{"id":17617,"date":"2026-09-21T10:33:36","date_gmt":"2026-09-21T10:33:36","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17617"},"modified":"2026-09-21T10:33:36","modified_gmt":"2026-09-21T10:33:36","slug":"microsoft-sc-100-practice-test-questions-and-exam-dumps-part10-q181-200","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-100-practice-test-questions-and-exam-dumps-part10-q181-200\/","title":{"rendered":"Microsoft SC-100 Practice Test Questions and Exam Dumps Part10 Q181-200"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-100-exam-dumps\"><b>Microsoft SC-100 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 181<\/b><\/h3>\n<p><b>Which Microsoft Entra capability can help organizations manage guest users and their access throughout the collaboration lifecycle?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra External ID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Monitor<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra External ID provides capabilities for managing external identities and supporting collaboration with people outside an organization. It can help organizations establish controlled authentication and authorization experiences for external users while maintaining appropriate governance. This is useful when partners, customers, or other external identities need access to selected resources. Azure Firewall and Azure Monitor address networking and monitoring, while Defender for Endpoint focuses on device security. External identity architecture should also include appropriate access reviews, Conditional Access, and least-privilege controls.<\/span><\/p>\n<h3><b>Question 182<\/b><\/h3>\n<p><b>A security architect wants applications to authenticate to Azure services without storing passwords or client secrets. Which option is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Managed identities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hard-coded credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public API keys<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Managed identities provide applications and Azure resources with an identity that can be used to authenticate to supported services without developers having to store credentials in application code. This reduces the exposure associated with long-lived secrets and simplifies credential management. Shared passwords and hard-coded credentials can be difficult to protect and rotate, while public API keys can be exposed to unauthorized parties. The managed identity should still receive only the permissions required by the workload to maintain least privilege.<\/span><\/p>\n<h3><b>Question 183<\/b><\/h3>\n<p><b>Which security architecture capability helps determine whether a cloud resource is configured according to organizational security standards?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration compliance assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Teams<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration compliance assessment evaluates resources against established security baselines, policies, or organizational requirements. It can identify deviations such as insecure network exposure, missing encryption settings, or other configuration weaknesses. This capability supports continuous security posture management because cloud environments can change frequently through deployments and administrative actions. Load Balancer and DNS provide networking functionality, while Teams is a collaboration service. Compliance assessment should be combined with policy governance, monitoring, remediation processes, and change management.<\/span><\/p>\n<h3><b>Question 184<\/b><\/h3>\n<p><b>Which approach can reduce the likelihood that a compromised endpoint will be able to access privileged administrative resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat network connectivity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privileged access isolation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal endpoint permissions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged access isolation separates sensitive administrative activities from ordinary endpoint operations. This can include dedicated administrative workstations, separate privileged identities, strong authentication, restricted network paths, and just-in-time elevation. The objective is to reduce opportunities for malware or compromised user sessions to reach highly privileged resources. Flat connectivity and shared credentials increase exposure, while universal permissions provide unnecessary access. Privileged access isolation is especially valuable for protecting accounts that can modify security controls or critical infrastructure.<\/span><\/p>\n<h3><b>Question 185<\/b><\/h3>\n<p><b>An organization wants to identify unusual sign-in behavior that could indicate account compromise. Which capability should be incorporated into the security architecture?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity risk detection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource tagging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity risk detection can identify suspicious authentication patterns and other signals associated with potentially compromised accounts. Examples may include unusual sign-in characteristics, leaked credentials, or other indicators that increase confidence that an identity requires additional scrutiny. Risk information can then be incorporated into access decisions through appropriate identity policies. Resource tagging and storage replication support governance and resilience, while load balancing addresses traffic distribution. Identity risk detection is particularly useful when combined with strong authentication and Conditional Access.<\/span><\/p>\n<h3><b>Question 186<\/b><\/h3>\n<p><b>Which Azure architecture component can help provide centralized policy and connectivity services for multiple workload networks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Virtual WAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Virtual WAN provides a managed networking architecture that can connect branch locations, virtual networks, and other network environments through a centralized framework. It can support large-scale connectivity and integration with security and routing capabilities. Azure Storage manages data, Key Vault manages secrets and cryptographic keys, and Purview supports data governance. Virtual WAN can be useful when an organization needs consistent connectivity across distributed environments, although the architecture should still address segmentation, traffic inspection, routing, and administrative boundaries.<\/span><\/p>\n<h3><b>Question 187<\/b><\/h3>\n<p><b>Which security practice helps ensure that software artifacts released to production have not been unexpectedly modified?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Artifact integrity verification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public artifact modification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared deployment credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted build access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Artifact integrity verification helps confirm that software packages, container images, or other deployment artifacts are the expected versions and have not been altered unexpectedly. Techniques such as digital signatures, hashes, trusted registries, and controlled build processes can support this objective. Public modification and unrestricted build access increase supply-chain risk, while shared credentials reduce accountability. Artifact security should be incorporated throughout the software delivery lifecycle, from source control and build processes through storage, deployment, and runtime validation.