{"id":17623,"date":"2026-09-21T10:37:18","date_gmt":"2026-09-21T10:37:18","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17623"},"modified":"2026-09-21T10:37:18","modified_gmt":"2026-09-21T10:37:18","slug":"microsoft-sc-100-practice-test-questions-and-exam-dumps-part13-q241-260","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-100-practice-test-questions-and-exam-dumps-part13-q241-260\/","title":{"rendered":"Microsoft SC-100 Practice Test Questions and Exam Dumps Part13 Q241-260"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-100-exam-dumps\"><b>Microsoft SC-100 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 241<\/b><\/h3>\n<p><b>Which Microsoft Entra feature can automate tasks such as onboarding, offboarding, and identity attribute changes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Lifecycle Workflows<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Cloud Apps<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Lifecycle Workflows can automate identity lifecycle processes such as onboarding, offboarding, and other identity-related tasks. Automation helps organizations apply consistent procedures when employees join, change roles, or leave the organization. This can reduce delays and help ensure that unnecessary access is removed promptly. Azure Firewall provides network protection, Defender for Cloud Apps focuses on cloud application security, and Front Door provides application delivery capabilities. Lifecycle automation should be integrated with identity governance and access management requirements.<\/span><\/p>\n<h3><b>Question 242<\/b><\/h3>\n<p><b>Which authentication approach provides strong resistance against phishing by using cryptographic credentials instead of reusable passwords?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password-only authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared security questions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing-resistant authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Email-based approval alone<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Phishing-resistant authentication uses authentication methods designed to prevent attackers from simply capturing and replaying reusable credentials. Cryptographic authentication methods can bind authentication to the legitimate service and user context, making common credential-phishing attacks significantly harder. Password-only authentication and shared security questions can be captured through phishing, while email-based approval alone may not provide sufficient assurance for high-risk scenarios. Security architects should select authentication methods according to application sensitivity, user requirements, regulatory obligations, and the organization&#8217;s identity security strategy.<\/span><\/p>\n<h3><b>Question 243<\/b><\/h3>\n<p><b>An organization wants to allow a workload in one Microsoft Entra tenant to access resources in another tenant without creating unnecessary local accounts. Which capability should be evaluated?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-tenant access settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Locks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra cross-tenant access settings provide controls for managing collaboration and access between organizations using Microsoft Entra tenants. They can help administrators establish trust relationships and determine how external identities are allowed to interact with resources. This can reduce the need for unmanaged local accounts while maintaining defined access boundaries. Resource Locks protect Azure resources, DDoS Protection addresses availability threats, and Purview Audit supports activity investigation. Cross-tenant designs should still use least privilege, strong authentication, and appropriate governance.<\/span><\/p>\n<h3><b>Question 244<\/b><\/h3>\n<p><b>Which Azure networking service can provide secure remote administrative access to virtual machines without requiring direct inbound RDP or SSH exposure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Bastion provides browser-based administrative access to supported virtual machines through the Azure portal without requiring the virtual machines to have public IP addresses for RDP or SSH. This can reduce direct exposure of administrative protocols to the internet. Load Balancer distributes traffic, Traffic Manager provides DNS-based traffic routing, and Azure DNS provides name-resolution services. Bastion should be combined with strong identity controls, privileged access management, network segmentation, monitoring, and appropriate administrative policies.<\/span><\/p>\n<h3><b>Question 245<\/b><\/h3>\n<p><b>Which security architecture approach helps ensure that a software pipeline cannot deploy directly to production unless required security checks have passed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared deployment accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security gates in CI\/CD<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual credential sharing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security gates in CI\/CD pipelines can require defined checks to pass before software is promoted to production. Depending on organizational requirements, gates may include code scanning, dependency analysis, infrastructure validation, secret detection, vulnerability assessment, approval requirements, and policy checks. Unrestricted deployment and shared credentials weaken control over production changes. Security gates help integrate security into the software delivery process while providing repeatable enforcement. They should be designed so that critical risks cannot be bypassed without an authorized and documented exception.<\/span><\/p>\n<h3><b>Question 246<\/b><\/h3>\n<p><b>Which security architecture capability is most useful for identifying vulnerable third-party software components used by an application?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dependency scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dependency scanning evaluates third-party libraries and packages used by applications to identify known vulnerabilities and other risks. Modern applications often depend on many external components, so understanding those dependencies is an important part of software supply-chain security. Network segmentation and DNS forwarding provide network controls, while data replication supports resilience. Dependency scanning can be integrated into CI\/CD pipelines and combined with software inventories, version management, vulnerability prioritization, and controlled update processes to reduce supply-chain exposure.<\/span><\/p>\n<h3><b>Question 247<\/b><\/h3>\n<p><b>Which security architecture principle requires access decisions to consider the identity, device, resource, and current context rather than network location alone?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perimeter-based trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero Trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implicit authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static network trust<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero Trust requires access decisions to consider relevant signals such as identity, device state, resource sensitivity, application, and current risk instead of assuming that users are trustworthy because they are inside a particular network. This approach supports continuous evaluation and least-privilege access. Perimeter-based and static network trust models can provide excessive confidence based on location. A Zero Trust architecture distributes security controls across identity, devices, applications, networks, and data so that compromise of one layer does not automatically provide broad access.