{"id":17613,"date":"2026-09-21T10:32:37","date_gmt":"2026-09-21T10:32:37","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17613"},"modified":"2026-09-21T10:32:37","modified_gmt":"2026-09-21T10:32:37","slug":"microsoft-sc-100-practice-test-questions-and-exam-dumps-part8-q141-160","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-100-practice-test-questions-and-exam-dumps-part8-q141-160\/","title":{"rendered":"Microsoft SC-100 Practice Test Questions and Exam Dumps Part8 Q141-160"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-100-exam-dumps\"><b>Microsoft SC-100 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 141<\/b><\/h3>\n<p><b>Which Microsoft Entra capability can help organizations automate the review and removal of unnecessary access to applications and resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Access Reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Access Reviews help organizations regularly verify whether users, groups, or other identities should continue to have access to resources. Reviewers can confirm, deny, or remove access according to organizational requirements. This helps prevent outdated permissions from accumulating over time, particularly for sensitive applications and external users. DDoS Protection, Defender for Endpoint, and Front Door provide different security or networking capabilities. Access reviews are an important identity governance control because access should remain aligned with current business responsibilities.<\/span><\/p>\n<h3><b>Question 142<\/b><\/h3>\n<p><b>Which architecture principle is most important when designing security controls for a critical business application?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Minimize all functionality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Align security requirements with business risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow unrestricted access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use identical controls for every application<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security architecture should align controls with the business risk associated with the application. Critical applications may require stronger authentication, stricter authorization, greater monitoring, resilience, and more comprehensive recovery capabilities than low-risk systems. Minimizing functionality without considering business requirements can create operational problems, while unrestricted access increases exposure. Applying exactly the same controls everywhere may also be inefficient. A risk-aligned approach helps security architects balance protection, availability, usability, compliance, and business objectives when designing application security.<\/span><\/p>\n<h3><b>Question 143<\/b><\/h3>\n<p><b>Which Azure service provides a managed firewall capability for controlling and inspecting network traffic in Azure environments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Monitor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Firewall provides a managed, cloud-based network security service that can control and inspect traffic according to configured rules and policies. It can be incorporated into centralized network architectures to control traffic flows between networks and other destinations. Key Vault protects cryptographic material and secrets, Monitor provides telemetry and monitoring capabilities, and Policy provides governance controls. Firewall architecture should be designed around traffic requirements, segmentation, routing, logging, application dependencies, and the organization&#8217;s overall security strategy.<\/span><\/p>\n<h3><b>Question 144<\/b><\/h3>\n<p><b>A security architect wants to ensure that only approved network traffic can leave sensitive workloads. Which design approach should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open outbound connectivity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted internet access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controlled egress architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Controlled egress architecture restricts outbound traffic from sensitive workloads according to defined security requirements. This can reduce the risk of data exfiltration, command-and-control communication, and unauthorized connections to external services. Depending on the environment, controls can include firewalls, network security rules, proxies, DNS filtering, private connectivity, and approved destination lists. Open outbound connectivity provides fewer restrictions and can increase exposure. Egress controls should be carefully designed so that required application dependencies remain functional while unnecessary communication paths are blocked.<\/span><\/p>\n<h3><b>Question 145<\/b><\/h3>\n<p><b>Which security architecture capability helps identify vulnerabilities in cloud resources and provides recommendations for improving their security posture?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Cloud<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Teams<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft SharePoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Cloud provides cloud security posture management capabilities that can identify security weaknesses and provide recommendations for improving resource configurations. It can help organizations assess security posture across supported cloud environments and identify areas requiring attention. Teams and SharePoint are collaboration services, while Azure DNS provides name-resolution functionality. Defender for Cloud can therefore contribute to continuous security assessment by helping security teams discover configuration gaps, prioritize recommendations, and improve the security posture of cloud workloads.<\/span><\/p>\n<h3><b>Question 146<\/b><\/h3>\n<p><b>Which Azure networking capability provides private connectivity to supported platform services through a private endpoint?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Public IP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private Endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Private Endpoint provides a network interface that connects privately to supported Azure services through a private IP address in a virtual network. This can help reduce exposure to the public internet and support private application architectures. Public IP addresses provide internet-facing connectivity, Load Balancer distributes network traffic, and Traffic Manager provides DNS-based traffic routing. Private endpoints should be integrated with appropriate DNS architecture, network access controls, identity controls, and monitoring to provide secure private connectivity.<\/span><\/p>\n<h3><b>Question 147<\/b><\/h3>\n<p><b>An organization needs a central location for security teams to collect and analyze telemetry from multiple sources. Which Microsoft service is designed for this purpose?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Sentinel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel is a cloud-native security information and event management platform that can collect, analyze, and correlate security data from multiple sources. It can support detection, investigation, incident management, automation, and threat hunting. Intune focuses on endpoint management, Purview focuses on data governance and compliance, and Entra ID provides identity services. Centralized security analytics are valuable because they allow organizations to correlate activity across different systems instead of investigating each security signal in isolation.