting a unified security posture.

  15. 15. A large multinational corporation is struggling to maintain consistent security and compliance across its diverse global operations, which include multiple cloud providers, on-premises data centers, and various regulatory landscapes. The current approach involves manual audits, disparate security tools, and a high volume of false positives, leading to significant overhead and delays in addressing critical risks. The cybersecurity architect is tasked with recommending a solution to centralize risk visibility, automate compliance checks, and streamline security operations across this complex environment. Which of the following strategies would best address these challenges?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Enhancing the existing Incident Response (IR) plan with more frequent drills and updated playbooks.
    • B. Adopting a comprehensive Data Loss Prevention (DLP) solution across all endpoints and networks.
    • C. Deploying an Integrated Risk Management (IRM) platform with GRC capabilities.
    • D. Implementing a Security Information and Event Management (SIEM) system with advanced correlation rules.
    Show answer

    C. Deploying an Integrated Risk Management (IRM) platform with GRC capabilities.

    An Integrated Risk Management (IRM) platform with GRC capabilities provides a centralized system to manage risks, compliance, and governance across disparate environments. It automates compliance checks, aggregates risk data, and offers a holistic view, which is essential for a large multinational corporation with diverse operations and regulatory requirements. This directly addresses the challenges of inconsistent security, manual audits, and high overhead.

  16. 16. A critical infrastructure organization (CIO) manages operational technology (OT) systems that control power distribution grids. These systems are air-gapped from the corporate IT network but still require remote access for maintenance and updates by approved vendors. The cybersecurity architect needs to implement a GRC technical strategy that ensures secure, auditable, and controlled remote access to these highly sensitive OT systems while maintaining their air-gapped isolation. Which strategy is BEST suited for this unique requirement?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Implementing a standard VPN solution with multi-factor authentication (MFA) for vendor access.
    • B. Establishing a Privileged Access Management (PAM) solution specifically designed for OT environments, often incorporating secure gateways or jump hosts.
    • C. Utilizing a dedicated, one-way data diode for all data transfers to and from the OT network.
    • D. Deploying a jump server architecture within a demilitarized zone (DMZ) and strict access controls.
    Show answer

    B. Establishing a Privileged Access Management (PAM) solution specifically designed for OT environments, often incorporating secure gateways or jump hosts.

    A PAM solution tailored for OT environments provides granular control, session recording, and strong authentication for privileged remote access, often leveraging secure gateways or jump hosts to bridge the air gap without directly connecting the OT network to external networks. This ensures auditable, controlled access while maintaining isolation.

  17. 17. An energy utility company operates critical infrastructure systems that are subject to NERC CIP (North American Electric Reliability Corporation Critical Infrastructure Protection) standards. The cybersecurity architect must ensure that remote access to these systems is highly secure and auditable. Which technical strategy provides the strongest control for managing and monitoring privileged remote access in compliance with NERC CIP?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Allowing only on-site physical access to critical systems to eliminate remote access risks.
    • B. Deploying a Privileged Access Management (PAM) solution that includes session recording, just-in-time access, and multi-factor authentication (MFA).
    • C. Implementing direct RDP/SSH access from administrator workstations with strong passwords.
    • D. Utilizing a VPN for all remote access without additional access controls.
    Show answer

    B. Deploying a Privileged Access Management (PAM) solution that includes session recording, just-in-time access, and multi-factor authentication (MFA).

    A PAM solution with session recording, just-in-time access, and MFA directly addresses NERC CIP requirements for strict control over privileged access, providing comprehensive auditing, least privilege enforcement, and robust authentication for critical systems.

  18. 18. A global energy utility company operates critical infrastructure systems that are subject to strict regulatory compliance (e.g., NERC CIP) and require maximum uptime. The cybersecurity architect needs to implement a strategy to manage and control access to highly sensitive operational technology (OT) systems, ensuring that only authorized personnel and processes can perform critical actions, and that all privileged activities are logged and auditable. Which GRC technical strategy is MOST suitable for this environment?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Deploying a comprehensive Privileged Access Management (PAM) solution tailored for OT environments.
    • B. Establishing a Data Loss Prevention (DLP) system to monitor data transfers from OT networks.
    • C. Implementing a standard Enterprise Identity and Access Management (IAM) solution.
    • D. Utilizing a Security Information and Event Management (SIEM) system for all OT logs.
    Show answer

    A. Deploying a comprehensive Privileged Access Management (PAM) solution tailored for OT environments.

    A PAM solution, especially one tailored for OT, is crucial for managing, monitoring, and auditing privileged access to sensitive OT systems, directly addressing the need for strict control, logging, and auditability for regulatory compliance and uptime.