<\/span><\/p>\n<h3><b>Question 248<\/b><\/h3>\n<p><b>Which Microsoft Sentinel capability can automatically execute response actions when a security incident meets defined conditions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Watchlists<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Playbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data connectors<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel playbooks use automation capabilities to execute predefined actions in response to security events or incidents. They can support tasks such as sending notifications, creating tickets, enriching alerts, or initiating other approved workflows. Workbooks provide visualization, watchlists provide reference information, and data connectors bring data into Sentinel. Automation can reduce repetitive manual work and accelerate response, but playbooks should be carefully designed with appropriate permissions, testing, logging, and safeguards to prevent unintended actions.<\/span><\/p>\n<h3><b>Question 249<\/b><\/h3>\n<p><b>Which architecture practice helps identify vulnerabilities in an application by analyzing its components, trust boundaries, and potential attack techniques?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat modeling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Capacity planning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS optimization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage replication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat modeling analyzes an application&#8217;s architecture to identify assets, trust boundaries, data flows, dependencies, and potential attack techniques. It allows security teams to reason about how an attacker could compromise components or move toward sensitive resources. Capacity planning addresses performance, DNS optimization addresses name resolution, and storage replication supports resilience. Threat modeling is most effective when performed during design and revisited after major architectural changes. Its findings can guide authentication, authorization, network controls, data protection, and monitoring decisions.<\/span><\/p>\n<h3><b>Question 250<\/b><\/h3>\n<p><b>Which Microsoft Purview capability can help organizations identify and manage potential insider-risk activities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Insider Risk Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Connect<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Insider Risk Management helps organizations identify potentially risky activities involving users and sensitive organizational information. It can use relevant signals and policies to help security and compliance teams investigate potential insider-risk scenarios while incorporating privacy and governance considerations. Azure Firewall provides network security, Entra Connect supports identity synchronization, and Traffic Manager provides traffic routing. Insider-risk architecture should include appropriate policies, role separation, investigation procedures, data protection, and controls that balance security requirements with organizational privacy obligations.<\/span><\/p>\n<h3><b>Question 251<\/b><\/h3>\n<p><b>Which Azure capability can help protect a web application from malicious HTTP requests by applying managed and custom WAF rules?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Web Application Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Web Application Firewall provides application-layer protection for supported web applications by inspecting HTTP traffic and applying security rules. Managed rules can help address common web attack patterns, while custom rules can support organization-specific requirements. Key Vault protects secrets and cryptographic material, Resource Manager manages Azure resources, and Storage provides data services. WAF should be considered one layer of application security and should complement secure coding, authentication, authorization, vulnerability management, monitoring, and other controls.<\/span><\/p>\n<h3><b>Question 252<\/b><\/h3>\n<p><b>Which identity architecture approach allows an application to authenticate using a federated workload identity rather than storing a long-lived secret?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workload identity federation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared application passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hard-coded client secrets<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Workload identity federation can allow workloads to obtain access tokens based on trusted identity assertions rather than storing long-lived client secrets. This can reduce secret-management requirements and the risk associated with exposed credentials in automation environments. Shared passwords and hard-coded client secrets create additional credential-management challenges, while public credentials should not be used to authorize sensitive operations. Federation should be configured with tightly scoped trust relationships and permissions so that only approved workloads can obtain access.<\/span><\/p>\n<h3><b>Question 253<\/b><\/h3>\n<p><b>A security architect wants to make sure an organization can continue critical operations after ransomware affects production systems. Which capability should be included in the architecture?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Immutable and isolated recovery copies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Publicly writable backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single backup administrator account<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup storage connected without restrictions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Immutable and isolated recovery copies can help protect backup data from ransomware and other attacks that attempt to encrypt or delete recovery resources. Isolation reduces the likelihood that compromise of production systems will automatically provide attackers with access to backup infrastructure. Publicly writable backups and unrestricted connectivity create significant risk, while a single administrator account creates a concentrated point of compromise. Cyber recovery architecture should also include tested restoration procedures, separate administrative controls, monitoring, and clearly defined recovery objectives.<\/span><\/p>\n<h3><b>Question 254<\/b><\/h3>\n<p><b>Which governance approach defines who is responsible for security decisions, approvals, and operational activities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RACI responsibility model<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public access policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator password<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Uncontrolled delegation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A RACI responsibility model can clarify who is Responsible, Accountable, Consulted, and Informed for important security activities. Clear ownership helps prevent gaps where multiple teams assume another group is handling a security requirement. It can be applied to areas such as incident response, architecture reviews, policy management, access approvals, and risk decisions. Shared passwords and uncontrolled delegation weaken accountability. Governance models should be aligned with organizational structure and reviewed when responsibilities, technologies, or business processes change.