Microsoft

SC-100 Free Practice Questions — Page 16

Question 158

HOTSPOT - You have an Azure subscription that contains multiple apps. The apps are managed by using continuous integration and continuous deployment (CCD) pipelines in Azure DevOps. You need to recommend DevSecOps controls for the Commit the code and the Build and test CI/CD process stages based on the Microsoft Cloud Adoption Framework for Azure. Which testing method should you recommend for each stage? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 158
Show Answer
Correct Answer: Commit the code: Static application security testing (SAST) Build and test: Dynamic application security testing (DAST)
Explanation:
SAST analyzes source code early during code commit/CI, while DAST tests the running application during the build/test stage. Penetration and smoke testing are not the primary DevSecOps controls for these stages in the Cloud Adoption Framework.

Question 159

Your on-premises network contains an Active Directory Domain Services (AD DS) domain and a hybrid deployment between a Microsoft Exchange Server 2019 organization and an Exchange Online tenant. The AD DS domain contains a group named Group1. Group1 is a member of the Organization Management role group for the Exchange deployment. You have a Microsoft 365 E5 subscription that uses Microsoft Defender. You have an Azure subscription that uses Microsoft Sentinel. You need to recommend a solution to ensure that Group1 is marked as a sensitive group and that any changes made to Group1 raises an alert in Microsoft Sentinel. The solution must minimize administrative effort. What should you include in the recommendation?

A. Microsoft Defender for Identity
B. Microsoft Entra ID Protection
C. Microsoft Entra Privileged Identity Management (PIM)
D. Microsoft Defender for Office 365
Show Answer
Correct Answer: A
Explanation:
Microsoft Defender for Identity allows you to mark Active Directory groups as sensitive accounts/groups and monitors changes to those groups. It integrates with Microsoft Sentinel so modifications to sensitive groups can generate alerts with minimal administrative effort. Entra ID Protection focuses on identity risk, PIM manages privileged role activation, and Defender for Office 365 protects email and collaboration workloads.

Question 161

You have on-premises Windows 11 devices that have the Global Secure Access client deployed. You have a Microsoft 365 subscription that uses Microsoft SharePoint Online and Exchange Online. You deploy Microsoft Entra Internet Access from the on-premises network to Microsoft 365. The deployment has the Microsoft 365 profile enabled and contains the following: • Default traffic policies for Microsoft 365 services • A linked Conditional Access policy that performs compliant network checks with continuous access evaluation and is applied to all users • An assignment to all the devices • An assignment to a remote network associated with the on-premises network Which Microsoft 365 resources are protected by using continuous access evaluation?

A. SharePoint Online only
B. Exchange Online only
C. both SharePoint Online and Exchange Online
Show Answer
Correct Answer: C
Explanation:
Continuous Access Evaluation (CAE) is supported by both Microsoft Exchange Online and SharePoint Online (including OneDrive). When Microsoft Entra Internet Access is deployed with a linked Conditional Access policy performing compliant network checks with CAE, both Exchange Online and SharePoint Online can enforce CAE-based access decisions.

Question 162

HOTSPOT - You have an Azure subscription that contains multiple Azure Storage blobs and Azure Files shares. You need to recommend a security solution for authorizing access to the blobs and shares. The solution must meet the following requirements: • Support access to the shares by using the SMB protocol. • Limit access to the blobs to specific periods of time. • Include authentication support when possible. What should you recommend for each resource? To answer, select the options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 162
Show Answer
Correct Answer: Blobs: User delegation shared access signatures (SAS) Shares: Microsoft Entra Domain Services
Explanation:
User delegation SAS provides time-limited access to Azure Blob Storage using Microsoft Entra authentication when possible. Azure Files over SMB supports identity-based authentication through Microsoft Entra Domain Services.

