{"id":17633,"date":"2026-09-21T10:38:44","date_gmt":"2026-09-21T10:38:44","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17633"},"modified":"2026-09-21T10:38:44","modified_gmt":"2026-09-21T10:38:44","slug":"microsoft-sc-100-practice-test-questions-and-exam-dumps-part18-q341-360","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-100-practice-test-questions-and-exam-dumps-part18-q341-360\/","title":{"rendered":"Microsoft SC-100 Practice Test Questions and Exam Dumps Part18 Q341-360"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-100-exam-dumps\"><b>Microsoft SC-100 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 341<\/b><\/h3>\n<p><b>Which security architecture capability helps identify security weaknesses in an organization&#8217;s cloud configuration before they are exploited?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud security posture management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud security posture management helps organizations continuously evaluate cloud environments against security requirements and identify configuration weaknesses. It can highlight issues such as excessive permissions, insecure network settings, missing protections, or policy violations. Load Balancer and Traffic Manager provide traffic-management capabilities, while Azure DNS provides name-resolution services. Security posture management is most effective when findings are prioritized according to business risk, monitored continuously, and connected to remediation workflows so that important weaknesses are addressed rather than simply reported.<\/span><\/p>\n<h3><b>Question 342<\/b><\/h3>\n<p><b>Which architecture practice helps ensure that an application&#8217;s security requirements are considered before its design is finalized?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Post-production incident review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security requirements analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual password sharing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security requirements analysis identifies the protection needs of an application before architectural decisions become difficult to change. Requirements may cover authentication, authorization, data protection, logging, availability, compliance, privacy, network boundaries, and incident response. Performing this analysis early allows architects and developers to design appropriate controls into the solution instead of adding them after deployment. Unrestricted deployment and shared passwords introduce unnecessary risk, while post-production review occurs too late to influence many foundational design decisions.<\/span><\/p>\n<h3><b>Question 343<\/b><\/h3>\n<p><b>Which Microsoft security architecture capability can help identify suspicious activity occurring within an organization&#8217;s on-premises Active Directory environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Identity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Records Management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Identity is designed to help detect identity-related threats and suspicious activities within on-premises Active Directory environments. It can provide security signals related to domain controllers and identities, helping organizations investigate techniques such as credential theft and lateral movement. Azure Bastion provides administrative connectivity, Front Door supports application delivery, and Purview Records Management addresses information governance. Defender for Identity can contribute to a broader hybrid identity security architecture alongside Entra ID, endpoint protection, monitoring, and privileged access controls.<\/span><\/p>\n<h3><b>Question 344<\/b><\/h3>\n<p><b>An organization wants to prevent a security team from granting itself unrestricted access while administering a sensitive environment. Which principle should be applied?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal administration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent privilege<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separation of duties prevents sensitive responsibilities from being concentrated in a single person or role. For example, the person requesting a high-risk privilege change may be different from the person approving it. This provides stronger accountability and reduces the opportunity for unauthorized activity. Universal administration, shared credentials, and permanent privilege increase the potential impact of a compromised or misused administrative account. Separation of duties should be applied according to risk and can be combined with approval workflows, privileged identity management, logging, and periodic reviews.<\/span><\/p>\n<h3><b>Question 345<\/b><\/h3>\n<p><b>Which Microsoft Sentinel capability can automatically respond to an alert by calling predefined workflows and external services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Watchlists<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Playbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data connectors<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel playbooks provide automation capabilities that can execute predefined workflows in response to alerts or incidents. They can perform tasks such as notifying teams, enriching incident information, creating service-management tickets, or initiating other approved actions. Watchlists provide reference information, workbooks visualize data, and data connectors ingest information into Sentinel. Playbooks should use appropriately scoped permissions and should be thoroughly tested because automated actions can have operational consequences. Logging and monitoring should also be implemented to verify automation effectiveness.<\/span><\/p>\n<h3><b>Question 346<\/b><\/h3>\n<p><b>Which architecture capability helps ensure that only trusted software artifacts are promoted through a deployment pipeline?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Artifact integrity verification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public deployment permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted artifact replacement<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Artifact integrity verification helps ensure that software packages or deployment artifacts have not been unexpectedly modified between build and deployment stages. Organizations can use mechanisms such as cryptographic hashes, signatures, trusted repositories, and controlled promotion processes to establish confidence in artifact integrity. Shared passwords and unrestricted replacement increase supply-chain risk, while public deployment permissions weaken control over production releases. Artifact security should be combined with secure build environments, source-code protection, dependency management, access controls, and monitoring throughout the software delivery lifecycle.<\/span><\/p>\n<h3><b>Question 347<\/b><\/h3>\n<p><b>Which security architecture approach is most appropriate for workloads that require access to sensitive services without exposing those services through public endpoints?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoints<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous service access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet-only routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Private endpoints provide private network connectivity to supported services without requiring the service to be directly exposed through a public endpoint. This can reduce public attack surface and help organizations build controlled network paths for sensitive workloads. Public IP architectures and internet-only routing can create unnecessary exposure, while anonymous service access does not provide adequate authorization. Private endpoint designs should still incorporate identity controls, authorization, DNS configuration, network segmentation, monitoring, and appropriate service-level security because private connectivity alone does not determine who is authorized.