{"id":17605,"date":"2026-09-21T10:30:25","date_gmt":"2026-09-21T10:30:25","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17605"},"modified":"2026-09-21T10:30:25","modified_gmt":"2026-09-21T10:30:25","slug":"microsoft-sc-100-practice-test-questions-and-exam-dumps-part4-q61-80","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-100-practice-test-questions-and-exam-dumps-part4-q61-80\/","title":{"rendered":"Microsoft SC-100 Practice Test Questions and Exam Dumps Part4 Q61-80"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-100-exam-dumps\"><b>Microsoft SC-100 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 61<\/b><\/h3>\n<p><b>An organization wants to replace several overlapping security products with a platform that provides integrated endpoint detection, identity protection, email security, and cloud application signals. Which architectural approach should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security consolidation through an integrated XDR platform<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separate unmanaged security products<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perimeter-only monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Independent endpoint logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An integrated XDR architecture can consolidate security signals from multiple domains and provide correlated detection and investigation capabilities. This can reduce duplicated functionality, improve visibility, and simplify security operations when appropriately designed. The goal is not simply to reduce the number of products but to create effective coverage and integration across security domains. Separate unmanaged tools can produce fragmented visibility, while perimeter-only monitoring misses activity occurring on endpoints, identities, cloud services, and applications.<\/span><\/p>\n<h3><b>Question 62<\/b><\/h3>\n<p><b>Which architectural capability helps an organization establish a common security policy framework while allowing individual business units to retain appropriate operational autonomy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Centralized governance with delegated administration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Completely independent security policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal administrator access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unmanaged local security controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized governance with delegated administration allows an organization to establish common security requirements while giving appropriate teams authority over resources within their responsibilities. This model can improve consistency without requiring a single team to perform every administrative task. Completely independent policies can create inconsistent protection, while universal administrator access violates least privilege. Unmanaged local controls can also create visibility and compliance gaps. Effective security architecture balances centralized standards with controlled delegation according to organizational structure and risk.<\/span><\/p>\n<h3><b>Question 63<\/b><\/h3>\n<p><b>A company wants to ensure that security policies continue to meet regulatory requirements after applications are moved to the cloud. Which architectural activity is most important?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compliance and regulatory requirements mapping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing audit logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling cloud governance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allowing unrestricted data movement<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Compliance and regulatory requirements mapping identifies the obligations that apply to systems, data, users, and business processes and translates them into architectural requirements. Moving workloads to the cloud does not automatically remove regulatory responsibilities. Architects should determine applicable requirements for data protection, retention, access, auditing, residency, and other areas. Removing logs or allowing unrestricted data movement can make compliance more difficult. Mapping requirements early helps ensure that cloud architecture incorporates appropriate governance and security controls.<\/span><\/p>\n<h3><b>Question 64<\/b><\/h3>\n<p><b>Which design consideration is particularly important when selecting where sensitive organizational data should be stored?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data residency and regulatory requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Monitor size<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User desktop wallpaper<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Keyboard layout<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data residency and regulatory requirements can determine where certain information may be stored, processed, or transferred. Security architects should identify applicable laws, contractual obligations, industry requirements, and organizational policies before selecting storage locations. These requirements can influence cloud regions, service configurations, encryption, access controls, and data-management processes. Monitor size, wallpaper, and keyboard layout have no meaningful relationship to data residency. Incorporating regulatory requirements into architecture early can prevent costly redesigns and reduce compliance risk.<\/span><\/p>\n<h3><b>Question 65<\/b><\/h3>\n<p><b>An organization wants to ensure that a compromised application cannot directly communicate with every other workload. Which architectural control should be emphasized?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsegmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat network connectivity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared service accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal firewall permissions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsegmentation creates smaller security boundaries around workloads, applications, or services and allows communication to be restricted according to defined requirements. This can reduce lateral movement and limit the impact of a compromised workload. Flat connectivity and universal firewall permissions allow broader communication, increasing the potential attack surface. Shared service accounts can also expand the consequences of credential compromise. Microsegmentation is particularly useful in modern cloud and hybrid architectures because it can enforce granular communication policies closer to the workload.<\/span><\/p>\n<h3><b>Question 66<\/b><\/h3>\n<p><b>Which security architecture capability provides protection against unauthorized changes to critical cloud infrastructure configurations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration governance and change control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous administrative access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent unrestricted permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling audit records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration governance and change control help ensure that important infrastructure modifications are authorized, reviewed, tracked, and monitored. This can include policy enforcement, configuration baselines, approval processes, and auditing. Unauthorized configuration changes can weaken security controls or expose sensitive resources, so maintaining visibility over changes is an important architectural requirement. Anonymous administration and permanent unrestricted permissions increase risk, while disabling audit records removes evidence needed to investigate changes. Governance should cover both cloud and on-premises infrastructure where applicable.