Microsoft · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
28% of exam · 6 sample questions below
Your organization uses Microsoft Sentinel and wants to automatically respond to high-severity incidents. Which feature should you configure?
Configure an automation rule to run a playbook automatically
Automation rules in Microsoft Sentinel are event-driven orchestration mechanisms that evaluate newly created or updated incidents against configured conditions—such as severity or name—and then execute one or more linked playbooks automatically. Playbooks are Azure Logic Apps that can perform remediation steps like isolation, data collection, or notification, ensuring consistent, immediate response without human involvement. This is the only approach listed that satisfies 'automatically' while honoring incident context, since automation rules trigger exactly when incidents are created or changed.
Create a playbook and run it manually for each incident
Set up an analytics rule with automatic response
Use a workbook to trigger a playbook
A company plans to implement Microsoft Purview to enforce data loss prevention (DLP) policies. They need to prevent users from sharing credit card numbers via email. What should they configure?
Create a sensitivity label and apply it to emails
Enable communication compliance policies
Create a DLP policy that detects and blocks credit card numbers in Exchange Online
A DLP policy scoped to Exchange Online inspects email traffic and applies sensitive information type matching for credit card numbers, blocking sharing at the transport layer. This directly satisfies the stem's requirement to prevent email exfiltration, since Exchange Online is the workload governing mail flow within Microsoft Purview.
Configure a retention policy for email
Your organization uses Microsoft Defender for Cloud to secure multi-cloud workloads. You need to ensure that Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP) resources are assessed against the same security baseline. What should you do?
Configure AWS Config and GCP Security Command Center to export findings to Microsoft Sentinel
Connect AWS and GCP accounts to Defender for Cloud and use Azure Policy to enforce the Microsoft Cloud Security Benchmark
Connecting AWS and GCP accounts to Defender for Cloud surfaces those resources in Azure Resource Graph, where Azure Policy can apply the Microsoft Cloud Security Benchmark (MCSB), a unified initiative built on CIS/NIST plus Microsoft controls. This gives continuous compliance assessment and enforcement, like DeployIfNotExists remediation, across all clouds. As a result, every subscription or cloud account is measured against the same baseline, regardless of native cloud tooling—this is the only option that both centralizes and enforces a single baseline.
Use regulatory compliance standards for each cloud separately
Enable the Cloud Security Posture Management (CSPM) plan and configure AWS and GCP connectors
Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. What should you configure?
Create a Conditional Access policy that requires compliant device
Conditional Access policies are the access-control layer that evaluates the device's compliance state at sign-in. When combined with an Intune compliance policy, the 'Require device to be marked as compliant' grant control forces Microsoft Entra ID to check the device's compliance status and block access if the device is non-compliant. This is the correct approach because it directly enforces the access requirement for corporate resources, unlike enrollment or configuration policies that only manage settings or enrollment.
Set up enrollment restrictions in Intune
Create a device configuration policy that blocks non-compliant devices
Configure an app protection policy for email apps
Your organization uses Microsoft Entra ID and wants to implement a passwordless authentication strategy. Users have smartphones. Which method should you recommend as the primary authentication method?
FIDO2 security keys
Microsoft Authenticator app with passwordless sign-in
Microsoft Authenticator app with passwordless sign-in is the correct choice because it leverages the user's smartphone as a possession factor, using a cryptographic challenge-response protocol. When the user enters their username, the Authenticator app displays a number or a number match prompt; the user's approval signs the request with a private key stored in the device's secure enclave, eliminating the password entirely. This method is phishing-resistant, supports conditional access policies, and works seamlessly on iOS and Android, making it ideal for smartphone-centric users.
SMS-based authentication
Windows Hello for Business
Your organization uses Microsoft Sentinel to aggregate logs from on-premises and cloud sources. You need to reduce the cost of data ingestion while ensuring security-critical logs are retained for at least one year. What should you do?
