{"id":17611,"date":"2026-09-21T10:31:55","date_gmt":"2026-09-21T10:31:55","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17611"},"modified":"2026-09-21T10:31:55","modified_gmt":"2026-09-21T10:31:55","slug":"microsoft-sc-100-practice-test-questions-and-exam-dumps-part7-q121-140","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-100-practice-test-questions-and-exam-dumps-part7-q121-140\/","title":{"rendered":"Microsoft SC-100 Practice Test Questions and Exam Dumps Part7 Q121-140"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-100-exam-dumps\"><b>Microsoft SC-100 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 121<\/b><\/h3>\n<p><b>Which Microsoft Entra capability allows an organization to manage the lifecycle of users and automate identity-related processes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Cloud<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Lifecycle Workflows<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Sentinel<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Lifecycle Workflows helps automate identity lifecycle processes such as onboarding, role changes, and offboarding. Automating these activities can reduce delays and help ensure that access is adjusted when a user&#8217;s organizational status changes. This is particularly important for preventing former employees or users with changed responsibilities from retaining unnecessary permissions. Defender for Cloud focuses on cloud security, Azure Firewall controls network traffic, and Sentinel provides security analytics. Lifecycle automation supports stronger identity governance and reduces manual administrative errors.<\/span><\/p>\n<h3><b>Question 122<\/b><\/h3>\n<p><b>An organization wants to protect highly privileged administrative accounts from compromised everyday workstations. Which architecture should the security architect consider?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privileged Access Workstations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator desktops<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public kiosks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unmanaged personal devices<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged Access Workstations are dedicated or specially secured devices designed for sensitive administrative activities. Separating privileged operations from everyday browsing, email, and general-purpose work reduces the opportunities for malware or phishing attacks to compromise administrative credentials. Shared desktops and unmanaged personal devices provide weaker control over the security environment. A privileged access workstation strategy can be combined with strong authentication, just-in-time access, endpoint protection, and strict administrative policies to create a hardened privileged access architecture.<\/span><\/p>\n<h3><b>Question 123<\/b><\/h3>\n<p><b>Which Microsoft Entra feature can control whether users from another organization are allowed to collaborate with users in your tenant?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-tenant access settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage Explorer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cross-tenant access settings provide controls for managing collaboration and access relationships between Microsoft Entra tenants. Organizations can establish policies governing inbound and outbound access with external tenants and can apply trust settings where appropriate. This is useful for controlling business-to-business collaboration while maintaining organizational security requirements. Azure Backup and Storage Explorer serve different purposes, while Microsoft Purview focuses on data governance and compliance. Cross-tenant governance is particularly important when organizations regularly collaborate with external companies.<\/span><\/p>\n<h3><b>Question 124<\/b><\/h3>\n<p><b>A security architect wants to ensure that a compromised application cannot automatically access every database in the environment. Which design principle should be applied?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Broad application permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workload isolation and least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared database accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat resource access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Workload isolation and least privilege limit an application&#8217;s access to only the resources required for its intended function. If an application is compromised, these restrictions can reduce the number of databases and services that an attacker can reach. Broad permissions and shared accounts increase the potential blast radius, while flat resource access removes useful security boundaries. Workload identities should receive narrowly scoped permissions, and sensitive resources should be segmented where appropriate. This approach supports Zero Trust and reduces the impact of application compromise.<\/span><\/p>\n<h3><b>Question 125<\/b><\/h3>\n<p><b>Which security architecture capability provides a visual representation of security metrics and operational information for analysts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Sentinel workbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra B2B<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private Link<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel workbooks provide dashboards and visualizations that help security teams understand security data, trends, incidents, and operational metrics. They can combine information from different sources into views that support investigation and reporting. Entra B2B addresses external collaboration, Key Vault manages secrets and cryptographic material, and Private Link provides private network connectivity. Workbooks can help security teams identify patterns and communicate security information, although the quality of the resulting dashboard depends on the underlying telemetry and queries.<\/span><\/p>\n<h3><b>Question 126<\/b><\/h3>\n<p><b>Which capability helps a security operations team enrich Sentinel investigations with known indicators such as malicious IP addresses or domains?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat intelligence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource locks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat intelligence provides information about known or suspected malicious indicators that can be used to enrich security investigations and detections. In Microsoft Sentinel, threat intelligence can help analysts correlate events with indicators such as IP addresses, domains, URLs, or file hashes. This additional context can help prioritize investigations and identify potentially malicious activity. Azure Policy governs resource configurations, Azure Bastion provides secure administrative connectivity, and resource locks help prevent accidental changes. Threat intelligence should be evaluated for reliability, freshness, and relevance.<\/span><\/p>\n<h3><b>Question 127<\/b><\/h3>\n<p><b>An organization wants to prevent sensitive information from being copied to unauthorized cloud applications. Which architectural approach should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data loss prevention controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public sharing by default<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted application access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous file transfers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data loss prevention controls can identify sensitive information and apply policies designed to prevent inappropriate movement, sharing, or transmission. This can be particularly useful when employees use cloud applications to process organizational data. Public sharing and unrestricted application access increase the risk of unauthorized disclosure, while anonymous transfers weaken accountability. DLP should be based on data classification, business requirements, user roles, and applicable compliance obligations. Security architects should also consider user experience so that legitimate business activities are not unnecessarily blocked.