<\/span><\/p>\n<h3><b>Question 148<\/b><\/h3>\n<p><b>Which security architecture practice helps ensure that application components cannot access resources outside their defined responsibilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workload isolation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal administrator access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Workload isolation separates application components and limits their ability to interact with unrelated resources. Combined with narrowly scoped permissions, isolation can reduce the impact of a compromised component and prevent unnecessary lateral movement. Shared permissions and universal administrator access increase the potential blast radius, while flat authorization provides fewer meaningful boundaries. Security architects should identify application dependencies and define required communication paths before implementing isolation. The resulting architecture should support legitimate functionality while restricting unnecessary access between components.<\/span><\/p>\n<h3><b>Question 149<\/b><\/h3>\n<p><b>Which approach is most appropriate for protecting secrets used by cloud applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Store secrets directly in source code<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use a centralized secret-management service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Publish secrets in configuration documentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Share one credential across applications<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A centralized secret-management service provides controlled storage and access to sensitive values such as passwords, API keys, certificates, and cryptographic material. Azure Key Vault is an example of such a service. Centralized management can support access control, auditing, rotation, and reduced exposure compared with embedding secrets directly in source code. Shared credentials and publicly documented secrets increase the consequences of compromise. Applications should retrieve only the secrets they require and should use managed identities or other secure authentication mechanisms where supported.<\/span><\/p>\n<h3><b>Question 150<\/b><\/h3>\n<p><b>Which security architecture concept describes using multiple independent security controls so that failure of one control does not expose the entire environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-layer security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implicit trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Defense in depth uses multiple layers of protection so that a failure or bypass of one security control does not automatically compromise the entire environment. Layers may include identity protection, endpoint security, network segmentation, application controls, data protection, monitoring, and incident response. Single-layer security creates greater dependence on one mechanism. Implicit trust and open access also reduce protection. Defense in depth should be designed carefully so that controls complement one another rather than creating unnecessary complexity or conflicting policies.<\/span><\/p>\n<h3><b>Question 151<\/b><\/h3>\n<p><b>A security architect wants to identify which business processes would be most affected by the loss of a specific application. Which activity should be performed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business impact analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint enrollment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Business impact analysis identifies the consequences of disruptions to applications, services, processes, and supporting resources. It can help determine business criticality, dependencies, acceptable downtime, and recovery requirements. This information is important when designing resilience, backup, disaster recovery, and availability strategies. Password rotation, DNS configuration, and endpoint enrollment address different security or operational requirements. Business impact analysis allows architects to prioritize protection and recovery investments according to the consequences of service disruption.<\/span><\/p>\n<h3><b>Question 152<\/b><\/h3>\n<p><b>Which Azure capability can provide centralized governance across a hierarchy of subscriptions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Management groups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Individual virtual machines<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage containers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private DNS zones<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure management groups provide a hierarchical structure above subscriptions and can help organizations apply governance consistently across groups of subscriptions. Policies and access controls can be organized at appropriate levels within the hierarchy. This is useful for large environments where security requirements need to be managed across multiple subscriptions while still allowing appropriate administrative delegation. Virtual machines, storage containers, and private DNS zones operate at different resource levels and do not provide the same organizational governance structure.<\/span><\/p>\n<h3><b>Question 153<\/b><\/h3>\n<p><b>Which security practice helps ensure that infrastructure changes are reviewed before they are introduced into a production environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted direct changes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Change control and approval<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabled logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Change control and approval processes help ensure that significant infrastructure modifications are reviewed for security, operational, and business impacts before implementation. These processes can include peer review, testing, authorization, documentation, and rollback planning. Unrestricted direct changes increase the risk of configuration errors and unauthorized modifications. Shared accounts reduce accountability, while disabled logging removes important evidence. Security architecture should integrate change management with identity governance, policy enforcement, monitoring, and automated deployment processes where appropriate.<\/span><\/p>\n<h3><b>Question 154<\/b><\/h3>\n<p><b>An organization wants to identify sensitive data stored across multiple repositories before deciding which protection policies to apply. What should be performed first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data discovery and classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public data sharing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential deletion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data discovery and classification help an organization understand what information exists, where it is stored, how sensitive it is, and which business or regulatory requirements apply. This information provides the foundation for selecting appropriate protection controls such as encryption, access restrictions, retention, and data loss prevention. Applying controls without understanding the underlying data can lead to gaps or unnecessary restrictions. Public sharing and load balancing do not provide data classification capabilities. A data-centric architecture should begin with visibility into information assets.