Microsoft SC-100 Practice Test Questions and Exam Dumps Part9 Q161-180

View Full Microsoft SC-100 Exam Dumps and Practice Test Dumps.

 

Question 161

Which Microsoft Entra capability helps organizations manage external users’ access to applications and resources through controlled packages and approval policies?

  1. Microsoft Entra Entitlement Management
  2. Azure Firewall
  3. Microsoft Defender for Endpoint
  4. Azure Monitor

Correct Answer: 1
Explanation

Microsoft Entra Entitlement Management helps organizations manage access to resources through access packages and associated policies. It can support request, approval, expiration, and review processes for users who need access to applications, groups, SharePoint sites, and other resources. This is especially useful when external users or temporary workers require controlled access. Azure Firewall provides network protection, Defender for Endpoint protects devices, and Azure Monitor provides monitoring capabilities. Entitlement management supports structured identity governance and helps reduce unmanaged access.

Question 162

A security architect wants to reduce the risk that stolen credentials can be used from an unfamiliar location to access sensitive applications. Which control should be considered?

  1. Conditional Access based on location and risk
  2. Public file sharing
  3. Permanent administrator access
  4. Anonymous authentication

Correct Answer: 1
Explanation

Conditional Access can evaluate contextual signals such as location, device state, user risk, sign-in risk, and application sensitivity before allowing access. Policies can require stronger authentication or block access when conditions indicate increased risk. This supports Zero Trust by avoiding automatic trust based solely on possession of valid credentials. Public sharing, permanent administrative access, and anonymous authentication do not provide equivalent protection. Conditional Access should be carefully designed to balance security requirements with legitimate user access and business continuity.

Question 163

Which security architecture component provides centralized visibility into security incidents by correlating events from multiple systems?

  1. Azure Storage
  2. Microsoft Sentinel
  3. Azure DNS
  4. Microsoft Intune

Correct Answer: 2
Explanation

Microsoft Sentinel provides security information and event management capabilities that can collect and correlate security data from multiple sources. By bringing telemetry together, security teams can identify relationships between events that may appear unrelated when viewed independently. Sentinel can support incident management, investigation, threat hunting, automation, and analytics. Azure Storage is primarily a data-storage service, DNS provides name resolution, and Intune manages endpoints. Centralized security analytics are particularly valuable in hybrid environments where security signals originate from many platforms.

Question 164

Which approach best protects a highly sensitive application from unnecessary access by other workloads in the same cloud environment?

  1. Shared administrative credentials
  2. Broad subscription permissions
  3. Workload-specific identities and network segmentation
  4. Public endpoints for all services

Correct Answer: 3
Explanation

Workload-specific identities restrict application permissions to the resources required by each workload, while network segmentation limits unnecessary communication paths. Together, these controls reduce the potential blast radius if another workload is compromised. Broad subscription permissions and shared administrative credentials create excessive access, while public endpoints can increase exposure. A secure architecture should define workload dependencies and explicitly permit required communication rather than allowing unrestricted connectivity. This approach aligns with least privilege and Zero Trust principles.

Question 165

Which Microsoft service helps detect malicious or suspicious email messages, links, and attachments?

  1. Microsoft Defender for Office 365
  2. Azure Policy
  3. Microsoft Entra ID Governance
  4. Azure Private Link

Correct Answer: 1
Explanation

Microsoft Defender for Office 365 provides security capabilities for protecting email and collaboration environments against threats such as phishing, malicious links, and harmful attachments. It can help organizations detect, investigate, and respond to email-based threats. Azure Policy manages cloud resource governance, Entra ID Governance manages identity and access lifecycle processes, and Private Link provides private connectivity. Email security is an important part of a broader architecture because compromised email accounts can become an entry point for identity compromise and data theft.

Question 166

An organization wants to prevent administrators from activating privileged roles without additional verification. Which control can be combined with privileged identity management?

  1. Strong authentication requirements
  2. Anonymous access
  3. Shared passwords
  4. Unrestricted role activation

Correct Answer: 1
Explanation

Strong authentication requirements can be applied to privileged role activation to ensure that elevated access receives additional protection. Combining strong authentication with privileged identity management can reduce the risk associated with stolen administrative credentials. Organizations may also require approval, justification, time-limited activation, and monitoring for sensitive roles. Anonymous access and shared passwords weaken accountability, while unrestricted activation removes important safeguards. Privileged operations should receive stronger controls than ordinary user activities because compromise of administrative identities can have significant consequences.

Question 167

Which Azure service can help protect applications from malicious web traffic while operating at the application layer?

