{"id":17609,"date":"2026-09-21T10:31:37","date_gmt":"2026-09-21T10:31:37","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17609"},"modified":"2026-09-21T10:31:37","modified_gmt":"2026-09-21T10:31:37","slug":"microsoft-sc-100-practice-test-questions-and-exam-dumps-part6-q101-120","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-100-practice-test-questions-and-exam-dumps-part6-q101-120\/","title":{"rendered":"Microsoft SC-100 Practice Test Questions and Exam Dumps Part6 Q101-120"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-100-exam-dumps\"><b>Microsoft SC-100 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 101<\/b><\/h3>\n<p><b>Which Microsoft capability allows administrators to manage privileged roles through temporary elevation rather than permanent assignment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Cloud Apps<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Sentinel<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management helps organizations manage, control, and monitor privileged roles. Instead of keeping administrators permanently assigned to sensitive roles, eligible users can activate privileges when needed for an approved period. This reduces standing administrative access and limits the opportunity for misuse or compromise. PIM can also support approval workflows, justification, notifications, and auditing. These capabilities make it useful for implementing least privilege and reducing risks associated with highly privileged identities across cloud environments.<\/span><\/p>\n<h3><b>Question 102<\/b><\/h3>\n<p><b>A security architect wants authentication requirements to become stronger when a user attempts to access highly sensitive resources. Which capability supports this design?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication strengths<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Address Translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage replication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authentication strengths allow organizations to define specific authentication methods that must be used for particular access scenarios. A security architect can require stronger methods for sensitive applications or privileged operations while using appropriate authentication requirements for lower-risk resources. This supports risk-based Zero Trust architecture because authentication requirements can be aligned with the sensitivity of the resource. Network translation, load balancing, and storage replication serve different architectural purposes and do not directly determine the strength of user authentication.<\/span><\/p>\n<h3><b>Question 103<\/b><\/h3>\n<p><b>Which Microsoft Entra capability can package resources and access rights so users can request access to a defined collection of organizational resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Entitlement management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra entitlement management helps organizations manage access to resources through access packages. An access package can group resources and define policies for requesting, approving, reviewing, and eventually removing access. This approach helps organizations manage access consistently while reducing manual administration. Conditional Access focuses on access conditions, access reviews help verify existing permissions, and ID Protection focuses on identity risks. Entitlement management is particularly useful when users need controlled access to multiple resources based on business roles, projects, or other defined requirements.<\/span><\/p>\n<h3><b>Question 104<\/b><\/h3>\n<p><b>An organization needs to allow external partners to collaborate with employees while maintaining governance over their access to company resources. Which capability is most relevant?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Monitor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra B2B collaboration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra B2B collaboration allows organizations to work with external users while maintaining control over access to organizational resources. External identities can be governed through authentication, authorization, Conditional Access, lifecycle controls, and access reviews. This provides a structured alternative to creating unmanaged internal accounts for partners. Azure Firewall and Azure Monitor provide infrastructure and monitoring capabilities, while Defender for Endpoint protects devices. External collaboration should still follow least privilege and should provide only the resources required for the partner&#8217;s business responsibilities.<\/span><\/p>\n<h3><b>Question 105<\/b><\/h3>\n<p><b>Which architecture principle requires every access request to be evaluated according to identity, resource, and relevant context rather than being trusted automatically?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero Trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network perimeter trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implicit authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat network architecture<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero Trust requires organizations to avoid implicit trust and evaluate access based on identity, resource, device, application, risk, and other relevant signals. Authentication alone does not automatically grant unrestricted access. Instead, authorization should be continuously evaluated according to organizational policies and the sensitivity of the requested resource. Perimeter-based and flat-network approaches may assume greater trust after a user or device enters a network. Zero Trust reduces this assumption and helps limit unauthorized access and lateral movement across modern hybrid environments.<\/span><\/p>\n<h3><b>Question 106<\/b><\/h3>\n<p><b>Which Azure service is designed to provide a centralized platform for managing cryptographic keys, secrets, and certificates?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Virtual Network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Key Vault provides centralized management of secrets, cryptographic keys, and certificates. Centralizing these sensitive assets helps organizations avoid embedding secrets directly into application code or configuration files. Key Vault can also integrate with identity and access controls so that applications and administrators receive only the permissions they require. Azure Virtual Network provides network connectivity, Azure Bastion supports secure administrative access to virtual machines, and Azure Front Door provides application delivery capabilities. Secure key and secret management is a core component of cloud security architecture.<\/span><\/p>\n<h3><b>Question 107<\/b><\/h3>\n<p><b>A company wants to ensure that security policies are consistently applied across multiple Azure subscriptions. Which capability is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Policy helps organizations define and enforce or assess rules for Azure resources. When combined with appropriate management-group and subscription structures, it can provide consistent governance across a large cloud environment. Policies can address requirements such as allowed resource configurations, locations, tagging, security settings, and compliance conditions. Azure DNS, Load Balancer, and Storage serve networking, traffic distribution, and data-storage functions rather than centralized configuration governance. Policy-based governance is therefore important when security requirements must be applied consistently across multiple environments.