Archive all logs to Azure Storage after 90 days
Ingress security-critical logs to the Analytics logs tier with 365-day retention, and other logs to the Auxiliary logs tier with shorter retention
This hybrid approach directly addresses the one-year retention requirement while optimizing cost. Security-critical logs reside in the Analytics tier, which supports full KQL, advanced hunting, detections, and 365-day retention, ensuring no loss of investigative power. The Auxiliary logs tier, introduced for verbose telemetry, offers lower ingestion cost and basic query functionality for non-critical data, letting you retain comprehensive logs without overpaying. This separation balances compliance, performance, and budget far better than a one-size-fits-all strategy.
Use the Basic logs tier for all logs and set retention to 365 days
Set the default retention to 30 days and export logs to Log Analytics Workspace
Want more Design security operations, identity, and compliance capabilities practice?
Practice this domain22% of exam · 6 sample questions below
Your organization wants to implement a zero-trust security model for on-premises and cloud resources. As part of this strategy, you need to ensure that all access requests are authenticated and authorized based on dynamic risk signals. Which Microsoft security solution should you use to enforce conditional access policies based on real-time risk?
Microsoft Entra ID Conditional Access
Microsoft Entra ID Conditional Access is the policy enforcement engine that operationalizes zero trust by evaluating real-time signals such as user identity, device health, location, and risk level at the moment of authentication. It dynamically allows or blocks access, or requires additional controls like MFA or session policies, integrated directly with identity authentication. This makes it the central decision point for enforcing conditional access policies, rather than a supporting or monitoring tool.
Microsoft Intune
Microsoft Sentinel
Microsoft Defender for Cloud
Refer to the exhibit. You are an Azure security engineer reviewing a custom Azure Policy definition. The policy is intended to audit virtual machines to ensure they have the Azure Security extension installed. However, the policy is not triggering on any resources. What is the most likely reason?
The policy condition requires a managed disk, but the VMs might have unmanaged disks.
The policy definition's 'if' clause matches only VMs that have a managed disk (e.g., by checking that the 'managedDisk' property is present). VMs that still use unmanaged disks do not satisfy this condition, so the 'auditIfNotExists' effect is never evaluated for them. Consequently, the policy silently ignores the very machines that likely need the missing-extension audit, making the compliance report incomplete rather than identifying all noncompliant VMs.
The 'existenceCondition' field path is incorrect; it should be 'Microsoft.Compute/virtualMachines/extensions/publisher'.
The policy is assigned to a management group, but the VMs are in a subscription under a different management group.
The policy effect should be 'Deny' instead of 'auditIfNotExists'.
Your company uses Microsoft Sentinel as a SIEM. You need to create an analytics rule that detects when a user account is created outside of business hours. The rule should trigger an incident for investigation. Which type of analytics rule should you use?
Anomaly rule
Fusion rule
Scheduled query rule
Scheduled query rules in Microsoft Sentinel are the appropriate choice because they run on a defined cadence (e.g., every 5 minutes or hourly) and execute a KQL query against ingested data. You can set a schedule that matches the desired time window, and the rule will trigger an incident if the query returns results. This allows you to easily implement a condition like 'alert when events occur during a specific time range' by embedding that time filter in the query and scheduling the rule to run accordingly.
NRT query rule
You are designing a security solution for Azure resources. You need to ensure that any changes to network security groups (NSGs) are automatically logged and sent to a central Log Analytics workspace. Which Azure feature should you use?
Diagnostic settings on the Azure Activity Log
Diagnostic settings on the Azure Activity Log are the correct mechanism because the Activity Log itself records every control-plane operation—such as resource creation, deletion, and configuration changes—for your Azure resources. By configuring a diagnostic setting on this log, you can stream those management events directly into a Log Analytics workspace, enabling centralized querying, alerting, and long-term retention for security auditing. This is the built-in, supported way to capture and route resource-level change activity to your security monitoring pipeline.
Azure Policy
NSG flow logs
Azure Monitor alerts
Refer to the exhibit. Your organization is required to comply with PCI DSS. You need to prioritize remediation efforts to meet PCI DSS requirements. Based on the exhibit, which recommendation should you address first?
Enable MFA on accounts with owner permissions
MFA on account owner permissions directly satisfies PCI DSS 8.3.1, which mandates multi-factor authentication for all administrative access to cardholder data environments. In Azure, the Owner role grants full control over all resource and security configurations, making it a primary target for credential compromise. Enabling MFA via Conditional Access or Microsoft Entra ID security defaults is an immediate, auditable control that closes a current high-risk exposure and is a prerequisite for passing any PCI DSS assessment.