  1. Azure WAF
  2. Azure Key Vault
  3. Azure Resource Locks
  4. Azure Backup

Correct Answer: 1
Explanation

Azure Web Application Firewall provides application-layer protection for supported web applications by inspecting HTTP traffic and applying security rules. It can help address common web attack patterns, including SQL injection and cross-site scripting, when properly configured. Key Vault manages secrets and cryptographic keys, Resource Locks help prevent certain resource changes, and Backup supports data recovery. WAF should not replace secure application development; it should complement secure coding, vulnerability management, identity controls, monitoring, and other architectural protections.

Question 168

A company is designing a security architecture for workloads that process regulated data. What should be established before selecting specific security technologies?

  1. Business, regulatory, and security requirements
  2. Vendor branding preferences
  3. Random product selections
  4. Unrestricted administrator access

Correct Answer: 1
Explanation

Security architecture should begin by identifying business, regulatory, data protection, availability, identity, and security requirements. These requirements provide the criteria for evaluating technology choices and architectural patterns. Selecting products before defining requirements can result in unnecessary costs, incompatible controls, or gaps in protection. Regulatory requirements may also influence data location, retention, encryption, access, and auditing decisions. A requirements-driven approach allows architects to select technologies that address actual risks and business needs rather than choosing products without a defined security objective.

Question 169

Which Microsoft capability helps security teams investigate endpoint incidents and determine whether devices are affected by a threat?

  1. Microsoft Defender for Endpoint
  2. Microsoft Entra B2B
  3. Azure DNS
  4. Microsoft Purview Retention

Correct Answer: 1
Explanation

Microsoft Defender for Endpoint provides endpoint detection and response capabilities that help security teams investigate suspicious activity on supported devices. It can provide device telemetry and security information that analysts can use to understand attack behavior and determine appropriate response actions. Entra B2B supports external collaboration, Azure DNS handles name resolution, and Purview retention features support information lifecycle management. Endpoint investigation is an important component of security operations because compromised devices can provide attackers with access to identities, applications, and sensitive resources.

Question 170

Which security design helps prevent a compromised user account from accessing every application in an organization?

  1. Identity-based segmentation and application-specific authorization
  2. Shared global administrator permissions
  3. Universal application access
  4. Flat authorization

Correct Answer: 1
Explanation

Identity-based segmentation and application-specific authorization restrict users according to their identity, role, risk, application requirements, and other relevant conditions. This prevents authentication from automatically resulting in broad access to unrelated applications. Shared global administrator permissions and universal access significantly increase the blast radius of compromised accounts. Flat authorization provides fewer meaningful boundaries. Application-specific access should be combined with least privilege, strong authentication, access reviews, and monitoring to provide layered protection against identity compromise.

Question 171

Which Azure capability can enforce organizational requirements such as approved regions, resource types, or configuration standards?

  1. Azure Policy
  2. Azure Bastion
  3. Azure Front Door
  4. Azure VPN Gateway

Correct Answer: 1
Explanation

Azure Policy allows organizations to define rules that evaluate or enforce resource configurations against organizational requirements. Policies can address areas such as permitted locations, resource types, tagging, security configurations, and compliance conditions. Bastion provides secure administrative access, Front Door supports application delivery, and VPN Gateway provides network connectivity. Policy is particularly useful in large environments because security and governance requirements can be applied consistently across subscriptions and management groups. Policies should be monitored and reviewed as requirements change.

Question 172

A security architect wants to ensure that security alerts from multiple Microsoft Defender products are investigated as related activity when appropriate. Which capability supports this goal?

  1. Microsoft Defender XDR
  2. Azure Storage
  3. Microsoft Entra Lifecycle Workflows
  4. Azure Resource Locks

Correct Answer: 1
Explanation

Microsoft Defender XDR can correlate signals across Microsoft security products and present related security activity within a unified incident context. This can help analysts understand attack chains that involve multiple security domains instead of investigating isolated alerts independently. Azure Storage provides data storage, Lifecycle Workflows automate identity lifecycle tasks, and Resource Locks protect Azure resources from certain administrative changes. Cross-domain correlation can improve investigation efficiency and provide broader visibility into attacks that span identities, endpoints, email, and applications.

Question 173

Which practice helps ensure that sensitive cryptographic keys are not directly embedded within application source code?

  1. Centralized key management
  2. Hard-coded encryption keys
  3. Public configuration files
  4. Shared developer credentials

Correct Answer: 1
Explanation

Centralized key management keeps cryptographic keys outside application source code and provides controlled mechanisms for authorized applications to use them. Services such as Azure Key Vault can support secure key storage, access control, auditing, and lifecycle management. Hard-coded keys can be exposed through source repositories or application packages, while public configuration files and shared developer credentials create additional risks. Separating key management from application logic also makes key rotation and administrative control easier without requiring extensive application changes.