<\/span><\/p>\n<h3><b>Question 128<\/b><\/h3>\n<p><b>Which Azure capability can help prevent accidental deletion or modification of important Azure resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Locks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Resource Locks can help protect resources against accidental deletion or modification by applying management restrictions at the resource or resource-group level. Locks are useful for protecting critical infrastructure and other resources where unintended administrative changes could cause outages or data loss. DNS provides name resolution, Front Door provides application delivery capabilities, and Load Balancer distributes network traffic. Resource locks should not be treated as a replacement for access control because authorized users and privileged identities still require appropriate governance.<\/span><\/p>\n<h3><b>Question 129<\/b><\/h3>\n<p><b>Which Microsoft Defender capability is specifically designed to detect threats involving on-premises Active Directory identities and domain controllers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Identity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Office 365<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Cloud Apps<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Cloud<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Identity monitors signals from on-premises identity environments such as Active Directory to help detect identity-related threats and suspicious activities. It can help identify techniques involving domain controllers, compromised accounts, credential abuse, and lateral movement. Defender for Office 365 focuses on email and collaboration threats, Defender for Cloud Apps provides cloud application security capabilities, and Defender for Cloud addresses cloud and hybrid workload security. Defender for Identity is especially relevant in hybrid architectures where on-premises identity infrastructure remains important.<\/span><\/p>\n<h3><b>Question 130<\/b><\/h3>\n<p><b>A security architect needs to ensure that administrators cannot directly use highly privileged accounts for routine email and web browsing. Which approach supports this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separate privileged and standard identities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent global administrator sessions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted browser access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separating privileged and standard identities reduces the chance that highly privileged credentials will be exposed during routine activities such as email, web browsing, or document handling. Administrators can use standard accounts for normal work and privileged identities only when administrative tasks require elevated permissions. Shared accounts and unrestricted privileged sessions increase exposure and reduce accountability. This model works particularly well when combined with privileged access workstations, strong authentication, just-in-time elevation, monitoring, and administrative session controls.<\/span><\/p>\n<h3><b>Question 131<\/b><\/h3>\n<p><b>Which Azure service can provide distributed denial-of-service protection for applications and network resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Automation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure DDoS Protection is designed to help protect supported Azure resources against distributed denial-of-service attacks. It provides capabilities intended to detect and mitigate attack traffic while helping maintain application and network availability. Key Vault protects secrets and cryptographic assets, Azure Policy manages resource governance, and Azure Automation provides automation capabilities. DDoS protection should be considered as part of a broader availability architecture that includes resilient application design, monitoring, capacity planning, and appropriate network controls.<\/span><\/p>\n<h3><b>Question 132<\/b><\/h3>\n<p><b>Which architectural control is most appropriate for securely connecting administrators to Azure virtual machines without exposing management ports directly to the public internet?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Bastion provides managed, browser-based connectivity to Azure virtual machines without requiring direct exposure of common management ports such as RDP or SSH through public IP addresses. This can reduce the attack surface associated with publicly accessible administrative endpoints. Load Balancer distributes traffic, DNS provides name resolution, and Storage manages data. Bastion should still be combined with identity controls, strong authentication, least privilege, monitoring, and appropriate network segmentation to provide secure administrative access.<\/span><\/p>\n<h3><b>Question 133<\/b><\/h3>\n<p><b>A company wants to scan infrastructure-as-code templates for insecure configurations before deployment. Which DevSecOps practice should be implemented?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Infrastructure-as-code security scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual password sharing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Production-only testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Post-deployment documentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Infrastructure-as-code security scanning evaluates templates for potentially insecure configurations before resources are deployed. Identifying problems earlier allows development and security teams to correct issues before they become production vulnerabilities. This practice can examine areas such as excessive permissions, insecure network exposure, weak encryption settings, and noncompliant configurations. Production-only testing delays detection and may increase remediation costs. IaC scanning should be integrated into development and CI\/CD workflows and complemented by runtime configuration monitoring and policy enforcement.<\/span><\/p>\n<h3><b>Question 134<\/b><\/h3>\n<p><b>Which practice helps prevent application dependencies with known vulnerabilities from being introduced into production?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dependency scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling vulnerability management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared production credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual network configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dependency scanning evaluates software libraries and packages used by applications to identify known vulnerabilities and other security concerns. Integrating this process into development pipelines can help teams identify vulnerable components before applications are released. Disabling vulnerability management removes an important security control, while shared credentials and manual network configuration address unrelated concerns. Dependency scanning should be combined with secure development practices, software composition analysis, patch management, and appropriate policies for handling vulnerabilities that cannot immediately be remediated.