Browse all practice questions for the Microsoft Certified: Microsoft Cybersecurity Architect Expert (SC-100) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Microsoft Cybersecurity Architect Expert Practice Test 2026 (SC-100) – Complete Exam Prep course image
Choose Microsoft Sentinel for Centralized Management of Security Incidents in Microsoft 365 E5What solution should be recommended for centralized management of security incidents across services in a Microsoft 365 E5 environment?Choosing the Best Security Solution for Temporary Employees in a Hybrid SetupFor an organization using a hybrid setup, which solution is optimal for securing access for temporary employees?Choosing the Right Solution for Remote Web App AccessWhich solution should be recommended for remote users needing access to internal web apps while ensuring security?Crafting a Winning Cybersecurity Strategy: The Essentials You NeedWhat are the main components of an effective cybersecurity strategy?Discover how Azure Arc streamlines hybrid cloud managementWhich tools can help organizations manage their hybrid cloud infrastructure effectively?Discover how Insider Risk Management protects against insider threatsWhich feature in Microsoft 365 helps in managing insider threats effectively?Discover Why Microsoft Viva Insights Is Key for Workplace Privacy ManagementWhat Microsoft tool should be recommended for enhancing privacy management in a workplace environment?Encryption is Key to Data Integrity – Let’s Break It DownWhich component is essential for achieving data integrity?Enhancing Backups to Safeguard Against Ransomware ThreatsWhich strategy can enhance the resiliency of the backup process to mitigate ransomware attacks on Azure Virtual Machines?Enhancing Identity Security with Azure AD Administrative UnitsWhat identity security solution is recommended for the Litware Azure AD tenant?Explore How Azure Logic Apps Can Automate Security Incident ResponsesWhat feature can be leveraged to automate responses to security incidents?Explore Key Recommendations for Enhancing Secure Management Port ControlsWhich recommendation could increase the score of Secure management ports controls by onboarding all virtual machines?Explore the Power of Microsoft Sentinel Workbooks for Security DashboardsWhat is the recommended solution in Microsoft Sentinel for creating custom views and dashboards for security events?Exploring Recommended Architecture for On-Premises SQL Server Migration to AzureWhat architecture is recommended for migrating on-premises SQL Server databases to Azure while ensuring security and low operational impact?Exploring the Effectiveness of Microsoft Defender for Containers in Vulnerability ScanningIn which environments can Microsoft Defender for Containers effectively scan for vulnerabilities?How Azure AD B2C Enhances Multi-Tenant SecurityFor a multi-tenant and hybrid security approach, which recommendation is most suitable?How Multi-Factor Authentication Revolutionizes User SecurityWhat does multi-factor authentication (MFA) enhance in cybersecurity?How to Add Watermarks to Email Attachments in Microsoft 365 E5What solution should be recommended for adding watermarks to email attachments containing sensitive data in Microsoft 365 E5?How to Enforce ISO 27001:2013 Standards for Azure with RBACWhat should you use to enforce ISO 27001:2013 standards for an Azure subscription with Microsoft Defender for Cloud enabled?How to Ensure Only Your Application Servers Access Azure Blob StorageWhich method should be recommended to ensure that only application servers can access Azure Blob Storage?How to Ensure Secure API Usage in Your OrganizationHow does an organization ensure secure API usage?How to Increase Secure Management Ports Controls Score in Azure Security Benchmark V3What should be done to increase the Secure management ports controls score in Azure Security Benchmark V3?How to Restrict User Connections to Azure AD Based on Geographic LocationWhat should be recommended to prevent users from specific countries from connecting to Azure AD custom enterprise applications?How to Secure Communication for Azure Applications in a Hybrid Cloud InfrastructureFor a hybrid cloud infrastructure, what should be used to secure communication for Azure applications?How to Secure Your Web App's Access Approval Process Using Azure ADWhat is an effective procedure to secure a web app's access requests approval process?How workload protections in Defender for Cloud guide alert triage with actionable remediation guidanceTo conduct alert triage effectively, which integration can provide actionable insights and suggestions for remediation?Kickstart Your Azure NIST 800-53 Compliance with Secure Score InsightsIn reviewing NIST 800-53 compliance for an Azure subscription, what is the first action to take?Learn How the Microsoft Security Compliance Toolkit Enhances