{"id":17607,"date":"2026-09-21T10:31:11","date_gmt":"2026-09-21T10:31:11","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17607"},"modified":"2026-09-21T10:31:11","modified_gmt":"2026-09-21T10:31:11","slug":"microsoft-sc-100-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-100-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"Microsoft SC-100 Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-100-exam-dumps\"><b>Microsoft SC-100 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 81<\/b><\/h3>\n<p><b>A security architect wants to ensure that sensitive workloads are protected even if a user&#8217;s credentials are compromised. Which combination provides the strongest architectural foundation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege, segmentation, and continuous monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator accounts and broad permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perimeter security without identity controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent access for authenticated users<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege limits what a compromised identity can access, segmentation restricts movement between resources, and continuous monitoring helps detect suspicious activity. Together, these controls reduce the potential impact of credential compromise and support the Zero Trust assumption that a breach may occur. Broad permissions and shared accounts increase the potential blast radius, while perimeter-only controls may not protect cloud or remote resources adequately. Permanent access also creates unnecessary exposure. A layered architecture should combine identity, resource, network, and monitoring controls.<\/span><\/p>\n<h3><b>Question 82<\/b><\/h3>\n<p><b>Which Microsoft capability can provide unified visibility into security incidents across identities, endpoints, applications, and other Microsoft security services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender XDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Excel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft SharePoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft PowerPoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender XDR correlates security signals across multiple Microsoft security products and domains. This unified approach can help analysts investigate incidents that involve identities, endpoints, email, applications, and other resources. Instead of investigating every alert independently, security teams can gain broader context about related activities. Excel, SharePoint, and PowerPoint are productivity and collaboration services and do not provide the same cross-domain security detection and response capabilities. XDR can therefore be an important part of an integrated security operations architecture.<\/span><\/p>\n<h3><b>Question 83<\/b><\/h3>\n<p><b>An organization wants to enforce security controls before users can access sensitive cloud applications. Which architectural model is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity-centric access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network location-based trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous application access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat internal networking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity-centric access control evaluates who is requesting access and can incorporate device, risk, application, and other contextual information. This model aligns with Zero Trust because access decisions are based on verified identity and relevant conditions rather than simply assuming trust based on network location. Anonymous access and flat networking increase exposure, while location-based trust becomes less effective when applications are hosted in cloud environments. Identity-centric controls can also support stronger authorization and least-privilege access to sensitive applications.<\/span><\/p>\n<h3><b>Question 84<\/b><\/h3>\n<p><b>Which Microsoft service can help protect identities by detecting risky users and risky authentication events?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Cloud<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra ID Protection provides capabilities for detecting and responding to identity-related risks, including risky users and risky sign-in activity. These signals can be used with Conditional Access to apply additional controls when authentication risk increases. Intune focuses on endpoint management, Defender for Cloud focuses on cloud security posture and workload protection, and Purview focuses on data governance and compliance. Identity risk detection is important in Zero Trust because authentication decisions should account for the security context surrounding an identity.<\/span><\/p>\n<h3><b>Question 85<\/b><\/h3>\n<p><b>A company wants to prevent users from accessing sensitive applications unless their devices meet defined security requirements. Which architecture combination is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device compliance and Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS filtering and file compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation and load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Email archiving and document sharing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Device compliance can evaluate whether an endpoint meets organizational requirements, while Conditional Access can use that information when making access decisions. Together, these capabilities can prevent noncompliant devices from accessing sensitive resources or require additional controls. DNS filtering and load balancing address different technical concerns, while email archiving and document sharing do not provide equivalent device-based access enforcement. This architecture supports Zero Trust by incorporating device health into authorization decisions rather than assuming that every authenticated device is trustworthy.<\/span><\/p>\n<h3><b>Question 86<\/b><\/h3>\n<p><b>Which security architecture capability helps identify whether an application has been granted more permissions than its business function requires?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permission and entitlement review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted administrative access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared service credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent role assignments<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Permission and entitlement reviews help organizations determine whether users, applications, and service identities have permissions beyond what their business functions require. This supports least privilege and can reduce exposure caused by excessive access. Shared credentials and permanent broad roles make it harder to determine which permissions are actually required and increase the consequences of compromise. Regular reviews should consider changes in business responsibilities, application functionality, and organizational risk. They are particularly important for high-value resources and privileged identities.<\/span><\/p>\n<h3><b>Question 87<\/b><\/h3>\n<p><b>An organization wants to protect its security architecture from compromised administrator credentials. Which control can reduce the duration of privileged access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Just-in-time privileged access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent administrator roles<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous administration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Just-in-time privileged access provides elevated permissions only when they are required and for an approved period. This reduces the time during which powerful privileges are available and therefore limits the exposure associated with compromised administrative credentials. Permanent roles provide attackers with a larger opportunity to abuse stolen credentials. Shared accounts also reduce accountability, while anonymous administration removes useful identity information. Just-in-time access should be combined with approval, authentication, monitoring, and auditing controls for sensitive administrative operations.