<\/span><\/p>\n<h3><b>Question 135<\/b><\/h3>\n<p><b>Which control can help ensure that a production deployment cannot proceed until required security checks have successfully completed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security gates in CI\/CD pipelines<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted deployment permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual credential sharing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabled build validation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security gates can require defined checks to pass before a CI\/CD pipeline is allowed to continue toward production. Depending on the architecture, gates may evaluate code scanning, dependency vulnerabilities, infrastructure configuration, secrets detection, tests, approvals, or compliance requirements. Unrestricted deployment permissions and disabled validation increase the risk of insecure changes reaching production. Security gates should be designed according to risk and should provide clear exception processes when legitimate deployment requirements conflict with automated controls.<\/span><\/p>\n<h3><b>Question 136<\/b><\/h3>\n<p><b>Which Microsoft Purview capability is designed to apply persistent sensitivity information to documents and emails?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retention policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sensitivity labels<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">eDiscovery searches<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Sensitivity labels in Microsoft Purview help organizations classify and protect documents and emails according to their sensitivity. Depending on configuration, labels can be associated with protection settings such as encryption or usage restrictions. Retention policies address how long content should be retained, audit logs provide activity information, and eDiscovery supports investigation and legal discovery. Sensitivity labeling is therefore an important component of a data-centric security architecture because it helps organizations apply protection based on the information&#8217;s classification and business value.<\/span><\/p>\n<h3><b>Question 137<\/b><\/h3>\n<p><b>An organization wants to identify unusual behavior by users and entities using multiple security signals. Which Sentinel capability can support this objective?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User and Entity Behavior Analytics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Locks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private Link<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User and Entity Behavior Analytics, or UEBA, can help identify unusual patterns by establishing behavioral context for users and entities. In security operations, this can provide additional insight when investigating activities that may differ from normal behavior. UEBA can contribute to risk-based detection and investigation by considering relationships and behavioral patterns rather than relying only on individual events. Resource Locks, Private Link, and DNS provide infrastructure controls and do not perform behavioral analytics. UEBA should be interpreted alongside other security signals and organizational context.<\/span><\/p>\n<h3><b>Question 138<\/b><\/h3>\n<p><b>Which architecture strategy helps ensure that backup data cannot easily be altered or deleted by an attacker who compromises production credentials?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Immutable or protected backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared backup administrator accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent production access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted backup modification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Immutable or otherwise strongly protected backups can help prevent attackers from modifying or deleting recovery data after compromising production systems. This is particularly important during ransomware incidents, where attackers may attempt to destroy backups before encrypting production resources. Backup protection can include immutability, separate administrative controls, isolation, strong authentication, monitoring, and appropriate retention. Shared credentials and unrestricted modification increase risk. Backup architecture should be tested regularly to confirm that recovery procedures actually work when production systems are unavailable.<\/span><\/p>\n<h3><b>Question 139<\/b><\/h3>\n<p><b>Which architectural approach helps reduce the risk of a compromised cloud workload accessing secrets belonging to unrelated workloads?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Centralized shared administrator passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workload-specific identities and scoped permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Publicly accessible secret stores<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Common credentials for every application<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Workload-specific identities with narrowly scoped permissions ensure that each application or service receives only the access required for its function. If one workload is compromised, the attacker is less likely to obtain credentials or secrets belonging to unrelated applications. Shared administrator passwords and common credentials significantly increase the blast radius of a compromise. Public secret stores are also inappropriate for sensitive information. Combining workload identities with Key Vault, managed identities, least privilege, and monitoring creates a stronger application security architecture.<\/span><\/p>\n<h3><b>Question 140<\/b><\/h3>\n<p><b>A security architecture team needs to measure whether its controls are improving the organization&#8217;s security posture over time. Which approach is most useful?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security metrics and key risk indicators<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignoring security telemetry<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Measuring only infrastructure cost<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing security baselines<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security metrics and key risk indicators help organizations measure changes in security posture and determine whether controls are producing the intended outcomes. Useful measurements can include vulnerability exposure, privileged access, incident response times, policy compliance, control coverage, and unresolved security risks. Measuring only infrastructure cost does not provide sufficient security insight, while ignoring telemetry removes valuable evidence. Security metrics should be tied to business and security objectives so that architecture teams can identify gaps, prioritize improvements, and track progress over time.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-100 Exam Dumps and Practice Test Dumps. &nbsp; Question 121 Which Microsoft Entra capability allows an organization to manage the lifecycle of users and automate identity-related processes? Microsoft Defender for Cloud Microsoft Entra Lifecycle Workflows Azure Firewall Microsoft Sentinel Correct Answer: 2 Explanation Microsoft Entra Lifecycle Workflows helps automate identity lifecycle processes [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17611"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17611"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17611\/revisions"}],"predecessor-version":[{"id":17612,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17611\/revisions\/17612"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17611"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17611"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17611"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}