Device SecurityWhat action can help improve the security posture of devices running Windows 10, Windows 11, or Windows Server?Phishing Defined: The Hidden Threat to Your CybersecurityWhat is Phishing?Protect sensitive information with SharePoint Online's key strategiesWhich two components should be included to protect confidential data in Microsoft SharePoint Online sites?Sending Security Events from Microsoft Sentinel to Splunk Made SimpleWhat is the recommended solution for sending security events from Microsoft Sentinel to Splunk?The Heart of Data Security: Why Encryption Is EssentialWhat is the primary goal of data encryption?The Importance of Configuring Secure Management Ports in AzureWhat does configuring secure management ports in Azure directly impact?The Vital Role of Threat Hunting in CybersecurityWhat is the role of threat hunting in cybersecurity?Third-Party Risk Management: The Key to Strengthening Cybersecurity PostureWhat aspect of cybersecurity can be improved through effective third-party risk management?Uncovering Hidden Threats: The Intriguing World of Threat HuntingWhat type of vulnerabilities does threat hunting aim to uncover?Understand how Azure Traffic Manager minimizes attack surface for web appsWhich of the following solutions minimizes the attack surface for Azure App Service web apps deployed in the West Europe region?Understanding Access Restrictions for Azure App Service Web AppsIs a recommendation for access restrictions using HTTP headers based on the Front Door ID adequate for Azure App Service web apps?Understanding Application Awareness in Firewalls for Cybersecurity ExpertsWhich of the following best describes application awareness in firewalls?Understanding Application Control for Windows 10 KiosksFor securing Windows 10 kiosks, which of the following solutions ensures that only authorized applications can run?Understanding Azure Active Directory Domain Services for Legacy Application MigrationWhat identity service should be recommended for legacy applications during a migration to a cloud-only infrastructure?Understanding Azure App Service Configuration for Enhanced SecurityWhat is a correct configuration to ensure Azure App Service web apps only allow access through Azure Front Door?Understanding Azure Arc for Hybrid Cloud Security StrategiesWhich Azure service helps organizations implement security policies for hybrid cloud environments?Understanding Azure Policy for Effective Compliance ManagementWhat Azure feature can be utilized for policy management to ensure compliance?Understanding Azure's Storage Workloads and Their Authentication FeaturesWhich two storage workloads in Azure support authentication via Azure Active Directory?Understanding Cloud Security Posture Management (CSPM)What does the term “cloud security posture management (CSPM)” refer to?Understanding Cloud Security: The Role of CSPM Tools in Managing RisksWhich of the following is a tool used for managing cloud security?Understanding Cyber Threat Actors and Their Impact on CybersecurityWhat is a cyber threat actor?Understanding Cyber Threats: Malware and BeyondWhich of the following is an example of a cyber threat?Understanding Cybersecurity Governance: The Key to Effective Risk ManagementWhich of the following is a core component of cybersecurity governance?Understanding Cybersecurity Integrity: Why It MattersWhat aspect of cybersecurity focuses on ensuring data is accurate and trustworthy?Understanding Data Masking: A Key Technique for Data ProtectionWhich technique is commonly used to protect sensitive data in databases?Understanding Firewalls and Their Role in Network SecurityWhat is the purpose of a firewall in a network?Understanding how Azure Key Vault Managed HSM Can Securely Manage Encryption KeysWhich Azure service should you recommend to manage encryption keys for cardholder data?Understanding How to Secure MedicalHistory Data in ClaimsDetail TablesHow can the MedicalHistory data in the ClaimsDetail table be secured?Understanding Incident Response in CybersecurityWhat is incident response in the context of cybersecurity?Understanding Insider Threats: The Hidden Security RisksWhat is an insider threat?Understanding Microsoft Defender for Cloud Apps and Its Role in Securing SharePoint Online and Exchange OnlineWhich services are essential to secure the SharePoint Online and Exchange Online data?Understanding Outbound Access Control with Azure Firewall in Multi-Cloud EnvironmentsWhat should be implemented to restrict outbound access from a Remote Desktop server in a multi-cloud environment?Understanding Phishing Attacks: The Art of ImpersonationWhat kind of attack involves impersonating a trustworthy entity?Understanding Ransomware and Its Impacts on CybersecurityWhat is the concept of ransomware?Understanding Regulatory Compliance within Azure EnvironmentsTo evaluate regulatory compliance