{"id":17621,"date":"2026-09-21T10:37:03","date_gmt":"2026-09-21T10:37:03","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17621"},"modified":"2026-09-21T10:37:03","modified_gmt":"2026-09-21T10:37:03","slug":"microsoft-sc-100-practice-test-questions-and-exam-dumps-part12-q221-240","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-100-practice-test-questions-and-exam-dumps-part12-q221-240\/","title":{"rendered":"Microsoft SC-100 Practice Test Questions and Exam Dumps Part12 Q221-240"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-100-exam-dumps\"><b>Microsoft SC-100 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 221<\/b><\/h3>\n<p><b>Which Microsoft Entra capability can require users to complete an approval process before receiving access to a collection of organizational resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Entitlement Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Monitor<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Entitlement Management can use access packages and associated policies to manage how users request and receive access to groups of resources. Organizations can configure approval requirements, expiration periods, and other conditions before access is granted. This provides a structured approach to managing access for employees, guests, and other identities. Azure Firewall focuses on network security, Defender for Endpoint protects devices, and Azure Monitor provides monitoring capabilities. Entitlement management supports identity governance by making resource access more controlled and reviewable.<\/span><\/p>\n<h3><b>Question 222<\/b><\/h3>\n<p><b>Which architecture approach helps protect an application from a compromised database credential by limiting what the credential can access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared database administration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Broad permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scoped database authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal database access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Scoped database authorization limits a credential to the specific databases, schemas, tables, or operations required by the application. If that credential is compromised, the attacker has fewer opportunities to access unrelated information or perform unauthorized operations. Shared administration and broad permissions increase the potential blast radius, while universal access removes useful security boundaries. Database access should be designed according to application requirements and should include strong identity controls, secret management, auditing, encryption, and periodic permission reviews.<\/span><\/p>\n<h3><b>Question 223<\/b><\/h3>\n<p><b>Which Microsoft security capability provides protection against threats targeting cloud applications and can help identify risky application usage?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Cloud Apps<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Lifecycle Workflows<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Locks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Cloud Apps provides capabilities for discovering, monitoring, and securing cloud application usage. It can help organizations identify risky applications, assess activity, and apply security controls to supported cloud services. Lifecycle Workflows automate identity lifecycle processes, Resource Locks protect Azure resources from certain administrative changes, and DNS provides name resolution. Cloud application security is important because employees may use many SaaS services, and security teams need visibility into how applications interact with organizational identities and data.<\/span><\/p>\n<h3><b>Question 224<\/b><\/h3>\n<p><b>A security architect wants to ensure that privileged access is automatically removed after an approved period. Which design should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent role assignment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Time-bound privileged access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator account<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal permissions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Time-bound privileged access automatically limits elevated permissions to a defined period, reducing the amount of time an administrator can use powerful privileges. This supports just-in-time access and reduces standing privilege. Permanent assignments leave sensitive permissions available for longer periods and can increase the consequences of credential compromise. Shared administrator accounts also weaken accountability. Time-bound access should be combined with strong authentication, approval requirements, monitoring, auditing, and periodic review to provide effective privileged identity governance.<\/span><\/p>\n<h3><b>Question 225<\/b><\/h3>\n<p><b>Which security architecture capability can help identify whether an endpoint meets required security conditions before granting application access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device compliance evaluation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Device compliance evaluation determines whether an endpoint meets defined security requirements, such as encryption, security software, configuration standards, or management status. This information can be used by access policies to determine whether a device should be permitted to access sensitive applications. Public DNS, storage replication, and load balancing address networking or availability rather than endpoint security state. Device compliance is most effective when integrated with identity verification, Conditional Access, endpoint management, and risk-based access policies.<\/span><\/p>\n<h3><b>Question 226<\/b><\/h3>\n<p><b>Which security architecture principle requires an organization to continuously evaluate access instead of assuming that previously approved access remains safe?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implicit trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Continuous verification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network perimeter trust<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Continuous verification means access decisions should account for changing identity, device, application, and risk conditions rather than relying indefinitely on an earlier authorization decision. This principle aligns with Zero Trust because authentication or previous approval does not automatically guarantee that access remains appropriate. Implicit and perimeter-based trust can allow access to continue without sufficient reassessment. Continuous verification can be supported through Conditional Access, risk detection, device compliance, monitoring, and periodic access reviews.<\/span><\/p>\n<h3><b>Question 227<\/b><\/h3>\n<p><b>Which Azure service can help protect an application against volumetric denial-of-service attacks at the network level?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure DDoS Protection is designed to help defend supported Azure resources against distributed denial-of-service attacks. It can detect and mitigate certain attack traffic while helping maintain availability. Key Vault protects secrets and cryptographic keys, Policy provides governance, and Storage provides data services. DDoS protection should be considered as one layer within a broader resilience architecture that includes high availability, traffic management, monitoring, capacity planning, application security, and tested recovery procedures.