{"id":17635,"date":"2026-09-21T10:38:59","date_gmt":"2026-09-21T10:38:59","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17635"},"modified":"2026-09-21T10:38:59","modified_gmt":"2026-09-21T10:38:59","slug":"microsoft-sc-100-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-100-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"Microsoft SC-100 Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-100-exam-dumps\"><b>Microsoft SC-100 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 361<\/b><\/h3>\n<p><b>Which security architecture capability helps organizations discover and assess security risks associated with cloud applications used by employees?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud application discovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud application discovery helps security teams identify applications and services being used across an organization, including applications that may not have gone through formal approval processes. This visibility can help assess security, compliance, data-handling, and access risks associated with cloud services. Load Balancer manages network traffic, Bastion provides secure administrative access, and Resource Manager handles Azure resources. Discovery should be followed by risk assessment, governance decisions, access controls, and monitoring so that identified applications are managed according to organizational requirements.<\/span><\/p>\n<h3><b>Question 362<\/b><\/h3>\n<p><b>Which security architecture practice helps ensure that sensitive workloads remain operational if one Azure availability zone becomes unavailable?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-zone deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local-only backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multi-zone deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted public access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multi-zone deployment distributes workload components across separate availability zones within a supported Azure region. If one zone experiences an outage, properly designed applications can continue operating through resources in other zones. Single-zone deployment creates a larger availability dependency, while public access does not improve resilience. A multi-zone design should consider application dependencies, state management, data replication, health monitoring, failover behavior, and recovery procedures. Availability architecture should also reflect the business impact of downtime and the required service-level objectives.<\/span><\/p>\n<h3><b>Question 363<\/b><\/h3>\n<p><b>Which Microsoft security capability can help identify malicious or suspicious email messages before they reach users?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Office 365<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Data Map<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Office 365 provides security capabilities designed to help protect email and collaboration environments from threats such as phishing, malicious links, and harmful attachments. It can provide detection and protection capabilities that contribute to an organization&#8217;s email security architecture. Key Vault manages secrets and keys, Bastion provides secure administrative access, and Purview Data Map supports data governance. Email protection should be combined with strong identity security, user awareness, endpoint protection, investigation capabilities, and appropriate anti-phishing policies.<\/span><\/p>\n<h3><b>Question 364<\/b><\/h3>\n<p><b>An organization wants to make sure security policies are not changed without authorization. Which governance control is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public policy editing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted administrator access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy change control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Policy change control establishes a formal process for modifying security policies, including authorization, review, testing, documentation, and approval. This helps prevent unauthorized changes that could weaken security controls or create compliance issues. Public editing and unrestricted administrative access increase the possibility of inappropriate changes, while shared administrator accounts weaken accountability. Policy changes should be traceable to authorized individuals and should include appropriate testing and rollback procedures. High-impact security policies should receive stronger review because changes can affect many workloads.<\/span><\/p>\n<h3><b>Question 365<\/b><\/h3>\n<p><b>Which architecture capability can help protect sensitive workloads by restricting which network paths they can use to communicate with other resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal connectivity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open inbound access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation divides environments into controlled security boundaries and limits communication between workloads according to documented requirements. This can reduce unnecessary exposure and restrict lateral movement if one system is compromised. Public routing and open inbound access can increase the attack surface, while universal connectivity removes important boundaries. Segmentation should be based on workload sensitivity, application dependencies, trust relationships, and business requirements. It should also be supported by network security controls, identity-based authorization, logging, and continuous validation.<\/span><\/p>\n<h3><b>Question 366<\/b><\/h3>\n<p><b>Which Microsoft Sentinel capability provides visual dashboards that help analysts understand security data and trends?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Playbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Analytics rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data connectors<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel workbooks provide visualization capabilities that can present security data through dashboards, charts, tables, and other visual elements. They can help analysts understand trends, investigate activity, monitor security posture, and communicate security information. Playbooks automate response actions, analytics rules identify suspicious activity, and data connectors ingest information. Workbooks should be designed around meaningful security and operational questions rather than simply displaying large volumes of data. Effective dashboards can help teams identify trends and prioritize investigation.<\/span><\/p>\n<h3><b>Question 367<\/b><\/h3>\n<p><b>Which security architecture principle requires access to be limited to only the resources and actions necessary for a user&#8217;s role?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Broad delegation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege ensures that users, applications, and administrators receive only the permissions required to perform their legitimate responsibilities. Limiting permissions reduces the potential impact of compromised accounts and helps prevent accidental or unauthorized actions. Permanent broad access and unrestricted delegation create unnecessary exposure. Least privilege should be implemented through role-based access, resource scoping, identity governance, privileged access controls, and regular reviews. Organizations should also remove permissions when responsibilities change so that accumulated access does not become a persistent security weakness.