<\/span><\/p>\n<h3><b>Question 188<\/b><\/h3>\n<p><b>A company wants to limit administrative permissions so that database administrators cannot automatically modify unrelated network security configurations. Which principle should be applied?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implicit trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal administration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared authorization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege ensures that users and administrators receive only the permissions required to perform their assigned responsibilities. Separating database administration from unrelated network security permissions reduces the potential impact of compromised or misused administrative accounts. Universal administration provides excessive privileges and increases the blast radius of a security incident. Shared authorization can also weaken accountability. Least privilege should be implemented through appropriately scoped roles, separate administrative responsibilities, periodic access reviews, and temporary elevation when higher privileges are genuinely required.<\/span><\/p>\n<h3><b>Question 189<\/b><\/h3>\n<p><b>Which Microsoft security capability can help detect suspicious activity involving identities in a hybrid Active Directory environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Identity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Identity is designed to help protect identity infrastructure by analyzing signals associated with on-premises Active Directory environments. It can identify suspicious activities involving domain controllers, credentials, accounts, and authentication behavior. This is particularly valuable for organizations operating hybrid environments where on-premises identity systems remain connected to cloud services. Load Balancer and Storage provide infrastructure capabilities, while Purview focuses on data governance and compliance. Defender for Identity can contribute important identity telemetry to a broader detection and response architecture.<\/span><\/p>\n<h3><b>Question 190<\/b><\/h3>\n<p><b>Which design approach provides stronger isolation between development, testing, and production environments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared unrestricted resources<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separate environments with controlled access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Common administrative credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Direct production modification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separating development, testing, and production environments reduces the likelihood that mistakes, compromised development systems, or unauthorized changes will directly affect production workloads. Each environment can have distinct identities, permissions, network boundaries, policies, and deployment processes. Shared unrestricted resources and common administrative credentials weaken these boundaries. Direct production modification also bypasses controlled deployment processes. Environment separation should be supported by CI\/CD controls, access governance, monitoring, and approval workflows appropriate to the sensitivity of production resources.<\/span><\/p>\n<h3><b>Question 191<\/b><\/h3>\n<p><b>Which security architecture capability helps identify relationships between users, devices, applications, and security events during an investigation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security analytics and entity correlation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource locking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security analytics and entity correlation connect events with related users, devices, applications, IP addresses, and other entities to provide broader investigation context. This can help analysts understand whether apparently separate activities are part of the same attack sequence. Security information and event management platforms can perform this type of correlation using collected telemetry. Storage replication, resource locks, and DNS forwarding serve other infrastructure purposes. Entity correlation is valuable for improving investigation quality and identifying complex attacks that cross multiple security domains.<\/span><\/p>\n<h3><b>Question 192<\/b><\/h3>\n<p><b>A security architect wants to protect a critical workload from accidental exposure caused by configuration changes. Which combination is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open permissions and public endpoints<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy enforcement and configuration monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared credentials and unrestricted administration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabled logging and manual changes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Policy enforcement can prevent or flag configurations that violate organizational requirements, while configuration monitoring can detect changes that occur after deployment. Together, these controls reduce the likelihood that accidental or unauthorized changes will leave a critical workload exposed. Public endpoints and open permissions can increase risk, while shared credentials weaken accountability. Disabled logging also makes investigation more difficult. Critical workloads should use layered governance that includes policy, identity controls, monitoring, change management, and regular security assessment.<\/span><\/p>\n<h3><b>Question 193<\/b><\/h3>\n<p><b>Which approach can help protect sensitive applications from unauthorized access originating from unmanaged devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device-based access controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent anonymous access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared application passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal device permissions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Device-based access controls can evaluate whether a device meets defined security or management requirements before permitting access to sensitive applications. Organizations can use device compliance information and Conditional Access policies to restrict or challenge access from unmanaged or noncompliant devices. Shared passwords and anonymous access provide weak protection, while universal device permissions do not account for device security state. Device-based controls are most effective when combined with identity verification, strong authentication, application-specific authorization, and continuous monitoring.<\/span><\/p>\n<h3><b>Question 194<\/b><\/h3>\n<p><b>Which security architecture practice helps an organization identify whether its current controls satisfy a defined target security state?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security gap analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public network exposure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password sharing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Uncontrolled configuration changes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security gap analysis compares the current security environment with a defined target state to identify missing controls, weaknesses, process deficiencies, or architectural differences. The findings can then be prioritized according to business risk and used to develop a security roadmap. Public exposure and uncontrolled changes can create risks but do not provide a structured method for measuring the gap between current and desired security states. A useful gap analysis should consider technology, identity, data, network, governance, operations, and compliance requirements.