across a managed environment, what solution is recommended?Understanding Role-Based Access Control in CybersecurityWhich security principle involves restricting user access based on their roles?Understanding Secure Remote Access for Azure Virtual MachinesWhich two actions should be included to provide secure remote access for administrators to virtual machines?Understanding the Benefits of Microsoft Defender for Cloud in Security ArchitectureWhat is a key benefit of using Microsoft Defender for Cloud in your security architecture?Understanding the Best Security Configurations for Azure AD B2C ApplicationsWhich two configurations are recommended for securing an application with Azure AD B2C?Understanding the CIA Triad: The Heart of CybersecurityWhat does the acronym CIA stand for in cybersecurity?Understanding the Cloud Security Model: Who’s Responsible for What?What cloud security model provides a shared responsibility between the client and the cloud provider?Understanding the Components of a Cybersecurity StrategyWhich component is NOT typically part of a cybersecurity strategy?Understanding the Core Objectives of Risk Management in CybersecurityWhat is one of the main objectives of risk management in cybersecurity?Understanding the Core of Incident Response PlansWhat is the primary goal of an incident response plan?Understanding the Core Principle of Zero-Trust ArchitectureWhat is a core principle of zero-trust architecture?Understanding the Core Purpose of a Web Application FirewallWhat is a primary purpose of a web application firewall?Understanding the Core Role of an Endpoint Protection PlatformWhat is the primary function of an endpoint protection platform (EPP)?Understanding the Critical Role of a Disaster Recovery Plan in CybersecurityWhat is the purpose of a Disaster Recovery Plan (DRP)?Understanding the Critical Role of Incident Response Teams in Cybersecurity ArchitectureWhat role does an incident response team play in cybersecurity architecture?Understanding the Crucial Role of Staff Training in CybersecurityWhy is staff training important in a cybersecurity framework?Understanding the Cyber Kill Chain: The Essential Model Every Cybersecurity Student Should KnowWhat is a cyber kill chain?Understanding the Cybersecurity Policy Document: Your Guiding Star in Cybersecurity StrategyWhat is the primary document that outlines an organization’s cybersecurity policies?Understanding the Essential Role of Vulnerability Management in CybersecurityWhat is the role of vulnerability management in cybersecurity?Understanding the GDPR: What Every Cybersecurity Architect Should KnowWhich compliance regulation requires organizations to protect the data of EU citizens?Understanding the Impact of Failing to Secure Sensitive InformationWhat is a potential consequence of failing to secure sensitive information?Understanding the Impact of Multi-Cloud Architecture on CybersecurityHow does multi-cloud architecture impact cybersecurity?Understanding the Importance of a Security Policy FrameworkWhat is a security policy framework?Understanding the Importance of Continuous Monitoring in CybersecurityWhy is continuous monitoring essential in cybersecurity?Understanding the Importance of Data Loss Prevention SolutionsWhat is the main goal of data loss prevention (DLP) solutions?Understanding the Importance of Governance, Risk, and Compliance in CybersecurityWhat cybersecurity concept emphasizes the need for audits and compliance checks?Understanding the Importance of Microsoft Defender for Cloud Apps in Protecting PII DataTo discover Personally Identifiable Information (PII) data at risk within Azure resources, what should you recommend?Understanding the Importance of Patch Management in CybersecurityWhat is a patch management process?Understanding the Importance of Risk Assessment in CybersecurityWhat is the purpose of risk assessment in cybersecurity?Understanding the Importance of the Information Security Triad for Cybersecurity SuccessWhich security model emphasizes the need to protect information before, during, and after it is processed?Understanding the Importance of the NIST Cybersecurity Framework for OrganizationsWhy is understanding the NIST Cybersecurity Framework important for organizations?Understanding the Importance of Third-Party Risk Management in CybersecurityWhy is third-party risk management vital in cybersecurity?Understanding the Importance of TLS for Securing Web TrafficWhich encryption algorithm is commonly used for securing web traffic?Understanding the Key Differences Between Symmetric and Asymmetric EncryptionWhat is the difference between symmetric and asymmetric encryption?Understanding the NIST Cybersecurity Framework: Your Essential GuideWhich framework is commonly utilized for establishing a risk management process in cybersecurity?Understanding the Principle of Least Privilege in CybersecurityWhat