Skip to content

SC-100 Practice Questions

Prepare for SC-100 with more than an answer.

169 questions in the full set20 sample questionsUpdated Jan 25, 2026
Exam fee
$165 USD
Level
Expert
Valid for
1 year
Domains covered on the exam 4
  1. Design solutions that align with security best practices and priorities22.5%
  2. Design security operations, identity, and compliance capabilities27.5%
  3. Design security solutions for infrastructure27.5%
  4. Design security solutions for applications and data22.5%
  1. 1

    A Case Study of Aperture Dynamics

    Company Background
    Aperture Dynamics is a high-tech engineering firm that develops sensitive intellectual property (IP). They have a hybrid environment with a significant on-premises data center running VMware, and they are aggressively migrating workloads to Azure. Their security strategy is based on Zero Trust principles.

    Current Environment
    Their Azure environment consists of multiple subscriptions organized under management groups. They use Azure AD for identity, with Azure AD Connect syncing from their on-premises Active Directory. Production workloads run in isolated virtual networks. Developers are using Azure DevOps for their CI/CD pipelines. The security team uses Microsoft Sentinel for SIEM and Microsoft Defender for Cloud for posture management.

    Requirements

    1. Privileged Access: All administrative access to Azure infrastructure must be just-in-time (JIT) and require approval. This applies to both permanent and temporary administrative roles.
    2. Data Protection: All sensitive IP stored in Azure Storage accounts must be protected from malicious activity, and access must be audited. The data must be classified, and policies must prevent its exfiltration.
    3. DevSecOps: The CI/CD pipeline must incorporate security checks. Specifically, any Infrastructure as Code (IaC) templates (ARM/Bicep) must be scanned for security misconfigurations before deployment.
    4. Network Security: The company wants to secure remote user access to the internet and Microsoft 365 services without backhauling traffic to the on-premises data center, following a Security Service Edge (SSE) model.

    Problem Statement
    The security architect needs to design solutions to meet these four key requirements. Which service should be used to meet the DevSecOps requirement of scanning IaC templates for misconfigurations before deployment?

    Show answer details

    Correct answer: A

    Microsoft Defender for DevOps is the service designed to provide security visibility and control across the development lifecycle. It integrates directly into source code management systems and CI/CD pipelines like Azure DevOps. A key feature is its ability to scan Infrastructure as Code (IaC) templates for security vulnerabilities and misconfigurations, providing feedback directly to developers and allowing for policies that can block non-compliant deployments. This directly fulfills requirement #3.

  2. 2

    A Case Study of Aperture Dynamics

    Company Background
    Aperture Dynamics is a high-tech engineering firm that develops sensitive intellectual property (IP). They have a hybrid environment with a significant on-premises data center running VMware, and they are aggressively migrating workloads to Azure. Their security strategy is based on Zero Trust principles.

    Current Environment
    Their Azure environment consists of multiple subscriptions organized under management groups. They use Azure AD for identity, with Azure AD Connect syncing from their on-premises Active Directory. Production workloads run in isolated virtual networks. Developers are using Azure DevOps for their CI/CD pipelines. The security team uses Microsoft Sentinel for SIEM and Microsoft Defender for Cloud for posture management.

    Requirements

    1. Privileged Access: All administrative access to Azure infrastructure must be just-in-time (JIT) and require approval. This applies to both permanent and temporary administrative roles.
    2. Data Protection: All sensitive IP stored in Azure Storage accounts must be protected from malicious activity, and access must be audited. The data must be classified, and policies must prevent its exfiltration.
    3. DevSecOps: The CI/CD pipeline must incorporate security checks. Specifically, any Infrastructure as Code (IaC) templates (ARM/Bicep) must be scanned for security misconfigurations before deployment.
    4. Network Security: The company wants to secure remote user access to the internet and Microsoft 365 services without backhauling traffic to the on-premises data center, following a Security Service Edge (SSE) model.

    Problem Statement
    The security architect needs to design solutions to meet these four key requirements. Which service should be used to meet the network security requirement for implementing an SSE model for remote users?

