Microsoft

SC-100 Free Practice Questions — Page 10

Question 72

HOTSPOT - You have an Azure subscription that contains the resources shown in the following table. You need to recommend a network security solution for App1. The solution must meet the following requirements: • Only the virtual machines that are connected to Subnet1 must be able to connect to DB1. • DB1 must be inaccessible from the internet. • Costs must be minimized. What should you include in the recommendation? To answer, select the options in the answer area. NOTE: Each correct answer is worth one point.

Illustration for SC-100 question 72 Illustration for SC-100 question 72
Show Answer
Correct Answer: A private endpoint Virtual network rules
Explanation:
A private endpoint (via Azure Private Link) places DB1 on a private IP in Subnet1, removing public internet access and allowing only resources in the VNet to connect. Virtual network rules on Azure SQL restrict access to the specified subnet, ensuring only VMs in Subnet1 can reach DB1 at minimal cost.

Question 73

HOTSPOT - You have an Azure subscription that contains a Microsoft Sentinel workspace named WS1. You need to configure WS1 to meet the following requirements: • Create custom dashboards to visualize the workload of security analysts that use Microsoft Sentinel. • Enable automated responses for the security alerts generated by Microsoft Sentinel analytics rules. What should you use for each requirement? To answer, select the options in the answer area. NOTE: Each correct answer is worth one point.

Illustration for SC-100 question 73
Show Answer
Correct Answer: Custom dashboards: Workbooks Automated responses: Playbooks
Explanation:
Microsoft Sentinel uses Workbooks to build custom dashboards and visualizations. Automated responses to analytics rule alerts are implemented using Playbooks, which are Azure Logic Apps–based workflows.

Question 74

Your company has an Azure subscription that uses Microsoft Defender for Cloud. The company signs a contract with the United States government. You need to review the current subscription for NIST 800-53 compliance. What should you do first?

A. From Azure Policy, assign a built-in initiative that has a scope of the subscription.
B. From Azure Policy, assign a built-in policy definition that has a scope of the subscription.
C. From Defender for Cloud, review the Azure security baseline for audit report.
D. From Defender for Cloud, enable Defender for Cloud plans.
Show Answer
Correct Answer: A
Explanation:
To review NIST SP 800-53 compliance in an Azure subscription, the first step is to assign the relevant regulatory compliance initiative. Azure provides a built-in NIST SP 800-53 Regulatory Compliance initiative in Azure Policy that maps NIST controls to Azure Policy definitions. Assigning this initiative at the subscription scope enables assessment and reporting of compliance against NIST 800-53. Individual policy definitions, Defender plans, or baseline reports are either too granular or occur after the compliance framework is applied.

Question 75

You have a Microsoft 365 tenant named contoso.com. You need to ensure that users can authenticate only to contoso.com. The solution must meet the following requirements: • Prevent the users from authenticating to other Microsoft 365 tenants. • Minimize administrative effort. What should you use?

A. Microsoft Entra Private Access
B. Microsoft Defender for Endpoint
C. Microsoft Entra Internet Access
D. Microsoft Defender for Cloud Apps
Show Answer
Correct Answer: C
Explanation:
To restrict users so they can authenticate only to the contoso.com tenant and not to any other Microsoft 365 tenants, you use Universal Tenant Restrictions. This capability is delivered through Microsoft Entra Internet Access (part of Global Secure Access). Entra Internet Access applies tenant restrictions to Microsoft traffic, blocking authentication to external tenants while allowing the home tenant. It is a tenant-wide, centrally managed control and therefore minimizes administrative effort. The other options do not natively enforce tenant-level authentication restrictions across Microsoft 365 sign-ins.

Question 76

HOTSPOT - You have on-premises servers and virtual machines that run Windows Server, Red Hat Enterprise Linux (RHEL) 7, or RHEL 8. You have an Azure subscription. The subscription contains virtual machines that run Windows Server Datacenter: Azure Edition. You need to recommend a solution to manage operating system updates for the on-premises servers and the virtual machines. The solution must meet the following requirements: • Enable hotpatching for the Azure virtual machines. • Enable the on-demand inventory and deployment of updates. • Enable the deployment of Extended Security Update (ESU) patches to the on-premises servers. What should you include in the recommendation? To answer, select the options in the answer area. NOTE: Each correct answer is worth one point.

Illustration for SC-100 question 76
Show Answer
Correct Answer: Azure Update Manager The Azure Connected Machine agent
Explanation:
Azure Update Manager supports hotpatching for Windows Server Datacenter: Azure Edition, on-demand update inventory and deployment, and ESU patch deployment. The Azure Connected Machine agent is required to onboard on-premises Windows and RHEL servers to Azure for centralized update management.