is the principle of least privilege?Understanding the Role of a Cybersecurity ArchitectWhat is the primary purpose of a cybersecurity architect?Understanding the Role of a SIEM Tool in Cybersecurity ArchitectureWhat is the function of a SIEM tool in a cybersecurity architecture?Understanding the Role of a Web Application Firewall (WAF)What is a web application firewall (WAF)?Understanding the Role of Access Control Lists in CybersecurityWhat is the function of an access control list (ACL)?Understanding the Role of Data Connectors in Integrating Azure WAF Logs with Microsoft SentinelWhat should be included in a solution for logging and auditing that integrates Azure WAF logs with Microsoft Sentinel?Understanding the Role of Endpoint Protection Platforms in CybersecurityWhich of the following is a role of the endpoint protection platform?Understanding the Role of Intrusion Detection Systems in CybersecurityWhat is the function of an intrusion detection system (IDS)?Understanding the Role of Microsoft Endpoint Manager in Device ComplianceTo assess whether devices meet compliance rules in a Microsoft 365 and Azure environment, which solution should be implemented?Understanding the Role of Microsoft Sentinel Playbooks in Incident ResponseWhat is the purpose of configuring Microsoft Sentinel playbooks when implementing security orchestration?Understanding Threat Intelligence: Why It Matters in CybersecurityWhat is Threat Intelligence?Understanding Vulnerabilities in Cybersecurity: A Key to ProtectionWhat does the term “vulnerability” refer to in cybersecurity?Understanding When to Upgrade from Azure AD Free to PremiumWhat triggers the need to upgrade from Azure AD Free edition to Premium edition for a customer using Microsoft 365 and Azure subscriptions?Understanding Workload Protections in Microsoft Defender for CloudWhich two components can provide additional information about security events during alert triage in Microsoft Defender for Cloud?Understanding Zero-Day Vulnerabilities: The Cybersecurity Threat You Can't IgnoreWhat are zero-day vulnerabilities?Unlocking the Mystery Behind Social Engineering in CybersecurityWhat does the term “social engineering” refer to in cybersecurity?What Does DLP Mean in Cybersecurity? Understanding Data Loss PreventionWhat does the acronym DLP stand for in cybersecurity?What Does IDS Stand for in Cybersecurity?In cybersecurity, what does IDS stand for?What Does SIEM Really Mean in Cybersecurity?What does SIEM stand for?What to Do When Noncompliant Resources Are Found in AzureWhat action should be taken when noncompliant resources are detected in Azure subscriptions?What You Need to Know About Data Breaches in CybersecurityWhat does the term "data breach" refer to?What You Need to Know About Data Loss Prevention in CybersecurityWhat aspect of cybersecurity does Data Loss Prevention focus on?What You Need to Know About MFA: The Key to CybersecurityWhat does the acronym MFA stand for?What You Need to Know About Next-Generation Firewalls (NGFWs)What is a next-generation firewall (NGFW)?Why Clear Communication Protocols Are Essential During a DisasterWhat is a critical component of an effective disaster recovery plan?Why Conducting a Security Audit is Essential for OrganizationsWhat is the benefit of conducting a security audit?Why is Penetration Testing Crucial for Cybersecurity?What is the purpose of penetration testing?Why Multi-factor Authentication is Essential for CybersecurityWhat role does Multi-factor Authentication (MFA) play in cybersecurity?Why Multi-Factor Authentication is Your Best Bet for Securing AccessWhich authentication method is considered the most secure?Why Network Segmentation is Key to CybersecurityWhat is the purpose of network segmentation?Why Onboarding Virtual Machines to Microsoft Defender for Endpoint is EssentialTo resolve issues with virtual machines, which solution should be recommended?Why Ongoing Training is Key to Strengthening Cybersecurity in OrganizationsHow can ongoing training benefit cybersecurity within an organization?Why Real-Time Analysis with a SIEM Tool is Essential for CybersecurityWhich of the following is a significant benefit of implementing a SIEM tool?Why Risk Assessments Are Essential in CybersecurityWhat is the primary purpose of risk assessments in cybersecurity?Why Security Tokens Are Essential in AuthenticationWhat role do security tokens play in authentication?Why Vulnerability Assessment is Crucial for Your Organization's CybersecurityWhy is vulnerability assessment important for organizations?Why Vulnerability Assessments are Key in CybersecurityWhat is the primary use of vulnerability assessments in cybersecurity?Why You Need an Application Security Assessment and How It WorksWhat is an application security assessment?Why You Should Care About Encryption in CybersecurityWhy is encryption important in cybersecurity?