<\/span><\/p>\n<h3><b>Question 368<\/b><\/h3>\n<p><b>Which approach helps an organization ensure that software dependencies are evaluated for known vulnerabilities before deployment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public source repositories<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dependency scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual password management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted package installation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dependency scanning evaluates application libraries and third-party packages against known vulnerabilities and other security information. Integrating dependency scanning into development and CI\/CD workflows can identify risks before vulnerable components reach production. Public repositories may contain useful software but do not themselves provide adequate security assurance. Manual password management and unrestricted package installation address different concerns and can introduce additional risks. Dependency management should also include version control, approved package sources, vulnerability prioritization, software inventories, and processes for updating affected components.<\/span><\/p>\n<h3><b>Question 369<\/b><\/h3>\n<p><b>Which security architecture approach can reduce the impact of a compromised user account by requiring additional verification before access to sensitive resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conditional access policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent trusted sessions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Conditional access policies can require additional verification or impose access restrictions when users attempt to access sensitive resources under specific conditions. Policies can evaluate factors such as user identity, device state, application, location, and risk. Anonymous access and shared passwords do not provide adequate identity assurance, while permanent trusted sessions can increase exposure if a session or device is compromised. Conditional access should be designed according to application sensitivity and business requirements, with appropriate authentication methods, policy testing, monitoring, and exception handling.<\/span><\/p>\n<h3><b>Question 370<\/b><\/h3>\n<p><b>Which security architecture capability helps organizations protect cryptographic keys using hardware-backed security mechanisms?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hardware-backed key protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Hardware-backed key protection can provide stronger protection for sensitive cryptographic material by storing or processing keys within dedicated hardware security mechanisms. This can reduce exposure of high-value keys and support requirements for strong cryptographic protection. Traffic Manager, Load Balancer, and Azure DNS address traffic and networking requirements rather than key protection. Hardware-backed security should be considered according to the sensitivity of the keys, compliance requirements, application architecture, key lifecycle, administrative controls, and recovery requirements.<\/span><\/p>\n<h3><b>Question 371<\/b><\/h3>\n<p><b>Which security architecture activity helps determine how an attacker could move from an exposed application to a sensitive internal resource?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat modeling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cost forecasting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage optimization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Capacity planning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat modeling helps architects analyze potential attack paths by examining assets, trust boundaries, data flows, dependencies, entry points, and attacker techniques. It can reveal how compromise of one component could lead to access to more sensitive resources. Cost forecasting and capacity planning address financial and performance concerns, while storage optimization focuses on infrastructure efficiency. Threat modeling should occur during design and be revisited after significant architectural changes. Its findings can influence segmentation, authentication, authorization, monitoring, encryption, and other security controls.<\/span><\/p>\n<h3><b>Question 372<\/b><\/h3>\n<p><b>Which identity architecture approach allows a workload to obtain access tokens without storing a long-term client secret?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared service account<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workload identity federation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hard-coded password<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent API key<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Workload identity federation allows supported workloads to authenticate using trusted identity assertions instead of relying on long-lived secrets. This can reduce credential-management overhead and lower the risk associated with secrets being exposed in source code, configuration, or CI\/CD systems. Shared service accounts and permanent API keys can create broader access and longer-lived credentials, while hard-coded passwords are difficult to manage securely. Federation should be configured with narrowly scoped trust relationships, limited permissions, appropriate issuer conditions, and monitoring.<\/span><\/p>\n<h3><b>Question 373<\/b><\/h3>\n<p><b>Which security architecture capability helps detect unexpected changes to important system configurations or files?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File integrity monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage performance monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">File integrity monitoring detects unexpected changes to designated files, configurations, or system components. Unexpected modifications can indicate malware activity, unauthorized administrative actions, or other security events. Traffic Manager and DNS provide networking capabilities, while storage performance monitoring focuses on operational performance rather than integrity. Integrity monitoring should establish expected change processes so that legitimate modifications can be distinguished from suspicious ones. Alerts should be integrated with centralized monitoring and incident-response processes to support timely investigation.<\/span><\/p>\n<h3><b>Question 374<\/b><\/h3>\n<p><b>Which security architecture capability can help detect suspicious behavior by analyzing patterns associated with users and entities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static firewall rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User and Entity Behavior Analytics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User and Entity Behavior Analytics, or UEBA, analyzes activity patterns associated with users, devices, and other entities to identify potentially unusual behavior. This can help security teams detect activity that may not match established behavioral patterns, such as unusual access or unexpected authentication behavior. Static firewall rules and DNS forwarding address network functions, while storage replication supports resilience. UEBA should be interpreted alongside other security signals because unusual activity does not automatically indicate malicious behavior. Appropriate baselines, context, and investigation procedures are important.