<\/span><\/p>\n<h3><b>Question 108<\/b><\/h3>\n<p><b>Which control is most appropriate for protecting web applications from common HTTP-based attacks such as SQL injection and cross-site scripting?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure VPN Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure ExpressRoute<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Web Application Firewall, or WAF, is designed to inspect web traffic and help protect applications against common application-layer attacks. Azure WAF can provide protection against threats such as SQL injection and cross-site scripting when appropriate rules and configurations are applied. VPN Gateway and ExpressRoute primarily address connectivity, while Azure DNS provides name-resolution services. A WAF should be part of a broader application security architecture that also includes secure coding, identity controls, vulnerability management, monitoring, and appropriate network protections.<\/span><\/p>\n<h3><b>Question 109<\/b><\/h3>\n<p><b>A security architect is designing an Azure environment where workloads should communicate privately with platform services without exposing those services through public endpoints. Which capability should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private Link<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Public IP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet-facing load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public DNS delegation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Private Link enables private connectivity to supported Azure services and other resources through private endpoints. This can reduce exposure by keeping traffic on private network paths rather than requiring workloads to communicate with services through publicly accessible endpoints. Public IP addresses and internet-facing load balancing may increase exposure depending on their use. Public DNS delegation is a naming capability rather than a private connectivity mechanism. Private connectivity should be designed alongside network segmentation, DNS resolution, access controls, and monitoring.<\/span><\/p>\n<h3><b>Question 110<\/b><\/h3>\n<p><b>Which architectural pattern commonly separates shared network security services from application workloads in Azure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-subnet architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat virtual network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hub-and-spoke architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unsegmented public network<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hub-and-spoke architecture separates shared services and network security functions in a central hub while placing application workloads in separate spoke networks. The hub can host services such as centralized connectivity, firewalling, monitoring, and other shared capabilities. Spokes can then be segmented according to applications, environments, or business requirements. This approach can improve isolation and governance compared with a flat network. The exact design should account for traffic flows, dependencies, administrative boundaries, performance, and organizational security requirements.<\/span><\/p>\n<h3><b>Question 111<\/b><\/h3>\n<p><b>Which Microsoft service is primarily focused on endpoint detection, investigation, and response capabilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Governance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint provides endpoint security capabilities designed to help organizations detect, investigate, and respond to threats affecting devices. It can provide security telemetry, threat detection, investigation capabilities, and response actions for supported endpoints. Microsoft Purview focuses primarily on data governance, compliance, and information protection. Entra ID Governance addresses identity lifecycle and access governance, while Azure Policy focuses on resource governance. Endpoint security should be integrated with identity, application, network, and security operations controls for broader protection.<\/span><\/p>\n<h3><b>Question 112<\/b><\/h3>\n<p><b>An organization wants security analysts to automatically execute predefined actions after a specific alert or incident occurs. Which Microsoft Sentinel capability supports this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Watchlists<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Playbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data connectors<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel playbooks provide automation capabilities that can execute predefined actions in response to security events. They can be used to integrate Sentinel with other services and automate tasks such as notifications, enrichment, ticket creation, or selected response activities. Workbooks are primarily used for visualization and analysis, watchlists provide reference data for analytics, and data connectors bring security information into Sentinel. Automation can improve response consistency and speed while reducing repetitive manual work for security operations teams.<\/span><\/p>\n<h3><b>Question 113<\/b><\/h3>\n<p><b>Which Microsoft Sentinel component defines the logic used to identify potentially suspicious activity in collected security data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Analytics rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Watchlists<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data retention settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Analytics rules in Microsoft Sentinel define detection logic that can identify potentially suspicious events or patterns in collected data. When configured appropriately, these rules can generate alerts or incidents for investigation by security teams. Workbooks provide visualization and reporting, while watchlists supply reference information that can be incorporated into queries and detections. Retention settings determine how long data remains available rather than defining the primary detection logic. Well-designed analytics rules should reflect relevant threats, organizational risks, and available telemetry.<\/span><\/p>\n<h3><b>Question 114<\/b><\/h3>\n<p><b>Which security architecture capability helps determine whether an organization&#8217;s controls continue to operate effectively as threats and business requirements change?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static documentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Continuous security assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent exceptions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabled monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Continuous security assessment helps organizations evaluate whether controls remain effective as technology, threats, configurations, and business requirements change. Security architecture should not be treated as a one-time implementation because new vulnerabilities, services, regulations, and attack techniques can create new risks. Ongoing assessment can include configuration reviews, security testing, monitoring, control validation, and risk analysis. Static documentation alone cannot confirm that controls remain effective. Permanent exceptions and disabled monitoring can create gaps that remain undetected for extended periods.