{"id":17631,"date":"2026-09-21T10:38:26","date_gmt":"2026-09-21T10:38:26","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17631"},"modified":"2026-09-21T10:38:26","modified_gmt":"2026-09-21T10:38:26","slug":"microsoft-sc-100-practice-test-questions-and-exam-dumps-part17-q321-340","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-100-practice-test-questions-and-exam-dumps-part17-q321-340\/","title":{"rendered":"Microsoft SC-100 Practice Test Questions and Exam Dumps Part17 Q321-340"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-100-exam-dumps\"><b>Microsoft SC-100 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 321<\/b><\/h3>\n<p><b>Which security architecture capability is designed to protect applications from common web-based attacks such as SQL injection and cross-site scripting?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Application Firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Web Application Firewall protects supported web applications by inspecting HTTP and HTTPS requests and applying security rules. It can help detect and block common web attacks such as SQL injection and cross-site scripting. Azure Bastion provides administrative connectivity to virtual machines, Azure DNS handles name resolution, and Load Balancer distributes network traffic. WAF should be part of a broader application security strategy that includes secure coding, authentication, authorization, vulnerability management, monitoring, and appropriate network protections.<\/span><\/p>\n<h3><b>Question 322<\/b><\/h3>\n<p><b>Which security architecture approach helps organizations enforce consistent security requirements across multiple Azure subscriptions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Individual manual configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Centralized policy governance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public resource access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separate unmanaged configurations<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized policy governance helps organizations apply consistent security requirements across multiple Azure subscriptions. Azure Policy and management structures can be used to define requirements for configurations, locations, tags, security settings, and other organizational standards. Manual configuration can lead to inconsistencies, while unmanaged subscriptions may develop different security postures. Centralized governance should still allow appropriate delegation to workload teams and should include documented exceptions, monitoring, change management, and periodic policy reviews to ensure that requirements remain practical and aligned with business needs.<\/span><\/p>\n<h3><b>Question 323<\/b><\/h3>\n<p><b>Which capability can help security teams determine whether an identity has been compromised based on unusual authentication patterns?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra ID Protection uses identity-related risk signals to help identify potentially compromised users and suspicious authentication activity. These signals can be incorporated into access decisions and remediation workflows. Azure Storage provides data services, Traffic Manager manages traffic routing, and Resource Manager provides resource management capabilities. Identity risk detection should be combined with strong authentication, Conditional Access, lifecycle governance, monitoring, and appropriate response procedures. Security architects should also establish processes for investigating risky sign-ins and handling legitimate activities that generate elevated risk signals.<\/span><\/p>\n<h3><b>Question 324<\/b><\/h3>\n<p><b>A company needs to protect an internal application while allowing employees to reach it without exposing the application directly to the public internet. Which architecture is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP with unrestricted access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous application access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private network connectivity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public DNS-only protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Private network connectivity can keep an internal application inaccessible directly from the public internet while allowing authorized users and workloads to reach it through controlled network paths. Depending on the architecture, private endpoints, virtual networks, VPN connectivity, or other private networking technologies can be used. Public exposure increases the attack surface, while DNS alone does not provide application authorization or network isolation. Private connectivity should still be combined with identity controls, authorization, monitoring, segmentation, and secure application design.<\/span><\/p>\n<h3><b>Question 325<\/b><\/h3>\n<p><b>Which security practice helps prevent developers from using production credentials during application development?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared production accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separate development identities and secrets<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent administrator access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Production credentials stored in source code<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separate development identities and secrets help maintain a security boundary between development and production environments. Developers should receive access appropriate to development activities without receiving unnecessary production privileges or credentials. Shared production accounts and permanent administrator access increase the consequences of compromised development systems or accounts. Storing production credentials in source code creates additional exposure. Environment separation should also include dedicated subscriptions or resource groups where appropriate, independent secrets, controlled deployment pipelines, and explicit approval processes for production changes.<\/span><\/p>\n<h3><b>Question 326<\/b><\/h3>\n<p><b>Which security architecture component can provide centralized collection and analysis of security events from multiple sources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Sentinel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel provides cloud-native SIEM capabilities for collecting, analyzing, and correlating security data from multiple sources. Centralized monitoring can help security teams identify suspicious patterns that might not be visible when logs are examined separately. Azure Bastion provides secure administrative access, Private DNS supports private name resolution, and Load Balancer distributes network traffic. Sentinel architecture should consider data connectors, analytics rules, retention, automation, investigation requirements, threat intelligence, and the operational needs of security analysts.<\/span><\/p>\n<h3><b>Question 327<\/b><\/h3>\n<p><b>Which security architecture approach reduces the likelihood that an attacker can move from a compromised endpoint to critical administrative systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrative isolation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator workstations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat network connectivity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal privileged access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Administrative isolation separates privileged systems, accounts, and management paths from ordinary user environments. This can reduce opportunities for attackers to move from a compromised endpoint toward critical administrative infrastructure. Shared workstations and flat connectivity increase exposure, while universal privileged access creates excessive permissions. Administrative isolation can include privileged access workstations, dedicated administrative identities, network restrictions, strong authentication, just-in-time elevation, and monitoring. The design should focus on protecting high-value administrative paths because compromise of these paths can affect many other resources.