<\/span><\/p>\n<h3><b>Question 375<\/b><\/h3>\n<p><b>Which architecture practice helps ensure that third-party vendors receive only the access necessary to perform their contracted responsibilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor-specific least-privilege access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent global administrator access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared internal accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted network connectivity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vendor-specific least-privilege access limits third-party permissions to the resources and activities required for their approved responsibilities. This reduces the potential impact if a vendor account is compromised or misused. Permanent global administrator access and unrestricted connectivity provide excessive privileges, while shared internal accounts reduce accountability. Third-party access should also include strong authentication, time-bound permissions where appropriate, access reviews, monitoring, contractual requirements, and defined offboarding procedures. Security architects should treat external access as a distinct trust relationship requiring explicit controls.<\/span><\/p>\n<h3><b>Question 376<\/b><\/h3>\n<p><b>Which Microsoft Purview capability helps organizations manage policies related to potentially inappropriate communications and content?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Communication Compliance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Communication Compliance helps organizations identify and review potentially inappropriate communications according to configured policies and organizational requirements. It can support compliance programs by helping designated reviewers examine relevant communication risks. Azure Firewall provides network security, Bastion provides administrative connectivity, and Resource Manager manages Azure resources. Communication compliance should be designed with appropriate privacy protections, reviewer permissions, retention requirements, documented policies, and escalation procedures. Organizations should also ensure that monitoring practices align with applicable legal and regulatory obligations.<\/span><\/p>\n<h3><b>Question 377<\/b><\/h3>\n<p><b>Which security architecture approach helps prevent unauthorized changes to software after it has passed the required security checks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted artifact modification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Artifact signing and verification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared deployment passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public package replacement<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Artifact signing and verification can help establish that software artifacts have not been modified after they were approved or produced by a trusted build process. Verification mechanisms can validate that the artifact corresponds to an expected publisher or build process before deployment. Unrestricted modification and public replacement weaken software supply-chain integrity, while shared passwords create credential risks. Artifact security should be combined with protected repositories, controlled build systems, dependency management, secure deployment identities, and appropriate audit logging throughout the software delivery lifecycle.<\/span><\/p>\n<h3><b>Question 378<\/b><\/h3>\n<p><b>Which architecture capability can help identify whether a cloud resource violates an organization&#8217;s required security configuration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration compliance monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public network access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration compliance monitoring evaluates resources against defined security and governance requirements. It can identify settings that deviate from approved standards, such as insecure network configurations, missing security controls, or unauthorized resource settings. Public network access, storage replication, and DNS caching serve different purposes and do not directly provide configuration compliance assessment. Continuous monitoring is valuable because resources can change after deployment. Findings should be prioritized, assigned to responsible teams, remediated, and rechecked to verify that compliance has been restored.<\/span><\/p>\n<h3><b>Question 379<\/b><\/h3>\n<p><b>Which security architecture principle is most important when designing access for a highly sensitive administrative function?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Broad permanent permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrative credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Strong authentication and least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous administrative access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Highly sensitive administrative functions require strong authentication and tightly scoped permissions because compromise of privileged access can affect many resources. Strong authentication reduces the likelihood that stolen credentials alone will be sufficient, while least privilege limits what an administrator can do after access is granted. Shared credentials reduce accountability, permanent broad permissions increase exposure, and anonymous administration is fundamentally inappropriate for sensitive operations. Additional protections can include just-in-time access, approval workflows, privileged workstations, monitoring, and separation of duties.<\/span><\/p>\n<h3><b>Question 380<\/b><\/h3>\n<p><b>Which architecture activity should be performed after a major security incident to determine whether existing controls need to be redesigned?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security architecture reassessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable security monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove access controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore the incident findings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security architecture reassessment after a major incident helps determine whether existing controls were sufficient, correctly implemented, and appropriate for the attack scenario. The review can examine the initial attack path, detection coverage, identity controls, segmentation, application security, data protection, response processes, and architectural assumptions. Disabling monitoring or removing access controls would reduce security visibility and protection. Incident findings should feed into an improvement cycle so that weaknesses are addressed and the architecture becomes more resilient against similar or related threats.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-100 Exam Dumps and Practice Test Dumps. &nbsp; Question 361 Which security architecture capability helps organizations discover and assess security risks associated with cloud applications used by employees? Azure Load Balancer Cloud application discovery Azure Bastion Azure Resource Manager Correct Answer: 2 Explanation Cloud application discovery helps security teams identify applications and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17635"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17635"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17635\/revisions"}],"predecessor-version":[{"id":17636,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17635\/revisions\/17636"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17635"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17635"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17635"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}