Important Microsoft SC-100 Exam Questions

CertPrep Microsoft SC-100 Exam Questions
Get Full Version

Microsoft Cybersecurity Architect SC-100 Exam

Attempt the Cybersecurity Architect Expert practice test and solve real exam-like SC-100 questions to prepare efficiently and increase your chances of success. Our Microsoft SC-100 practice questions match the actual Microsoft Cybersecurity Architect exam format, helping you enhance confidence and improve performance. With our SC-100 practice exam software, you can analyze your performance, identify weak areas, and work on them effectively to boost your final Cybersecurity Architect Expert exam score.

Vendor: Microsoft
Exam Name: Microsoft Cybersecurity Architect
Registration Code: SC-100
Related Certification: Microsoft Cybersecurity Architect Expert Certification
Exam Track: Cybersecurity certifications
Exam Audience: Microsoft Security architects and cybersecurity professionals,

Total Questions

246

Last Updated

21-01-2026

Exam Duration

100 MINUTES

Upgrade to Premium

GET FULL PDF

Question: 1

Your company has a hybrid cloud infrastructure.

The company plans to hire several temporary employees within a brief period. The temporary employees will need to access applications and data on the company' premises network.

The company's security policy prevents the use of personal devices for accessing company data and applications.

You need to recommend a solution to provide the temporary employee with access to company resources. The solution must be able to scale on demand.

What should you include in the recommendation?

Question: 2

Your company has an on-premise network in Seattle and an Azure subscription. The on-premises network contains a Remote Desktop server.

The company contracts a third-party development firm from France to develop and deploy resources to the virtual machines hosted in the Azure subscription.

Currently, the firm establishes an RDP connection to the Remote Desktop server. From the Remote Desktop connection, the firm can access the virtual machines hosted in Azure by using custom administrative tools installed on the Remote Desktop server. All the traffic to the Remote Desktop server is captured by a firewall, and the firewall only allows specific connections from France to the server.

You need to recommend a modern security solution based on the Zero Trust model. The solution must minimize latency tor developers.

Which three actions should you recommend? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Question: 3

Your on-premises network contains an Active Directory Domain Services (AD DS) domain named corpxontoso.com and an AD DS-integrated application named App1.

Your perimeter network contains a server named Server1 that runs Windows Server.

You have a Microsoft Entra tenant named contoso.com that syncs with corp.contoso.com.

You plan to implement a security solution that will include the following configurations:

* Manage access to App1 by using Microsoft Entra Private Access.

* Deploy a Microsoft Entra application proxy connector to Server1.

* Implement single sign-on (SSO) for App1 by using Kerberos constrained delegation.

* For Server1, configure the following rules in Windows Defender Firewall with Advanced Security:

o Rule1: Allow TCP 443 inbound from a designated set of Azure URLs.

o Rule2: Allow TCP 443 outbound to a designated set of Azure URLs.

o Rule3: Allow TCP 80 outbound to a designated set of Azure URLs.

o Rule4: Allow TCP 389 outbound to the domain controllers on corp.contoso.com.

You need to maximize security for the planned implementation. The solution must minimize the impact on the connector.

Which rule should you remove?

Question: 4

You are evaluating an Azure environment for compliance.

You need to design an Azure Policy implementation that can be used to evaluate compliance without changing any resources.

Which effect should you use in Azure Policy?

Question: 5

Your company has a main office and 10 branch offices. Each branch office contains an on-premises file server that runs Windows Server and multiple devices that run either Windows 11 or macOS. The devices are enrolled in Microsoft Intune.

You have a Microsoft Entra tenant.

You need to deploy Global Secure Access to implement web filtering for device traffic to the internet The solution must ensure that all the web traffic from the devices in the branch offices is controlled by using Global Secure Access.

What should you do first in each branch office?

Other Microsoft Certification Exams

MB-310 Exam

Microsoft Dynamics 365 Finance Functional Consultant

PL-600 Exam

Microsoft Power Platform Solution Architect

MB-820 Exam

Microsoft Dynamics 365 Business Central Developer

DP-300 Exam

Administering Microsoft Azure SQL Solutions

MS-900 Exam

Microsoft 365 Fundamentals

AZ-104 Exam

Microsoft Azure Administrator Exam