<\/span><\/p>\n<h3><b>Question 155<\/b><\/h3>\n<p><b>Which Microsoft Purview capability helps organizations manage how long content should be retained or when it should be deleted?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retention policies and labels<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra B2B<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview retention capabilities help organizations define how long content should be retained and, where appropriate, when it can be deleted. Retention policies and labels can support organizational, legal, regulatory, and business requirements for information lifecycle management. Defender for Endpoint protects devices, Azure Bastion provides secure virtual machine administration, and Entra B2B supports external collaboration. Retention should be designed alongside classification, records management, privacy requirements, and data governance so that information is neither retained unnecessarily nor deleted prematurely.<\/span><\/p>\n<h3><b>Question 156<\/b><\/h3>\n<p><b>Which network architecture provides centralized connectivity and security services while allowing application networks to remain separated?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hub-and-spoke<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single public subnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unsegmented LAN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hub-and-spoke architecture places shared connectivity and security services in a central hub while application workloads can reside in separate spoke networks. This structure can support centralized inspection, connectivity, routing, and security controls while maintaining workload separation. A flat network provides fewer boundaries and can increase lateral movement opportunities. Public or unsegmented designs may expose resources unnecessarily. The hub-and-spoke model should be designed around traffic flows, application dependencies, administrative ownership, and security requirements.<\/span><\/p>\n<h3><b>Question 157<\/b><\/h3>\n<p><b>Which security architecture capability helps identify and investigate potentially malicious activity across application and identity data without waiting for a predefined alert?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat hunting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource locking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat hunting involves proactively searching security telemetry for suspicious patterns, behaviors, or indicators that may not have triggered an existing detection. Security analysts can use queries and contextual information to investigate hypotheses and uncover potentially hidden threats. Resource locking protects infrastructure from certain administrative changes, replication supports resilience, and load balancing distributes traffic. Threat hunting is especially useful as part of a mature security operations program because it complements automated detection with proactive investigation and analysis.<\/span><\/p>\n<h3><b>Question 158<\/b><\/h3>\n<p><b>A company needs to ensure that a critical application can continue operating when individual infrastructure components fail. Which architecture principle should guide the design?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">High availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-point dependency<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual-only recovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Centralized failure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">High availability architecture reduces dependence on individual components and uses redundancy, failover, or distributed resources to maintain service availability when failures occur. The exact design depends on application requirements and may include redundant instances, availability zones, load balancing, or other resilience mechanisms. Single points of failure create greater outage risk, while manual-only recovery may increase recovery time. High availability should be designed together with monitoring, capacity planning, dependency analysis, and appropriate recovery objectives.<\/span><\/p>\n<h3><b>Question 159<\/b><\/h3>\n<p><b>Which security governance practice provides a formal mechanism for accepting a known security risk when immediate remediation is not practical?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk acceptance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security policy removal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous administration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk acceptance is a formal governance decision in which an authorized party acknowledges a known risk and agrees to accept it under defined conditions. It should include documented justification, ownership, scope, duration, and review requirements. Risk acceptance does not mean that the risk has disappeared or that security controls should be removed. Unrestricted access and anonymous administration increase exposure without providing governance. Formal risk acceptance allows organizations to make accountable decisions when technical, financial, operational, or business constraints prevent immediate remediation.<\/span><\/p>\n<h3><b>Question 160<\/b><\/h3>\n<p><b>Which architecture approach is most useful when an organization must securely connect on-premises resources with cloud workloads while maintaining defined network boundaries?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hybrid network architecture with controlled connectivity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public internet access for every workload<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted routing between all networks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared credentials for network devices<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A controlled hybrid network architecture can connect on-premises infrastructure with cloud workloads while maintaining defined security boundaries and traffic controls. Depending on requirements, organizations may use VPN or dedicated connectivity, network segmentation, firewalls, private DNS, routing controls, and identity-based administration. Public access for every workload and unrestricted routing increase exposure and reduce isolation. Shared network credentials also weaken accountability. Hybrid architecture should be designed around business dependencies, security requirements, traffic flows, resilience, and administrative responsibilities.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-100 Exam Dumps and Practice Test Dumps. &nbsp; Question 141 Which Microsoft Entra capability can help organizations automate the review and removal of unnecessary access to applications and resources? Microsoft Entra Access Reviews Azure DDoS Protection Microsoft Defender for Endpoint Azure Front Door Correct Answer: 1 Explanation Microsoft Entra Access Reviews help [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17613"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17613"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17613\/revisions"}],"predecessor-version":[{"id":17614,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17613\/revisions\/17614"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17613"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17613"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17613"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}