{"id":17619,"date":"2026-09-21T10:36:44","date_gmt":"2026-09-21T10:36:44","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17619"},"modified":"2026-09-21T10:36:44","modified_gmt":"2026-09-21T10:36:44","slug":"microsoft-sc-100-practice-test-questions-and-exam-dumps-part11-q201-220","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-100-practice-test-questions-and-exam-dumps-part11-q201-220\/","title":{"rendered":"Microsoft SC-100 Practice Test Questions and Exam Dumps Part11 Q201-220"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-100-exam-dumps\"><b>Microsoft SC-100 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 201<\/b><\/h3>\n<p><b>Which Microsoft Entra capability allows an organization to define specific authentication methods that must be used for sensitive applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access Reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication strengths<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lifecycle Workflows<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Entitlement Management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authentication strengths allow organizations to define which authentication methods are acceptable for specific access scenarios. This can help require stronger authentication for sensitive applications, privileged operations, or other high-risk resources. Authentication requirements can therefore be aligned with resource sensitivity rather than applying identical controls everywhere. Access Reviews focus on reviewing existing permissions, Lifecycle Workflows automate identity lifecycle tasks, and Entitlement Management manages resource access packages. Authentication strengths can be combined with Conditional Access and risk signals to create stronger identity security.<\/span><\/p>\n<h3><b>Question 202<\/b><\/h3>\n<p><b>Which Azure capability can help protect virtual machines from accidental deletion while allowing normal operational changes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Locks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Resource Locks can help prevent accidental deletion or modification of protected Azure resources. A delete lock, for example, can prevent a resource from being deleted while still allowing certain configuration operations. This provides an additional safeguard for important infrastructure where accidental administrative actions could cause service disruption. DNS and Traffic Manager address name resolution and traffic routing, while Bastion provides secure administrative connectivity. Resource locks should complement role-based access control and change management rather than serve as the only protection.<\/span><\/p>\n<h3><b>Question 203<\/b><\/h3>\n<p><b>An organization wants to ensure that an application can access only the secrets required for its specific function. Which design principle should be applied?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared secret storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least-privilege secret access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal application permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public secret access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least-privilege secret access ensures that an application receives permission only to the secrets required for its intended operation. This limits the potential impact if the application or its identity is compromised. Shared or universal access can allow a compromised workload to obtain unrelated credentials, increasing the blast radius. Public secret access is inappropriate for sensitive information. A secure design should combine narrowly scoped permissions with centralized secret management, workload identities, monitoring, auditing, and regular reviews of application access.<\/span><\/p>\n<h3><b>Question 204<\/b><\/h3>\n<p><b>Which security architecture capability helps identify sensitive information stored in locations that security teams were previously unaware of?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data discovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Address Translation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data discovery helps organizations identify where information is stored across supported repositories and services. This visibility is important because security teams cannot effectively protect sensitive information that they do not know exists. Discovery can support later activities such as classification, labeling, retention, encryption, access control, and data loss prevention. Load balancing, firewalling, and network address translation provide infrastructure and networking capabilities rather than data visibility. Data discovery should be performed regularly because new applications and repositories can introduce previously unknown information stores.<\/span><\/p>\n<h3><b>Question 205<\/b><\/h3>\n<p><b>Which Microsoft Sentinel capability can use predefined reference lists to enrich security queries and detections?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Watchlists<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Playbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incidents<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel watchlists allow organizations to store reference information that can be used in queries, analytics, and investigations. Examples may include approved administrative accounts, critical assets, known IP addresses, or other organizational reference data. Workbooks focus on visualization, playbooks automate actions, and incidents represent security cases that require investigation. Watchlists can therefore provide useful context when analyzing telemetry and developing detections. They should be maintained carefully so that outdated or inaccurate reference information does not negatively affect security analysis.<\/span><\/p>\n<h3><b>Question 206<\/b><\/h3>\n<p><b>A security architect needs to ensure that cloud workloads cannot communicate with each other unless communication is explicitly required. Which approach should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation with controlled traffic flows<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat networking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal inbound access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP addressing for every workload<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation with controlled traffic flows creates boundaries between workloads and permits communication only where legitimate dependencies require it. This reduces unnecessary connectivity and can limit lateral movement following a compromise. Flat networking and universal access provide fewer restrictions, while public IP addresses may increase external exposure. Segmentation should be based on application dependencies, data sensitivity, trust boundaries, and business requirements. Security groups, firewalls, routing controls, and private connectivity can then enforce the intended communication model.<\/span><\/p>\n<h3><b>Question 207<\/b><\/h3>\n<p><b>Which capability helps an organization detect and respond to security incidents involving multiple Microsoft security products through a unified incident view?