SC-100 Sample Questions

SC-100 Sample Questions & Answers

Security operations, identity design and infrastructure security tie for the top weight, alongside a ransomware resiliency strategy aligned with Microsoft's frameworks, and securing applications, Microsoft 365 and organizational data.

Launch the full SC-100 simulator →

Free SC-100 Sample Questions with Answers

Real questions from the Microsoft Cybersecurity Architect practice test — answers and explanations included. Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Design security solutions for infrastructure · Evaluate network designs to align with security requirements and best practices

    Stellaron Corp is designing a network security architecture for their Azure environment. They want to inspect all outbound internet traffic from their virtual networks to prevent data exfiltration and enforce corporate web policies. Additionally, they need to inspect traffic between spoke virtual networks that are peered to a central hub VNet. The solution must be a managed, cloud-native service that offers advanced threat protection, including TLS inspection and intrusion detection and prevention systems (IDPS). Which Azure service should be deployed in the hub VNet to meet all these requirements?

    Show answer & explanation

    Correct answer: C

    Azure Firewall Premium is the ideal choice for this scenario. It is a managed, cloud-native firewall service that can be deployed in a central hub VNet to inspect both east-west (spoke-to-spoke) and north-south (outbound to internet) traffic. The Premium SKU specifically provides advanced capabilities like TLS inspection to decrypt and inspect outbound traffic, a signature-based IDPS to detect and prevent malicious activity, and URL filtering for web policies. NSGs operate at Layer 4 and lack these advanced features, while Application Gateway is primarily for protecting inbound web traffic.

  2. Question 2Beginner

    Design solutions that align with security best practices and priorities · Design a resiliency strategy for ransomware and other attacks based on Microsoft Security Best Practices

    True or False: When designing a resiliency strategy against ransomware, the primary focus should be on implementing advanced threat detection tools like EDR, with backup and recovery solutions being a secondary consideration.

    Show answer & explanation

    Correct answer: B

    This statement is false. While detection tools are critical for prevention, a comprehensive ransomware resiliency strategy must prioritize business continuity and disaster recovery (BCDR). The assumption should always be that a preventative control might fail. Therefore, a robust, tested, and secure backup and recovery solution is the ultimate safety net to ensure the business can recover its data and operations without paying a ransom. Microsoft security best practices emphasize a balanced approach but highlight BCDR as a cornerstone of ransomware resilience.

  3. Question 3Intermediate

    Design security solutions for infrastructure · Evaluate solutions that use Microsoft Entra Private Access

    A university needs to provide secure access to on-premises legacy web applications for its researchers, who often work remotely. The university wants to avoid using a traditional VPN and instead adopt a Zero Trust approach. The solution must integrate with their existing Azure Active Directory for authentication, enforce Conditional Access policies like requiring MFA, and not require opening inbound ports on their on-premises firewall. Which service should the university's security architect recommend?

    Show answer & explanation

    Correct answer: B

    Microsoft Entra Private Access (which includes the capabilities of the former Azure AD Application Proxy) is the correct solution. It acts as a Zero Trust Network Access (ZTNA) service. It allows publishing on-premises web applications to external users through the Microsoft Entra service. Lightweight connectors are installed on-premises and make outbound connections to the service, meaning no inbound firewall ports need to be opened. It fully integrates with Azure AD, allowing pre-authentication and the application of Conditional Access policies before granting access to the on-premises application, perfectly matching all the requirements.

  4. Question 4Intermediate

    Design security solutions for applications and data · Evaluate solutions that include Microsoft Defender for Office 365 and Microsoft Defender for Cloud Apps

    A retail company is expanding its use of Microsoft 365 and is concerned about data leakage through both managed and unmanaged devices. A security architect must design a solution that provides visibility into cloud app usage, including discovering 'shadow IT' applications. The solution must also enforce granular session controls for sanctioned apps, such as blocking downloads of sensitive files to unmanaged devices. Which Microsoft 365 security service is the primary tool for achieving these Cloud Access Security Broker (CASB) functionalities?

    Show answer & explanation

    Correct answer: C

    Microsoft Defender for Cloud Apps is Microsoft's Cloud Access Security Broker (CASB) solution. It directly addresses the requirements by providing capabilities for shadow IT discovery (discovering and assessing cloud apps used by the organization) and by acting as a reverse proxy to apply session controls. These session controls can enforce policies like blocking downloads, uploads, or copy/paste actions for specific users or devices, which is exactly what is needed to prevent data leakage to unmanaged devices.

  5. Question 5Intermediate

    Design solutions that align with security best practices and priorities · Design solutions that align with the Microsoft Cloud Adoption Framework for Azure and the Microsoft Azure Well-Architected Framework

    You are designing a security architecture for a new Azure environment. To align with the Microsoft Cloud Adoption Framework (CAF), you must ensure that all newly deployed resources automatically adhere to corporate security standards, such as enforcing specific NSG rules, enabling encryption, and restricting public IP addresses. What is the most effective way to implement this governance and security requirement at scale for all new subscriptions and resource groups?

