Microsoft

SC-100 Free Practice Questions

This is the free Microsoft SC-100 practice question bank — 160 of 314 total questions, each with a full explanation, free to read with no signup required. Updated 2026-08-06.

Every answer is verified against official Microsoft documentation — see our methodology.

Question 1

You have an Azure subscription and a Microsoft 365 subscription. All users are assigned Microsoft 365 E5 licenses. All computers run Windows 11 and are Microsoft Entra joined. You need to recommend a solution to prevent computers that run early builds of Windows 11 from connecting to Microsoft 365 services. Which two types of policies should you include in the recommendation? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

A. Microsoft Defender for Endpoint endpoint security policy
B. Microsoft Defender for Cloud regulatory compliance policy
C. Microsoft Intune compliance policy
D. Microsoft Entra ID Protection sign-in risk policy
E. Microsoft Entra Conditional Access policy
Show Answer
Correct Answer: C, E
Explanation:
Use an Intune compliance policy to define the minimum allowed Windows 11 OS version so devices running early builds are marked noncompliant. Then use a Microsoft Entra Conditional Access policy requiring the device to be compliant before accessing Microsoft 365 services, which blocks noncompliant devices.

Question 2

You have an Azure subscription. You have an on-premises datacenter. The datacenter contains 20 servers that run Windows Server. Each server is onboarded to Azure Arc and is protected by using Microsoft Defender for Servers Plan 1. You have a Microsoft 365 subscription. You need to recommend a solution to identify which servers have outdated hardware drivers or firmware. What should you include in the recommendation?

A. Change all the servers to Microsoft Defender for Servers Plan 2.
B. Add the Microsoft Intune Suite add-on.
C. Onboard all the servers to Azure Update Manager.
D. Add Microsoft Defender Vulnerability Management add-ons.
Show Answer
Correct Answer: D
Explanation:
Microsoft Defender Vulnerability Management add-ons provide hardware and firmware assessment capabilities, including detection of outdated drivers and firmware. Defender for Servers Plan 1 alone does not include these capabilities. Upgrading to Plan 2 adds broader server protection but does not specifically replace the need for the Vulnerability Management add-on for this feature. Azure Update Manager focuses on OS update management, not hardware driver/firmware assessment, and Microsoft Intune Suite is not the appropriate solution for these Arc-enabled Windows Server systems.

Question 3

You have an Azure subscription. You have an on-premises datacenter that contains Microsoft SQL Server instances. Each instance contains multiple databases. You have a Microsoft 365 subscription. You plan to implement a solution to scan the databases for vulnerabilities that compromise data security. You need to recommend what to configure before the databases can be scanned. What should you recommend?

A. Microsoft Purview data loss prevention (DLP)
B. Microsoft Purview data governance
C. Microsoft Defender for Cloud
D. Microsoft Defender Vulnerability Management
Show Answer
Correct Answer: C
Explanation:
To scan SQL Server databases for security vulnerabilities, you should configure Microsoft Defender for Cloud. For on-premises SQL Server instances, this is typically enabled by onboarding the servers (commonly via Azure Arc) so SQL vulnerability assessment and related security capabilities can be used. Microsoft Purview focuses on governance and DLP, while Defender Vulnerability Management is for endpoint/device vulnerability management rather than SQL database vulnerability assessments.

Question 4

HOTSPOT - You have a Microsoft Entra tenant named contoso.com that is linked to an Azure subscription named Sub1 and a Microsoft 365 subscription. Sub1 contains a publicly accessible Azure App Service web app named App1. You have an external partner that has a Microsoft Entra tenant named fabrikam.com. You need to recommend a solution that meets the following requirements: • Ensures that the users in fabrikam.com can be granted permissions to specific Microsoft Teams channels in contoso.com • Ensures that the users of App1 can authenticate by using social media accounts • Minimizes administrative effort Which authentication method should you recommend for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 4
Show Answer
Correct Answer: B2B direct connect Microsoft Entra External ID for customers
Explanation:
B2B direct connect is designed for cross-tenant access to Microsoft Teams shared channels. Microsoft Entra External ID for customers supports customer sign-in with social identity providers for web applications.

Question 5

You are designing a ransomware mitigation strategy. You perform a ransomware risk assessment and identify business-critical assets. You need to recommend a solution to mitigate ransomware threats. The solution must follow Microsoft security best practices. Which two actions should you include in the recommendation? Each correct answer presents a complete solution. NOTE: Each correct answer is worth one point.

A. Enable firewall logging for auditing, without restricting inbound or outbound traffic.
B. Use extended patching cycles to reduce the risk of update-related service disruptions.
C. Implement immutable, offline backups that have restricted access and test restore procedures regularly.
D. Deploy Privileged Identity Management (PIM) that uses just-in-time (JIT) access and approval workflows.
Show Answer
Correct Answer: C, D
Explanation:
Microsoft ransomware guidance emphasizes resilient backup strategies with immutable/offline backups, restricted access, and regular restore testing. It also recommends least-privilege administration using Privileged Identity Management with just-in-time access and approval workflows to reduce the impact of compromised privileged accounts. Firewall logging alone does not mitigate ransomware, and extended patching cycles increase exposure rather than following security best practices.

