Microsoft SC-100 Practice Test Questions and Exam Dumps Part15 Q281-300

View Full Microsoft SC-100 Exam Dumps and Practice Test Dumps.

 

Question 281

Which Microsoft architecture resource provides guidance for designing security capabilities across identity, data, applications, and infrastructure in Microsoft cloud environments?

  1. Microsoft Cybersecurity Reference Architectures
  2. Azure Pricing Calculator
  3. Microsoft Service Health
  4. Azure Cost Management

Correct Answer: 1
Explanation

Microsoft Cybersecurity Reference Architectures provide architectural guidance for combining Microsoft security capabilities across areas such as identity, devices, applications, data, infrastructure, and security operations. They can help security architects understand how different services fit together when designing a comprehensive security strategy. Pricing and cost-management tools serve financial planning purposes, while Service Health provides information about service issues. Reference architectures should not be copied blindly; they should be adapted to an organization’s business requirements, existing environment, regulatory obligations, and risk profile.

Question 282

An organization is designing a new Azure environment and wants security controls to be established before application teams begin deploying workloads. Which approach supports this objective?

  1. Allow unrestricted subscriptions
  2. Secure Azure landing zone
  3. Deploy applications first
  4. Disable centralized governance

Correct Answer: 2
Explanation

A secure Azure landing zone establishes foundational governance, identity, networking, monitoring, and security controls before workloads are deployed at scale. This approach helps application teams operate within predefined boundaries rather than implementing security independently for every workload. Unrestricted subscriptions can result in inconsistent configurations, while deploying applications before establishing foundational controls can create remediation challenges. A landing zone should be aligned with organizational requirements and can include policies, management structures, network architecture, logging, identity controls, and standardized security configurations.

Question 283

Which security control is specifically intended to reduce the attack surface by preventing unnecessary or risky behaviors on managed endpoints?

  1. Azure Firewall
  2. Microsoft Purview Audit
  3. Attack Surface Reduction rules
  4. Azure Resource Locks

Correct Answer: 3
Explanation

Attack Surface Reduction rules in Microsoft Defender for Endpoint can help reduce endpoint exposure by restricting behaviors commonly associated with malicious activity. Depending on configuration, these controls can prevent or limit activities that attackers may use during exploitation, credential theft, or malware execution. Azure Firewall protects network traffic, Purview Audit records relevant activities, and Resource Locks help prevent accidental or unauthorized resource deletion. ASR rules should be introduced carefully, tested for application compatibility, monitored for effectiveness, and deployed according to organizational risk requirements.

Question 284

Which Microsoft Entra feature allows organizations to establish policies controlling collaboration and trust with identities from other Microsoft Entra tenants?

  1. Microsoft Entra cross-tenant access settings
  2. Azure Resource Locks
  3. Microsoft Defender for Endpoint
  4. Azure Backup

Correct Answer: 1
Explanation

Microsoft Entra cross-tenant access settings allow organizations to control inbound and outbound collaboration with other Microsoft Entra organizations. Administrators can define how external identities are treated and establish organizational trust settings according to security requirements. This is useful for business partnerships, mergers, acquisitions, and controlled external collaboration. Resource Locks, Defender for Endpoint, and Azure Backup address different security or infrastructure requirements. Cross-tenant policies should be combined with strong authentication, access governance, least privilege, and appropriate external identity lifecycle controls.

Question 285

A company wants to prevent sensitive information from being accidentally shared through email or cloud applications. Which security capability should be considered?

  1. Azure Bastion
  2. Data Loss Prevention
  3. Azure Load Balancer
  4. Azure Traffic Manager

Correct Answer: 2
Explanation

Data Loss Prevention policies can help identify and restrict activities involving sensitive information according to organizational requirements. Depending on the configured policy and supported workloads, DLP can help reduce accidental or unauthorized sharing through channels such as email, cloud applications, and other supported services. Azure Bastion provides administrative connectivity, Load Balancer distributes traffic, and Traffic Manager handles traffic routing. DLP should be based on data classification, business requirements, regulatory obligations, and carefully tested policies to avoid unnecessary disruption to legitimate business processes.

Question 286

Which security architecture model separates administrative operations from ordinary user activities by using a dedicated hardened workstation?

  1. Privileged Access Workstation
  2. Public kiosk
  3. Shared desktop
  4. Standard office workstation

Correct Answer: 1
Explanation

A Privileged Access Workstation, or PAW, is a dedicated and hardened device intended for performing sensitive administrative activities. Separating privileged administration from normal browsing, email, and other everyday tasks reduces opportunities for privileged credentials to be exposed to threats targeting ordinary user activity. Shared desktops and standard workstations may have broader exposure. A PAW architecture should be combined with strong authentication, privileged identity controls, restricted applications, monitoring, patch management, and clearly defined administrative procedures.

Question 287

Which Microsoft Sentinel capability can enrich security investigations by providing information about known malicious IP addresses, domains, or other indicators?