<\/span><\/p>\n<h3><b>Question 255<\/b><\/h3>\n<p><b>Which security architecture capability helps identify vulnerabilities in infrastructure-as-code templates before resources are deployed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Infrastructure-as-code security scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual production editing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public deployment permissions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Infrastructure-as-code security scanning examines templates for insecure configurations before they are used to deploy resources. It can identify issues such as overly permissive network rules, insecure storage settings, missing encryption, or excessive permissions. Detecting problems before deployment allows teams to correct them earlier and reduces the chance of introducing insecure infrastructure into production. Manual production editing and broad deployment permissions reduce consistency and control. IaC scanning works best when integrated into pull requests and CI\/CD pipelines with defined security policies.<\/span><\/p>\n<h3><b>Question 256<\/b><\/h3>\n<p><b>Which Microsoft Entra capability allows administrators to periodically confirm whether users still require access to specific resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Access Reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Access Reviews help organizations periodically evaluate whether users, groups, guests, or other identities should retain access to resources. Reviewers can confirm continued access or remove permissions that are no longer justified. This supports least privilege and helps address access accumulation caused by role changes or temporary business requirements. DDoS Protection, Defender for Endpoint, and Front Door address different security or infrastructure needs. Access reviews should be scheduled according to resource sensitivity and organizational governance requirements.<\/span><\/p>\n<h3><b>Question 257<\/b><\/h3>\n<p><b>Which network security design can restrict communication between application tiers to only the ports and protocols they actually require?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Broad network access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network security rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal inbound connectivity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network security rules can restrict traffic between application tiers according to defined source, destination, port, protocol, and other conditions. This supports segmentation and reduces unnecessary communication paths. Broad or universal connectivity can increase the attack surface and make lateral movement easier if one component is compromised. Network security rules should be based on documented application dependencies and reviewed as workloads change. They should also be combined with identity controls, application authorization, monitoring, and other defense-in-depth measures.<\/span><\/p>\n<h3><b>Question 258<\/b><\/h3>\n<p><b>Which security architecture metric can help determine whether the organization is improving its ability to detect and respond to incidents?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mean time to detect and respond<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Number of application logos<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Number of unused subscriptions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Total storage capacity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mean time to detect and respond can provide useful operational measurements for understanding how quickly security teams identify and address incidents. Tracking these measures over time can help organizations evaluate detection coverage, investigation processes, automation, staffing, and response capabilities. The metric should be interpreted alongside incident severity, detection quality, false positives, and other operational measures. Storage capacity or unrelated infrastructure counts do not directly indicate security response effectiveness. Metrics should support improvement rather than become isolated targets.<\/span><\/p>\n<h3><b>Question 259<\/b><\/h3>\n<p><b>Which architecture approach can help prevent a compromised CI\/CD pipeline from obtaining unrestricted access to production resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pipeline identity with narrowly scoped permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Global administrator credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared production passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent unrestricted deployment rights<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Pipeline identities should receive only the permissions required to perform their specific deployment tasks. Narrowly scoped permissions reduce the potential impact if a build agent, deployment token, or pipeline configuration is compromised. Global administrator credentials and permanent unrestricted deployment rights create excessive privilege, while shared passwords weaken accountability and make credential rotation more difficult. Secure pipeline architecture should also include protected branches, approval gates, secret management, workload identities, logging, and controls that prevent unauthorized changes to deployment definitions.<\/span><\/p>\n<h3><b>Question 260<\/b><\/h3>\n<p><b>Which security architecture activity helps validate that a proposed solution satisfies both technical security requirements and business objectives before implementation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Architecture decision review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Uncontrolled deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Immediate policy removal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared credential setup<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An architecture decision review evaluates whether a proposed solution satisfies defined security requirements while also supporting business objectives, operational needs, and relevant constraints. The review can examine identity, data, network, application, compliance, resilience, and monitoring considerations before implementation. Uncontrolled deployment can introduce unreviewed risks, while policy removal and shared credentials weaken security. A documented review also creates a record of important architectural decisions, assumptions, risks, and accepted trade-offs that can be revisited as the environment evolves.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-100 Exam Dumps and Practice Test Dumps. &nbsp; Question 241 Which Microsoft Entra feature can automate tasks such as onboarding, offboarding, and identity attribute changes? Azure Firewall Microsoft Entra Lifecycle Workflows Microsoft Defender for Cloud Apps Azure Front Door Correct Answer: 2 Explanation Microsoft Entra Lifecycle Workflows can automate identity lifecycle processes [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17623"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17623"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17623\/revisions"}],"predecessor-version":[{"id":17624,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17623\/revisions\/17624"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17623"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17623"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17623"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}