Migrate VMs from classic to ARM
Enable vulnerability assessment on SQL databases
Enable diagnostic logs in Key Vault
Your organization uses Microsoft Intune to manage devices. You need to ensure that devices that are not compliant with your organization's security policies are blocked from accessing corporate resources. Which Intune feature should you configure?
App protection policies
Device configuration profiles
Compliance policies
Compliance policies in Intune define the specific conditions a device must meet to be considered compliant, such as required OS versions, password requirements, encryption status, and threats detected by Mobile Threat Defense. Each device periodically uploads its health and configuration to the Intune service, which computes a compliant/non-compliant state. This state can then be consumed by Microsoft Entra Conditional Access to allow or block access to emails, apps, and data based on real-time compliance. When a policy is combined with a Conditional Access policy requiring device compliance, non-compliant devices are blocked from accessing protected resources—making this the correct answer.
Enrollment restrictions
Want more Design solutions that align with security best practices and priorities practice?
Practice this domain22% of exam · 6 sample questions below
Your organization is deploying a new line-of-business application on Azure App Service. The app must authenticate users from Microsoft Entra ID and also access a downstream API that requires a client secret. You need to recommend the most secure method for managing the client secret. What should you use?
Store the secret in the Microsoft Entra ID app registration manifest.
Store the secret in an App Service application setting.
Store the secret in Azure Key Vault and use a Key Vault reference in App Service.
Correct. Azure Key Vault provides secure, centralized storage for secrets with encryption and access auditing. App Service can reference Key Vault secrets via Key Vault references, using a managed identity to authenticate without exposing the secret.
Store the secret in the application code as a constant.
Your organization stores sensitive customer data in Azure Blob Storage. You need to implement data classification and labeling using Microsoft Purview. Which resource should you use to automatically scan and classify the data?
Azure Policy
Microsoft Purview Data Map
Microsoft Purview Data Map is the correct choice because it performs automated metadata scanning and classification of assets across data sources, including Azure Blob Storage. It uses built-in system classification rules and custom classification rules to inspect actual data content (e.g., regex, keywords) and applies classifications like "Person's Name" or "Credit Card Number" to the schema and data. These classifications are then used in the Data Catalog, enabling sensitivity reporting and integration with information protection for labeling. It does not enforce access control or policy, but it is specifically designed for data discovery and classification at scale.
Microsoft Purview Information Protection
Microsoft Purview Data Loss Prevention
Your organization uses Microsoft Purview Information Protection to label and protect sensitive emails and documents. You need to ensure that when a user applies a 'Highly Confidential' label, the content is automatically encrypted and a watermark is added. Which configuration should you use?
Use Azure Information Protection scanner to apply labels automatically.
Create a DLP policy that blocks sharing of highly confidential content.
Configure a sensitivity label with encryption and watermark settings.
Sensitivity labels are the only Microsoft Purview option that can simultaneously apply encryption with Azure Rights Management and configure content marking, including visual watermarks, headers, and footers. When a label with these settings is applied to a document or email, the watermark is automatically rendered behind the content or in the header, and encryption protects the file at rest and in transit. This provides a unified, policy-driven way to add watermarks without separate tooling or manual intervention.
Enable Microsoft 365 Message Encryption for all emails.
Your organization is planning to use Microsoft Sentinel for security information and event management (SIEM). You need to ingest security logs from on-premises Active Directory. What should you deploy?
Microsoft Monitoring Agent (MMA)
Log Analytics agent
Microsoft Defender for Cloud agent
Azure Monitor Agent
Azure Monitor Agent (AMA) is the correct modern agent for Microsoft Sentinel because it unifies data collection across the entire Azure Monitor platform. It uses data collection rules (DCRs) to define exactly which data sources to collect, enabling granular filtering, multi-homing to multiple workspaces, and support for both Windows and Linux without the overhead of separate agents. AMA is the only forward-looking agent that Microsoft is actively investing in, with rich features like network isolation, Azure Arc support, and the ability to handle all log types Sentinel consumes.
