Weekend Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: certbig75

SC-100 Exam Dumps - Microsoft Certified: Cybersecurity Architect Expert Questions and Answers

Question # 14

You are evaluating the security of ClaimsApp.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE; Each correct selection is worth one point.

Options:

Buy Now
Question # 15

You need to recommend a solution to meet the requirements for connections to ClaimsDB.

What should you recommend using for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Question # 16

You have an Azure subscription.

You plan to deploy enterprise-scale landing zones based on the Microsoft Cloud Adoption Framework for Azure. The deployment will include a single-platform landing zone for all shared services and three application landing zones that will each host a different Azure application.

You need to recommend which resource to deploy to each landing zone. The solution must meet the Cloud Adoption Framework best-practice recommendations for enterprise-scale landing zones.

What should you recommend?

Options:

A.

an Azure Private DNS zone

B.

an Azure key vault

C.

an Azure firewall

D.

an Azure virtual network gateway

Buy Now
Question # 17

You have multiple on-premises Hyper-V hosts that contain virtual machines. The virtual machines run Windows Server.

You have an Azure subscription

You need to recommend a solution to collect Security event logs from the virtual machines by using Microsoft Sentinel. The solution must meet the following requirements:

• Leverage the Windows Security Events via AMA data connector.

• Ensure that only specific events are collected.

• Minimize costs.

What should you recommend? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Question # 18

A customer has a hybrid cloud infrastructure that contains a Microsoft 365 E5 subscription and an Azure subscription.

All on-premises Windows servers in the perimeter network are prevented from connecting directly to the internet.

The customer recently recovered from a tansomware attack.

The customer plans to deploy Microsoft Sentinel.

You need to recommend solutions to meet the following requirements:

• Ensure that the security operations team can access the security logs and the operation logs.

• Ensure that the IT operations team can access only the operations logs, including the event logs of the servers in the perimeter network.

Which two solutions should you include in the recommendation? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Options:

A.

the Azure Monitor agent

B.

Microsoft Entra Conditional Access policies

C.

Windows Server event subscription

D.

resource-based role-based access control (RBAC)

Buy Now
Question # 19

You are designing a security strategy for providing access to Azure App Service web apps through an Azure Front Door instance.

You need to recommend a solution to ensure that the web apps only allow access through the Front Door instance.

Solution: You recommend configuring gateway-required virtual network integration.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Question # 20

Azure subscription that uses Azure Storage.

The company plans to share specific blobs with vendors. You need to recommend a solution to provide the vendors with secure access to specific blobs without exposing the blobs publicly. The access must be t\me-Vim\ted. What should you include in the recommendation?

Options:

A.

Create shared access signatures (SAS).

B.

Share the connection string of the access key.

C.

Configure private link connections.

D.

Configure encryption by using customer-managed keys (CMKs)

Buy Now
Question # 21

You have an Azure subscription and a Microsoft 365 subscription. All users are assigned Microsoft 365 E5 licenses. All computers run Windows 11 and are Microsoft Entra joined.

You need to recommend a solution to prevent computers that run early builds of Windows 11 from connecting to Microsoft 365 services.

Which two types of policies should you include in the recommendation? Each correct answer presents part of the solution.

Options:

A.

Microsoft Defender for Cloud regulatory compliance policy

B.

Microsoft Defender for Endpoint endpoint security policy

C.

Microsoft Entra ID Protection sign-in risk policy

D.

Microsoft Entra Conditional Access policy

E.

Microsoft Intune compliance policy

Buy Now
Question # 22

You are designing a security strategy for providing access to Azure App Service web apps through an Azure Front Door instance.

You need to recommend a solution to ensure that the web apps only allow access through the Front Door instance.

Solution: You recommend access restrictions that allow traffic from the Front Door service tags.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Question # 23

You have an Azure subscription that uses Microsoft Defender for Cloud.

You have Amazon Web Services (AWS), Google Cloud Platform (GCP). and Oracle Cloud Infrastructure (OCI) subscriptions.

You create a custom security standard in Defender for Cloud.

To which subscriptions can the Defender for Cloud standard be applied?

Options:

A.

Azure and AWS only

B.

Azure and GCP only

C.

Azure. AWS, and GCP only

D.

Azure, AWS. and OCI only

E.

Azure, AWS, GCP. and OCI

Buy Now
Exam Code: SC-100
Exam Name: Microsoft Cybersecurity Architect
Last Update: Oct 4, 2026
Questions: 344
SC-100 pdf

SC-100 PDF

$23.75  $94.99
SC-100 Engine

SC-100 Testing Engine

$27.5  $109.99
SC-100 PDF + Engine

SC-100 PDF + Testing Engine

$36.25  $144.99