  19. 19. A mid-sized financial institution is undergoing a digital transformation, migrating many on-premises applications and data to a hybrid cloud environment. The security team is facing challenges in gaining unified visibility into security events, managing alerts, and automating responses across both environments. The current setup involves separate security tools for on-premises and cloud, leading to blind spots and delayed incident response. Which approach would best address these challenges by providing a centralized view and automated security operations?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Implementing a dedicated Cloud Security Posture Management (CSPM) solution for cloud assets.
    • B. Enhancing Data Loss Prevention (DLP) policies and enforcement across all data repositories.
    • C. Deploying an advanced Intrusion Detection System/Intrusion Prevention System (IDS/IPS) at network perimeters.
    • D. Adopting a unified Hybrid/Multi-Cloud Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platform.
    Show answer

    D. Adopting a unified Hybrid/Multi-Cloud Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platform.

    A unified Hybrid/Multi-Cloud SIEM/SOAR platform is designed to consolidate security event data, provide centralized visibility, and automate incident response workflows across both on-premises and diverse cloud environments. This directly addresses the challenges of fragmented visibility, alert overload, and delayed response in a hybrid cloud setup.

  20. 20. A global pharmaceutical company is undergoing a major divestiture, separating a significant portion of its R&D division into a new entity. This involves disentangling highly sensitive intellectual property (IP), patient data, and regulated systems while ensuring continuous compliance with GxP (Good Practice) regulations and maintaining data integrity. The cybersecurity architect needs to define a GRC technical strategy for securely and compliantly migrating the separated assets. Which strategy is MOST critical to ensure the integrity and auditable transfer of regulated data and IP?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Implementing a new, isolated network infrastructure for the divested entity.
    • B. Deploying a robust Identity and Access Management (IAM) solution for the new entity.
    • C. Conducting comprehensive penetration testing on the new entity's systems post-migration.
    • D. Utilizing cryptographic hashing and digital signatures for all transferred data packages with a verifiable chain of custody.
    Show answer

    D. Utilizing cryptographic hashing and digital signatures for all transferred data packages with a verifiable chain of custody.

    For regulated data and IP transfer during a divestiture, ensuring data integrity and an auditable chain of custody is paramount for GxP compliance. Cryptographic hashing confirms data hasn't been altered, and digital signatures prove its origin and authenticity. A verifiable chain of custody documents every step of the transfer, satisfying stringent regulatory requirements.

  21. 21. A global technology company is developing a new suite of cloud-native microservices applications. The development teams operate autonomously, using various CI/CD pipelines and deploying to different cloud environments. The security team needs to ensure that all deployed cloud resources adhere to corporate security policies and regulatory compliance requirements without impeding developer agility. Manual policy enforcement and audits have proven unsustainable. Which strategy would best enable automated, consistent policy enforcement across these diverse cloud-native deployments?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Deploying a comprehensive Security Information and Event Management (SIEM) solution for real-time threat detection.
    • B. Mandating the use of a single, approved cloud provider with strict access controls.
    • C. Implementing a centralized Cloud Access Security Broker (CASB) to monitor cloud traffic and enforce data policies.
    • D. Adopting Policy-as-Code (PaC) integrated into CI/CD pipelines and cloud-native security tools.
    Show answer

    D. Adopting Policy-as-Code (PaC) integrated into CI/CD pipelines and cloud-native security tools.

    Policy-as-Code (PaC) allows security policies to be defined, managed, and enforced programmatically, often as machine-readable code. Integrating PaC into CI/CD pipelines and cloud-native security tools enables automated, consistent policy enforcement at various stages of development and deployment across diverse cloud environments, directly supporting developer agility while ensuring compliance.