<\/span><\/p>\n<h3><b>Question 67<\/b><\/h3>\n<p><b>A security architect needs to design protection for an application that processes payment information. Which architectural principle should be applied first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identify the data and business risk that require protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Select a security product based only on popularity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow unrestricted application access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove all application logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The architecture should begin by identifying the information being processed, its sensitivity, business importance, applicable requirements, and potential consequences of compromise. Payment information may require stronger controls for identity, encryption, access, monitoring, and data handling. Selecting a product before understanding these requirements can lead to ineffective or unnecessarily complex designs. Unrestricted access and removing logs increase risk. A risk-based approach ensures that security controls are selected because they address defined requirements rather than because a technology is widely marketed or adopted.<\/span><\/p>\n<h3><b>Question 68<\/b><\/h3>\n<p><b>Which architecture capability helps prevent an application from accessing data stores that are unrelated to its intended business function?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application-specific authorization and data access controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared database administrator accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Broad database permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous database access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application-specific authorization and data access controls restrict applications to the information required for their intended functions. This supports least privilege and reduces the potential impact of an application compromise. Broad database permissions or shared administrative accounts can expose large amounts of information unnecessarily. Anonymous access creates additional security concerns and removes accountability. Architects should consider application identities, database roles, segmentation, and resource-level authorization when designing access to sensitive data stores.<\/span><\/p>\n<h3><b>Question 69<\/b><\/h3>\n<p><b>An organization wants to identify sensitive information before applying protection policies. Which Microsoft capability can assist with discovering and classifying organizational data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Paint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Windows Calculator<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview provides data governance and compliance capabilities that can help organizations discover, classify, and manage information across supported data sources. Understanding where sensitive information exists is an important prerequisite for designing effective protection, retention, compliance, and data-loss prevention policies. Network load balancing and general-purpose desktop applications do not provide comparable data-governance capabilities. A security architecture should establish visibility into sensitive information before determining how that information should be protected and governed.<\/span><\/p>\n<h3><b>Question 70<\/b><\/h3>\n<p><b>A security architect is designing an identity strategy for automated workloads such as applications and services. Which approach reduces the need to embed long-lived passwords in application code?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use managed identities or workload identities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Store administrator passwords in source code<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use one shared password for all services<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable authentication for internal applications<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Managed identities or workload identities allow applications and services to authenticate without requiring developers to embed long-lived passwords or secrets directly in source code. This reduces credential exposure and supports more controlled identity lifecycle management. Shared passwords and credentials stored in source code can be difficult to rotate and may be exposed through repositories or application artifacts. Disabling authentication is not an appropriate solution. Workload identity is an important component of modern cloud security architecture because applications increasingly require access to other services.<\/span><\/p>\n<h3><b>Question 71<\/b><\/h3>\n<p><b>Which security architecture practice helps ensure that cryptographic keys are protected separately from the data they encrypt?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Centralized key management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storing keys in application source code<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sharing keys through email<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Using one permanent key for every workload<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized key management provides controlled storage, access, rotation, monitoring, and lifecycle management for cryptographic keys. Separating key management from application data can reduce the risk that compromise of an application or storage location automatically exposes the keys required to decrypt protected information. Storing keys in source code or sharing them through email creates unnecessary exposure. Using one permanent key for every workload also increases the impact of key compromise. Proper key management should reflect data sensitivity and organizational requirements.<\/span><\/p>\n<h3><b>Question 72<\/b><\/h3>\n<p><b>An organization wants to make sure that encryption keys can be rotated without redesigning every application that uses encrypted data. Which architecture principle is helpful?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of cryptographic key management from application logic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hard-coding keys into applications<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Using plaintext secrets<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling key rotation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separating cryptographic key management from application logic allows organizations to manage key lifecycle operations independently of individual applications. This can simplify rotation, access control, auditing, and recovery while reducing the need to modify application code whenever cryptographic requirements change. Hard-coded keys make rotation difficult and increase exposure if source code is compromised. Plaintext secrets provide no meaningful protection, while disabling rotation can leave organizations dependent on outdated or compromised keys. Centralized key-management services can support this architectural separation.<\/span><\/p>\n<h3><b>Question 73<\/b><\/h3>\n<p><b>Which architecture approach helps protect security-sensitive services from failures affecting a single geographic location?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Geographic redundancy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-region dependency<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">One-server architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Centralized local-only storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Geographic redundancy distributes critical services or supporting capabilities across separate locations so that a regional outage does not necessarily make the entire service unavailable. Depending on business requirements, this can involve multiple regions, availability zones, backup environments, or disaster-recovery arrangements. A single-region dependency creates a larger availability risk when that location experiences an outage. Architects should determine the required recovery objectives and business impact before selecting the appropriate level of geographic redundancy.<\/span><\/p>\n<h3><b>Question 74<\/b><\/h3>\n<p><b>A business requires critical applications to recover within a short period after a major security incident. Which architectural requirement should be defined?