SC-100 sample questions with answers

10 free practice questions for the Microsoft Certified: Cybersecurity Architect Expert exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Design solutions that align with security best practices and priorities

Fabrikam, Inc. operates 14 manufacturing plants. Security spending is currently spread evenly across all systems, and the audit committee can't tell which outages the company could absorb and which would halt production. You must recommend a security strategy that supports business resiliency goals and that makes the prioritization of business-critical assets defensible to the committee. Which two elements should you include in the recommendation? Each correct answer presents part of the solution. (Choose TWO.)

Choose 2.

  1. A.

    ExpressRoute circuits replacing all site-to-site VPNs between plants and Azure

  2. B.

    Business-agreed impact tiers, each with an RTO, RPO, and protection level

  3. C.

    Scheduled isolated restore tests of the top tier, reporting achieved recovery times

  4. D.

    A 90 percent Secure Score target, funding the fastest-scoring recommendations

  5. E.

    Two-year interactive retention for every table in the Log Analytics workspace

Show answer

Answer: B, C

A defensible resiliency strategy needs business-agreed impact tiers with recovery objectives and regular proof that the most critical tier can be recovered within them.

  • A. ExpressRoute is a connectivity decision; it doesn't classify critical assets or prove that they can be recovered.
  • B. Tiers agreed with business owners, each with recovery objectives, turn resiliency priorities into a defensible and auditable service level.
  • C. Rehearsed restores prove the objectives are achievable and expose hidden dependencies before a real incident, which Microsoft's guidance requires.
  • D. Chasing a posture score optimizes a metric and can move funding away from the business-critical systems the committee asked about.
  • E. Longer log retention helps investigation, but it neither prioritizes assets nor improves the ability to recover them.
Question 2Design solutions that align with security best practices and priorities

Fincher Architects ships a design application built from several hundred open-source packages. During an audit, it emerged that a build server had been compromised and had produced a release that no developer could account for, and that nobody could list which component versions the release contained. The architecture board wants a strategy aligned with the Microsoft cloud security benchmark. What should you include in the recommendation?

  1. A.

    An Azure Policy that denies images not pulled from the company's container registry

  2. B.

    Secure the DevOps infrastructure, and gate components with an SBOM and vulnerability checks

  3. C.

    Azure Web Application Firewall in prevention mode, with bot protection turned on

  4. D.

    Defender for Containers runtime protection on the production Kubernetes clusters

Show answer

Answer: B

The benchmark's DevOps Security controls answer both findings: DS-3 secures the DevOps infrastructure, and DS-2 manages an SBOM with gating criteria for components.

  • A. Restricting pulls to a trusted registry proves the storage location only; a compromised build server can still publish a malicious image there.
  • B. DS-3 secures build servers, pipelines, and artifact repositories, and DS-2 requires an SBOM and gating criteria that keep vulnerable or malicious components out.
  • C. A web application firewall filters inbound HTTP traffic and has no visibility into build, dependency, or release integrity.
  • D. Runtime container protection defends the deployed workload but can't secure the build infrastructure or list what a release contains.
Question 3Design solutions that align with security best practices and priorities

Dovecote Bakeries found generative AI resources that nobody had registered, and it's about to expose Model Context Protocol (MCP) servers for its agents to call. Following the Cloud Adoption Framework guidance for securing AI resources, which two actions should you recommend? Each correct answer presents part of the solution. (Choose TWO.)

Choose 2.

  1. A.

    Put Azure API Management in front of the MCP server endpoints

  2. B.

    Track AI resources on a manually maintained wiki page

  3. C.

    Build an AI inventory with Azure Resource Graph and Defender for Cloud AI discovery

  4. D.

    Give each MCP server a static API key that agents embed in their code

  5. E.

    Publish the MCP servers directly on public IP addresses for simplicity

Show answer

Answer: A, C

An automated AI inventory from Azure Resource Graph and Defender for Cloud, and API Management in front of MCP endpoints, are CAF's controls for these two gaps.

  • A. CAF says to deploy Azure API Management to secure MCP server endpoints as part of securing AI communication channels.
  • B. A manual list drifts; CAF says to maintain the inventory through automated scanning and regular validation.
  • C. CAF says to discover AI resources with Azure Resource Graph and use Defender for Cloud to identify generative AI workloads, then maintain the inventory automatically.
  • D. Static keys embedded in code are stored credentials; CAF recommends managed identities for workload authentication.
  • E. Direct public exposure contradicts CAF's guidance to isolate AI communications and secure the endpoints.
Question 4Design solutions that align with security best practices and priorities

Marlowe Legal runs 80 Windows Server 2025 Datacenter servers on physical hosts in its own datacenter. The firm wants monthly security updates to install without restarting the servers in most months, and it wants to orchestrate the updates from Azure. What should you recommend?