  22. 22. A global software development company utilizes numerous open-source libraries and components in its commercial products. To comply with software supply chain security regulations (e.g., NIST SSDF) and manage associated risks, the cybersecurity architect needs a strategy to continuously identify and mitigate vulnerabilities in these components. Which technical strategy is most effective?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Implementing a Software Composition Analysis (SCA) tool integrated into the CI/CD pipeline and artifact repositories to continuously scan for known vulnerabilities and license compliance issues.
    • B. Restricting the use of all open-source software to only components listed on an approved internal whitelist.
    • C. Manually reviewing the license agreements of all open-source components during product release.
    • D. Performing annual penetration tests on the final product to detect supply chain vulnerabilities.
    Show answer

    A. Implementing a Software Composition Analysis (SCA) tool integrated into the CI/CD pipeline and artifact repositories to continuously scan for known vulnerabilities and license compliance issues.

    An SCA tool integrated into the CI/CD pipeline provides continuous, automated scanning for known vulnerabilities and license compliance issues in open-source components, directly addressing software supply chain security risks and regulatory requirements.

  23. 23. A software-as-a-service (SaaS) provider is required to achieve SOC 2 Type 2 certification, which necessitates strong controls over data security, availability, processing integrity, confidentiality, and privacy. The cybersecurity architect is evaluating security operations strategies. Which strategy best supports continuous evidence collection and reporting for SOC 2 Type 2 compliance?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Performing quarterly manual audits of system configurations and access logs.
    • B. Relying on developers to self-attest to secure coding practices and change management processes.
    • C. Implementing a Governance, Risk, and Compliance (GRC) platform integrated with cloud security posture management (CSPM) and security information and event management (SIEM) for automated control monitoring, evidence collection, and reporting.
    • D. Focusing solely on external penetration testing to identify vulnerabilities before the audit.
    Show answer

    C. Implementing a Governance, Risk, and Compliance (GRC) platform integrated with cloud security posture management (CSPM) and security information and event management (SIEM) for automated control monitoring, evidence collection, and reporting.

    An integrated GRC platform with CSPM and SIEM provides automated, continuous monitoring of security controls, real-time evidence collection, and streamlined reporting, which is essential for demonstrating continuous compliance required for SOC 2 Type 2 certification.

  24. 24. A global software development company utilizes numerous open-source libraries and components in its commercial products. Due to recent supply chain attacks and increased scrutiny on software integrity, the cybersecurity architect needs to implement a technical strategy that automatically identifies vulnerabilities and license compliance issues within these open-source dependencies throughout the entire software development lifecycle (SDLC). The strategy must also provide actionable remediation guidance and integrate with existing CI/CD pipelines. Which strategy is MOST appropriate?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Deploying a Software Composition Analysis (SCA) solution.
    • B. Establishing a manual code review process for all open-source components.
    • C. Utilizing a Dynamic Application Security Testing (DAST) tool for production applications.
    • D. Implementing a Static Application Security Testing (SAST) tool for proprietary code.
    Show answer

    A. Deploying a Software Composition Analysis (SCA) solution.

    Software Composition Analysis (SCA) solutions are specifically designed to scan and identify open-source components within an application, detect known vulnerabilities in those components, and flag license compliance issues, integrating well into CI/CD pipelines.

  25. 25. A financial institution is under increasing pressure from regulators to demonstrate continuous compliance with industry-specific regulations (e.g., PCI DSS, SWIFT CSP) and data privacy laws (e.g., GDPR, CCPA). The cybersecurity architect needs to implement a technical strategy that provides real-time visibility into the organization's compliance posture across its hybrid IT environment, automates evidence collection for audits, and proactively identifies non-compliant configurations before they become issues. Which GRC technical strategy is BEST suited to meet these continuous compliance and audit requirements?

    Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies

    • A. Utilizing an advanced Data Loss Prevention (DLP) solution for sensitive data monitoring.
    • B. Deploying a comprehensive Enterprise GRC Platform with automated compliance mapping and control validation.
    • C. Implementing a federated Security Information and Event Management (SIEM) system for log correlation.
    • D. Establishing a dedicated Vulnerability Management (VM) program with monthly penetration tests.
    Show answer

    B. Deploying a comprehensive Enterprise GRC Platform with automated compliance mapping and control validation.

    An Enterprise GRC Platform is specifically designed to manage and automate compliance processes, map controls to regulations, validate their effectiveness continuously, and collect audit evidence across the entire IT estate, providing real-time compliance posture.

Microsoft Cybersecurity Architect (SC-100) flashcards

Tap a card to flip it. 131 flashcards in the full deck.