Question 174

Which security architecture practice is most useful for identifying how an attacker could exploit weaknesses in an application before deployment?

  1. Threat modeling
  2. Load balancing
  3. Data replication
  4. DNS delegation

Correct Answer: 1
Explanation

Threat modeling systematically examines an application, its assets, trust boundaries, data flows, dependencies, and potential attack paths. Performing threat modeling during design can help security and development teams identify weaknesses before deployment and determine appropriate mitigations. Load balancing, data replication, and DNS delegation address availability, data, and networking requirements rather than analyzing attack scenarios. Threat modeling should be revisited when major architectural changes occur because new components or dependencies can introduce additional threats.

Question 175

Which DevSecOps practice helps detect accidentally committed passwords, API keys, or other sensitive credentials in source repositories?

  1. Secrets scanning
  2. Network load balancing
  3. Data replication
  4. DNS filtering

Correct Answer: 1
Explanation

Secrets scanning examines source code and related repositories for credentials and other sensitive values that may have been accidentally committed. Detecting exposed secrets early can allow organizations to revoke or rotate them before attackers can exploit them. Load balancing, replication, and DNS filtering serve different architectural purposes. Secrets scanning should be combined with secure secret storage, managed identities where appropriate, access controls, repository protection, and automated pipeline checks. If a real credential is exposed, simply deleting it from the latest commit may not be sufficient because repository history may retain it.

Question 176

An organization needs to investigate who accessed a sensitive document and when the access occurred. Which capability is most relevant?

  1. Audit logging
  2. Network address translation
  3. Azure Load Balancer
  4. Azure DDoS Protection

Correct Answer: 1
Explanation

Audit logging records relevant user and system activities and can provide evidence about actions performed on sensitive resources. For data security investigations, audit information can help determine who accessed, modified, shared, or otherwise interacted with information, depending on the service and configuration. Network address translation, load balancing, and DDoS protection address networking and availability rather than activity auditing. Audit architecture should consider event coverage, retention, access restrictions, integrity, privacy requirements, and integration with security monitoring platforms.

Question 177

Which approach can help protect containerized workloads by identifying vulnerabilities in container images before deployment?

  1. Container image scanning
  2. Disabling image validation
  3. Shared container credentials
  4. Public registry access

Correct Answer: 1
Explanation

Container image scanning examines container images for vulnerabilities, insecure packages, configuration issues, and other security concerns before workloads are deployed. Integrating scanning into CI/CD pipelines allows development teams to identify problems earlier and establish policies for blocking or approving images according to risk. Disabling validation and relying on unrestricted registry access can increase exposure. Container security should also include image provenance, registry protection, runtime monitoring, least-privilege identities, network isolation, and regular vulnerability management.

Question 178

Which architecture capability helps ensure that an organization’s security configuration remains aligned with an approved baseline?

  1. Configuration compliance monitoring
  2. Unrestricted manual changes
  3. Anonymous administration
  4. Disabled policy evaluation

Correct Answer: 1
Explanation

Configuration compliance monitoring compares deployed resources and settings against defined security baselines or organizational requirements. This helps identify drift caused by manual changes, deployments, or configuration errors. Without continuous assessment, an environment can gradually move away from its approved security posture. Unrestricted manual changes and disabled policy evaluation make drift harder to detect, while anonymous administration weakens accountability. Compliance monitoring should be integrated with policy enforcement, alerting, remediation workflows, and change management.

Question 179

A company wants to isolate security administration from ordinary application administration so that no single team has unrestricted control. Which principle supports this design?

  1. Separation of duties
  2. Universal access
  3. Shared administration
  4. Implicit trust

Correct Answer: 1
Explanation

Separation of duties divides sensitive responsibilities among different individuals or teams so that one person or group does not have unrestricted control over critical operations. This can reduce insider risk, limit the impact of compromised accounts, and provide stronger oversight for sensitive activities. Shared administration without defined responsibilities can weaken accountability, while universal access and implicit trust increase exposure. Separation of duties should be implemented according to organizational risk and should include clearly defined responsibilities, approvals, monitoring, and appropriate exceptions.

Question 180

Which security architecture activity should be performed when a new business application is proposed to determine its security requirements and risks before implementation?

  1. Security architecture review
  2. Immediate production deployment
  3. Credential sharing
  4. Security control removal

Correct Answer: 1
Explanation

A security architecture review evaluates a proposed application against security requirements, business risks, data sensitivity, identity needs, network dependencies, compliance obligations, and other architectural concerns before implementation. Early review allows security requirements to be incorporated into the design rather than attempting to correct major weaknesses after deployment. Immediate production deployment can introduce avoidable risks, while credential sharing and control removal weaken security. A structured review should produce documented requirements, identified risks, architectural decisions, and appropriate security controls.