More practice questions

These questions are part of the practice quiz. Start practicing

  • What is a key feature of Microsoft Defender for Cloud?
  • Which Azure service is recommended for continuous security assessment?
  • What is a common requirement for securing file shares in Azure?
  • Which controls should be included to ensure Azure Backup can restore resources affected by a ransomware attack?
  • What management tool should be used to delegate access for the InfraSec group to meet security requirements?
  • How does Microsoft Sentinel contribute to security management within an organization?
  • What is the primary purpose of Azure Bastion?
  • What is a key component to include in a security orchestration, automation, and response (SOAR) strategy to minimize manual intervention?
  • Which solution should be used to track sensitive data across different platforms seamlessly?
  • For encrypting cardholder and insurance claim data, which configurations meet compliance and privacy requirements?
  • To improve developer productivity, what should be included as part of the solution?
  • What solution can be recommended to restrict access key retrieval while allowing legacy applications to function?
  • Which service should be incorporated to ensure secure classification of sensitive documents in an organization?
  • What should be created in Azure AD to meet the requirements for Contoso developers?
  • How can you effectively monitor compliance with the ISO 27001:2013 standards across multiple Azure subscriptions?
  • Which Azure resource can provide centralized control over key management for sensitive projects?
  • What should you recommend to audit all users accessing data in Azure Cosmos DB accounts?
  • What access restriction would not ensure web apps only allow traffic through Azure Front Door?
  • What solution should be included to meet AWS requirements effectively?
  • What component should be included in a centralized logging solution for Azure landing zones to meet auditing requirements?
  • What is the recommended method to enable extended detection and response (EDR) capabilities for Microsoft Sentinel on Windows Server virtual machines?
  • Which solution should be recommended to ensure that only authorized applications can run on virtual machines in an Azure subscription?
  • To ensure minimal costs while connecting developers securely to Azure, which network design is ideal?
  • Which three services can be used to extend Azure security strategy to an AWS implementation without Azure Arc?
  • Which strategy should be recommended for SIEM and SOAR implementation that aligns with hybrid and compliance requirements?
  • What should be included in a recommendation for evaluating and remediating suspicious authentication activity alerts?
  • Which feature should be implemented for enhancing identity management in Azure AD?
  • What is the first step to evaluate the security posture of all workloads in an Azure landing zone?
  • Which solution helps in reducing the operational requirements for patch management in cloud databases?
  • What access security architecture should be recommended for an Azure App Service web app that requires user approval for access?
  • To prevent access to adult content websites, which service should be included in the recommendation for Windows 11 devices?
  • To successfully migrate legacy applications to the cloud, what must be minimized?
  • In designing a privileged identity strategy under the Zero Trust model, what framework is recommended?
  • To classify sensitive data in Microsoft Teams and SharePoint Online, which tool should be utilized?
  • What solution can be included to secure data copy processes in Azure Automation?
  • In Microsoft Defender for Cloud, what should be done to enhance security for Azure resources?
  • Which automation tool is recommended to meet compliance requirements?
  • Which tool should you integrate into your DevOps strategy to scan code during the uploading phase?
  • Which strategy can be effective in securing Azure App Service web apps?
  • What should be recommended to update the secure score for Azure Kubernetes Service (AKS) resources?
  • To fully isolate web app components in Azure, which architecture should NOT be proposed?
  • Which service should be recommended for managing the security posture of Azure IoT Edge devices and AWS EC2 instances?
  • What is the role of Microsoft Defender for Cloud in an Azure security strategy?
  • To evaluate compliance without affecting any resources in Azure, which Azure Policy effect should be used?
  • Which two preventive controls can increase the secure score for Azure landing zones?
  • After remediating a security alert in Microsoft Defender for Cloud, which policy definition should you assign to prevent recurrence of the threat?