  • Cloud-Native XDR

    Flip card

    Cloud-native XDR (Extended Detection and Response) unifies security data from multiple domains (endpoint, cloud, identity, network) into a single platform for improved threat detection, investigation, and automated response across hybrid and multi-cloud environments.

    • Unifies telemetry across multiple security layers.
    • Provides enhanced threat detection and context.
    • Automates response actions across the attack chain.
    Study this card →
  • Zero Trust Architecture (ZTA)

    Flip card

    A security model where no user, device, or application is implicitly trusted, regardless of their location. All access requests are authenticated, authorized, and continuously verified.

    • Based on the principle 'never trust, always verify'.
    • Enforces least privilege access.
    • Requires continuous monitoring and validation of trust.
    Study this card →
  • Cloud Security Posture Management (CSPM)

    Flip card

    CSPM tools continuously monitor cloud environments for misconfigurations, compliance violations, and security risks, providing visibility and automated remediation capabilities.

    • Identifies cloud misconfigurations.
    • Ensures compliance with regulatory standards.
    • Provides continuous security assessment.
    Study this card →
  • Data Classification and Protection (DCP)

    Flip card

    DCP is a framework that categorizes data based on its sensitivity and regulatory requirements, then applies appropriate security controls (encryption, access controls, integrity checks) throughout its lifecycle.

    • Identifies and tags sensitive data.
    • Enforces granular access policies.
    • Applies encryption at rest and in transit.
    Study this card →
  • Data Security Posture Management (DSPM)

    Flip card

    DSPM is a security solution that provides continuous, real-time visibility into sensitive data across hybrid and multi-cloud environments. It automates data discovery, classification, and risk assessment, identifying misconfigurations, access risks, and compliance gaps related to data.

    • Automates data discovery and classification.
    • Identifies data risks and compliance gaps.
    • Provides continuous monitoring of data posture.
    Study this card →
  • DLP + IRM Integration

    Flip card

    Integrating Data Loss Prevention (DLP) with Information Rights Management (IRM) creates a powerful defense that prevents unauthorized data outflow and maintains control over data usage even when it's shared.

    • DLP prevents data exfiltration.
    • IRM controls data access and usage post-distribution.
    • Encrypts and enforces policies on sensitive files.
    Study this card →
  • Policy-as-Code & Cloud-Native Secrets Management

    Flip card

    Policy-as-Code defines security and compliance policies in machine-readable code, while cloud-native secrets management secures and distributes sensitive credentials in dynamic cloud environments.

    • Automates policy enforcement in CI/CD.
    • Ensures consistent security across environments.
    • Secures API keys, database credentials, etc., for microservices.
    Study this card →
  • Threat Intelligence Platform (TIP)

    Flip card

    A software solution that aggregates, processes, and disseminates threat intelligence from various sources, making it actionable for security operations.

    • Normalizes and enriches threat data from multiple feeds.
    • Integrates with SIEM, SOAR, firewalls, and other security controls.
    • Enables proactive defense and automated incident response.
    Study this card →
  • Secure Collaboration Platforms

    Flip card

    These platforms enable secure communication and data sharing among users, often incorporating encryption, access controls, and audit trails to meet compliance requirements.

    • Ensures confidentiality and integrity of shared data.
    • Provides granular access controls.
    • Often includes audit and logging features for compliance.
    Study this card →
  • Container Security Platforms

    Flip card

    These platforms provide comprehensive security for containerized applications throughout their lifecycle, including vulnerability management, runtime protection, and compliance.

    • Scans container images for vulnerabilities.
    • Monitors container runtime behavior for anomalies.
    • Enforces security policies within container environments.
    Study this card →
  • Data Loss Prevention (DLP)

    Flip card

    DLP is a set of tools and processes designed to ensure that sensitive data is not lost, misused, or accessed by unauthorized users.

    • Prevents unauthorized data exfiltration.
    • Enforces data handling policies.
    • Monitors data in use, in motion, and at rest.
    Study this card →
  • Integrated Risk Management (IRM)

    Flip card

    IRM is a set of practices and processes supported by technology that enables an organization to understand and manage the full scope of its risks. It integrates governance, risk, and compliance (GRC) activities into a unified framework.

