{"id":17625,"date":"2026-09-21T10:37:35","date_gmt":"2026-09-21T10:37:35","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17625"},"modified":"2026-09-21T10:37:35","modified_gmt":"2026-09-21T10:37:35","slug":"microsoft-sc-100-practice-test-questions-and-exam-dumps-part14-q261-280","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-100-practice-test-questions-and-exam-dumps-part14-q261-280\/","title":{"rendered":"Microsoft SC-100 Practice Test Questions and Exam Dumps Part14 Q261-280"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-100-exam-dumps\"><b>Microsoft SC-100 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 261<\/b><\/h3>\n<p><b>Which Microsoft Entra capability can help organizations manage access for external users through predefined resource collections and lifecycle controls?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Identity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Entitlement Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Entitlement Management provides structured access management through access packages and policies. Organizations can group resources together and define how users request, receive, review, and eventually lose access. This is particularly useful for external users, temporary workers, and projects where access should not remain indefinitely. Azure Policy governs Azure resources, Defender for Identity monitors identity-related threats, and DDoS Protection helps defend against network attacks. Entitlement Management supports governance by making access more controlled, time-bound, and reviewable.<\/span><\/p>\n<h3><b>Question 262<\/b><\/h3>\n<p><b>Which security architecture principle limits an application identity to only the operations it actually needs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perimeter trust<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege limits an identity to the minimum permissions necessary to perform its intended responsibilities. For application identities, this means granting only required operations on specific resources rather than broad permissions across an environment. If the identity is compromised, narrowly scoped permissions can reduce the attacker&#8217;s ability to access unrelated systems or perform destructive actions. Universal access and open authorization create excessive exposure, while perimeter trust does not provide sufficient application-level restrictions. Least privilege should be reviewed regularly as application requirements change.<\/span><\/p>\n<h3><b>Question 263<\/b><\/h3>\n<p><b>Which Microsoft Sentinel component is responsible for bringing security data from supported external sources into the platform?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data connectors<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Playbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Watchlists<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel data connectors provide mechanisms for bringing security data from supported Microsoft and third-party sources into the platform. Ingested data can then be used by analytics rules, investigations, workbooks, hunting queries, and other security capabilities. Workbooks visualize information, playbooks automate response actions, and watchlists provide reference data. A security architecture should carefully plan which data sources are necessary, how much telemetry is collected, retention requirements, and the value of each source so that monitoring remains effective without unnecessary data and operational costs.<\/span><\/p>\n<h3><b>Question 264<\/b><\/h3>\n<p><b>An organization wants to make sure that a cloud storage resource cannot be deployed in an unauthorized geographic region. Which control is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Policy can enforce organizational requirements concerning resource locations and other deployment characteristics. A policy can audit or deny resources that are deployed outside approved regions, helping organizations address data residency, regulatory, and operational requirements. Bastion provides secure virtual machine access, Key Vault protects secrets and keys, and Load Balancer distributes network traffic. Geographic governance should be combined with resource classification, identity controls, monitoring, and exception processes when legitimate business requirements require deviations from the standard policy.<\/span><\/p>\n<h3><b>Question 265<\/b><\/h3>\n<p><b>Which security approach helps ensure that application secrets are rotated without requiring developers to modify source code each time?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hard-coded credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Centralized secret management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credentials stored in comments<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized secret management separates sensitive credentials from application source code and can support controlled access and rotation. Applications can retrieve the required secret through an authorized identity instead of embedding credentials directly in code. This reduces exposure and makes credential lifecycle operations easier to manage. Hard-coded credentials and shared passwords are more difficult to rotate safely and may be exposed through repositories or deployment artifacts. Centralized secret management should be combined with least privilege, auditing, automated rotation where supported, and secure workload identities.<\/span><\/p>\n<h3><b>Question 266<\/b><\/h3>\n<p><b>Which architecture capability can help security teams understand whether an endpoint is potentially compromised based on suspicious device activity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Records Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint provides endpoint detection and response capabilities that can help security teams investigate suspicious device activity. It collects relevant endpoint signals and can support investigation, threat detection, response, and hunting. Traffic Manager handles traffic routing, Purview Records Management supports information governance, and Resource Manager manages Azure resources. Endpoint security should be part of a broader architecture that also addresses identity, application, network, data, and incident-response requirements because endpoint compromise can affect multiple security layers.<\/span><\/p>\n<h3><b>Question 267<\/b><\/h3>\n<p><b>Which security design provides different security boundaries for workloads based on their sensitivity and business role?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk-based segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal network access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public workload connectivity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk-based segmentation establishes security boundaries according to factors such as workload sensitivity, business criticality, regulatory requirements, and trust relationships. Highly sensitive workloads can receive stronger isolation and stricter communication controls than lower-risk systems. Flat architectures and universal connectivity provide fewer boundaries and can increase lateral movement opportunities. Public connectivity can also increase exposure. Risk-based segmentation should be supported by network controls, identity-based authorization, monitoring, and documented application dependencies so that required business communication remains functional.