Your organization uses Azure Data Lake Storage Gen2 for big data analytics. You need to secure access to the data using Azure RBAC and ACLs. Which two methods can you use to authorize access? (Choose two.)
Configure IP firewall rules to restrict access.
Assign Azure RBAC roles such as Storage Blob Data Contributor to security principals.
Azure RBAC role assignments are the recommended, identity-based authorization method for controlling access to Azure Data Lake Storage Gen2. Roles like Storage Blob Data Contributor grant a security principal (user, group, service principal, or managed identity) permissions at the storage account, container, or directory/file scope using Azure's centralized control plane. When a principal makes a request, Azure evaluates RBAC assignments, integrating with Microsoft Entra ID, to determine coarse-grained access such as read, write, delete, and list, making this the go-to choice for broad or automated access control.
Set POSIX-like access control lists (ACLs) on directories and files.
Azure Data Lake Storage Gen2 supports hierarchical ACLs that mirror POSIX permissions, allowing you to define read, write, and execute permissions for the owning user, owning group, named users, named groups, and others on each directory and file. ACLs operate at the data plane and are evaluated after RBAC, providing fine-grained, per-file/per-directory control required in a hierarchical namespace. This mechanism is essential when you need to distinguish access between different users within the same container, with effective permissions computed recursively through the directory tree.
Use managed identities for Azure resources.
Generate shared access signatures (SAS) for delegated access.
Refer to the exhibit. You are reviewing an Azure Policy definition that uses a 'modify' effect. The policy is intended to automatically enable transparent data encryption (TDE) on Azure SQL databases after they are created. Which condition must be met for the modify effect to work?
The policy must be assigned at the management group scope.
A managed identity must be associated with the policy assignment and have permissions to modify TDE.
The Modify effect in Azure Policy requires a managed identity to be attached to the policy assignment and that identity must be granted RBAC permissions, such as SQL Security Manager, on the target SQL servers or databases to change Transparent Data Encryption settings. Without a properly configured identity, the policy assignment fails during evaluation/remediation and cannot apply the desired TDE state. This is a mandatory prerequisite, making the option the correct answer.
The database must be newly created.
The SQL database must be using the General Purpose service tier.
Want more Design security solutions for applications and data practice?
Practice this domain28% of exam · 6 sample questions below
Your organization uses Microsoft Sentinel to monitor hybrid workloads. You need to design a solution to detect lateral movement attempts from compromised on-premises servers to Azure VMs. Which data connector should you prioritize?
Syslog via AMA
Office 365 Logs
Windows Security Events via AMA
Windows Security Events via AMA is the correct choice because the Azure Monitor Agent can collect Windows Security log entries from on-premises and Azure Arc-enabled Windows servers. These events include critical authentication-related event IDs like 4624 (successful logon), 4625 (failed logon), and 4768 (Kerberos ticket request), which are essential for detecting lateral movement. The data can be streamed directly to Microsoft Sentinel, allowing analysts to build detections for suspicious logon patterns and pass-the-hash attacks across hybrid identities.
Azure Activity Log
A company plans to use Microsoft Defender for Cloud to secure a multi-cloud environment including Azure, AWS, and GCP. What is the first step to enable multi-cloud visibility?
Enable all Defender plans for subscription
Connect AWS and GCP accounts using the cloud connectors in Defender for Cloud
The Defender for Cloud multi-cloud connectors establish the onboarding bridge between Azure and AWS or GCP, synchronizing security configurations, threat indicators, and resource inventory into the unified Azure dashboard. This connector-level integration, which leverages read-only credentials from the foreign cloud, is the mandatory first step because all subsequent security policies, recommendations, and Defender plan coverage depend on the cloud accounts being visible to Azure. Without this connector, Defender for Cloud has no access to the AWS or GCP workloads.
Create custom compliance policies
Deploy Azure Arc agents on all cloud VMs
Which TWO Azure policies should you assign to enforce secure configuration of Azure SQL Database? (Select two.)
Ensure that 'Auditing' is set to 'On' for SQL Database
Enabling SQL Database auditing satisfies the secure-configuration requirement by recording all database events to a storage, Log Analytics or Event Hub destination, giving the detective evidence trail that Azure Policy's Auditing effect enforces at scale across every server and database in scope.