<\/span><\/p>\n<h3><b>Question 195<\/b><\/h3>\n<p><b>Which architecture approach helps ensure that security controls are applied consistently when applications are deployed repeatedly through automation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security as code<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual configuration only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Uncontrolled production changes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security as code represents security requirements through automated policies, configurations, tests, or deployment controls that can be consistently applied during infrastructure and application delivery. This reduces dependence on manual configuration and helps organizations repeat approved security patterns across environments. Manual-only configuration can produce inconsistent results, while shared administrator accounts reduce accountability. Security as code can include policy checks, infrastructure scanning, secure configuration templates, and automated validation within CI\/CD pipelines. It should complement runtime monitoring and governance rather than replace them.<\/span><\/p>\n<h3><b>Question 196<\/b><\/h3>\n<p><b>Which security architecture capability can help an organization discover and manage applications that employees use without formal approval?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud application discovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Locks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud application discovery helps organizations identify applications being used within their environment, including applications that may not have gone through formal security review. Understanding this usage can help security teams assess application risk, data exposure, compliance implications, and appropriate governance requirements. Azure Backup focuses on recovery, Bastion provides secure administrative connectivity, and Resource Locks protect resources from certain changes. Cloud application discovery is useful for addressing shadow IT and improving visibility into the organization&#8217;s actual application landscape.<\/span><\/p>\n<h3><b>Question 197<\/b><\/h3>\n<p><b>Which control can help prevent a user from downloading sensitive information when the activity violates organizational policy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data Loss Prevention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure VPN Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data Loss Prevention policies can identify sensitive information and apply actions when users attempt activities that violate organizational data protection requirements. Depending on the supported workload and configuration, DLP can provide warnings, restrictions, or other policy-driven responses. Load Balancer, VPN Gateway, and Traffic Manager address networking and traffic management rather than sensitive-data handling. DLP should be based on classification and business requirements, and organizations should monitor policy effectiveness to ensure protection does not unnecessarily interfere with legitimate workflows.<\/span><\/p>\n<h3><b>Question 198<\/b><\/h3>\n<p><b>Which security architecture strategy is most appropriate for a service that must recover quickly after a destructive cyberattack?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cyber recovery with isolated and protected backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single copy of production data<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Publicly writable backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared backup credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cyber recovery architecture should protect recovery resources from the same attack that affects production. Isolated and protected backups can reduce the likelihood that attackers will alter or destroy recovery data after compromising production systems. Depending on requirements, the design may include immutable storage, separate administrative identities, restricted connectivity, monitoring, and regularly tested recovery procedures. A single production copy or publicly writable backup provides poor resilience. Shared backup credentials also increase the risk that compromise of one account could affect recovery resources.<\/span><\/p>\n<h3><b>Question 199<\/b><\/h3>\n<p><b>Which governance mechanism allows an organization to establish security requirements while providing a documented process for handling legitimate exceptions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security policy and exception management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted administrative access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous configuration changes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public resource permissions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security policy defines the expected security requirements, while exception management provides a controlled process for situations where those requirements cannot immediately be met. A formal exception should document the affected system, business justification, risk, compensating controls, owner, approval, and review or expiration date. This prevents temporary deviations from becoming unmanaged permanent weaknesses. Unrestricted access and public permissions increase exposure rather than governing exceptions. Effective governance balances consistent security requirements with documented business and technical realities.<\/span><\/p>\n<h3><b>Question 200<\/b><\/h3>\n<p><b>A security architect is creating a long-term security roadmap. Which factor should receive priority when deciding which initiatives to implement first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor popularity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk reduction and business impact<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Number of available products<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preference for newer technology<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security roadmaps should prioritize initiatives according to risk reduction, business impact, regulatory requirements, dependencies, and implementation feasibility. A control that significantly reduces a critical business risk may deserve earlier attention than a technology initiative simply because it is newer or more popular. Focusing on vendor popularity or the number of available products does not establish whether an initiative addresses an important organizational need. A risk-based roadmap provides a structured way to sequence security improvements while aligning architecture investments with business objectives.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-100 Exam Dumps and Practice Test Dumps. &nbsp; Question 181 Which Microsoft Entra capability can help organizations manage guest users and their access throughout the collaboration lifecycle? Azure Firewall Microsoft Defender for Endpoint Microsoft Entra External ID Azure Monitor Correct Answer: 3 Explanation Microsoft Entra External ID provides capabilities for managing external [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17617"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17617"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17617\/revisions"}],"predecessor-version":[{"id":17618,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17617\/revisions\/17618"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17617"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17617"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17617"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}