  1. Azure Resource Locks
  2. Threat intelligence
  3. Azure Bastion
  4. Microsoft Purview Records Management

Correct Answer: 2
Explanation

Microsoft Sentinel threat intelligence capabilities can provide security teams with information about indicators associated with potentially malicious activity. Threat intelligence can be used alongside security events and analytics to improve detection, investigation, and threat hunting. Resource Locks protect Azure resources, Bastion supports administrative access, and Purview Records Management addresses information governance. Threat intelligence should be evaluated for source quality, relevance, freshness, and confidence because inaccurate or outdated indicators can create unnecessary alerts or investigation effort.

Question 288

Which security architecture approach helps prevent a compromised workload from communicating freely with unrelated workloads?

  1. Flat network design
  2. Microsegmentation
  3. Universal routing
  4. Shared network access

Correct Answer: 2
Explanation

Microsegmentation creates smaller security boundaries around workloads or application components and restricts communication according to defined requirements. If one workload is compromised, segmentation can make it more difficult for an attacker to move laterally into unrelated systems. Flat networks and unrestricted routing provide fewer barriers to lateral movement. Microsegmentation should be based on documented application dependencies and supported by identity-aware controls, network policies, monitoring, and continuous validation. Security architects should also consider operational complexity when defining segmentation boundaries.

Question 289

Which Microsoft Defender XDR capability can automatically investigate alerts and take approved remediation actions?

  1. Automated investigation and response
  2. Azure Resource Manager
  3. Microsoft Purview Data Map
  4. Azure DNS

Correct Answer: 1
Explanation

Microsoft Defender XDR automated investigation and response capabilities can investigate certain alerts and perform approved remediation actions based on detected threats and configured capabilities. Automation can reduce repetitive analyst work and accelerate response to common security events. Azure Resource Manager handles resource management, Purview Data Map supports data governance capabilities, and Azure DNS provides name-resolution services. Automated response should be carefully governed with appropriate permissions, testing, monitoring, and escalation procedures so that legitimate activities are not unnecessarily disrupted.

Question 290

Which identity architecture approach is most appropriate when an application running in Azure needs to access another Azure service without storing credentials in application code?

  1. Managed identity
  2. Embedded password
  3. Shared service account
  4. Hard-coded secret

Correct Answer: 1
Explanation

Managed identities allow supported Azure resources and workloads to authenticate to other services without requiring developers to store credentials directly in application code. Azure manages the identity lifecycle, reducing the need to create, distribute, and rotate long-lived secrets manually. Embedded passwords and hard-coded secrets can be exposed through source code or deployment artifacts, while shared service accounts increase accountability and privilege-management challenges. The managed identity should still receive only the permissions required for its workload and should be monitored like other important identities.

Question 291

Which security architecture concept separates administrative operations, application processing, and stored information into distinct security considerations?

  1. Identity plane, control plane, and data plane
  2. Public network, private network, and DNS
  3. User plane, billing plane, and storage plane
  4. Development, testing, and marketing

Correct Answer: 1
Explanation

The identity, control, and data planes represent different security considerations within cloud architectures. Identity controls determine who or what can authenticate and access resources, the control plane manages configuration and administrative operations, and the data plane handles access to the actual workload resources or information. Treating these planes separately helps architects identify different attack paths and apply appropriate controls. A compromise of administrative control-plane access, for example, can have broader consequences than access to a single application component.

Question 292

Which Azure service can provide a private connection to supported platform services without sending traffic through the public internet?

  1. Azure Private Link
  2. Azure Traffic Manager
  3. Azure Load Balancer
  4. Azure DNS

Correct Answer: 1
Explanation

Azure Private Link enables private connectivity to supported Azure services and other supported resources through private endpoints. This can reduce public network exposure and support architectures where sensitive service traffic should remain on private network paths. Traffic Manager provides DNS-based traffic routing, Load Balancer distributes network traffic, and Azure DNS provides name-resolution capabilities. Private connectivity should still be combined with identity authorization, network segmentation, monitoring, and appropriate service-level security because a private network path does not automatically authorize every requester.

Question 293

Which software supply-chain practice provides a machine-readable inventory of software components included in an application?

  1. Security baseline
  2. Software bill of materials
  3. Network access list
  4. Data retention schedule

Correct Answer: 2
Explanation

A Software Bill of Materials, or SBOM, provides an inventory of software components and dependencies included in an application or software artifact. This visibility can help organizations identify affected components when vulnerabilities are discovered and improve supply-chain risk management. Security baselines define secure configuration expectations, network access lists control traffic, and retention schedules govern data lifecycle requirements. SBOMs are most useful when integrated with build pipelines, vulnerability management, dependency tracking, software inventories, and processes for responding to newly discovered component risks.

Question 294

Which security architecture control can help prevent unauthorized modification of critical application files after deployment?

