Microsoft

SC-100 Free Practice Questions — Page 13

Question 104

HOTSPOT - You have a Microsoft Entra tenant that is linked to a Microsoft 365 subscription and an Azure subscription. The tenant contains service principals that are used to access applications in the Azure subscription. You need to recommend a solution to detect risky sign-ins and other risky activities performed by the service principals in the tenant. The solution must minimize costs. What should you include in the recommendation? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 104
Show Answer
Correct Answer: Service: Microsoft Entra ID Protection License type: Microsoft Entra Workload ID Premium
Explanation:
Risk detection for service principals (workload identities) is provided by Microsoft Entra ID Protection. Viewing risky workload identity detections requires the Entra Workload ID Premium license, which is the minimum and most cost‑effective option for this scenario.

Question 105

You have an on-premises network that has several legacy applications. The applications perform LDAP queries against an existing directory service. You are migrating the on-premises infrastructure to a cloud-only infrastructure. You need to recommend an identity solution for the infrastructure that supports the legacy applications. The solution must minimize the administrative effort to maintain the infrastructure. Which identity service should you include in the recommendation?

A. Microsoft Entra External ID
B. Microsoft Entra Domain Services
C. Microsoft Entra ID
D. Active Directory Domain Services (AD DS)
Show Answer
Correct Answer: B
Explanation:
Legacy applications require LDAP queries. Microsoft Entra ID alone does not provide LDAP, and Entra External ID is for customer identities. Running full AD DS would increase administrative overhead. Microsoft Entra Domain Services provides managed LDAP, Kerberos, and NTLM in the cloud without deploying or maintaining domain controllers, meeting the requirement while minimizing admin effort.

Question 106

You have an Azure subscription that contains 100 virtual machines, a virtual network named VNet1, and 20 users. The virtual machines run Windows Server and are connected to VNet1. The users work remotely and access Azure resources from Linux workstations. You need to ensure that the users can connect to the virtual machines from the workstations by using Secure Shell (SSH). The solution must meet the following requirements: • Ensure that the users authenticate by using their Microsoft Entra credentials. • Prevent the users from transferring files from the virtual machines by using SSH. • Prevent the users from directly accessing the virtual machines by using the public IP address of the virtual machines. What should you include in the solution?

A. Azure NAT Gateway
B. just-in-time (JIT) VM access
C. Azure Bastion
D. Point-to-Site (P2S) VPN
Show Answer
Correct Answer: C
Explanation:
Azure Bastion allows users to connect to Azure VMs using SSH through the Azure portal or native client while authenticating with Microsoft Entra ID. It eliminates the need for public IP access to the virtual machines, as connections are made over the Azure backbone. Bastion also restricts capabilities such as SSH port forwarding and file transfer when configured appropriately, meeting the requirement to prevent file transfers. Other options do not satisfy all requirements simultaneously.

Question 107

You have an on-premises app named App1. Remote users access App1 by using VPN connections. You have a third-party software as a service (SaaS) app named App2. You need to deploy Global Secure Access to manage access to App1 and App2. What should you use for each app?

A. Microsoft Entra Private Access for App2 and Microsoft Entra Internet Access for App1
B. Microsoft Entra Private Access for App1 and Microsoft Entra Internet Access for App2
C. Microsoft Entra Internet Access for App1 and App2
D. Microsoft Entra Private Access for App1 and App2
Show Answer
Correct Answer: B
Explanation:
App1 is an on-premises application currently accessed via VPN, which aligns with Microsoft Entra Private Access in Global Secure Access for private, internal resources without traditional VPNs. App2 is a third-party SaaS application accessed over the internet, which is managed using Microsoft Entra Internet Access to secure and control outbound internet and SaaS access.

Question 108

You have a Microsoft 365 tenant that uses Microsoft SharePoint Online and Microsoft Purview. Microsoft Purview has a sensitivity label named Label1 that is applied to the files stored on SharePoint Online sites. You need to recommend a Microsoft Purview Data Loss Prevention (DLP) policy that meets the following requirements: • Prevents users from uploading the files to third-party external websites • Allows users to upload the files to Microsoft OneDrive for Business To which location should you apply the DLP policy?

A. Devices
B. OneDrive accounts
C. SharePoint sites
D. Microsoft Defender for Cloud Apps
Show Answer
Correct Answer: A
Explanation:
To block uploads of labeled SharePoint files to third‑party external websites while still allowing uploads to OneDrive for Business, the DLP policy must control data leaving the endpoint to web destinations. This capability is provided by Endpoint DLP, which is configured under the **Devices** location in Microsoft Purview. SharePoint or OneDrive locations only govern data within those services, and Microsoft Defender for Cloud Apps is not a selectable DLP policy location.

Question 109

You have a Microsoft Entra tenant named contoso.com and use Microsoft Intune. Each user in contoso.com has a Microsoft Entra ID P1 license and a Windows 11 device that has the Global Secure Access client deployed. You plan to deploy the following configuration of Microsoft Entra Internet Access: • Enable a baseline profile. • Create a security profile named Profile1 that has a priority of 300 and contains a single web content filtering policy named WCFPolicy1. Configure WCFPolicy1 as follows: o Set Action to allow. o Include a single rule that has a fully qualified domain name (FQDN) destination of *.adatum.com. • Link Profile1 to a Conditional Access policy named CAPolicy1, apply CAPolicy1 to all users, and grant access unless a user's device is noncompliant. You need to evaluate the impact of the planned deployment on traffic to the following resources: • https://www.adatum.com:8433 • https://www.fabrikam.com Which two traffic scenarios will occur? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