<\/span><\/p>\n<h3><b>Question 88<\/b><\/h3>\n<p><b>Which architecture approach helps protect identities from credential theft by reducing reliance on traditional passwords?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passwordless authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password reuse<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted legacy authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Passwordless authentication can reduce risks associated with password theft, reuse, phishing, and credential stuffing by using stronger authentication methods such as security keys, platform credentials, or supported biometric mechanisms. Although passwordless authentication does not eliminate every identity risk, it can significantly improve the security of authentication architecture when properly implemented. Shared passwords and password reuse increase exposure, while unrestricted legacy authentication may provide weaker protection. Passwordless strategies should be integrated with Conditional Access, device security, and identity governance.<\/span><\/p>\n<h3><b>Question 89<\/b><\/h3>\n<p><b>A security architect is evaluating whether an organization can identify every privileged identity across its cloud environment. Which capability is most important?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privileged identity inventory and governance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous administrator access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unmanaged service accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged identity inventory and governance provide visibility into which users, applications, and other identities possess elevated permissions. Without this visibility, organizations may have forgotten administrative accounts, excessive permissions, or unmanaged service identities that create security risks. Governance can include role reviews, approval processes, just-in-time access, monitoring, and lifecycle management. Anonymous administration and shared credentials reduce accountability, while unmanaged service accounts may retain access long after it is needed. Maintaining an accurate privileged identity inventory is essential for effective Zero Trust governance.<\/span><\/p>\n<h3><b>Question 90<\/b><\/h3>\n<p><b>Which security architecture capability helps prevent unauthorized use of an application identity after the workload no longer requires access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity lifecycle management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent service permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared application credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted role assignments<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity lifecycle management ensures that identities and their permissions are created, modified, reviewed, and removed according to defined requirements. For application identities, this can prevent abandoned service principals, managed identities, or workload accounts from retaining unnecessary access. Permanent permissions and shared credentials increase the likelihood that access remains active after the original requirement disappears. Lifecycle management supports least privilege by keeping access aligned with current business and technical needs. It should include ownership, periodic review, and appropriate deprovisioning procedures.<\/span><\/p>\n<h3><b>Question 91<\/b><\/h3>\n<p><b>A company needs to determine which applications are being used by employees without formal approval. Which Microsoft security capability can provide visibility into cloud application usage?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Cloud Apps<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Sentinel alone<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Cloud Apps can help organizations discover and assess cloud application usage, including services that may not be formally approved by security teams. This visibility can support governance decisions and help identify applications that introduce security, compliance, or data-protection risks. Defender Antivirus focuses on endpoint malware protection, while Intune focuses on endpoint and application management. Sentinel provides broad security analytics but is not specifically designed as the primary cloud application discovery platform. Cloud application visibility is important as SaaS adoption increases.<\/span><\/p>\n<h3><b>Question 92<\/b><\/h3>\n<p><b>Which architecture capability helps ensure that security incidents can be investigated after they occur?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Centralized logging and audit trails<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabled event collection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Short-term undocumented logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous administrative actions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized logging and audit trails provide the evidence needed to investigate security events, understand what happened, identify affected resources, and support incident response. Logs should be protected against unauthorized modification and retained according to organizational, legal, and compliance requirements. Disabling event collection or retaining undocumented logs creates significant visibility gaps. Anonymous administrative actions also reduce accountability. Security architecture should therefore define what events need to be collected, where they are stored, how long they are retained, and who can access them.<\/span><\/p>\n<h3><b>Question 93<\/b><\/h3>\n<p><b>An organization wants to prevent unauthorized users from changing security configurations in Azure. Which architectural capability should be applied?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Role-based access control with policy governance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared global administrator credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted contributor permissions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Role-based access control limits administrative permissions according to defined responsibilities, while policy governance can enforce or assess required configurations. Together, these capabilities reduce the likelihood that unauthorized users can make security-sensitive changes. Shared global administrator credentials create significant accountability and compromise risks. Anonymous access is inappropriate for administrative functions, and unrestricted contributor permissions may provide more access than users require. Administrative roles should be carefully scoped, reviewed, monitored, and elevated only when necessary.<\/span><\/p>\n<h3><b>Question 94<\/b><\/h3>\n<p><b>Which architectural capability can help protect data if storage media or cloud storage credentials are compromised?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Plaintext storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared storage accounts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Encryption helps protect data by making information unreadable without the appropriate cryptographic key or mechanism. It can provide an additional protection layer if storage media, backups, or other storage locations are exposed. Plaintext storage and open permissions increase the consequences of unauthorized access. Shared storage accounts can also weaken accountability and make access control more difficult. Encryption should be designed alongside identity, access control, key management, data classification, and monitoring because encryption alone does not prevent unauthorized access.