  1. A.

    Approve only security updates for the servers in WSUS

  2. B.

    Enroll the servers in Windows Autopatch hotpatch update policies

  3. C.

    Connect the servers to Azure Arc and enable Hotpatch for them

  4. D.

    Reinstall the servers with the Datacenter: Azure Edition image

Show answer

Answer: C

Azure Arc-enabled Hotpatch lets on-premises Windows Server 2025 Standard and Datacenter machines install most monthly security updates without a restart.

  • A. Security-only approvals in WSUS still install updates that require restarts, so they don't meet the requirement.
  • B. Windows Autopatch manages hotpatch for Windows 11 client devices through Intune, not for Windows Server.
  • C. Azure Arc-connected Windows Server 2025 Standard and Datacenter machines can receive hotpatches once the feature is enabled, orchestrated with Update Manager.
  • D. Azure Edition hotpatch images are supported on Azure and Azure Local VMs, not on physical servers in a private datacenter.
Question 5Design solutions that align with security best practices and priorities

Quarrymoor Construction deploys shared networking resources through a pipeline. Operators with the Contributor role keep changing and deleting those resources in the portal, which causes outages, and the pipeline must still be able to update them. Following the Adopt guidance in the Cloud Adoption Framework Secure methodology, what should you recommend?

  1. A.

    Review the Azure activity log each month for manual changes

  2. B.

    Deploy the resources as a deployment stack with deny settings

  3. C.

    Place a ReadOnly lock on every networking resource group

  4. D.

    Assign an Azure Policy with the Audit effect to networking resources

Show answer

Answer: B

Deployment stacks with deny settings, recommended in CAF's Adopt guidance, block unauthorized changes to managed resources while the deploying pipeline keeps control.

  • A. A monthly review detects changes long after the outage has already happened.
  • B. CAF recommends deployment stacks with deny settings to prevent unauthorized modifications, and excluded principals let the pipeline keep deploying.
  • C. A ReadOnly lock applies to everyone, so it would also block the pipeline's legitimate updates.
  • D. An Audit effect only reports changes; it doesn't prevent operators from modifying or deleting resources.
Question 6Design solutions that align with security best practices and priorities

Adatum Corporation runs production workloads on Azure virtual machines and on Hyper-V virtual machines in its own datacenter. After a tabletop exercise, the CISO states that a backup design is acceptable only if an attacker who obtains the Owner role on the production Azure subscription still can't delete recovery points or shorten their retention. The recovery point objective is 24 hours, and the operations team is small. What should you include in the recommendation?

  1. A.

    A nightly script that copies backup files to a storage account in the production subscription

  2. B.

    Enhanced soft delete on the vault, with Backup Contributor granted to the backup operators

  3. C.

    Azure Site Recovery replication of every workload to a secondary Azure region instead of backup

  4. D.

    Azure Backup Server for Hyper-V, a locked immutable vault, and a Resource Guard in another subscription

Show answer

Answer: D

Azure Backup Server protects the Hyper-V VMs, and locked immutability plus multi-user authorization with a Resource Guard in a separate subscription stops a compromised subscription Owner from destroying recovery points.

  • A. The copy lands in the subscription the attacker controls, and a hand-built script adds operational overhead that the small team can't sustain.
  • B. Soft delete only delays permanent deletion: the Owner can still delete recovery points or cut retention, and the data is purged when the soft-delete period ends.
  • C. Site Recovery replicates the current state of a machine, including encrypted data, so replicas aren't a point-in-time backup source for ransomware recovery.
  • D. Locked immutability can't be reversed by the compromised Owner, the Resource Guard sits outside that Owner's scope, and Azure Backup Server protects the Hyper-V VMs.
Question 7Design solutions that align with security best practices and priorities

Corvid Analytics keeps most user documents on laptops and on shared on-premises file servers where many users have write and delete access. After a ransomware incident, restoring those files took the IT team two weeks. The CISO wants to cut the cost and time of recovering user files in future attacks, without users reintroducing the attacker's malware. Following Microsoft's ransomware guidance, what should you recommend?

  1. A.

    Consolidate user files on one share that everyone can write to

  2. B.

    Let users restore their own files as soon as encryption is detected

  3. C.

    Move user data to OneDrive and SharePoint, with user restores after eviction

  4. D.

    Back up every laptop nightly to a NAS appliance on the office network

Show answer

Answer: C

Moving user data to OneDrive and SharePoint gives versioning and self-service recovery, and Microsoft says users should restore only after the attacker is evicted.