  1. File integrity monitoring
  2. Traffic Manager
  3. Azure DNS
  4. Cost Management

Correct Answer: 2
Explanation

File integrity monitoring can detect changes to important files, configurations, or system components and can alert security teams when unexpected modifications occur. This can help identify unauthorized changes resulting from compromise, malware, or improper administrative activity. Traffic Manager handles traffic routing, Azure DNS provides name resolution, and Cost Management supports financial governance. Integrity monitoring should define which files or configurations are important, establish expected change processes, and integrate relevant alerts with security monitoring and incident-response workflows.

Question 295

Which Microsoft Purview capability can help organizations identify risky user behavior involving sensitive information before it becomes a significant security incident?

  1. Insider Risk Management
  2. Azure Bastion
  3. Azure Firewall
  4. Azure Load Balancer

Correct Answer: 1
Explanation

Microsoft Purview Insider Risk Management helps organizations identify potentially risky activities involving users and sensitive organizational information. It can use configured indicators and policies to help security teams investigate situations that may represent inappropriate or risky behavior. Azure Bastion, Firewall, and Load Balancer address infrastructure and network requirements rather than insider-risk analysis. Insider-risk programs should include appropriate governance, privacy considerations, role separation, investigation procedures, and carefully defined policies to ensure that security monitoring is proportionate and aligned with organizational requirements.

Question 296

Which architecture approach helps protect an organization’s DNS requests by directing internal workloads to controlled private name-resolution services?

  1. Private DNS architecture
  2. Public-only DNS resolution
  3. Unrestricted external forwarding
  4. Shared public resolver

Correct Answer: 1
Explanation

A private DNS architecture can provide controlled name resolution for internal workloads and private services without requiring internal resources to rely entirely on public DNS paths. This can support private endpoints, internal application naming, and controlled network architectures. Public-only resolution or unrestricted forwarding can expose unnecessary information or create dependencies on external infrastructure. Private DNS should be designed with appropriate forwarding rules, access controls, monitoring, redundancy, and clearly documented ownership to ensure reliable and secure name resolution across the environment.

Question 297

Which security architecture capability can help detect suspicious authentication behavior associated with compromised user identities?

  1. Microsoft Entra ID Protection
  2. Azure Load Balancer
  3. Azure Storage
  4. Azure Resource Manager

Correct Answer: 1
Explanation

Microsoft Entra ID Protection can identify identity-related risks using signals associated with authentication and user activity. It can help organizations detect potentially compromised identities and integrate risk information into access decisions and remediation workflows. Load Balancer manages traffic distribution, Storage provides data services, and Resource Manager handles Azure resource management. Identity risk detection should be combined with strong authentication, Conditional Access, lifecycle governance, monitoring, and appropriate incident-response processes so that suspicious identity activity can be investigated and addressed promptly.

Question 298

A security team wants application developers to receive security feedback while code is still being developed rather than after production deployment. Which approach supports this goal?

  1. Shift-left security
  2. Production-only testing
  3. Post-incident review
  4. Manual production inspection

Correct Answer: 3
Explanation

Shift-left security integrates security activities earlier in the software development lifecycle. Developers can receive feedback through code scanning, dependency analysis, secret detection, infrastructure-as-code checks, and other security controls before applications reach production. This can reduce the cost and complexity of correcting security issues later. Production-only testing may identify problems after deployment, while manual inspection can be inconsistent. Shift-left security should complement, rather than replace, production monitoring, runtime protection, vulnerability management, and incident-response capabilities.

Question 299

Which architecture principle requires organizations to consider how a security control affects business processes before implementing it?

  1. Business-aligned security design
  2. Security isolation without assessment
  3. Unrestricted access
  4. Technology-first deployment

Correct Answer: 1
Explanation

Business-aligned security design considers security requirements alongside business processes, operational dependencies, user needs, and organizational objectives. A technically strong control can still create unacceptable operational problems if it blocks critical workflows or ignores legitimate requirements. Technology-first deployment can result in controls being selected before the actual risk is understood. Security isolation without assessment can also produce unnecessary restrictions. Architects should evaluate risk reduction, business impact, regulatory requirements, usability, implementation effort, and measurable outcomes when selecting security controls.

Question 300

Which activity provides evidence that a security control is operating as designed and reducing the intended risk?

  1. Control effectiveness assessment
  2. Immediate policy removal
  3. Unrestricted administrative access
  4. Unreviewed configuration changes

Correct Answer: 1
Explanation

A control effectiveness assessment evaluates whether a security control is implemented correctly, operating as intended, and achieving its expected risk-reduction objective. Testing can include technical validation, configuration reviews, simulated scenarios, audit evidence, operational metrics, and control-owner assessments. Merely deploying a control does not prove that it is effective. Policy removal and unrestricted access weaken security, while unreviewed changes can invalidate previously tested configurations. Effectiveness assessments should be repeated periodically and after significant environmental or architectural changes.