Question 77

HOTSPOT - You have an Azure subscription. The subscription contains an Azure Bastion host and 100 virtual machines that run Windows Server 2022. The virtual machines have Microsoft Defender for Servers Plan 2 enabled. You need to recommend a security solution for the virtual machines that meets the following requirements: • Administrators must request RDP access to the virtual machines by using the Azure portal. • Remote Desktop sessions must be limited to a maximum of three hours. • Agentless scanning must be scheduled to run on each virtual machine. What should you recommend using? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 77
Show Answer
Correct Answer: Just-in-time (JIT) VM access The Microsoft Defender for Cloud integrated Qualys vulnerability scanner
Explanation:
JIT VM access requires administrators to request RDP access via the Azure portal and allows setting a maximum access duration (e.g., three hours). Defender for Cloud’s integrated Qualys vulnerability scanner supports scheduled, agentless vulnerability scanning for VMs under Defender for Servers Plan 2.

Question 78

HOTSPOT - You have the Azure subscriptions shown in the following table. The tenants contain the groups shown in the following table. You perform the flowing actions: • Configure multi-user authorization (MUA) for Vault1 by using a resource guard deployed to Sub2. • Enable all available MUA controls for Vault1. • In contoso.com, create a Privileged Identity Management (PIM) assignment named Assignment1. • Configure Assignment1 to enable Group1 to activate the Contributor role for Vault1. For each of the following statements, select Yes if the statements is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 78 Illustration for SC-100 question 78 Illustration for SC-100 question 78
Show Answer
Correct Answer: No Yes No
Explanation:
• MUA resource guards can be deployed in a different subscription/tenant than the vault, so Sub1 is not required. • With all MUA controls enabled, protected operations (such as backup policy changes) require approval from security admins (Group2). • Disabling soft delete is an MUA-protected operation and still requires approval from Group2, even if Group1 activates the Contributor role via PIM.

Question 79

HOTSPOT - You have an Azure subscription that contains 100 virtual machines. The virtual machines are accessed by using Azure Bastion. You need to recommend a solution to ensure that only specific users in specific locations can access the virtual machines. The solution must meet the following requirements: • Restrict access to the virtual machines based on an originating IP address or a connection request by using just-in-time (JIT) VM access network-based controls. • Restrict access to the virtual machines based on role-based access control (RBAC) role assignments by using JIT VM access authorization controls. Which Microsoft cloud services should you include in the recommendation? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 79
Show Answer
Correct Answer: For the network controls: Microsoft Defender for Cloud For the authorization controls: Microsoft Entra Privileged Identity Management (PIM)
Explanation:
Just-in-time (JIT) VM access network-based controls are provided by Microsoft Defender for Cloud. JIT authorization using RBAC role assignments is handled through Microsoft Entra Privileged Identity Management (PIM), which controls eligible and time-bound role activation.

Question 80

HOTSPOT - You have an Azure subscription. You plan to deploy a storage account named storage1 that will store confidential data. You will assign tags to the confidential data. You need to ensure that access to storage1 can be defined by using the assigned tags. Which authorization mechanism should you enable, and which type of resource should you use to store the data? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 80
Show Answer
Correct Answer: Authorization mechanism: Attribute-based access control (ABAC) Resource type: Blob
Explanation:
Azure supports using ABAC conditions with Azure RBAC to control access based on attributes such as blob index tags. Blob storage supports blob index tags, enabling tag-based authorization for confidential data.

Question 81

You have an Azure subscription. You plan to deploy Azure Kubernetes Service (AKS) clusters that will be used to host web services. You need to recommend an ingress controller solution that will protect the hosted web services. What should you include in the recommendation?

A. Azure Load Balancer
B. Azure Application Gateway
C. Azure Front Door
D. Azure Firewall
Show Answer
Correct Answer: B
Explanation:
Azure Application Gateway is the appropriate ingress controller solution for AKS when you need to protect web services. It provides Layer 7 (HTTP/HTTPS) load balancing, SSL termination, Web Application Firewall (WAF) capabilities, and integrates directly with AKS via the Application Gateway Ingress Controller. The other options either operate at Layer 4 only (Azure Load Balancer), are global edge routing services rather than Kubernetes ingress controllers (Azure Front Door), or are network security appliances not designed for HTTP ingress into AKS (Azure Firewall).

$19

Get all 316 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.