<\/span><\/p>\n<h3><b>Question 228<\/b><\/h3>\n<p><b>Which practice helps ensure that a cloud application does not retain permissions after its business purpose has ended?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity deprovisioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent role assignments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared service accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity deprovisioning removes or disables identities and permissions when they are no longer required. This is important for users, applications, service accounts, and other workload identities because unused permissions can become security liabilities. Permanent role assignments and shared accounts make it harder to maintain accurate access control, while unrestricted access increases exposure. Deprovisioning should be integrated with identity lifecycle processes, ownership records, access reviews, automated workflows, and appropriate logging so that access is removed promptly when business requirements change.<\/span><\/p>\n<h3><b>Question 229<\/b><\/h3>\n<p><b>Which Microsoft security solution can correlate endpoint, identity, email, and application signals to help identify coordinated attacks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender XDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender XDR correlates security signals across supported Microsoft security products to provide a broader view of related attack activity. This can help security teams connect events involving endpoints, identities, email, applications, and other security domains. Purview focuses on data governance and compliance, Azure Resource Manager manages Azure resources, and Intune provides device and application management. Cross-domain correlation is useful because sophisticated attacks often involve multiple systems, and isolated alerts may not reveal the complete attack sequence.<\/span><\/p>\n<h3><b>Question 230<\/b><\/h3>\n<p><b>An organization wants to ensure that security requirements are considered before a cloud migration begins. What should the architecture team perform?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security architecture assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Immediate workload migration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential sharing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy removal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security architecture assessment evaluates workloads, identities, data, dependencies, network connectivity, compliance obligations, and security requirements before migration. Performing this work early helps identify risks and determine appropriate controls before production workloads are moved. Immediate migration can transfer existing weaknesses into a new environment, while credential sharing and policy removal increase exposure. The assessment should result in documented security requirements, architectural decisions, migration risks, and appropriate controls for the target cloud environment.<\/span><\/p>\n<h3><b>Question 231<\/b><\/h3>\n<p><b>Which architecture approach helps reduce the impact of a compromised application by separating its network traffic from unrelated workloads?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat networking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public connectivity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation creates boundaries between workloads and restricts communication to approved paths. If one application becomes compromised, segmentation can reduce the attacker&#8217;s ability to move directly into unrelated systems. Flat networking and universal routing provide broader connectivity and can increase lateral movement opportunities. Public connectivity may also increase exposure depending on the workload. Segmentation should be based on application dependencies, trust boundaries, data sensitivity, and business requirements and should be enforced through appropriate network security controls.<\/span><\/p>\n<h3><b>Question 232<\/b><\/h3>\n<p><b>Which Microsoft Sentinel feature is primarily used to visualize security information and operational trends through dashboards?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Analytics rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Playbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data connectors<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel workbooks provide interactive visualizations and dashboards for security data. They can display trends, incidents, metrics, and other information to help analysts and security leaders understand the security environment. Analytics rules detect potentially suspicious activity, playbooks automate response actions, and data connectors ingest information from supported sources. Workbooks are useful for operational monitoring and reporting, although their effectiveness depends on the quality and completeness of the underlying security data.<\/span><\/p>\n<h3><b>Question 233<\/b><\/h3>\n<p><b>Which control can help ensure that security-sensitive changes to production infrastructure are traceable to an identified administrator?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Individual administrative identities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Generic passwords<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Individual administrative identities provide accountability by associating security-sensitive actions with specific users. This allows organizations to determine who performed a change and supports auditing, investigation, and governance. Shared administrator accounts and generic passwords weaken attribution because multiple people may use the same credentials. Anonymous access eliminates identity information altogether. Administrative identities should be protected with strong authentication, least privilege, privileged access controls, logging, and periodic review. Clear attribution is especially important for critical infrastructure and security configuration changes.<\/span><\/p>\n<h3><b>Question 234<\/b><\/h3>\n<p><b>Which architecture capability can help ensure that sensitive data is encrypted while moving between applications and services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption in transit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Plaintext communication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared network passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public file permissions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Encryption in transit protects data while it moves between clients, applications, services, and other endpoints. Secure protocols such as TLS can help prevent unauthorized parties from reading or modifying transmitted information. Plaintext communication exposes sensitive information to interception, while shared passwords and public permissions address different security concerns. Encryption in transit should be combined with encryption at rest, strong identity controls, certificate management, secure network architecture, and appropriate authorization to provide comprehensive data protection.