Microsoft

SC-100 Free Practice Questions — Page 16

Question 137

You have on-premises Windows 11 devices that have the Global Secure Access client deployed. You have a Microsoft 365 subscription that uses Microsoft SharePoint Online and Exchange Online. You deploy Microsoft Entra Internet Access from the on-premises network to Microsoft 365. The deployment has the Microsoft 365 profile enabled and contains the following: • Default traffic policies for Microsoft 365 services • A linked Conditional Access policy that performs compliant network checks with continuous access evaluation and is applied to all users • An assignment to all the devices • An assignment to a remote network associated with the on-premises network Which Microsoft 365 resources are protected by using continuous access evaluation?

A. SharePoint Online only
B. Exchange Online only
C. both SharePoint Online and Exchange Online
Show Answer
Correct Answer: C
Explanation:
Continuous Access Evaluation (CAE) is supported for both SharePoint Online and Exchange Online. With Microsoft Entra Internet Access using the Microsoft 365 profile and a linked Conditional Access policy enforcing compliant network checks with CAE, access to both SharePoint Online and Exchange Online is continuously evaluated and protected.

Question 138

HOTSPOT - You have an Azure subscription that contains multiple Azure Storage blobs and Azure Files shares. You need to recommend a security solution for authorizing access to the blobs and shares. The solution must meet the following requirements: • Support access to the shares by using the SMB protocol. • Limit access to the blobs to specific periods of time. • Include authentication support when possible. What should you recommend for each resource? To answer, select the options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 138
Show Answer
Correct Answer: Blobs: User delegation shared access signatures (SAS) Shares: Microsoft Entra Domain Services
Explanation:
User delegation SAS provides time-limited, identity-based access to Azure Blob data using Microsoft Entra ID. Azure Files access over SMB requires directory-based authentication, which is supported by Microsoft Entra Domain Services.

Question 141

HOTSPOT - Case Study - This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided. To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other question in this case study. At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section. To start the case study - To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question. Overview - Litware, Inc. is a financial services company that has main offices in New York and San Francisco. Litware has 30 branch offices and remote employees across the United States. The remote employees connect to the main offices by using a VPN. Litware has grown significantly during the last two years due to mergers and acquisitions. The acquisitions include several companies based in France. Existing Environment - Litware has a Microsoft Entra tenant that syncs with an Active Directory Domain Services (AD DS) forest named litware.com and is linked to 20 Azure subscriptions. Microsoft Entra Connect is used to implement pass-through authentication. Password hash synchronization is disabled, and password writeback is enabled. All Litware users have Microsoft 365 E5 licenses. The environment also includes several AD DS forests, Microsoft Entra tenants, and hundreds of Azure subscriptions that belong to the subsidiaries of Litware. Requirements. Planned Changes - Litware plans to implement the following changes: • Create a management group hierarchy for each Microsoft Entra tenant. • Design a landing zone strategy to refactor the existing Azure environment of Litware and deploy all future Azure workloads. • Implement Microsoft Entra Application Proxy to provide secure access to internal applications that are currently accessed by using the VPN. Requirements. Business Requirements Litware identifies the following business requirements: • Minimize any additional on-premises infrastructure. • Minimize the operational costs associated with administrative overhead. Requirements. Hybrid Requirements Litware identifies the following hybrid cloud requirements: • Enable the management of on-premises resources from Azure, including the following: o Use Azure Policy for enforcement and compliance evaluation. o Provide change tracking and asset inventory. o Implement patch management. • Provide centralized, cross-tenant subscription management without the overhead of maintaining guest accounts. Requirements. Microsoft Sentinel Requirements Litware plans to leverage the security information and event management (SIEM) and security orchestration automated response (SOAR) capabilities of Microsoft Sentinel. The company wants to centralize Security Operations Center (SOC) by using Microsoft Sentinel. Requirements. Identity Requirements Litware identifies the following identity requirements: • Detect brute force attacks that directly target AD DS user accounts. • Implement leaked credential detection in the Microsoft Entra tenant of Litware. • Prevent AD DS user accounts from being locked out by brute force attacks that target Microsoft Entra user accounts. • Implement delegated management of users and groups in the Microsoft Entra tenant of Litware, including support for: o The management of group properties, membership, and licensing o The management of user properties, passwords, and licensing o The delegation of user management based on business units Requirements. Regulatory Compliance Requirements Litware identifies the following regulatory compliance requirements: • Ensure data residency compliance when collecting logs, telemetry, and data owned by each United States- and France-based subsidiary. • Leverage built-in Azure Policy definitions to evaluate regulatory compliance across the entire managed environment. • Use the principle of least privilege. Requirements. Azure Landing Zone Requirements Litware identifies the following landing zone requirements: • Route all internet-bound traffic from landing zones through Azure Firewall in a dedicated Azure subscription. • Provide a secure score scoped to the landing zone. • Ensure that the Azure virtual machines in each landing zone communicate with Azure App Service web apps in the same zone over the Microsoft backbone network, rather than over public endpoints. • Minimize the possibility of data exfiltration. • Maximize network bandwidth. The landing zone architecture will include the dedicated subscription, which will serve as the hub for internet and hybrid connectivity. Each landing zone will have the following characteristics: • Be created in a dedicated subscription. • Use a DNS namespace of litware.com. Requirements. Application Security Requirements Litware identifies the following application security requirements: • Identify internal applications that will support single sign-on (SSO) by using Microsoft Entra Application Proxy. • Monitor and control access to Microsoft SharePoint Online and Exchange Online data in real time. You need to recommend a multi-tenant and hybrid security solution that meets to the business requirements and the hybrid requirements. What should you recommend? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 141
Show Answer
Correct Answer: Azure Lighthouse Azure Arc
Explanation:
Azure Lighthouse enables centralized, cross-tenant subscription and resource management without requiring guest accounts, minimizing administrative overhead. Azure Arc extends Azure management capabilities to on-premises resources, enabling Azure Policy, inventory, change tracking, and patch management from Azure.