<\/span><\/p>\n<h3><b>Question 268<\/b><\/h3>\n<p><b>Which authentication method is generally designed to provide stronger protection against phishing than traditional password-based authentication?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password reuse<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FIDO2 security keys<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security questions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared passwords<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FIDO2 security keys use public-key cryptography and are designed to provide phishing-resistant authentication. The authentication process is bound to the legitimate relying party, making common credential-replay attacks more difficult. Password reuse, security questions, and shared passwords can be exposed through phishing or other credential attacks. Organizations should evaluate FIDO2 and other strong authentication methods according to application compatibility, user requirements, recovery processes, and regulatory needs. Strong authentication should also be combined with risk-based access controls and least privilege.<\/span><\/p>\n<h3><b>Question 269<\/b><\/h3>\n<p><b>Which Microsoft Entra capability can provide temporary elevated permissions instead of leaving administrators permanently assigned to privileged roles?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Cloud Apps<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management helps organizations manage privileged roles through controls such as time-limited activation, approval, justification, and monitoring. This reduces standing privilege because administrators do not need to remain permanently elevated. Azure DNS and Storage provide infrastructure services, while Defender for Cloud Apps focuses on cloud application security. Privileged access should be designed with strong authentication, appropriate approval requirements, auditing, access reviews, and separate administrative identities to reduce the risks associated with highly privileged accounts.<\/span><\/p>\n<h3><b>Question 270<\/b><\/h3>\n<p><b>Which architecture practice helps ensure that a security control remains effective when business requirements or technology change?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Periodic security architecture review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent configuration freeze<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabled monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unreviewed exceptions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Periodic security architecture reviews help organizations determine whether existing controls still satisfy current business, technology, threat, and regulatory requirements. Applications, identities, infrastructure, and attack techniques can change over time, making previously appropriate controls less effective or unnecessarily restrictive. Configuration freezes do not guarantee security, while disabled monitoring reduces visibility. Unreviewed exceptions can also create persistent weaknesses. Architecture reviews should consider changes in dependencies, data sensitivity, access patterns, threats, and business objectives and should result in documented improvements when required.<\/span><\/p>\n<h3><b>Question 271<\/b><\/h3>\n<p><b>Which Microsoft Purview capability is primarily used to apply sensitivity information to documents and emails so that protection can follow the data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sensitivity labels<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview sensitivity labels can classify and protect supported documents and emails based on organizational requirements. Labels can be associated with protection settings such as encryption, access restrictions, or visual markings depending on configuration. This supports a data-centric security architecture because protection can remain associated with the information rather than depending only on the network where the data is stored. Azure Firewall and Bastion provide infrastructure controls, while Defender for Endpoint protects devices. Sensitivity labeling should align with classification and governance policies.<\/span><\/p>\n<h3><b>Question 272<\/b><\/h3>\n<p><b>A security architect needs to reduce the risk of administrators using privileged accounts for routine activities. Which design should be adopted?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separate standard and privileged identities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">One account for all activities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent global administrator access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separating standard and privileged identities reduces the chance that highly privileged credentials will be exposed during routine activities such as email, web browsing, or ordinary application use. Administrators can use standard identities for everyday work and activate or use privileged identities only when elevated permissions are required. A single account or shared administrator account increases exposure and weakens accountability. Permanent global administrator access also creates excessive standing privilege. Separate identities should be protected with strong authentication, monitoring, and appropriate privileged access controls.<\/span><\/p>\n<h3><b>Question 273<\/b><\/h3>\n<p><b>Which security architecture capability can help identify applications that are being used but have not been formally approved by the organization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud application discovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud application discovery helps organizations identify cloud services and applications being used across the environment, including applications that may not have been formally approved. This visibility can help security teams assess application risk, data handling, compliance requirements, and potential shadow IT. Azure Backup supports recovery, Private DNS provides private name resolution, and Load Balancer distributes traffic. Discovery findings can be used to establish governance decisions, improve application inventories, and determine whether specific services require additional security controls or restrictions.<\/span><\/p>\n<h3><b>Question 274<\/b><\/h3>\n<p><b>Which Microsoft Sentinel capability is designed to identify suspicious activity by evaluating incoming security events against defined detection logic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Analytics rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Watchlists<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Playbooks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel analytics rules evaluate collected security data according to defined detection logic and can generate alerts or incidents when suspicious conditions are identified. They form an important part of the detection architecture. Workbooks provide visualization, watchlists provide reference information, and playbooks automate response activities. Analytics rules should be designed around meaningful threat scenarios and should be tuned to reduce unnecessary alerts. Their effectiveness depends on appropriate data sources, quality telemetry, detection logic, and continuous review.<\/span><\/p>\n<h3><b>Question 275<\/b><\/h3>\n<p><b>Which network security architecture helps route application traffic through centralized inspection and security services before reaching protected workloads?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hub-and-spoke architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Direct unrestricted routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public-only connectivity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hub-and-spoke architecture can centralize shared network services such as firewalls, routing, monitoring, and connectivity while keeping workload networks separated in individual spokes. Traffic between workloads or external locations can be routed through appropriate inspection points according to security requirements. Flat networks provide fewer boundaries, while unrestricted routing can bypass important controls. Public-only connectivity may expose workloads unnecessarily. The architecture should be designed around required traffic flows, inspection needs, latency, resilience, and administrative responsibilities.<\/span><\/p>\n<h3><b>Question 276<\/b><\/h3>\n<p><b>Which security architecture approach helps protect an API from unauthorized requests while allowing legitimate applications to consume it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">API authentication and authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous API access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared public credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted API permissions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">API authentication verifies the identity of a calling application or user, while authorization determines which operations and resources that identity can access. Together, these controls prevent an API from treating every request as trusted. Anonymous access and shared credentials make it harder to establish identity and accountability, while unrestricted permissions increase the impact of compromise. Secure API architecture should also consider rate limiting, input validation, transport encryption, logging, monitoring, secret management, and appropriate network restrictions.<\/span><\/p>\n<h3><b>Question 277<\/b><\/h3>\n<p><b>Which practice can help identify vulnerable operating system packages and applications installed on managed endpoints?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling endpoint telemetry<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public device enrollment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vulnerability assessment identifies known security weaknesses in operating systems, applications, and other software components. On managed endpoints, this information can help security teams prioritize patching and remediation according to severity and business risk. Disabling telemetry reduces visibility, while shared administrator access increases exposure. Public device enrollment does not provide vulnerability management. Effective vulnerability architecture should include asset inventory, risk prioritization, remediation workflows, patch management, verification, and reporting so that identified vulnerabilities are addressed rather than merely documented.<\/span><\/p>\n<h3><b>Question 278<\/b><\/h3>\n<p><b>Which security architecture practice helps ensure that backups can be restored successfully when they are actually needed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Regular recovery testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup creation without validation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared backup passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unmonitored backup jobs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Regular recovery testing validates whether backup data can actually be restored within the required recovery objectives. A backup process that appears successful may still fail during recovery because of corruption, missing dependencies, configuration problems, or incomplete data. Testing can identify these issues before a real outage or cyberattack occurs. Shared passwords and unmonitored jobs introduce additional risks. Recovery testing should include representative workloads, documented procedures, appropriate access controls, monitoring, and measurement against defined recovery requirements.<\/span><\/p>\n<h3><b>Question 279<\/b><\/h3>\n<p><b>Which governance control can help ensure that a security policy exception receives approval from an authorized risk owner?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Formal exception approval workflow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatic exception acceptance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous approval<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted policy bypass<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A formal exception approval workflow ensures that deviations from security policy are reviewed and approved by an authorized person or risk owner. The process should document the affected control, business justification, risk, compensating measures, ownership, and review or expiration date. Automatic acceptance and anonymous approval weaken governance, while unrestricted policy bypass removes accountability. Formal exception management allows organizations to accommodate legitimate business requirements without losing visibility into security risks or allowing undocumented deviations to become permanent.<\/span><\/p>\n<h3><b>Question 280<\/b><\/h3>\n<p><b>Which architecture strategy best supports protecting data even when an attacker gains access to the underlying storage infrastructure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data encryption with controlled key management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public storage permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared encryption keys<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted storage access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data encryption can protect information from unauthorized disclosure even if an attacker gains access to the underlying storage infrastructure. Controlled key management is equally important because encryption provides limited protection if attackers can easily obtain the encryption keys. Public permissions and unrestricted access increase exposure, while shared keys make it harder to maintain proper separation and accountability. A comprehensive data protection architecture should consider encryption at rest and in transit, key rotation, access controls, classification, monitoring, and appropriate separation of key-management responsibilities.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-100 Exam Dumps and Practice Test Dumps. &nbsp; Question 261 Which Microsoft Entra capability can help organizations manage access for external users through predefined resource collections and lifecycle controls? Azure Policy Microsoft Defender for Identity Microsoft Entra Entitlement Management Azure DDoS Protection Correct Answer: 3 Explanation Microsoft Entra Entitlement Management provides structured [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17625"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17625"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17625\/revisions"}],"predecessor-version":[{"id":17626,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17625\/revisions\/17626"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17625"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17625"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17625"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}