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender XDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Lifecycle Workflows<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender XDR correlates security signals from supported Microsoft security products and can present related activities through unified incidents. This allows security teams to investigate attack activity across areas such as identities, endpoints, email, and applications rather than treating every alert as an isolated event. Azure Storage provides data storage, Lifecycle Workflows handles identity lifecycle automation, and Azure Resource Manager manages Azure resources. Cross-domain correlation can improve investigation context and help security teams identify broader attack chains.<\/span><\/p>\n<h3><b>Question 208<\/b><\/h3>\n<p><b>Which architecture approach is most appropriate for protecting administrative access to critical cloud resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privileged access controls with strong authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent unrestricted access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous administration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged access controls combined with strong authentication provide stronger protection for administrative operations. The architecture can include separate privileged identities, phishing-resistant authentication, just-in-time elevation, approval requirements, privileged workstations, monitoring, and auditing. Shared accounts reduce accountability, while permanent unrestricted access increases the period during which powerful permissions are available. Anonymous administration removes identity assurance altogether. Administrative access should be treated as a high-risk activity and protected with stronger controls than ordinary user operations.<\/span><\/p>\n<h3><b>Question 209<\/b><\/h3>\n<p><b>Which Azure capability can help enforce that only approved resource types are deployed within an environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Policy can define organizational requirements for Azure resources and can deny, audit, or otherwise evaluate configurations according to policy definitions. An organization can use policy to restrict resource types, regions, configurations, or other deployment characteristics. Bastion provides secure administrative access, Key Vault manages secrets and keys, and Front Door provides application delivery capabilities. Policy is particularly useful for enforcing governance consistently across large Azure environments and can be applied at appropriate management-group, subscription, or resource scopes.<\/span><\/p>\n<h3><b>Question 210<\/b><\/h3>\n<p><b>An organization wants to reduce the risk of sensitive information being exposed through email attachments. Which capability should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data Loss Prevention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure VPN Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data Loss Prevention can identify sensitive information in supported communication channels and apply organizational policies designed to reduce inappropriate sharing. For email scenarios, DLP can help detect sensitive content and provide actions such as warnings, restrictions, or other policy responses depending on configuration. Traffic Manager, VPN Gateway, and Load Balancer provide networking and traffic management functions. Effective DLP should be based on data classification and business requirements and should be tested to ensure that legitimate communication is not unnecessarily disrupted.<\/span><\/p>\n<h3><b>Question 211<\/b><\/h3>\n<p><b>Which Microsoft Purview capability is most relevant when an organization needs to investigate user activity involving sensitive information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Audit provides capabilities for searching and reviewing recorded activities across supported Microsoft services. This can help organizations investigate actions involving users, documents, sharing, administrative operations, and other activities depending on the available audit events. Azure Firewall, Bastion, and DDoS Protection address network security and infrastructure protection rather than information activity auditing. Audit data can support security investigations, compliance reviews, and governance activities when appropriate retention, permissions, and access controls are established.<\/span><\/p>\n<h3><b>Question 212<\/b><\/h3>\n<p><b>A security architect wants to prevent a single compromised identity from obtaining access to unrelated high-value systems. Which principle should guide the design?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege and segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat authorization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege limits what an identity can access, while segmentation creates additional boundaries between systems and workloads. Together, these controls reduce the potential impact of an account compromise by limiting the resources that the attacker can reach. Universal trust and flat authorization provide fewer restrictions, while shared credentials make it difficult to establish accountability and can expand the scope of compromise. Security architects should define access based on business responsibilities, resource sensitivity, and required communication paths.<\/span><\/p>\n<h3><b>Question 213<\/b><\/h3>\n<p><b>Which practice helps ensure that security controls remain effective after significant changes to an application&#8217;s architecture?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security reassessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent exception<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabled monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unreviewed deployment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security reassessment evaluates whether existing controls continue to meet security requirements after an application&#8217;s architecture, dependencies, data flows, or deployment model changes. Significant changes can introduce new attack paths or invalidate assumptions made during the original design. A reassessment may include threat modeling, configuration reviews, access analysis, vulnerability testing, and policy validation. Permanent exceptions and disabled monitoring reduce visibility, while unreviewed deployments can introduce unmanaged risks. Security architecture should evolve as systems and business requirements change.<\/span><\/p>\n<h3><b>Question 214<\/b><\/h3>\n<p><b>Which Azure service provides a dedicated hardware-based option for protecting highly sensitive cryptographic keys?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Dedicated HSM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Dedicated HSM provides dedicated hardware security module capabilities for organizations with requirements for hardware-based cryptographic key protection. HSMs can provide stronger control over cryptographic operations and key storage for workloads with stringent security or regulatory requirements. DNS, Load Balancer, and Traffic Manager provide networking and traffic management functions. The decision to use an HSM should be based on regulatory requirements, threat models, application architecture, operational complexity, and the sensitivity of the cryptographic material being protected.