<\/span><\/p>\n<h3><b>Question 235<\/b><\/h3>\n<p><b>A company wants to ensure that a critical application can survive the failure of an individual availability zone. Which design should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multi-zone deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-instance deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-zone dependency<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">One-server architecture<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A multi-zone deployment places application components across separate availability zones so that a failure affecting one zone does not necessarily make the entire application unavailable. This design can improve resilience for workloads that require higher availability. A single-instance or single-zone architecture creates a larger dependency on one infrastructure location. Multi-zone designs should consider application state, data replication, load balancing, dependencies, failover behavior, monitoring, and recovery procedures to ensure that the architecture actually meets the required availability objectives.<\/span><\/p>\n<h3><b>Question 236<\/b><\/h3>\n<p><b>Which security architecture capability helps identify whether a user has accumulated unnecessary permissions across multiple applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity governance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage replication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity governance provides processes and capabilities for managing access throughout the identity lifecycle. It can help identify excessive permissions through access reviews, entitlement management, lifecycle processes, and role governance. This reduces the risk of privilege accumulation when users change responsibilities or gain access to additional applications over time. Network address translation and traffic management address connectivity, while storage replication supports resilience. Identity governance should be aligned with business roles, resource sensitivity, approval processes, and least-privilege requirements.<\/span><\/p>\n<h3><b>Question 237<\/b><\/h3>\n<p><b>Which approach can help detect unauthorized modifications to critical configuration files or security policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Integrity monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public write access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabled auditing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Integrity monitoring can detect unexpected changes to protected files, configurations, or other security-sensitive resources. This can help security teams identify unauthorized modifications that may indicate compromise, malicious activity, or accidental configuration changes. Public write access increases the likelihood of unauthorized changes, while shared accounts reduce accountability. Disabled auditing also makes investigation more difficult. Integrity monitoring should be combined with access controls, centralized logging, change management, configuration baselines, and alerting to provide effective protection.<\/span><\/p>\n<h3><b>Question 238<\/b><\/h3>\n<p><b>Which security architecture practice helps organizations determine whether a security control actually reduces the intended risk after implementation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Control effectiveness testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Control removal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabled monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control effectiveness testing evaluates whether a security control operates as intended and reduces the risk it was designed to address. Testing may include technical validation, configuration checks, simulated scenarios, audit reviews, or analysis of security metrics. Simply deploying a control does not guarantee that it is effective. Removing controls or disabling monitoring reduces assurance, while unrestricted access may undermine the control&#8217;s purpose. Effectiveness testing should be repeated when systems, threats, or business requirements change significantly.<\/span><\/p>\n<h3><b>Question 239<\/b><\/h3>\n<p><b>Which Microsoft service can help protect identities by detecting risky users and sign-ins and providing signals for access decisions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra ID Protection provides identity risk detection capabilities that can identify potentially compromised users and risky sign-in activity. These risk signals can be incorporated into Conditional Access policies to require additional authentication or block access when appropriate. Load Balancer and Storage provide infrastructure services, while Purview focuses on data governance and compliance. Identity risk detection is particularly valuable in Zero Trust architectures because access decisions can consider the security risk associated with an authentication event rather than relying only on a valid credential.<\/span><\/p>\n<h3><b>Question 240<\/b><\/h3>\n<p><b>A security architect wants to establish reusable security configurations for multiple cloud workloads. Which approach is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security baselines and architecture patterns<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Independent manual configuration for every workload<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Uncontrolled production changes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security baselines and reusable architecture patterns provide predefined configurations and design practices that can be applied consistently across workloads. They help reduce configuration drift, accelerate secure deployments, and establish a common security standard. Manual configuration for every workload can produce inconsistencies and increase operational effort. Shared passwords and uncontrolled production changes create additional security risks. Baselines should still allow documented exceptions where justified and should be regularly reviewed to ensure that they remain aligned with current threats, technologies, and organizational requirements.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-100 Exam Dumps and Practice Test Dumps. &nbsp; Question 221 Which Microsoft Entra capability can require users to complete an approval process before receiving access to a collection of organizational resources? Microsoft Entra Entitlement Management Azure Firewall Microsoft Defender for Endpoint Azure Monitor Correct Answer: 1 Explanation Microsoft Entra Entitlement Management can [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17621"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17621"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17621\/revisions"}],"predecessor-version":[{"id":17622,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17621\/revisions\/17622"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17621"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17621"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17621"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}