<\/span><\/p>\n<h3><b>Question 328<\/b><\/h3>\n<p><b>Which security capability can automatically investigate certain endpoint alerts and recommend or perform remediation actions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender automated investigation and response<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Locks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Records Management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender automated investigation and response capabilities can investigate certain security alerts and perform or recommend remediation actions based on supported detections and configured permissions. Automation can reduce repetitive analyst tasks and help accelerate response to common threats. Azure Policy manages resource governance, Resource Locks protect resources from certain changes, and Purview Records Management handles information governance. Automated remediation should be tested carefully and governed with appropriate permissions, monitoring, approval requirements, and escalation procedures for situations where automated action could affect legitimate business activity.<\/span><\/p>\n<h3><b>Question 329<\/b><\/h3>\n<p><b>Which architecture principle requires every access request to be evaluated according to available identity, device, and risk information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perimeter trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implicit trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero Trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static authorization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero Trust requires organizations to avoid assuming that a user or device is trustworthy simply because it is located within a particular network. Access decisions should consider identity, device state, resource sensitivity, application context, and relevant risk signals. Perimeter-based and static authorization models may provide insufficient protection when an attacker obtains valid credentials or compromises an internal device. Zero Trust architecture applies continuous verification, least privilege, segmentation, and monitoring across identity, endpoint, application, network, and data security layers.<\/span><\/p>\n<h3><b>Question 330<\/b><\/h3>\n<p><b>Which security control helps ensure that only approved applications can execute on a sensitive endpoint?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage replication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application control can restrict software execution according to approved rules, reducing the likelihood that unauthorized or malicious applications will run on sensitive endpoints. This can be particularly useful for privileged workstations, critical servers, and high-value systems. Public DNS, load balancing, and storage replication address different infrastructure requirements. Application control should be carefully tested because overly restrictive policies can interfere with legitimate business applications. Deployment should include monitoring, exception management, change control, and regular review of approved software.<\/span><\/p>\n<h3><b>Question 331<\/b><\/h3>\n<p><b>Which security architecture capability can provide centralized protection for cryptographic keys and application secrets?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Key Vault provides centralized management for secrets, cryptographic keys, and certificates. Centralizing sensitive material can reduce the need to embed secrets within application code or configuration files and can support controlled access, auditing, and lifecycle management. Traffic Manager and Load Balancer provide traffic management capabilities, while Bastion provides secure administrative access to virtual machines. Key Vault access should follow least privilege and should be combined with managed identities, monitoring, appropriate key rotation, and separation of administrative responsibilities.<\/span><\/p>\n<h3><b>Question 332<\/b><\/h3>\n<p><b>Which security architecture practice helps identify whether an organization&#8217;s controls address the most important threats before implementation begins?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security gap and threat analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public access testing only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cost estimation without risk analysis<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security gap and threat analysis helps organizations determine whether planned controls address relevant threats, business risks, and security requirements. It can identify missing capabilities, weak assumptions, unnecessary controls, and areas requiring stronger protection before implementation. Unrestricted deployment can introduce unmanaged risks, while cost estimation alone does not determine security effectiveness. Analysis should consider assets, threat scenarios, business impact, regulatory requirements, existing controls, and target-state architecture. The results can then be used to prioritize security improvements and architectural decisions.<\/span><\/p>\n<h3><b>Question 333<\/b><\/h3>\n<p><b>Which identity architecture capability can allow an external organization to collaborate with internal users while maintaining controlled access to organizational resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra B2B collaboration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Locks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra B2B collaboration can allow external users to access selected organizational resources using their external identities while maintaining organizational controls over that access. This can support partners, contractors, suppliers, and other external collaborators. DDoS Protection addresses availability threats, Storage replication supports resilience, and Resource Locks protect Azure resources from certain changes. External identity architecture should include appropriate invitation controls, authentication requirements, lifecycle management, access reviews, least privilege, and monitoring to prevent external access from becoming excessive or permanent.<\/span><\/p>\n<h3><b>Question 334<\/b><\/h3>\n<p><b>Which architecture approach provides separate security controls for internet-facing applications and internal workloads?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single flat security zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Distinct security zones<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal network access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared unrestricted firewall rules<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Distinct security zones allow organizations to apply different controls according to the exposure and sensitivity of workloads. Internet-facing applications may require stronger edge protection, WAF capabilities, restricted inbound traffic, and additional monitoring, while internal workloads may have different connectivity requirements. A flat security zone can make it harder to apply differentiated protections. Universal access and shared unrestricted firewall rules increase exposure. Security zones should be designed around trust boundaries, data sensitivity, business requirements, application dependencies, and expected traffic flows.