Ensure that 'TDE' is enabled for SQL Server VMs
Audit SQL Server level audit setting
Ensure that 'Firewall and virtual network settings' for SQL Database are configured
Configuring firewall and virtual network settings satisfies the network-isolation constraint by denying public Azure service access and permitting only approved IP ranges, private endpoints or subnet delegations, so Azure Policy blocks any SQL server left reachable from the open internet.
Ensure secure transfer to storage accounts is enabled
Which THREE features of Microsoft Defender for Cloud help secure Azure Kubernetes Service (AKS) clusters? (Select three.)
Advanced threat protection for Azure Cosmos DB
Azure Defender for Kubernetes (cluster hardening)
Azure Defender for Kubernetes, now part of Microsoft Defender for Containers, provides continuous security assessment of your cluster's configuration, including checks against CIS Kubernetes Benchmarks, overly permissive RBAC roles, and insecure pod settings. It automatically generates prioritized hardening recommendations that analysts can implement to reduce attack surface. This directly helps secure AKS clusters and is the correct answer for cluster hardening.
Vulnerability assessment for container images
Vulnerability assessment for container images, built into Defender for Containers, scans images in Azure Container Registry (and other supported registries) for known vulnerabilities in OS packages and application dependencies. It uses Qualys or Microsoft Defender Vulnerability Management engines, performing both pull-based and push-based scans. By identifying and remediating image weaknesses before deployment, it strengthens the entire AKS supply chain.
DDoS Protection Standard
Runtime threat detection for AKS clusters
Runtime threat detection for AKS clusters, also part of Defender for Containers, continuously monitors cluster audit logs, node events, and host-level signals to identify suspicious activity such as privilege escalation, malicious containers, or crypto-mining. When a threat is detected, security alerts with recommendations are raised in Defender for Cloud, enabling immediate incident response without manual log analysis. This provides real-time protection during cluster operation, making it a correct feature.
Which TWO actions should you take to improve the security posture of an Azure subscription using Microsoft Defender for Cloud? (Select two.)
Assign Azure Policy to enforce resource compliance
Enable Azure Defender plans for all supported resource types
Enabling Azure Defender plans for all supported resource types activates integrated threat protection, including endpoint detection, vulnerability scanning, and security alerts across workloads. This directly strengthens security posture by providing continuous monitoring and automated responses to attacks, while also feeding findings into Secure Score to guide further improvements. It is a foundational action that covers multiple aspects of security simultaneously.
Implement the top security recommendations from the Secure Score
Implementing the top Secure Score recommendations is a direct, prioritized approach to improving security posture by addressing the most impactful gaps, such as enabling MFA or remediating critical vulnerabilities. Secure Score quantifies your security controls and suggests the highest-value actions first, giving you clear, risk-based remediation steps. Acting on these recommendations reduces your attack surface and measurably increases the score.
Create custom security policies
Deploy vulnerability assessment solution to all VMs
Refer to the exhibit. You are reviewing an Azure Policy definition. What does this policy accomplish?
Requires that all network security rules have destination port range between 22 and 3389
Denies all inbound traffic except SSH and RDP
Allows only SSH and RDP inbound traffic
Denies creation of network security rules that allow traffic to ports other than 22 and 3389
This is correct because the policy definition uses the 'deny' effect on Microsoft.Network/networkSecurityGroups/securityRules whose destinationPortRange or destinationPortRanges include values not in ['22', '3389']. When a user or service attempts to create or update an NSG rule that permits traffic to any port other than 22 or 3389, the Resource Manager deployment is rejected before the rule is applied, making it impossible to add such a rule to an NSG. The policy does not, however, automatically delete existing noncompliant rules; it applies at deployment time, so already-existing rules that violate the condition remain until manually changed or removed.
Want more Design security solutions for infrastructure practice?
Practice this domainThe SC-100 exam has 50 questions and must be completed in 120 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 4 domains: Design security operations, identity, and compliance capabilities, Design solutions that align with security best practices and priorities, Design security solutions for applications and data, Design security solutions for infrastructure. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Microsoft SC-100 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.