Question 165

HOTSPOT - Case Study - This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided. To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other question in this case study. At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section. To start the case study - To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question. Overview - Litware, Inc. is a financial services company that has main offices in New York and San Francisco. Litware has 30 branch offices and remote employees across the United States. The remote employees connect to the main offices by using a VPN. Litware has grown significantly during the last two years due to mergers and acquisitions. The acquisitions include several companies based in France. Existing Environment - Litware has a Microsoft Entra tenant that syncs with an Active Directory Domain Services (AD DS) forest named litware.com and is linked to 20 Azure subscriptions. Microsoft Entra Connect is used to implement pass-through authentication. Password hash synchronization is disabled, and password writeback is enabled. All Litware users have Microsoft 365 E5 licenses. The environment also includes several AD DS forests, Microsoft Entra tenants, and hundreds of Azure subscriptions that belong to the subsidiaries of Litware. Requirements. Planned Changes - Litware plans to implement the following changes: • Create a management group hierarchy for each Microsoft Entra tenant. • Design a landing zone strategy to refactor the existing Azure environment of Litware and deploy all future Azure workloads. • Implement Microsoft Entra Application Proxy to provide secure access to internal applications that are currently accessed by using the VPN. Requirements. Business Requirements Litware identifies the following business requirements: • Minimize any additional on-premises infrastructure. • Minimize the operational costs associated with administrative overhead. Requirements. Hybrid Requirements Litware identifies the following hybrid cloud requirements: • Enable the management of on-premises resources from Azure, including the following: o Use Azure Policy for enforcement and compliance evaluation. o Provide change tracking and asset inventory. o Implement patch management. • Provide centralized, cross-tenant subscription management without the overhead of maintaining guest accounts. Requirements. Microsoft Sentinel Requirements Litware plans to leverage the security information and event management (SIEM) and security orchestration automated response (SOAR) capabilities of Microsoft Sentinel. The company wants to centralize Security Operations Center (SOC) by using Microsoft Sentinel. Requirements. Identity Requirements Litware identifies the following identity requirements: • Detect brute force attacks that directly target AD DS user accounts. • Implement leaked credential detection in the Microsoft Entra tenant of Litware. • Prevent AD DS user accounts from being locked out by brute force attacks that target Microsoft Entra user accounts. • Implement delegated management of users and groups in the Microsoft Entra tenant of Litware, including support for: o The management of group properties, membership, and licensing o The management of user properties, passwords, and licensing o The delegation of user management based on business units Requirements. Regulatory Compliance Requirements Litware identifies the following regulatory compliance requirements: • Ensure data residency compliance when collecting logs, telemetry, and data owned by each United States- and France-based subsidiary. • Leverage built-in Azure Policy definitions to evaluate regulatory compliance across the entire managed environment. • Use the principle of least privilege. Requirements. Azure Landing Zone Requirements Litware identifies the following landing zone requirements: • Route all internet-bound traffic from landing zones through Azure Firewall in a dedicated Azure subscription. • Provide a secure score scoped to the landing zone. • Ensure that the Azure virtual machines in each landing zone communicate with Azure App Service web apps in the same zone over the Microsoft backbone network, rather than over public endpoints. • Minimize the possibility of data exfiltration. • Maximize network bandwidth. The landing zone architecture will include the dedicated subscription, which will serve as the hub for internet and hybrid connectivity. Each landing zone will have the following characteristics: • Be created in a dedicated subscription. • Use a DNS namespace of litware.com. Requirements. Application Security Requirements Litware identifies the following application security requirements: • Identify internal applications that will support single sign-on (SSO) by using Microsoft Entra Application Proxy. • Monitor and control access to Microsoft SharePoint Online and Exchange Online data in real time. You need to recommend a multi-tenant and hybrid security solution that meets to the business requirements and the hybrid requirements. What should you recommend? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 165
Show Answer
Correct Answer: To centralize subscription management: Azure Lighthouse To enable the management of on-premises resources: Azure Arc
Explanation:
Azure Lighthouse provides centralized cross-tenant Azure subscription management without requiring guest accounts. Azure Arc extends Azure management to on-premises resources, enabling Azure Policy, change tracking, inventory, and patch management.