<\/span><\/p>\n<h3><b>Question 348<\/b><\/h3>\n<p><b>Which security architecture metric measures the proportion of relevant assets that have appropriate security monitoring and detection coverage?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage utilization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network throughput<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detection coverage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application response time<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Detection coverage measures how effectively an organization can monitor and detect threats across relevant assets, systems, and scenarios. High-value assets should have appropriate telemetry and detection capabilities based on their business importance and threat exposure. Storage utilization, network throughput, and application response time can be useful operational metrics but do not directly measure security detection coverage. Security teams can use coverage measurements to identify monitoring gaps, prioritize telemetry investments, improve analytics rules, and determine whether critical threat scenarios can be detected and investigated.<\/span><\/p>\n<h3><b>Question 349<\/b><\/h3>\n<p><b>Which architecture control helps prevent a compromised application from using credentials belonging to an unrelated workload?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workload-specific identities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared service accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Global administrator credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Common application passwords<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Workload-specific identities allow applications and services to authenticate independently and receive permissions appropriate to their own responsibilities. This limits the impact if one workload is compromised because its credentials should not automatically provide access to unrelated resources. Shared service accounts and common passwords create broader trust relationships and make accountability more difficult. Global administrator credentials create excessive privilege. Workload identity architecture should include managed identities or appropriate federation where supported, narrowly scoped permissions, monitoring, and regular access reviews.<\/span><\/p>\n<h3><b>Question 350<\/b><\/h3>\n<p><b>Which security architecture capability helps organizations identify and prioritize vulnerabilities based on the assets and business services they could affect?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability risk prioritization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public network routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage replication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vulnerability risk prioritization considers more than the technical severity of a vulnerability. It can incorporate asset criticality, exploitability, exposure, business impact, compensating controls, and the importance of affected services. This helps security teams focus remediation efforts on weaknesses that represent greater organizational risk. DNS caching and storage replication address infrastructure requirements, while public routing concerns network connectivity. Effective vulnerability management should include asset inventory, scanning, prioritization, remediation, verification, reporting, and continuous reassessment as threats and environments change.<\/span><\/p>\n<h3><b>Question 351<\/b><\/h3>\n<p><b>Which Microsoft security capability can help protect endpoints by detecting malicious behavior and providing response capabilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Data Map<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint provides endpoint security capabilities including threat detection, endpoint detection and response, investigation, and response actions. It can help security teams identify malicious behavior occurring on supported devices and investigate associated activity. Azure Policy manages resource governance, Resource Manager manages Azure resources, and Purview Data Map supports data governance. Endpoint protection should be integrated into the broader security architecture so that endpoint signals can be correlated with identity, email, application, and cloud security information when investigating incidents.<\/span><\/p>\n<h3><b>Question 352<\/b><\/h3>\n<p><b>Which approach helps an organization maintain consistent security configurations across newly deployed cloud workloads?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security baselines<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual one-time configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Uncontrolled workload deployment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security baselines define approved configuration standards that can be applied consistently across workloads and environments. They can cover identity settings, logging, encryption, network controls, endpoint protections, and other requirements appropriate to the workload. Manual one-time configuration can lead to configuration drift, while shared passwords and uncontrolled deployments increase security risks. Baselines should be version-controlled, tested, monitored, and periodically updated as threats, technologies, and organizational requirements change. Exceptions should be documented and governed through an established process.<\/span><\/p>\n<h3><b>Question 353<\/b><\/h3>\n<p><b>Which security architecture model places security controls close to users, devices, applications, and data rather than relying primarily on a central network perimeter?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perimeter-only security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Distributed Zero Trust architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public network architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat network architecture<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A distributed Zero Trust architecture applies security controls across multiple layers rather than depending primarily on a central network perimeter. Identity, device, application, network, and data controls can each contribute to access decisions and risk reduction. Perimeter-only models may provide insufficient protection when users work remotely or when applications and services are distributed across cloud environments. A Zero Trust architecture supports continuous verification, least privilege, segmentation, monitoring, and contextual access decisions across the environment.<\/span><\/p>\n<h3><b>Question 354<\/b><\/h3>\n<p><b>Which capability helps an organization determine whether sensitive information is being accessed or shared in ways that violate organizational policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data governance and monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data governance and monitoring capabilities help organizations understand how sensitive information is classified, accessed, used, and shared. Microsoft Purview capabilities can support classification, auditing, data lifecycle management, and compliance-related monitoring across supported environments. Load Balancer and Traffic Manager manage network traffic, while Bastion provides administrative connectivity. Data monitoring should be aligned with sensitivity classifications, business requirements, privacy considerations, and regulatory obligations. Appropriate controls should also be established for investigating and responding to policy violations.