<\/span><\/p>\n<h3><b>Question 95<\/b><\/h3>\n<p><b>A security architect wants to reduce the impact of compromised credentials by requiring stronger authentication for sensitive resources. Which control should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing-resistant multifactor authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-factor authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password reuse<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Phishing-resistant multifactor authentication provides stronger protection against credential theft because it uses authentication mechanisms designed to resist common phishing techniques. This can be particularly valuable for privileged accounts and sensitive applications. Shared passwords and password reuse increase credential exposure, while single-factor authentication provides fewer protections if credentials are stolen. Authentication strength should be selected according to resource sensitivity and risk. Combining strong authentication with device controls, Conditional Access, and least privilege creates a more resilient identity architecture.<\/span><\/p>\n<h3><b>Question 96<\/b><\/h3>\n<p><b>Which security architecture practice helps determine whether users still require access after changing roles within an organization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Periodic access reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent access assignments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous permissions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Periodic access reviews help verify that permissions remain appropriate as users change roles, projects, responsibilities, or organizational units. Without regular review, users may accumulate access that was necessary for previous responsibilities but is no longer required. Permanent assignments can therefore create privilege accumulation over time. Shared credentials and anonymous permissions further reduce accountability. Access reviews should focus especially on sensitive applications, privileged roles, and high-value data. They support identity governance and the least-privilege principle within a broader Zero Trust architecture.<\/span><\/p>\n<h3><b>Question 97<\/b><\/h3>\n<p><b>An organization wants to limit the ability of a compromised endpoint to communicate with critical servers. Which architecture control is most relevant?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal internal access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat networking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation separates systems into controlled communication zones and can restrict which endpoints are allowed to communicate with critical resources. If an endpoint is compromised, segmentation can prevent or limit direct access to sensitive servers and reduce lateral movement. Flat networks and universal internal access provide fewer restrictions, while shared administrator credentials can increase the consequences of endpoint compromise. Segmentation should be designed around application dependencies, business requirements, and security risk so that necessary communications remain available while unnecessary paths are restricted.<\/span><\/p>\n<h3><b>Question 98<\/b><\/h3>\n<p><b>Which architectural approach allows an organization to apply different security controls according to the sensitivity of data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification and labeling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identical protection for every file<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted public sharing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous data access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data classification and labeling allow organizations to identify information according to sensitivity, business value, or regulatory requirements. Security policies can then apply appropriate controls based on those classifications. Highly sensitive information may require stronger encryption, access restrictions, monitoring, or data-loss prevention policies than publicly available content. Applying identical protection to every file may be inefficient, while public sharing and anonymous access increase exposure. Classification provides the context required for risk-based data protection and governance.<\/span><\/p>\n<h3><b>Question 99<\/b><\/h3>\n<p><b>A company wants to reduce the security impact of a compromised endpoint by preventing it from reaching unrelated workloads. Which Zero Trust concept does this most directly support?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assume breach<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implicit trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perimeter-only security<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The assume-breach principle encourages organizations to design environments so that compromise of one device, identity, or workload does not automatically result in broad access. Segmentation, least privilege, monitoring, and strong authorization can limit what a compromised endpoint can reach. Implicit trust and open access have the opposite effect by allowing broader connectivity. Perimeter-only security also provides limited protection once an attacker has gained internal access. Designing for assumed compromise helps reduce lateral movement and overall blast radius.<\/span><\/p>\n<h3><b>Question 100<\/b><\/h3>\n<p><b>Which activity should occur after implementing a major security architecture change to determine whether the expected security outcome was achieved?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Validation and effectiveness assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Immediate removal of monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent administrator access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling security policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Validation and effectiveness assessment determine whether a newly implemented architecture or control actually meets its intended security objectives. This can involve testing configurations, reviewing telemetry, measuring policy enforcement, checking access behavior, and confirming that business requirements remain satisfied. Removing monitoring or disabling security policies would eliminate important safeguards. Permanent administrator access is unrelated to validating architectural outcomes. Security architecture should therefore include feedback mechanisms so that implemented controls can be measured, improved, and adjusted when they do not provide the expected level of protection.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-100 Exam Dumps and Practice Test Dumps. &nbsp; Question 81 A security architect wants to ensure that sensitive workloads are protected even if a user&#8217;s credentials are compromised. Which combination provides the strongest architectural foundation? Least privilege, segmentation, and continuous monitoring Shared administrator accounts and broad permissions Perimeter security without identity controls [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17607"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17607"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17607\/revisions"}],"predecessor-version":[{"id":17608,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17607\/revisions\/17608"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17607"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17607"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17607"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}