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery time objective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen resolution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password length only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS hostname format<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Recovery Time Objective, or RTO, defines the maximum acceptable time required to restore a service after an outage or disruptive event. It is an important input into disaster recovery and resilience architecture because it influences redundancy, backup strategies, recovery procedures, and technology choices. Password length can improve authentication security but does not define service recovery requirements. Screen resolution and hostname formatting are unrelated. Architects should define RTO together with other business continuity requirements, including recovery point objectives.<\/span><\/p>\n<h3><b>Question 75<\/b><\/h3>\n<p><b>Which requirement defines how much data loss an organization can tolerate after a disruptive event?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery Point Objective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery Time Objective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Maximum administrator count<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network throughput target<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Recovery Point Objective, or RPO, defines the amount of data loss that an organization can tolerate, typically expressed as a period of time. For example, an organization requiring an RPO of a few minutes needs recovery mechanisms that minimize the age of restored data. RTO instead focuses on how quickly a service must become operational again. RPO and RTO are therefore complementary requirements that influence backup, replication, disaster recovery, and resilience architecture.<\/span><\/p>\n<h3><b>Question 76<\/b><\/h3>\n<p><b>A security architect is evaluating a business application that must remain available during maintenance of individual infrastructure components. Which design characteristic should be emphasized?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">High availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single point of failure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual-only recovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent administrative access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">High availability architecture reduces service disruption by using redundancy, failover capabilities, resilient components, and appropriate maintenance strategies. The objective is to keep important services operational when individual components fail or require maintenance. A single point of failure creates a dependency that can interrupt service, while manual-only recovery may increase restoration time. Administrative access does not itself provide availability. Architects should determine availability requirements from business impact and then design redundancy and failover mechanisms that meet those requirements.<\/span><\/p>\n<h3><b>Question 77<\/b><\/h3>\n<p><b>Which architectural capability helps an organization determine whether an identity, device, or application should be trusted at a particular moment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Continuous risk evaluation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent trust assignment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static network location<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Continuous risk evaluation allows security decisions to change as relevant conditions change. A user&#8217;s risk, device state, authentication context, or application behavior can change after initial access has been granted. A Zero Trust architecture therefore benefits from mechanisms that can reevaluate access rather than relying on permanent trust. Static network location and shared credentials provide limited context and can create excessive trust. Continuous evaluation supports adaptive security and helps organizations respond when the security posture of an identity or device changes.<\/span><\/p>\n<h3><b>Question 78<\/b><\/h3>\n<p><b>A company wants to ensure that security policies are enforced consistently across multiple Azure subscriptions. Which architectural capability should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy and centralized governance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separate undocumented configurations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual configuration on every resource<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator passwords<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Policy can help organizations enforce or assess compliance with defined requirements across Azure resources. When combined with centralized governance structures, it can provide consistency across subscriptions and resource groups while allowing appropriate delegation. Manual configuration of every resource is difficult to maintain at scale and can result in configuration drift. Shared administrator passwords weaken accountability and security. Policy-based governance helps architects translate organizational requirements into repeatable controls that can be monitored over time.<\/span><\/p>\n<h3><b>Question 79<\/b><\/h3>\n<p><b>Which architecture capability helps detect when cloud resources drift away from an approved security configuration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Continuous configuration assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">One-time manual review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling configuration monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous resource administration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Continuous configuration assessment helps identify when resources no longer match approved security requirements or organizational baselines. Configuration drift can occur because of administrative changes, automation errors, application deployments, or other operational activities. Detecting drift promptly allows security teams to investigate and remediate deviations before they create significant exposure. A one-time review provides only a snapshot and may miss changes that occur later. Disabling monitoring or allowing anonymous administration further reduces visibility and accountability.<\/span><\/p>\n<h3><b>Question 80<\/b><\/h3>\n<p><b>An organization is defining security architecture standards for new cloud workloads. Which approach best supports repeatable and consistent deployments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security architecture patterns and reusable baselines<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Designing every workload independently<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allowing unrestricted configuration choices<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Avoiding documented security requirements<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security architecture patterns and reusable baselines provide standardized approaches that teams can apply when designing new workloads. They can define expectations for identity, networking, logging, encryption, access control, monitoring, and other security capabilities. Reusable patterns improve consistency and reduce the likelihood that teams overlook important controls. Designing every workload independently can produce inconsistent security and increase engineering effort. Undocumented or unrestricted configurations also make governance and compliance more difficult. Standardized patterns should remain adaptable to workload-specific risks and requirements.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-100 Exam Dumps and Practice Test Dumps &nbsp; Question 61 An organization wants to replace several overlapping security products with a platform that provides integrated endpoint detection, identity protection, email security, and cloud application signals. Which architectural approach should be considered? Security consolidation through an integrated XDR platform Separate unmanaged security products [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17605"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17605"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17605\/revisions"}],"predecessor-version":[{"id":17606,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17605\/revisions\/17606"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17605"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17605"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17605"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}