<\/span><\/p>\n<h3><b>Question 215<\/b><\/h3>\n<p><b>Which security architecture approach helps prevent developers from receiving unnecessary permissions to production resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of development and production access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared production administrator accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal contributor permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Direct production modification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separating development and production access limits the permissions developers receive to critical production resources. Developers can use appropriate development environments and controlled deployment pipelines while production administration remains restricted to authorized personnel or processes. Shared administrator accounts and universal contributor permissions increase exposure and reduce accountability. Direct production modification also bypasses controlled deployment practices. Strong separation should be supported by role-based access, CI\/CD security, approval gates, monitoring, and just-in-time access for exceptional administrative requirements.<\/span><\/p>\n<h3><b>Question 216<\/b><\/h3>\n<p><b>Which security capability helps an organization detect whether cloud resources have drifted from approved security configurations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security posture and configuration monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public resource access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabled policy checks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security posture and configuration monitoring can identify deviations between deployed resources and approved security requirements. Configuration drift can occur because of manual changes, new deployments, emergency modifications, or other operational activities. Detecting drift helps security teams investigate and remediate unexpected changes before they become significant vulnerabilities. Shared passwords and public access increase risk, while disabled policy checks reduce visibility. Continuous configuration monitoring should be integrated with governance policies, alerts, remediation workflows, and change management.<\/span><\/p>\n<h3><b>Question 217<\/b><\/h3>\n<p><b>An organization needs to determine whether a new security control could negatively affect a critical business process before deployment. What should the architect perform?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security and business impact assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Immediate production rollout<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent administrator access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Control removal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security and business impact assessment evaluates how a proposed control may affect availability, performance, user workflows, application dependencies, and other business requirements. This allows architects to identify conflicts before deployment and design compensating approaches when necessary. Immediate rollout may introduce unexpected operational problems, while removing the control eliminates the intended protection. A balanced architecture should reduce risk without unnecessarily disrupting essential business activities. Testing and stakeholder consultation can provide additional evidence before a control is implemented broadly.<\/span><\/p>\n<h3><b>Question 218<\/b><\/h3>\n<p><b>Which architecture capability helps protect cloud applications from unauthorized access to backend services by keeping service connectivity private?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoints<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public endpoints<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open firewall rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous service access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Private endpoints allow supported services to be accessed through private IP addresses within a virtual network. This can reduce exposure by avoiding the need to publish backend services through publicly accessible endpoints. Public endpoints and open firewall rules may increase exposure, while anonymous service access removes important authorization controls. Private connectivity should be combined with identity-based authorization, network segmentation, DNS configuration, monitoring, and appropriate service policies. The objective is to ensure that only intended workloads and users can reach sensitive backend services.<\/span><\/p>\n<h3><b>Question 219<\/b><\/h3>\n<p><b>Which security architecture practice helps identify potential attack paths between application components, identities, and sensitive resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat modeling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat modeling examines how assets, identities, components, trust boundaries, and data flows interact and how attackers might exploit weaknesses. This process can identify potential attack paths before or during implementation and allows architects to select appropriate mitigations. Storage replication supports resilience, load balancing distributes traffic, and DNS caching improves name-resolution performance. Threat modeling is most valuable when performed early and revisited after major architectural changes. It can help organizations prioritize security controls based on realistic attack scenarios.<\/span><\/p>\n<h3><b>Question 220<\/b><\/h3>\n<p><b>Which governance practice helps ensure that a security exception does not remain active indefinitely without reassessment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exception expiration and periodic review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent approval<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous ownership<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Exception expiration and periodic review ensure that approved security deviations are revisited and either remediated, renewed with justification, or formally closed. Without expiration or review, temporary exceptions can become permanent weaknesses that are forgotten over time. Permanent approval and unrestricted access do not provide adequate governance, while anonymous ownership prevents clear accountability. A mature exception process should identify an accountable owner, document the business justification and risk, define compensating controls, and establish a specific review or expiration date.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-100 Exam Dumps and Practice Test Dumps. &nbsp; Question 201 Which Microsoft Entra capability allows an organization to define specific authentication methods that must be used for sensitive applications? Access Reviews Authentication strengths Lifecycle Workflows Entitlement Management Correct Answer: 2 Explanation Authentication strengths allow organizations to define which authentication methods are acceptable [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17619"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17619"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17619\/revisions"}],"predecessor-version":[{"id":17620,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17619\/revisions\/17620"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17619"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17619"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17619"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}