    Show answer details

    Correct answer: A

    Microsoft Entra Internet Access is a key component of Microsoft's Security Service Edge (SSE) solution. It is a cloud-delivered Secure Web Gateway (SWG) that secures access to the internet, SaaS, and Microsoft 365 apps for remote users. It allows traffic to be routed directly to the Microsoft global network for inspection and policy enforcement, eliminating the need to backhaul traffic to an on-premises data center. This perfectly matches the SSE requirement (#4).

  3. 3

    True or False: The Microsoft Cybersecurity Reference Architectures (MCRA) provides a prescriptive, one-size-fits-all deployment guide that must be implemented exactly as documented to achieve a secure posture.

    Show answer details

    Correct answer: B

    This statement is false. The MCRA is not a prescriptive implementation guide but rather a set of reference architectures, principles, and best practices. It is designed to be adaptable to an organization's specific needs, existing environment, and business goals. Architects should use the MCRA as a starting point and a comprehensive guide to understand Microsoft's security capabilities and how they integrate, but they must tailor the design to their unique requirements.

  4. 4

    A government agency is required to comply with the NIST SP 800-53 regulatory standard. The security architect needs a tool to continuously assess the agency's Azure environment against this standard, provide a compliance score, and offer actionable recommendations for remediation. The solution must be a native Azure service. Which component of Microsoft Defender for Cloud should be used to meet this requirement?

    Show answer details

    Correct answer: C

    The Regulatory compliance dashboard in Microsoft Defender for Cloud is the specific feature designed for this purpose. It allows organizations to add various regulatory standards (like NIST SP 800-53, PCI DSS, ISO 27001) to their dashboard. Defender for Cloud then continuously assesses the Azure environment against the controls specified in that standard, provides a compliance score, and details which controls are passing or failing with remediation steps. This directly addresses the agency's requirements.

  5. 5

    A security architect at TerraLogix is reviewing the network design for their Azure environment, which uses a hub-and-spoke topology. The design is intended to force all traffic between spoke virtual networks to be inspected by an Azure Firewall in the hub VNet. However, testing reveals that VMs in Spoke A can communicate directly with VMs in Spoke B. The VNet peerings are configured correctly between the hub and each spoke, but not directly between spokes. What is the most likely misconfiguration causing this unintended traffic flow?

    graph TD subgraph Hub_VNet [Hub VNet] Firewall[Azure Firewall] end subgraph Spoke_A_VNet [Spoke A VNet] VM_A[VM in Spoke A] end subgraph Spoke_B_VNet [Spoke B VNet] VM_B[VM in Spoke B] end UDR_A[UDR on Spoke A Subnet] --> Firewall UDR_B[UDR on Spoke B Subnet] --> Firewall VM_A -- "Peering with Hub" --> Hub_VNet VM_B -- "Peering with Hub" --> Hub_VNet VM_A -- "UNEXPECTED DIRECT PATH" --> VM_B

    Show answer details

    Correct answer: D

    For a Network Virtual Appliance (NVA) like Azure Firewall to route traffic between spokes, the peering connections from the hub to the spokes must have the 'Allow forwarded traffic' setting enabled. This setting permits traffic that did not originate in the hub VNet to be forwarded through the hub to its destination. If this is disabled, the firewall can't route the traffic from Spoke A to Spoke B, and Azure's default routing might allow direct communication if not properly overridden.

  6. 6

    A financial services firm, QuantumLeap Financials, is designing a Zero Trust architecture for its hybrid environment. They have a critical on-premises Active Directory Domain Services (AD DS) infrastructure and a growing footprint in Azure. A key requirement is to protect privileged administrative accounts in AD DS from pass-the-hash and other credential theft attacks originating from compromised workstations. The security architect needs to recommend a solution that isolates administrative tasks from daily user activities like email and web browsing. Which solution best meets this requirement by implementing a tiered access model?