  • What security aspect should be prioritized when offering vendor access to sensitive blobs in Azure?
  • What recommendation should be included during the application design phase in the security standard for onboarding applications to Azure?
  • When designing a strategy for internet-bound traffic routing in a landing zone, what should be recommended?
  • What should happen to the configurations after recovering from a ransomware attack?
  • To evaluate the security posture of Windows 11 devices, Azure storage accounts, and virtual machines, what should you use?
  • To meet application security requirements, which two authentication methods must applications support?
  • How can you ensure sensitive data remains protected across on-premises and cloud environments?
  • In the context of Azure security, what is the primary benefit of using Microsoft Defender for SQL?
  • How many Azure Bastion subnets are required for a company moving all on-premises virtual machines to Azure?
  • What is essential for blocking unauthorized applications from running on virtual machines?
  • When reviewing security alerts, which modern tool can assist in automating responses with minimal development effort?
  • Which Azure service can be used for scanning vulnerabilities in Linux containers deployed in Azure?
  • What networking approach should be recommended to allow developers to connect to Azure VMs over SSL while preventing public IP exposure?
  • What is the function of activity policies within Microsoft Defender for Cloud Apps?
  • Which connectivity strategy should be recommended for App Service web apps to fulfill landing zone requirements?
  • Which feature of Microsoft Defender for Identity should you recommend for monitoring accounts potentially being exploited by attackers?
  • Which tool would you recommend to classify and encrypt sensitive Microsoft Office 365 data stored both on-premises and in the cloud?
  • What is essential for maintaining the security infrastructure of a hybrid model in Microsoft environments?
  • Which method can ensure data protection within Azure databases?
  • What is the recommended solution for securing the landing zones to meet both landing zone and business requirements?
  • Which strategy can help prevent protected health information from being shared outside a company using Microsoft 365?
  • Which solution should be included to secure virtual machines comprehensively?
  • Which type of diagram is most appropriate for threat modeling in an Azure App Service web app?
  • What should you recommend to address storage account network access risks identified in recommendations from Microsoft Defender for Cloud?
  • What is recommended for secure connections to ClaimsDB?
  • Which measure should be taken to regularly harden kiosks against new threats?
  • What method can be recommended for securely sharing specific blobs with vendors while ensuring limited public exposure?
  • Which service should be recommended for an app that requires external identity integration with customizable branding?
  • Which solution is recommended for scanning application code that meets development requirements?
  • Which tool allows the configuration of adaptive network hardening in Azure?
  • What is required for Azure AD Conditional Access to be effective for remote access solutions?
  • What is necessary to ensure the security operations team can access both security and operation logs in Microsoft Sentinel?
  • In Azure Backup strategies, what is crucial for recovering from ransomware attacks?
  • What tool should be used to compare Microsoft security baselines to current device configurations?
  • Which configuration can help ensure that storage accounts restrict network access?
  • Which security solution should be included for securing the Litware.com forest to meet identity requirements?
  • What aspect of data governance can be improved by using Azure Policy?
  • Which service should not be utilized when extending Azure security to AWS if Azure Arc is not being used?
  • What conditions must be met before infected endpoints can access corporate applications again?
  • When designing security standards for Azure App Service web apps accessing on-premises SQL Server databases, what minimizes internet exposure?
  • What management tool should be used to ensure logging capability for Azure virtual machine operations?
  • What configuration can be recommended to increase Secure management ports controls score in Azure Security Benchmark V3 report?
  • To ensure security and operations teams have the appropriate access to logs in a hybrid cloud infrastructure, which configuration is recommended?
  • What configuration is critical for implementing Azure AD B2C in a hybrid cloud solution?
  • What feature can be enabled to limit permissions for administrators connecting to Azure virtual machines?
  • Which tool should be used to visualize and analyze security logs in Microsoft Sentinel?
  • What is the best solution for granting temporary employees access to company resources in a hybrid cloud infrastructure?
  • What testing method should be included to check for vulnerabilities in an Azure App Service web app?
  • Which Azure service would you use to analyze logs and ist security-related events for security postures?
  • Which security control is necessary to ensure only authorized applications can run on Azure virtual machines?
  • In developing a serverless application on Azure, which service should be recommended to isolate compute components on an Azure virtual network?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy