{"id":17629,"date":"2026-09-21T10:38:07","date_gmt":"2026-09-21T10:38:07","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17629"},"modified":"2026-09-21T10:38:07","modified_gmt":"2026-09-21T10:38:07","slug":"microsoft-sc-100-practice-test-questions-and-exam-dumps-part16-q301-320","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-100-practice-test-questions-and-exam-dumps-part16-q301-320\/","title":{"rendered":"Microsoft SC-100 Practice Test Questions and Exam Dumps Part16 Q301-320"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-100-exam-dumps\"><b>Microsoft SC-100 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 301<\/b><\/h3>\n<p><b>Which Microsoft security architecture capability helps correlate security signals from identities, endpoints, email, and applications to investigate an attack across multiple surfaces?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender XDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Cost Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Records Management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender XDR correlates security signals across multiple Microsoft security products to provide a broader view of attacks and related entities. This can help security teams investigate incidents that span identities, endpoints, email, applications, and other supported resources. Cost Management focuses on financial analysis, Resource Manager manages Azure resources, and Records Management addresses information governance. Cross-domain correlation is valuable because attackers often move between security surfaces rather than remaining within a single technology layer.<\/span><\/p>\n<h3><b>Question 302<\/b><\/h3>\n<p><b>An organization needs to ensure that development workloads cannot access production secrets even though both environments use the same cloud platform. Which architecture should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared credentials across environments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separate identities and access boundaries<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Global administrator permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Common unrestricted secret store<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separate identities and access boundaries help prevent development workloads from accessing production resources and secrets. Development, testing, and production environments should have clearly defined trust boundaries, permissions, and administrative controls. Sharing credentials across environments increases the impact of compromise and makes accountability difficult. Global administrator permissions and unrestricted secret stores create excessive privilege. Environment separation should also include distinct deployment pipelines, access policies, monitoring, and approval processes so that production resources remain protected from lower-trust environments.<\/span><\/p>\n<h3><b>Question 303<\/b><\/h3>\n<p><b>Which Microsoft security capability is designed to help discover and govern sensitive data across an organization&#8217;s data estate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview provides data governance and compliance capabilities that can help organizations discover, classify, govern, and protect information across supported data sources. Understanding where sensitive information exists is an important architectural requirement because security controls depend on knowing which data requires stronger protection. Azure Bastion provides administrative access, Azure Firewall provides network security, and Traffic Manager provides traffic routing. Purview capabilities can support data classification, governance, compliance, lifecycle management, and protection decisions across an organization&#8217;s information environment.<\/span><\/p>\n<h3><b>Question 304<\/b><\/h3>\n<p><b>Which approach provides a dedicated security boundary for high-value administrative accounts and systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public administration network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared workstation model<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Standard user environment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privileged administrative tiering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged administrative tiering separates highly privileged systems and accounts from lower-trust environments. This limits pathways through which an attacker compromising an ordinary workstation or account could reach critical administrative infrastructure. A public administration network or shared workstation model does not provide adequate separation, while a standard user environment is not designed for highly privileged operations. Tiered administration should be supported by dedicated administrative identities, hardened workstations, strong authentication, monitoring, restricted connectivity, and clearly defined administrative procedures.<\/span><\/p>\n<h3><b>Question 305<\/b><\/h3>\n<p><b>Which security control is most appropriate for preventing unauthorized users from changing critical Azure resource configurations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Role-based access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public network access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted contributor access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Role-based access control helps limit Azure resource management operations according to assigned roles and permissions. By granting users only the permissions required for their responsibilities, organizations can reduce unauthorized configuration changes. Public network access does not determine administrative authorization, while anonymous authentication and unrestricted contributor access provide insufficient protection. RBAC should be combined with privileged identity management, strong authentication, access reviews, logging, and separation of duties for sensitive administrative operations.<\/span><\/p>\n<h3><b>Question 306<\/b><\/h3>\n<p><b>Which security architecture practice helps determine whether an organization has sufficient telemetry to investigate a particular threat scenario?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cost optimization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detection coverage assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage expansion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network bandwidth planning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Detection coverage assessment evaluates whether the organization collects and analyzes the signals necessary to identify and investigate relevant threats. It can reveal gaps such as missing endpoint telemetry, insufficient identity logs, unavailable application events, or incomplete cloud activity data. Cost optimization and bandwidth planning may influence architecture decisions but do not directly establish detection coverage. A security architecture should map important threat scenarios to required data sources, detection logic, investigation capabilities, retention requirements, and response procedures.<\/span><\/p>\n<h3><b>Question 307<\/b><\/h3>\n<p><b>Which Microsoft Sentinel feature can help analysts investigate entities and relationships associated with a security incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sentinel investigation capabilities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Locks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel provides investigation capabilities that help analysts examine incidents, entities, alerts, and related security information. Understanding relationships between users, devices, IP addresses, applications, and other entities can help analysts determine the scope and potential progression of an attack. Azure Policy governs resource configurations, Purview focuses on data governance and compliance, and Resource Locks protect resources from certain changes. Investigation capabilities are most effective when Sentinel receives relevant, high-quality telemetry from appropriately selected data sources.<\/span><\/p>\n<h3><b>Question 308<\/b><\/h3>\n<p><b>Which architecture pattern is most appropriate when multiple applications require a common security service such as centralized authentication or policy enforcement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Duplicate independent security implementations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared centralized security service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public anonymous service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Uncontrolled application-specific access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A shared centralized security service can provide consistent capabilities across multiple applications while reducing duplicated implementations. Examples include centralized identity services, policy enforcement, key management, logging, or security monitoring. Independent implementations can create inconsistent controls and increase maintenance requirements. Anonymous or uncontrolled access weakens security boundaries. Centralized services should still support appropriate isolation, availability, least privilege, scalability, and clear ownership so that a shared service does not become an unnecessary single point of failure or excessive trust boundary.<\/span><\/p>\n<h3><b>Question 309<\/b><\/h3>\n<p><b>Which security architecture principle requires sensitive operations to be approved by a different individual from the person performing them?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network openness<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared responsibility without ownership<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separation of duties divides sensitive responsibilities among multiple individuals or roles so that one person cannot independently complete a high-risk process. For example, one administrator may request a privileged change while another authorized person approves it. This reduces the opportunity for unauthorized actions and provides stronger accountability. Public access and network openness do not provide this governance control. Separation of duties should be applied according to risk, especially for activities such as privileged access, security policy changes, production deployments, and financial or regulatory operations.<\/span><\/p>\n<h3><b>Question 310<\/b><\/h3>\n<p><b>Which Azure architecture component can centralize management of subscriptions and apply governance consistently across multiple workloads?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Management Groups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Management Groups provide a hierarchical structure for organizing subscriptions and applying governance at an appropriate scope. Policies, role assignments, and other governance mechanisms can be managed across groups of subscriptions rather than configured independently for every subscription. Bastion provides secure administrative access, Load Balancer distributes traffic, and Key Vault manages secrets and keys. Management groups are useful in large environments where centralized governance and delegated administration must coexist with workload-specific responsibilities.<\/span><\/p>\n<h3><b>Question 311<\/b><\/h3>\n<p><b>Which security architecture approach helps ensure that cloud resources are created according to a predefined set of organizational security requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual configuration after deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted resource creation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy-based governance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public deployment permissions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Policy-based governance allows organizations to define requirements that can be evaluated or enforced during resource deployment and ongoing operation. Policies can address areas such as permitted regions, required configurations, tagging, security settings, and other organizational standards. Manual post-deployment configuration can leave temporary security gaps, while unrestricted creation makes consistent governance difficult. Policy-based controls should be supported by monitoring, exception management, change control, and periodic review so that requirements remain aligned with business and security needs.<\/span><\/p>\n<h3><b>Question 312<\/b><\/h3>\n<p><b>Which authentication architecture is designed to remove the need for users to regularly enter passwords while using strong cryptographic credentials?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passwordless authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared password authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Basic authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password rotation only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Passwordless authentication allows users to authenticate without relying on traditional passwords as the primary authentication factor. Supported methods can use cryptographic credentials or device-based authentication mechanisms, reducing exposure to password theft, reuse, and phishing. Shared passwords and basic authentication provide weaker protection, while password rotation still depends on passwords. A passwordless architecture should consider device registration, recovery procedures, identity protection, authentication strength, user experience, and application compatibility to ensure that the stronger authentication model can be adopted securely.<\/span><\/p>\n<h3><b>Question 313<\/b><\/h3>\n<p><b>Which security architecture capability can help determine whether a user should receive access based on the risk level of the sign-in?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk-based Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk-based Conditional Access can use identity risk and sign-in risk information to apply appropriate access requirements. Depending on the detected risk and configured policies, an organization can require stronger authentication, block access, or require remediation. Azure Storage, DNS, and Load Balancer provide infrastructure capabilities rather than identity risk evaluation. Risk-based access should be carefully designed to balance security and usability, with appropriate authentication methods, policy exclusions, monitoring, and procedures for handling false positives or legitimate high-risk situations.<\/span><\/p>\n<h3><b>Question 314<\/b><\/h3>\n<p><b>Which software development security control can detect credentials accidentally committed into source-code repositories?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secret scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage replication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secret scanning examines source code and related repositories for credentials, tokens, keys, and other sensitive values that may have been accidentally exposed. Detecting secrets early can allow developers and security teams to revoke compromised credentials and prevent them from reaching production systems. Load balancing and DNS filtering address network concerns, while storage replication supports resilience. Secret scanning should be combined with secure secret management, automated credential rotation, developer education, repository controls, and pipeline enforcement so that discovered secrets are handled promptly.<\/span><\/p>\n<h3><b>Question 315<\/b><\/h3>\n<p><b>Which architecture capability helps an organization identify whether an application has an excessive number of permissions compared with its actual business requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network packet inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application authorization review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage performance testing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An application authorization review evaluates whether an application or workload has more permissions than necessary for its intended functions. Excessive permissions can increase the impact of compromised applications or identities. Reviewing permissions against documented business requirements helps identify opportunities to reduce privileges and improve authorization boundaries. Network inspection, DNS monitoring, and storage performance testing address different concerns. Authorization reviews should consider application roles, service identities, resource scopes, privileged operations, and changes introduced during application development or deployment.<\/span><\/p>\n<h3><b>Question 316<\/b><\/h3>\n<p><b>Which security architecture capability can help reduce the impact of a compromised administrator by requiring privileged access to be activated only when needed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent administrator access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Just-in-time privileged access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous administration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Just-in-time privileged access limits elevated permissions to a defined period rather than keeping them permanently active. This reduces standing privilege and can limit the time available for attackers to misuse compromised administrative credentials. Permanent access and shared credentials increase exposure, while anonymous administration eliminates appropriate accountability. Just-in-time access should be combined with strong authentication, approval or justification requirements where appropriate, logging, monitoring, and periodic review to ensure that privileged access remains aligned with administrative responsibilities.<\/span><\/p>\n<h3><b>Question 317<\/b><\/h3>\n<p><b>Which architecture approach can help ensure that security requirements are automatically included when infrastructure is deployed through code?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security as code<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual configuration only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Post-deployment inspection only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted infrastructure deployment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security as code expresses security requirements through machine-readable configurations, policies, tests, and automated checks that can be integrated into infrastructure and deployment processes. This approach can improve consistency and allow security controls to be evaluated repeatedly as infrastructure changes. Manual configuration alone can introduce inconsistency, while post-deployment inspection may identify issues after exposure has already occurred. Security as code should include version control, peer review, automated validation, controlled deployment, exception handling, and continuous monitoring of the resulting environment.<\/span><\/p>\n<h3><b>Question 318<\/b><\/h3>\n<p><b>Which security architecture approach is most appropriate for protecting an application that processes highly sensitive information while still allowing required business connectivity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove all monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use layered security controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Provide unrestricted network access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rely only on passwords<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Layered security controls provide multiple complementary protections around a sensitive application. These can include strong authentication, least privilege, network segmentation, encryption, application authorization, endpoint protection, monitoring, vulnerability management, and incident-response capabilities. Relying on a single control creates a larger impact if that control fails or is bypassed. Unrestricted access and password-only authentication provide insufficient protection for highly sensitive workloads. The architecture should be based on the application&#8217;s data sensitivity, business criticality, threat exposure, regulatory obligations, and required connectivity.<\/span><\/p>\n<h3><b>Question 319<\/b><\/h3>\n<p><b>Which recovery architecture feature prevents backup data from being modified or deleted during a defined protection period?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Immutable backup storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public storage permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared backup credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted administrator access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Immutable backup storage can prevent protected backup data from being modified or deleted during a defined retention or protection period. This can be particularly important in ransomware scenarios where attackers attempt to destroy recovery resources after compromising production systems. Public permissions and shared credentials increase the risk of unauthorized access, while unrestricted administrator access can undermine recovery protections. Immutable backups should be combined with isolated administration, monitoring, recovery testing, appropriate retention requirements, and documented procedures for restoring critical business services.<\/span><\/p>\n<h3><b>Question 320<\/b><\/h3>\n<p><b>Which security architecture activity should occur when a major business application introduces a significant new data-processing capability?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore the change until an incident occurs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove existing security controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reassess security and privacy requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Grant all application users administrative access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A major change in how an application processes data can introduce new security, privacy, compliance, and operational risks. Reassessing requirements allows architects to determine whether existing controls remain appropriate and whether additional protections are needed. The assessment may cover data classification, access permissions, encryption, retention, monitoring, regulatory obligations, third-party dependencies, and threat scenarios. Ignoring the change or removing controls can create unmanaged exposure, while granting broad administrative access violates least-privilege principles. Security architecture should evolve as business capabilities and data usage change.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-100 Exam Dumps and Practice Test Dumps. &nbsp; Question 301 Which Microsoft security architecture capability helps correlate security signals from identities, endpoints, email, and applications to investigate an attack across multiple surfaces? Microsoft Defender XDR Azure Cost Management Azure Resource Manager Microsoft Purview Records Management Correct Answer: 1 Explanation Microsoft Defender XDR [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17629"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17629"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17629\/revisions"}],"predecessor-version":[{"id":17630,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17629\/revisions\/17630"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17629"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17629"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17629"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}