    Show answer details

    Correct answer: D

    The core requirement is to isolate administrative tasks from daily user activities to prevent credential theft. Privileged Access Workstations (PAWs) are specifically designed for this purpose. A PAW provides a dedicated, hardened operating system for sensitive tasks, completely separate from the user's standard workstation used for email and browsing. This directly prevents credential theft vectors like phishing and browser exploits from compromising high-privilege accounts. While Defender for Identity is crucial for detection and PIM for just-in-time access, neither provides the required task isolation at the workstation level.

  7. 7

    A global logistics company, TerraNova Logistics, is migrating its infrastructure to a multi-cloud environment, using Azure, AWS, and GCP. The CISO is concerned about inconsistent permission management and the risk of privilege escalation across the different cloud platforms. They need a unified solution to discover, remediate, and monitor permissions for all identities and resources across their entire multi-cloud estate. Which Microsoft solution is specifically designed to address this Cloud Infrastructure Entitlement Management (CIEM) challenge?

    Show answer details

    Correct answer: B

    Microsoft Entra Permissions Management is the Cloud Infrastructure Entitlement Management (CIEM) solution from Microsoft. It is designed to provide comprehensive visibility and control over permissions for any identity and any resource across multi-cloud infrastructures, including Azure, AWS, and GCP. It helps enforce the principle of least privilege by discovering unused or excessive permissions. Azure Arc extends the Azure control plane, and Defender for Cloud provides posture management, but neither is primarily a CIEM solution for managing granular permissions across clouds.

  8. 8

    An e-commerce company is building a new application on Azure Kubernetes Service (AKS). As part of their DevSecOps pipeline, they need to ensure that only approved and vulnerability-scanned container images are deployed to their production AKS cluster. The security policy dictates that any attempt to deploy an image that has not passed a security scan or is from an untrusted registry must be blocked. Which combination of Azure services should be used to enforce this policy? (Select TWO)

    Show answer details

    Correct answer: A, D

    Microsoft Defender for Containers provides vulnerability scanning for images in Azure Container Registry and real-time threat detection for containerized environments. Azure Policy for Kubernetes can then enforce policies at deployment time, such as blocking the deployment of images that have known vulnerabilities identified by Defender for Containers. This combination directly addresses the requirement to scan images and block non-compliant deployments.

  9. 9

    A healthcare organization uses Azure to store patient records in Azure SQL Database and Azure Blob Storage. They need to design a security solution that meets the following requirements:

    • Discover and classify sensitive patient data across all Azure data stores.
    • Provide a unified view of data security posture and identify potential threats to the data.
    • Detect anomalous activities, such as unusual data access or potential SQL injection attacks, against the data stores.

    Which two Microsoft Defender plans should be central to this design? (Select TWO)

    Show answer details

    Correct answer: B, D

    The requirements specifically call for securing data in Azure SQL Database and Azure Blob Storage. Microsoft Defender for SQL is designed to discover and classify sensitive data, manage vulnerabilities, and detect anomalous activities in SQL databases. Microsoft Defender for Storage provides advanced threat protection for Azure Storage, detecting unusual and potentially harmful attempts to access or exploit storage accounts. Together, these two plans directly address the specified data security needs.

  10. 10

    A manufacturing company, Aperture Dynamics, is implementing Microsoft Sentinel as its SIEM. They have a hybrid environment with on-premises servers, Azure VMs, and several Microsoft 365 services. The security operations team needs to automate the initial triage and response to common alerts, such as impossible travel alerts from Azure AD Identity Protection. The automation must post a message in a specific Microsoft Teams channel for the on-duty analyst, temporarily disable the user account, and create a high-priority ticket in ServiceNow. Which Microsoft Sentinel feature should be used to build this automated workflow?

    Show answer details

    Correct answer: D

    Microsoft Sentinel Playbooks are collections of procedures that can be run from Microsoft Sentinel in response to an alert or incident. Playbooks are built on Azure Logic Apps, which provide a powerful, customizable, and scalable engine for creating automated workflows. This allows for integration with various services like Microsoft Teams, Azure AD, and ServiceNow to perform the required actions (post message, disable user, create ticket), fulfilling the SOAR (Security Orchestration, Automation, and Response) requirement.

Create an account to continue.