A. Traffic to https://www.fabrikam.com will be allowed from all the devices.
B. Traffic to https://www.adatum.com:8433 will be blocked from all the devices.
C. Traffic to https://www.adatum.com:8433 will be allowed from all the devices.
D. Traffic to https://www.fabrikam.com will be allowed from compliant devices only.
E. Traffic to https://www.adatum.com:8433 will be allowed from compliant devices only.
F. Traffic to https://www.fabrikam.com will be blocked from noncompliant devices only.
Show Answer
Correct Answer: D, E
Explanation:
The baseline Internet Access profile is enabled and Profile1 is linked to a Conditional Access policy that grants access only if the device is compliant. Traffic that matches Internet Access processing is therefore subject to device compliance. • The web content filtering rule explicitly allows the FQDN *.adatum.com, which matches https://www.adatum.com regardless of the port number. Because access is gated by the linked Conditional Access policy, this traffic is allowed only from compliant devices. • There is no explicit allow rule for fabrikam.com. With the baseline profile enabled and the Conditional Access policy applied to all users, access is still evaluated through Internet Access and granted only when the device is compliant. Noncompliant devices are denied. Therefore, both URLs are accessible only from compliant devices.

Question 110

You have a Microsoft 365 subscription that contains 1,000 Microsoft Exchange Online mailboxes. Incoming email from the internet is scanned for security threats by using a third-party cloud service. You are evaluating whether to replace the third-party service with Microsoft Defender for Office 365. What should you modify to ensure that all the incoming email is scanned by Defender for Office 365 only?

A. the accepted domains in Exchange Online
B. the DNS records
C. the Exchange Online transport rule
D. the Exchange Online connectors
Show Answer
Correct Answer: B
Explanation:
To ensure all inbound internet email is scanned only by Microsoft Defender for Office 365, mail must be delivered directly to Exchange Online. This is controlled by the MX DNS records. If the MX records still point to a third-party filtering service, that service will always receive and scan the mail first. Exchange Online connectors and transport rules only affect mail after it reaches Exchange Online and cannot prevent prior third‑party scanning. Therefore, modifying the DNS (MX) records is required.

Question 111

You have an Azure subscription that contains multiple network security groups (NSGs), multiple virtual machines, and an Azure Bastion host named bastion1. Several NSGs contain rules that allow direct RDP access to the virtual machines by bypassing bastion1. You need to ensure that the virtual machines can be accessed only by using bastion1. The solution must prevent the use of NSG rules to bypass bastion1. What should you include in the solution?

A. Azure Virtual Network Manager security admin rules
B. Azure Virtual Network Manager connectivity configurations
C. Azure Firewall application rules
D. Azure Firewall network rules
Show Answer
Correct Answer: A
Explanation:
Azure Virtual Network Manager (AVNM) security admin rules have higher priority than NSG rules and cannot be overridden by them. By using security admin rules, you can centrally deny direct RDP access to virtual machines and allow access only via Azure Bastion. This directly prevents any NSG from being configured to bypass bastion1. Connectivity configurations and Azure Firewall rules do not inherently prevent NSG-based bypass, and Azure Firewall is not mentioned as part of the existing environment.

Question 112

You have a Microsoft Entra tenant named contoso.com. You have an external partner that has a Microsoft Entra tenant named fabnkam.com. You need to recommend an identity governance solution for contoso.com that meets the following requirements: • Enables the users in contoso.com and fabrikam.com to communicate by using shared Microsoft Teams channels • Manages access to shared Teams channels in contoso.com by using groups in fabrikam.com • Supports single sign-on (SSO) • Minimizes administrative effort • Maximizes security What should you include in the recommendation?

A. Cross-tenant synchronization
B. Microsoft Entra B2B collaboration
C. B2B direct connect
D. Microsoft Entra Connect Sync
Show Answer
Correct Answer: C
Explanation:
B2B direct connect is designed specifically for Microsoft Teams shared channels between separate Microsoft Entra tenants. It allows users from fabrikam.com to access shared channels in contoso.com using their home tenant identities, providing true single sign-on without creating guest accounts. It supports managing access via the external tenant’s groups, minimizes administrative overhead compared to guest lifecycle management, and maximizes security through cross-tenant access policies and mutual trust. B2B collaboration relies on guest users and doesn’t natively meet the group-based access and SSO requirements as cleanly for shared channels.

Question 114

Your on-premises network contains an Active Directory Domain Services (AD DS) domain named corp.contoso.com and an AD DS-integrated application named App1. Your perimeter network contains a server named Server1that runs Windows Server. You have a Microsoft Entra tenant named contoso.com that syncs with corp.contoso.com. You plan to implement a security solution that will include the following configurations: • Manage access to App1 by using Microsoft Entra Private Access. • Deploy a Microsoft Entra application proxy connector to Server1. • Implement single sign-on (SSO) for App1 by using Kerberos constrained delegation. • For Server1, configure the following rules in Windows Defender Firewall with Advanced Security: o Rule1: Allow TCP 443 inbound from a designated set of Azure URLs, o Rule2: Allow TCP 443 outbound to a designated set of Azure URLs, o Rule3: Allow TCP 80 outbound to a designated set of Azure URLs, o Rule4: Allow TCP 389 outbound to the domain controllers on corp.contoso.com. You need to maximize security for the planned implementation. The solution must minimize the impact on the connector. Which rule should you remove?

A. Rule1
B. Rule2
C. Rule3
D. Rule4
Show Answer
Correct Answer: A
Explanation:
Microsoft Entra Private Access/Application Proxy connectors are outbound-only agents. They initiate outbound connections to Azure over TCP 443 (and TCP 80 for certificate/CRL checks) and do not require any inbound connectivity. Allowing inbound TCP 443 to Server1 provides no functional benefit and increases attack surface. Removing Rule1 maximizes security while having no negative impact on the connector.

$19

Get all 316 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.