Question 142

HOTSPOT - You are designing a privileged access strategy for a company named Contoso, Ltd. and its partner company named Fabrikam, Inc. Contoso has an Azure AD tenant named contoso.com. Fabrikam has an Azure AD tenant named fabrikam.com. Users at Fabrikam must access the resources in contoso.com. You need to provide the Fabrikam users with access to the Contoso resources by using access packages. The solution must meet the following requirements: • Ensure that the Fabrikam users can use the Contoso access packages without explicitly creating guest accounts in contoso.com. • Allow non-administrative users in contoso.com to create the access packages. What should you use for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 142
Show Answer
Correct Answer: A connected organization Catalogs
Explanation:
A connected organization lets external users from another Azure AD tenant access access packages without pre-creating guest accounts. Delegating access package creation to non-admin users is done by assigning them as catalog owners or contributors within catalogs.

Question 143

DRAG DROP - You have a Microsoft 365 subscription. You need to recommend a security solution to monitor the following activities: • User accounts that were potentially compromised • Users performing bulk file downloads from Microsoft SharePoint Online What should you include in the recommendation for each activity? To answer, drag the appropriate components to the correct activities. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 143
Show Answer
Correct Answer: User accounts that were potentially compromised: Azure AD Identity Protection Users performing bulk file downloads from SharePoint Online: Microsoft Defender for Cloud Apps
Explanation:
Azure AD Identity Protection detects and reports risky sign-ins and compromised identities. Microsoft Defender for Cloud Apps provides activity monitoring and threat detection, including alerts for mass or bulk file downloads in SharePoint Online.

Question 144

You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled. The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019. You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application. Which security control should you recommend?

A. app discovery anomaly detection policies in Microsoft Defender for Cloud Apps
B. Azure Security Benchmark compliance controls in Defender for Cloud
C. app registrations in Azure AD
D. application control policies in Microsoft Defender for Endpoint
Show Answer
Correct Answer: D
Explanation:
The requirement is to allow only authorized applications to run on Windows Server virtual machines and to automatically block unauthorized apps until approved. Application control policies in Microsoft Defender for Endpoint (based on Windows Defender Application Control) provide allow/deny controls, enforcement mode, and centralized management to block unapproved applications by default. The other options do not enforce runtime application blocking on VMs.

Question 145

You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled. The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019. You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application. Which security control should you recommend?

A. app registrations in Azure AD
B. Azure AD Conditional Access App Control policies
C. app discovery anomaly detection policies in Microsoft Defender for Cloud Apps
D. adaptive application controls in Defender for Cloud
Show Answer
Correct Answer: D
Explanation:
Adaptive application controls in Microsoft Defender for Cloud are designed to allow only approved applications to run on virtual machines. They build an allow list based on observed, known-good applications and automatically block unauthorized or unknown applications from executing until an administrator explicitly approves them. This directly meets the requirement to prevent unauthorized applications from running or being installed on Windows Server VMs.

Question 146

HOTSPOT - You plan to automate the development and deployment of a Node.js-based app by using GitHub. You need to recommend a DevSecOps solution for the app. The solution must meet the following requirements: • Automate the generation of pull requests that remediate identified vulnerabilities. • Automate vulnerability code scanning for public and private repositories. • Minimize administrative effort. • Minimize costs. What should you recommend using? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 146
Show Answer
Correct Answer: GitHub Enterprise Cloud Dependabot
Explanation:
GitHub Enterprise Cloud provides built-in automated code scanning for public and private repositories with minimal administration. Dependabot automatically detects vulnerable dependencies and creates pull requests to remediate them at low cost.

Question 147

HOTSPOT - You have an on-premises datacenter named Site1. You have an Azure subscription that contains a virtual network named VNet1 and multiple Azure App Service apps. Site1 is connected to VNet1 by using a Site-to-Site (P2S) VPN connection. The apps are accessed by using public internet connections. You need to recommend a solution for providing secure access to the apps. The solution must meet the following requirements: • Servers on Site1 must use a VPN connection to access the apps. • Access to the apps must be restricted to specific servers on Site1. • Security administrators for VNet1 must be able to control which servers can access the apps. • Costs must be minimized. What should you include in the recommendation? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 147
Show Answer
Correct Answer: Private endpoints App Service static IP address restrictions
Explanation:
Private endpoints allow on-premises servers to access App Service apps privately over the Site-to-Site VPN, without using the public internet and at low cost. App Service static IP address restrictions let administrators explicitly allow only specific source IP addresses (the on-premises servers), providing precise access control without additional infrastructure.

Question 149

You have an on-premises datacenter and an Azure Kubernetes Service (AKS) cluster named AKS1. You need to restrict internet access to the public endpoint of AKS1. The solution must ensure that AKS1 can be accessed only from the public IP addresses associated with the on-premises datacenter. What should you use?

A. a private endpoint
B. a network security group (NSG)
C. a service endpoint
D. an authorized IP range
Show Answer
Correct Answer: D
Explanation:
AKS exposes its control plane via a public API server endpoint. To restrict access so that only specific public IP addresses (such as those from an on-premises datacenter) can reach it, you configure API server authorized IP ranges. NSGs and service endpoints do not protect the managed AKS control plane endpoint, and a private endpoint would eliminate public access rather than restrict it to specific public IPs.

$19

Get all 316 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.