Question 6

You have an Azure subscription. You have a subscription to a third-party cloud provider. The subscription contains 100 virtual machines. You manage cloud security for both subscriptions from the Azure subscription. You need to recommend a solution to validate the security posture of the virtual machines. Which two services should you include in the recommendation? Each correct answer presents part of the solution. NOTE: Each correct answer is worth one point.

A. Microsoft Sentinel
B. Azure Arc
C. Microsoft Defender for Cloud
D. Azure Lighthouse
E. Microsoft Defender for Endpoint
Show Answer
Correct Answer: B, C
Explanation:
Use Azure Arc to onboard and manage servers/virtual machines from third-party clouds in Azure. Then use Microsoft Defender for Cloud to assess and continuously validate their security posture across hybrid and multicloud environments. Microsoft Sentinel is a SIEM/SOAR rather than a posture assessment service, Azure Lighthouse is for cross-tenant management, and Defender for Endpoint focuses on endpoint protection rather than overall cloud security posture.

Question 7

You have an Azure subscription. The subscription contains multiple Azure App Service web apps that are distributed across multiple Azure regions and are accessed via the internet. You need to ensure that all incoming requests to the apps are inspected for threats based on the Core Rule Set (CRS) from the Open Web Application Security Project (OWASP). The solution must meet the following requirements: • Support the use of Microsoft-managed X.509 certificates. • Route users to the geographically closest app. • Minimize administrative effort. What should you use?

A. Azure Firewall Premium
B. Azure Front Door with a web application firewall (WAF)
C. Azure Firewall Standard
D. Azure Application Gateway with a web application firewall (WAF)
Show Answer
Correct Answer: B
Explanation:
Azure Front Door with WAF provides OWASP Core Rule Set (CRS) inspection, supports Microsoft-managed certificates, performs global anycast-based routing to the closest healthy regional backend, and is a fully managed service that minimizes administrative effort. Azure Application Gateway with WAF is regional and does not provide global nearest-region routing. Azure Firewall Standard/Premium are network firewalls and do not satisfy the web application routing and managed certificate requirements.

Question 9

HOTSPOT - You have a Microsoft 365 subscription. You configure Microsoft Purview Information Protection to apply sensitivity labels automatically. You need to recommend a solution that will prevent users from uploading unlabeled files to Microsoft SharePoint Online if the files contain content defined by Microsoft Purview classifiers as sensitive. What should you include in the recommendation? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 9
Show Answer
Correct Answer: Policy type: App control policy Microsoft 365 service: Microsoft Defender for Cloud Apps
Explanation:
Defender for Cloud Apps app control policies can enforce real-time controls on SharePoint Online uploads, including blocking uploads of files that are unlabeled while containing sensitive information detected through Microsoft Purview classification.

Question 10

Your network contains an on-premises Active Directory Domain Services (AD DS) domain named Domain1. Domain1 contains 10 domain controllers. You have an Azure subscription named Sub1 that contains a Microsoft Sentinel workspace named WS1. You have a Microsoft 365 subscription that contains 5,000 users. Each user is assigned a Microsoft 365 E3 license. You need to recommend a solution to ingest security logs from all the domain controllers into WS1. The solution must meet the following requirements: • The cost of ingesting data into WS1 must be minimized. • WS1 must ingest all the Windows Security event logs generated by the domain controllers. • The solution must support the generation of approximately 350 MB of logs per day from each domain controller. What should you recommend?

A. Upgrade the user licenses to Microsoft 365 E5.
B. Onboard each domain controller to Microsoft Defender for Servers Plan 2.
C. Configure Auxiliary logs in WS1.
D. Configure a volume cap for WS1.
E. Only ingest data from one domain controller into WS1.
Show Answer
Correct Answer: B
Explanation:
Microsoft Defender for Servers Plan 2 includes the Defender for Cloud data ingestion benefit for specific security data, allowing Windows Security event ingestion into Microsoft Sentinel at no additional ingestion cost when using the supported connector. This satisfies the requirement to ingest all domain controller security logs while minimizing Sentinel ingestion costs. Upgrading users to Microsoft 365 E5 does not cover on-premises domain controller Sentinel ingestion, Auxiliary logs are not intended for full Security event ingestion, a volume cap limits ingestion rather than minimizing cost, and ingesting from only one domain controller fails the requirements.

Question 11

You have a Microsoft 365 subscription. You have a Conditional Access policy that has the following settings: • Name: Policy 1 • Assignments o Users: - Include: All users o Target resources - Include: Select apps; Office 365 o Network - Include: Any network or location - Exclude: Selected networks and locations; Site1 o Access controls - Grant: Require multifactor authentication, Require Hybrid Microsoft Entra joined device You plan to implement Zero Trust Rapid Modernization Plan (RaMP). You need to ensure that Policy1 aligns with best practice recommendations in RaMP. Which setting should you change?

A. Include: Any network or location
B. Exclude: Selected networks and locations; Site1
C. Grant Require Hybrid Microsoft Entra joined device
D. Grant: Require multifactor authentication
Show Answer
Correct Answer: B
Explanation:
The Zero Trust Rapid Modernization Plan recommends enforcing Conditional Access consistently regardless of network location and avoiding trusted network exclusions where possible. Excluding a corporate site weakens Zero Trust principles because access decisions should rely on strong identity, device, and risk signals rather than network location. Requiring multifactor authentication remains a core recommendation, and requiring a Hybrid Microsoft Entra joined device is not the primary misalignment compared with having a trusted location exclusion.

$19

Get all 314 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.