    • Centralizes risk data and management.
    • Automates compliance and audit processes.
    • Provides a holistic view of an organization's risk posture.
    Study this card →
  • OT PAM (Privileged Access Management)

    Flip card

    OT PAM extends traditional PAM principles to operational technology environments, providing secure, controlled, and auditable access to critical industrial control systems, often via specialized gateways.

    • Secures privileged access to industrial systems.
    • Provides granular control and session monitoring.
    • Helps maintain network segmentation and isolation.
    Study this card →
  • Privileged Access Management (PAM)

    Flip card

    PAM solutions manage and secure privileged accounts, credentials, and sessions, enforcing least privilege and providing comprehensive auditing capabilities.

    • Controls access to sensitive systems and data.
    • Reduces the attack surface by limiting privileged credential exposure.
    • Enables session recording and auditing for compliance and forensics.
    Study this card →
  • Privileged Access Management (PAM) for OT

    Flip card

    PAM for OT is a specialized solution that secures, manages, and monitors privileged accounts and access to operational technology systems, ensuring strict control, auditability, and compliance.

    • Manages shared and administrative credentials.
    • Enforces least privilege for critical OT systems.
    • Records and audits privileged sessions.
    Study this card →
  • Hybrid/Multi-Cloud SIEM/SOAR

    Flip card

    This refers to the integration of Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) capabilities to provide unified security visibility, alert management, and automated incident response across complex hybrid and multi-cloud environments.

    • Centralizes security event data from diverse sources.
    • Automates incident detection and response workflows.
    • Provides a holistic view of security posture across hybrid/multi-cloud.
    Study this card →
  • Cryptographic Integrity for Data Migration

    Flip card

    Using cryptographic hashing and digital signatures, combined with a verifiable chain of custody, to ensure the integrity, authenticity, and auditable transfer of sensitive and regulated data during migrations.

    • Hashing verifies data hasn't changed.
    • Digital signatures prove sender identity and message integrity.
    • Chain of custody documents every data handling step.
    Study this card →
  • Policy-as-Code (PaC)

    Flip card

    Policy-as-Code defines security and compliance policies in machine-readable code, enabling automated enforcement throughout the software development lifecycle and across infrastructure. It allows policies to be version-controlled, tested, and deployed like any other code.

    • Automates policy enforcement.
    • Integrates with CI/CD pipelines.
    • Ensures consistency across environments.
    Study this card →
  • Software Composition Analysis (SCA)

    Flip card

    SCA tools analyze software applications to identify and inventory open-source and third-party components, scanning them for known security vulnerabilities and license compliance issues.

    • Essential for managing software supply chain risks.
    • Integrates into CI/CD pipelines for continuous monitoring.
    • Helps ensure compliance with licensing and security policies.
    Study this card →
  • GRC Platform

    Flip card

    A software solution that integrates and manages an organization's governance, risk management, and compliance activities, providing a unified view of risk and control status.

    • Automates compliance monitoring and evidence collection.
    • Streamlines audit processes and reporting.
    • Provides visibility into risk posture and control effectiveness.
    Study this card →
  • Enterprise GRC Platform

    Flip card

    An Enterprise GRC Platform is a centralized system that helps organizations manage governance, risk, and compliance activities, automate control validation, and provide real-time compliance posture.

    • Maps controls to multiple regulations.
    • Automates evidence collection for audits.
    • Provides real-time visibility into compliance posture.
    Study this card →
  • SOAR (Security Orchestration, Automation, and Response)

    Flip card

    SOAR platforms automate and orchestrate security operations tasks, incident response workflows, and threat intelligence management.

    • Reduces manual effort and response times for security incidents.
    • Integrates with various security tools (e.g., SIEM, firewalls).
    • Enables consistent and repeatable incident response processes.
    Study this card →
  • Security Orchestration, Automation, and Response (SOAR)

    Flip card

    SOAR platforms integrate security tools, automate incident response workflows, and orchestrate threat hunting and management tasks.

    • Automates repetitive security tasks.
    • Orchestrates complex incident response processes.
    • Enhances threat intelligence utilization.
    Study this card →
  • Edge Anonymization for IoT/Vehicles

    Flip card

    Processing and anonymizing sensitive data directly at the data source (e.g., within a vehicle or IoT device) using edge computing, ensuring privacy-by-design before data leaves the local environment.

    • Implements privacy-by-design at the source.
    • Reduces sensitive data exposure during transmission and storage.
    • Enables compliance with privacy regulations for real-time data.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.