Question 166

HOTSPOT - You are designing a privileged access strategy for a company named Contoso, Ltd. and its partner company named Fabrikam, Inc. Contoso has an Azure AD tenant named contoso.com. Fabrikam has an Azure AD tenant named fabrikam.com. Users at Fabrikam must access the resources in contoso.com. You need to provide the Fabrikam users with access to the Contoso resources by using access packages. The solution must meet the following requirements: • Ensure that the Fabrikam users can use the Contoso access packages without explicitly creating guest accounts in contoso.com. • Allow non-administrative users in contoso.com to create the access packages. What should you use for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 166
Show Answer
Correct Answer: A connected organization Catalogs
Explanation:
A connected organization lets external users from another Entra tenant request access packages without pre-creating guest accounts; guest accounts are created automatically when needed. Catalogs support delegated administration, allowing non-admin users assigned as catalog creators/owners to create and manage access packages.

Question 167

DRAG DROP - You have a Microsoft 365 subscription. You need to recommend a security solution to monitor the following activities: • User accounts that were potentially compromised • Users performing bulk file downloads from Microsoft SharePoint Online What should you include in the recommendation for each activity? To answer, drag the appropriate components to the correct activities. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 167
Show Answer
Correct Answer: User accounts that were potentially compromised: Azure AD Identity Protection Users performing bulk file downloads from SharePoint Online: Microsoft Defender for Cloud Apps
Explanation:
Azure AD Identity Protection detects and reports risky users and sign-ins that indicate potential account compromise. Microsoft Defender for Cloud Apps can detect anomalous behaviors such as mass downloads from SharePoint Online using activity policies.

Question 168

You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled. The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019. You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application. Which security control should you recommend?

A. app discovery anomaly detection policies in Microsoft Defender for Cloud Apps
B. Azure Security Benchmark compliance controls in Defender for Cloud
C. app registrations in Azure AD
D. application control policies in Microsoft Defender for Endpoint
Show Answer
Correct Answer: D
Explanation:
Application control policies in Microsoft Defender for Endpoint (using Microsoft Defender Application Control/Windows Defender Application Control) allow only authorized applications to run. Unauthorized applications are automatically blocked until they are explicitly allowed by an administrator. The other options do not provide application allowlisting and enforcement on Windows Server virtual machines.

Question 170

HOTSPOT - You plan to automate the development and deployment of a Node.js-based app by using GitHub. You need to recommend a DevSecOps solution for the app. The solution must meet the following requirements: • Automate the generation of pull requests that remediate identified vulnerabilities. • Automate vulnerability code scanning for public and private repositories. • Minimize administrative effort. • Minimize costs. What should you recommend using? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 170
Show Answer
Correct Answer: To automate vulnerability code scanning: GitHub Enterprise Cloud To automatically generate pull requests: Dependabot
Explanation:
GitHub Enterprise Cloud provides built-in code scanning for public and private repositories. Dependabot automatically creates pull requests to remediate vulnerable dependencies, minimizing administration and cost.

Question 171

HOTSPOT - You have an on-premises datacenter named Site1. You have an Azure subscription that contains a virtual network named VNet1 and multiple Azure App Service apps. Site1 is connected to VNet1 by using a Site-to-Site (P2S) VPN connection. The apps are accessed by using public internet connections. You need to recommend a solution for providing secure access to the apps. The solution must meet the following requirements: • Servers on Site1 must use a VPN connection to access the apps. • Access to the apps must be restricted to specific servers on Site1. • Security administrators for VNet1 must be able to control which servers can access the apps. • Costs must be minimized. What should you include in the recommendation? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-100 question 171
Show Answer
Correct Answer: Provide access: Private endpoints Enable access control: App Service static IP address restrictions
Explanation:
Private Endpoints let on-premises servers reach App Service privately over the VPN via Azure Private Link. To restrict access to only specific Site1 servers at low cost, use App Service IP access restrictions to allow only the required source IP addresses.

$19

Get all 314 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.