<\/span><\/p>\n<h3><b>Question 355<\/b><\/h3>\n<p><b>Which architecture practice can reduce the risk created by long-lived application credentials in automated deployment environments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workload identity federation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent client secrets<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared deployment passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hard-coded credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Workload identity federation can allow automated workloads to authenticate using trusted identity assertions rather than storing long-lived credentials. This reduces the need to manage permanent secrets within deployment systems and can lower the impact of credential leakage. Permanent client secrets, shared passwords, and hard-coded credentials create additional risks because they may be exposed through source code, configuration, or build systems. Federation should use narrowly defined trust relationships and permissions so that only approved workloads can obtain access to the required resources.<\/span><\/p>\n<h3><b>Question 356<\/b><\/h3>\n<p><b>Which architecture approach helps an organization maintain security visibility when applications are distributed across multiple cloud and on-premises environments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Isolated monitoring systems with no correlation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Centralized security monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabled logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local-only security analysis<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized security monitoring can provide a unified view of security events across cloud, on-premises, identity, endpoint, and application environments. This is particularly useful in hybrid and multicloud architectures where individual systems may generate valuable but disconnected security signals. Isolated monitoring can make cross-environment investigation more difficult, while disabled logging removes important evidence. Centralized monitoring should include appropriate data connectors, normalization, retention, analytics, access controls, and automation so that security teams can efficiently identify and investigate relevant activity.<\/span><\/p>\n<h3><b>Question 357<\/b><\/h3>\n<p><b>Which security architecture capability can help ensure that a user who leaves the organization no longer retains access to protected resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity lifecycle automation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public network filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity lifecycle automation can help ensure that access is removed when users leave the organization or undergo relevant employment changes. Automated workflows can disable accounts, remove group memberships, revoke access packages, and trigger other defined offboarding activities. Manual processes can leave accounts active longer than necessary. Storage replication, DNS forwarding, and network filtering do not address identity lifecycle directly. Lifecycle automation should be integrated with authoritative HR information, identity governance, access reviews, privileged access management, and exception handling.<\/span><\/p>\n<h3><b>Question 358<\/b><\/h3>\n<p><b>Which security architecture approach provides stronger protection for highly privileged administrative activities by requiring administration from a hardened environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Standard employee laptop<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared public workstation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privileged Access Workstation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unmanaged personal device<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Privileged Access Workstation is designed specifically for sensitive administrative operations and can be hardened to reduce exposure to threats commonly encountered during ordinary user activity. Using a dedicated environment helps protect privileged credentials and administrative sessions from compromised applications, websites, or user activities. Standard employee laptops and unmanaged personal devices typically have broader exposure, while shared public workstations provide weak security boundaries. PAWs should be combined with strong authentication, restricted software, patching, monitoring, privileged identities, and controlled administrative workflows.<\/span><\/p>\n<h3><b>Question 359<\/b><\/h3>\n<p><b>Which security architecture practice helps identify whether an implemented control actually reduces the risk it was intended to address?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Control effectiveness testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application performance testing only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage capacity measurement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network bandwidth testing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control effectiveness testing evaluates whether a security control is correctly implemented, operates as intended, and provides the expected level of risk reduction. Testing may include technical validation, simulated attacks, configuration reviews, audit evidence, operational metrics, or other appropriate assessment methods. Performance and capacity measurements can be useful for infrastructure planning but do not demonstrate security effectiveness. Control testing should be performed periodically and after major changes because an effective control can become ineffective if configurations, threats, dependencies, or business processes change.<\/span><\/p>\n<h3><b>Question 360<\/b><\/h3>\n<p><b>Which architecture principle requires security teams to design controls according to the sensitivity and importance of the resources being protected?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Equal controls for every resource<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk-based security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Technology-first architecture<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk-based security applies controls according to factors such as data sensitivity, business criticality, threat exposure, regulatory requirements, and potential impact. High-value resources may require stronger authentication, tighter network boundaries, enhanced monitoring, and more restrictive authorization than lower-risk resources. Applying identical controls everywhere can waste resources or create unnecessary operational restrictions. Unrestricted access increases exposure, while technology-first architecture may select controls without first understanding the actual risk. Risk-based architecture helps align security investment with the consequences of compromise.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-100 Exam Dumps and Practice Test Dumps. &nbsp; Question 341 Which security architecture capability helps identify security weaknesses in an organization&#8217;s cloud configuration before they are exploited? Cloud security posture management Azure Load Balancer Azure Traffic Manager Azure DNS Correct Answer: 1 Explanation Cloud security posture management helps organizations continuously evaluate cloud [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17633"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17633"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17633\/revisions"}],"predecessor-version":[{"id":17634,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17633\/revisions\/17634"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17633"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17633"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17633"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}