    Show answer & explanation

    Correct answer: B

    The Cloud Adoption Framework emphasizes establishing governance from the start. The most effective and scalable way to enforce security standards across an entire Azure estate is by using Azure Policy assignments or Azure Blueprints at a high level in the management group hierarchy. This ensures that any new subscription created under that management group automatically inherits the policies, guaranteeing compliance without manual intervention. This approach is a core principle of designing and governing Azure landing zones.

  6. Question 6Intermediate

    Design security operations, identity, and compliance capabilities · Design and evaluate threat detection coverage by using MITRE ATT&CK matrices

    An organization is evaluating its threat detection coverage. The CISO wants to ensure that the security monitoring capabilities in Microsoft Sentinel effectively cover the tactics and techniques used by adversaries in cloud environments. The security architect needs to map the active analytic rules in Sentinel to a standardized framework to identify gaps in detection. Which framework is natively integrated into Microsoft Sentinel for this purpose?

    Show answer & explanation

    Correct answer: C

    Microsoft Sentinel has native integration with the MITRE ATT&CK framework. When creating or viewing analytic rules, you can map them to specific ATT&CK tactics and techniques. Sentinel also provides a dedicated 'MITRE ATT&CK' view that visualizes the current detection coverage against the framework's matrices (Enterprise, Cloud, etc.), allowing security teams to easily identify and prioritize gaps in their defenses.

  7. Question 7Intermediate

    Design security operations, identity, and compliance capabilities · Design a modern authentication and authorization strategy

    A multinational corporation has a complex hybrid identity setup using Azure AD Connect to synchronize its on-premises Active Directory with Azure AD. They are concerned about legacy authentication protocols (like POP3, IMAP, SMTP) being used to bypass modern security controls such as MFA. The security architect must recommend a policy to block these weak protocols for all users. What is the most direct and effective method to achieve this in Azure AD?

    Show answer & explanation

    Correct answer: C

    The most effective and recommended method to block legacy authentication in Azure AD is to use a Conditional Access policy. Specifically, you create a policy, and under the 'Conditions' section, you configure 'Client apps'. Within this configuration, you select 'Other clients', which includes clients that use legacy authentication protocols. By setting the access control for this condition to 'Block access', you effectively prevent these protocols from being used to authenticate against Azure AD.

  8. Question 8Intermediate

    Design security solutions for infrastructure · Design a solution for Microsoft Defender External Attack Surface Management (Defender EASM)

    Your organization's security team is concerned about its external attack surface. They are unaware of all the internet-facing assets that are associated with the company's primary domain names. They want to proactively discover and catalog all external assets, such as domains, hosts, and web pages, including those that might have been created without the IT department's knowledge ('shadow IT'). Which Microsoft security solution is designed for this specific purpose of external discovery and attack surface mapping?

    Show answer & explanation

    Correct answer: B

    Microsoft Defender External Attack Surface Management (Defender EASM) is the service specifically designed for this use case. It continuously scans the internet to discover assets that are related to an organization's known online infrastructure. It provides an outside-in view, showing the organization what an attacker would see. This helps identify unknown or unmanaged assets and assess the external security posture.

  9. Question 9Advanced

    Design security solutions for applications and data · Evaluate solutions for encryption of data at rest and in transit

    A medical research institute is running high-performance computing (HPC) workloads on Azure Virtual Machines. These VMs process sensitive genetic data and must be protected by multiple layers of encryption. The security architect has already enabled Azure Disk Encryption for the OS and data disks. To meet an enhanced compliance requirement, they must also ensure that the data is encrypted at the infrastructure level before it is even written to the storage clusters. Which feature provides this additional layer of encryption at the Azure data center hardware level?

    Show answer & explanation

    Correct answer: D

    Encryption at host provides an additional layer of protection by encrypting data on the VM host itself. This ensures that data is encrypted from the host's CPU to the storage clusters, protecting against any compromises at the hypervisor or physical hardware level. This feature, when combined with Azure Disk Encryption (which encrypts within the guest OS), provides end-to-end encryption and supports double encryption scenarios for highly sensitive data, meeting the compliance requirement.

  10. Question 10Beginner

    Design security solutions for applications and data · Evaluate threats to business-critical applications by using threat modeling

    A company is designing a threat modeling process for its new business-critical applications. The goal is to systematically identify and mitigate potential security threats during the design phase of the software development lifecycle (SDLC). The security architect recommends using a structured threat modeling methodology. Which of the following is a widely recognized threat modeling methodology developed by Microsoft?

    Show answer & explanation

    Correct answer: B

    STRIDE is a threat modeling methodology developed by Microsoft to help identify and categorize threats to a system. It provides a mnemonic for security threats: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. It is a foundational element of the Microsoft Security Development Lifecycle (SDL) and is commonly used with tools like the Microsoft Threat Modeling Tool.

Ready for the real thing?

The full SC-100 simulator has every exam-style question, timed mode, and instant scoring.

Go to the SC-100 simulator →