<\/span><\/p>\n<h3><b>Question 335<\/b><\/h3>\n<p><b>Which Microsoft Purview capability can help organizations manage how long information should be retained and when it can be disposed of?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defender for Endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Records management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Records Management supports information governance requirements related to retention, records, and disposition. Organizations can define policies that determine how certain information should be retained and managed throughout its lifecycle. This can help address regulatory, legal, and business requirements while reducing unnecessary retention. Defender for Endpoint protects devices, Azure Firewall provides network security, and Bastion provides administrative connectivity. Retention architecture should consider data classification, legal requirements, business value, privacy obligations, and documented disposal processes.<\/span><\/p>\n<h3><b>Question 336<\/b><\/h3>\n<p><b>Which security architecture practice can help prevent unauthorized infrastructure changes from being introduced directly into production?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controlled change management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Direct unrestricted editing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous deployment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Controlled change management requires infrastructure modifications to follow defined processes such as review, testing, approval, deployment, and documentation. This helps prevent unauthorized or poorly tested changes from reaching production and provides accountability for significant modifications. Shared passwords and unrestricted editing weaken accountability and make it difficult to determine who changed a configuration. Anonymous deployment also removes important governance controls. Change management should be integrated with infrastructure as code, version control, automated validation, security testing, monitoring, and documented emergency-change procedures.<\/span><\/p>\n<h3><b>Question 337<\/b><\/h3>\n<p><b>Which security architecture capability helps identify potentially dangerous attack paths involving cloud resources and permissions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cost Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attack path analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attack path analysis can help security teams understand how weaknesses, exposed resources, identities, permissions, and network relationships could combine to create a route toward valuable assets. This perspective can help prioritize remediation based on potential attack impact rather than treating every finding independently. Cost Management addresses financial analysis, DNS handles name resolution, and Load Balancer distributes traffic. Attack path findings should be evaluated alongside business criticality, asset sensitivity, exploitability, existing controls, and operational feasibility when prioritizing security improvements.<\/span><\/p>\n<h3><b>Question 338<\/b><\/h3>\n<p><b>Which architecture approach helps ensure that security controls are tested before an application is promoted to production?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security validation in CI\/CD<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Production-only testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual credential sharing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security validation in CI\/CD integrates security checks into the software delivery process before an application reaches production. Depending on requirements, validation can include code analysis, dependency scanning, secret detection, infrastructure checks, configuration validation, and security tests. Production-only testing can discover problems too late, while unrestricted deployment bypasses important controls. Manual credential sharing also introduces security risks. Automated validation should be combined with appropriate approval gates, exception management, secure identities, artifact integrity controls, and continuous runtime monitoring.<\/span><\/p>\n<h3><b>Question 339<\/b><\/h3>\n<p><b>Which security architecture capability helps protect users when accessing applications by requiring stronger authentication under specific risk conditions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access enables organizations to create policies that evaluate access conditions and apply requirements such as stronger authentication or access restrictions. Policies can consider factors including user identity, device state, application, location, and risk signals. Storage, Private DNS, and Traffic Manager provide infrastructure capabilities rather than access-policy enforcement. Conditional Access should be designed carefully to avoid creating unnecessary business disruption while still enforcing appropriate security requirements for sensitive applications and elevated-risk access attempts.<\/span><\/p>\n<h3><b>Question 340<\/b><\/h3>\n<p><b>Which security architecture principle recommends continuously improving controls based on new threats, incidents, and changes in business requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static security configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Continuous security improvement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent exception acceptance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Technology deployment without reassessment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Continuous security improvement recognizes that threats, technologies, business processes, and regulatory requirements change over time. Organizations should regularly assess security controls, review incidents, analyze new threats, measure control effectiveness, and update architecture when necessary. Static configurations may become ineffective as environments evolve, while permanent exceptions can introduce unmanaged risk. Technology should not be deployed without reassessment of its security implications. Continuous improvement creates a feedback loop between security operations, architecture, risk management, compliance, and business stakeholders.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-100 Exam Dumps and Practice Test Dumps. &nbsp; Question 321 Which security architecture capability is designed to protect applications from common web-based attacks such as SQL injection and cross-site scripting? Azure Bastion Azure DNS Azure Load Balancer Web Application Firewall Correct Answer: 4 Explanation A Web Application Firewall protects supported web applications [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17631"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17631"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17631\/revisions"}],"predecessor-version":[{"id":17632,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17631\/revisions\/17632"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17631"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17631"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17631"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}