  • A. Microsoft says to find and reduce broad write and delete permissions on business-critical data, because ransomware relies on broad access.
  • B. Microsoft says users should restore files only after you're confident the attacker is evicted, so immediate restores risk bringing the malware back.
  • C. Microsoft recommends moving user data to OneDrive and SharePoint for versioning and the recycle bin, and teaching users to restore their own files once the attacker is evicted.
  • D. A backup target on the same network is reachable by the attacker and isn't immutable or offline, so it can be encrypted too.
Question 8Design solutions that align with security best practices and priorities

Lucerne Publishing has lost two unpublished manuscripts to authors who resigned and copied files to personal cloud storage in their final weeks. The legal team wants a capability that raises the strictness of data loss prevention controls automatically for employees whose behavior and circumstances indicate elevated risk, rather than blocking all copying for everyone. The design must follow Microsoft's insider risk guidance. What should you include in the recommendation?

  1. A.

    ID Protection user risk policies requiring a password change

  2. B.

    Defender for Cloud Apps anomaly detection policies for mass downloads

  3. C.

    Sentinel UEBA with a watchlist of employees serving notice

  4. D.

    Microsoft Purview Insider Risk Management with Adaptive Protection

Show answer

Answer: D

Insider Risk Management with Adaptive Protection is the capability that turns insider risk levels into automatically stricter data loss prevention for only the risky users.

  • A. ID Protection measures account compromise risk, which stays low when a legitimate employee signs in normally and copies data.
  • B. Anomaly policies alert on unusual activity in connected SaaS apps but don't assign insider risk levels that tighten DLP for specific users.
  • C. UEBA can surface anomalies, but you'd have to build the correlation and the response yourself, and it doesn't tighten Purview DLP per user.
  • D. Insider Risk Management assigns insider risk levels, and Adaptive Protection dynamically applies stricter data loss prevention policies to users at those levels.
Question 9Design solutions that align with security best practices and priorities

Harborline Clinics runs Microsoft Defender XDR and Microsoft Defender for Cloud across Azure, AWS, and on-premises servers. The security team wants posture recommendations, attack paths, and incident triage ordered by business impact, starting with domain controllers, databases that hold sensitive data, and privileged identity groups. The team doesn't want to maintain a hand-built spreadsheet of assets. What should you recommend?

  1. A.

    A Microsoft Sentinel watchlist of critical servers, updated monthly

  2. B.

    Critical asset management in Microsoft Security Exposure Management

  3. C.

    Per-subscription Secure Score targets set in Microsoft Defender for Cloud

  4. D.

    Resource tags on Azure resources, queried with Azure Resource Graph

Show answer

Answer: B

Critical asset management in Security Exposure Management automatically classifies business-critical assets and uses that criticality to prioritize recommendations, attack paths, and investigations.

  • A. A watchlist is a manual list that only enriches SIEM queries, which is the hand-maintained approach the team wants to avoid.
  • B. Critical asset management identifies business-critical devices, identities, and cloud resources automatically and feeds criticality into inventory, hunting, and attack paths.
  • C. Secure Score measures posture across controls; it doesn't identify which assets are business-critical.
  • D. Tags must be applied and maintained by hand, cover only Azure resources, and don't change how Defender prioritizes recommendations or attack paths.
Question 10Design solutions that align with security best practices and priorities

Whitcombe Legal is designing segmentation for a new case management workload. The network team proposes subnets and network security groups only. Following recommendation SE:04 of the Azure Well-Architected Framework security checklist, what else should the segmentation strategy include?

  1. A.

    One shared identity for every component

  2. B.

    A single resource group that holds all of the environments

  3. C.

    Roles, workload identities, and resource organization

  4. D.

    Nothing more, because network controls alone satisfy SE:04

Show answer

Answer: C

Well-Architected SE:04 requires segmentation across networks, roles and responsibilities, workload identities, and resource organization, not networks alone.

  • A. A shared identity removes identity segmentation, which SE:04 requires.
  • B. Mixing all environments in one resource group removes resource organization boundaries.
  • C. SE:04 says the segmentation strategy must include networks, roles and responsibilities, workload identities, and resource organization.
  • D. SE:04 explicitly goes beyond networks, so a network-only design is incomplete.

Keep going with 502 more SC-100 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

SC-100 sample questions with answers (10 free) · CertifyCloudx