<\/span><\/p>\n<h3><b>Question 115<\/b><\/h3>\n<p><b>A development team wants applications to obtain Azure resources without storing long-lived passwords or secrets in source code. Which capability is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Managed identities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared service passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hard-coded access keys<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public application credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Managed identities allow supported Azure resources and applications to authenticate to services without requiring developers to store credentials directly in application code. Azure can manage the identity credentials, reducing the need for long-lived secrets that may be accidentally exposed. Shared passwords, hard-coded keys, and public credentials create greater security risks and complicate credential rotation. Managed identities should still be assigned only the permissions required by the workload. Their use supports secure workload identity architecture and reduces unnecessary secret-management responsibilities.<\/span><\/p>\n<h3><b>Question 116<\/b><\/h3>\n<p><b>Which practice helps protect a software delivery pipeline from unauthorized changes to deployment processes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared pipeline administrator accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted developer permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pipeline access controls and approval gates<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Publicly accessible build credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Pipeline access controls and approval gates can restrict who is permitted to modify build and deployment processes and can require additional authorization before sensitive changes reach production. This helps protect the software supply chain from unauthorized modifications. Shared administrator accounts weaken accountability, unrestricted permissions increase the potential impact of compromised identities, and publicly accessible credentials create severe security exposure. Secure DevOps architecture should also consider source-control protection, secret management, dependency security, artifact integrity, logging, and separation of duties.<\/span><\/p>\n<h3><b>Question 117<\/b><\/h3>\n<p><b>Which security control is designed to identify sensitive information before it is shared through supported communication or collaboration channels?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Data Loss Prevention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Data Loss Prevention helps identify and protect sensitive information according to defined organizational policies. DLP policies can detect sensitive data patterns and apply actions designed to reduce inappropriate sharing or transmission. Azure Firewall focuses on network traffic control, Azure Bastion provides secure administrative connectivity, and Defender for Endpoint focuses on endpoint security. DLP should be aligned with data classification, business requirements, regulatory obligations, and user workflows so that protection is effective without unnecessarily disrupting legitimate business activity.<\/span><\/p>\n<h3><b>Question 118<\/b><\/h3>\n<p><b>An organization needs to protect critical Azure applications from a regional outage. Which architecture approach should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-region deployment only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-region redundancy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">One virtual machine without backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Centralized single point of failure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cross-region redundancy can help maintain application availability when a regional failure affects the primary deployment location. Depending on application requirements, this may involve deploying workloads, data, or supporting services across multiple regions and implementing appropriate failover mechanisms. A single-region design provides less resilience against regional outages. A single virtual machine or centralized single point of failure can create additional availability risks. The architecture should consider application dependencies, recovery objectives, data consistency, failover testing, cost, and regional service availability.<\/span><\/p>\n<h3><b>Question 119<\/b><\/h3>\n<p><b>Which governance practice provides a structured way to document who is responsible for security decisions, controls, and operational activities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RACI responsibility mapping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public network access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A RACI responsibility matrix identifies who is Responsible, Accountable, Consulted, and Informed for defined activities or decisions. In security architecture, this can clarify ownership for policies, incident response, access approvals, risk decisions, control implementation, and ongoing monitoring. Clear responsibility reduces gaps caused by assumptions that another team owns a security activity. Encryption and load balancing provide technical capabilities, while public network access concerns connectivity. Governance structures should align responsibilities with organizational authority and operational processes.<\/span><\/p>\n<h3><b>Question 120<\/b><\/h3>\n<p><b>A security architecture review identifies a control that cannot currently be implemented because of a legacy application dependency. What should the architect do first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore the dependency<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove all security requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Grant unrestricted access permanently<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Document the exception, assess the risk, and define compensating controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When a required security control cannot immediately be implemented because of a legitimate technical dependency, the exception should be documented and its associated risk assessed. The architect should then determine appropriate compensating controls and establish ownership, approval, and a review or remediation timeline. Ignoring the dependency or removing security requirements creates unmanaged risk, while permanent unrestricted access may unnecessarily increase exposure. A formal exception process allows the organization to balance business constraints with security objectives while maintaining accountability and visibility.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-100 Exam Dumps and Practice Test Dumps. &nbsp; Question 101 Which Microsoft capability allows administrators to manage privileged roles through temporary elevation rather than permanent assignment? Microsoft Purview Microsoft Entra Privileged Identity Management Microsoft Defender for Cloud Apps Microsoft Sentinel Correct Answer: 2 Explanation Microsoft Entra Privileged Identity Management helps organizations manage, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17609"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17609"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17609\/revisions"}],"predecessor-version":[{"id":17610,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17609\/revisions\/17610"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17609"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17609"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17609"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}