Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Adventure Works is a startup that uses Microsoft 365 Business Premium. They have 20 employees and no cloud expertise. The CEO has been hearing about ransomware attacks on small businesses. They want to implement basic protection against ransomware using built-in Microsoft 365 features. They also want to ensure they can recover from an attack quickly. What should you recommend?

⚠ Common exam trap

The trap here is that candidates often over-engineer the solution by recommending enterprise-grade tools like Azure Backup or Sentinel, failing to recognize that Microsoft 365 Business Premium includes sufficient built-in capabilities for a small startup with no cloud expertise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable Microsoft Defender for Office 365 to block malicious attachments and links. Configure Microsoft Defender for Business to enable controlled folder access and ransomware protection. Educate users on phishing. Use OneDrive Files Restore to recover from ransomware.

It leverages built-in Microsoft 365 Business Premium features to provide immediate ransomware protection without requiring cloud expertise. Microsoft Defender for Office 365 blocks malicious attachments and links at the email gateway, while Defender for Business provides endpoint protection with controlled folder access. OneDrive Files Restore enables self-service recovery of files from ransomware within the last 30 days, aligning with the startup's need for quick recovery without additional infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Purchase Azure Backup for all user devices. Configure backup policies to run daily. Use Microsoft Intune to enforce encryption. Implement Conditional Access to require MFA.

    Why it's wrong here

    This option is incorrect because Azure Backup is not designed for user devices or endpoints; it primarily protects Azure VMs, on-premises servers, and file shares. Requiring the MARS agent on every device adds licensing cost and operational overhead, while daily backups cannot prevent fast-moving ransomware from encrypting files before the next backup. Intune-managed encryption and Conditional Access MFA are foundational hardening steps, but they do not deliver the built-in, coordinated ransomware response that Microsoft 365 Business provides.

  • Enable Microsoft Defender for Office 365 to block malicious attachments and links. Configure Microsoft Defender for Business to enable controlled folder access and ransomware protection. Educate users on phishing. Use OneDrive Files Restore to recover from ransomware.

    Why this is correct

    This option is correct because it leverages the built-in, integrated protections of Microsoft 365 Business Premium. Microsoft Defender for Office 365 filters malicious attachments and link-time detonation in Exchange Online, while Defender for Business provides endpoint detection and response plus controlled folder access that blocks unauthorized processes from modifying user files. Phishing education reduces initial compromise, and OneDrive Files Restore enables users to roll back an entire library to a known-good state within 30 days without heavy IT administration.

  • Use Microsoft Sentinel as a SIEM to detect ransomware patterns. Deploy Azure ATP for identity protection. Use Azure Policy to enforce backup.

    Why it's wrong here

    This option is unsuitable for a startup because Microsoft Sentinel is an enterprise SIEM requiring continuous log ingestion, custom analytics rules, and significant cost/licensing commitment. Azure ATP (now Microsoft Defender for Identity) focuses on detecting on-premises Active Directory attacks, not endpoint ransomware behavior, and Azure Policy does not perform backups—it only audits or enforces configurations. The complexity and operational burden are disproportionate to the simplified, out-of-the-box security tools available in Microsoft 365 Business.

  • Implement Azure Site Recovery for on-premises servers. Use Microsoft Defender for Cloud for threat detection. Deploy a third-party antivirus.

    Why it's wrong here

    This option is wrong because Azure Site Recovery is a disaster-recovery service for Azure VMs and on-premises server workloads, not for user endpoints or Microsoft 365 data. Microsoft Defender for Cloud is designed to protect cloud workloads and subscriptions, not individual Windows devices, and deploying a third-party antivirus would overlap with the built-in Microsoft Defender antivirus already included in Windows. Taken together, these tools are aimed at infrastructure rather than the endpoint-centric ransomware vectors that hit a startup's user devices.

About these practice questions

This SC-100 question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.