Courseiva

Microsoft Cybersecurity Architect (SC-100) — Questions 601–605

605 questions total · 9pages · All types, answers revealed

Page 8

Page 9 of 9

601
MCQmedium

Your organization is using Microsoft Defender for Cloud to manage security across multiple Azure subscriptions. You need to ensure that all virtual machines in the subscriptions are monitored by Defender for Cloud and that security alerts are sent to the security operations team. You also need to enforce that any new VMs are automatically onboarded to Defender for Cloud. You have a Log Analytics workspace in the central subscription. What should you do?

A.Enable Defender for Cloud on each subscription and configure email notifications for alerts.
B.Assign an Azure Policy that deploys the Log Analytics agent to all VMs.
C.In Defender for Cloud, enable auto-provisioning for the Log Analytics agent at the management group level and specify the central workspace.
D.Create a Log Analytics workspace in each subscription and configure Defender for Cloud to use that workspace.
AnswerC

Enabling auto-provisioning at the management group level is the correct approach because it applies the Log Analytics agent deployment setting to every subscription under that group, guaranteeing unified coverage. When you specify a central workspace, all VMs report to the same Log Analytics workspace, enabling a single pane-of-glass view for security analytics and cross-subscription hunting. Auto-provisioning also automatically installs the agent on new VMs as they are created, closing the coverage gap that exists with manual or policy-based deployment methods.

Why this answer

Enabling auto-provisioning of the Log Analytics agent at the management group scope ensures all VMs across subscriptions are monitored and new VMs are automatically onboarded. Option A is wrong because configuring only the workspace does not auto-provision. Option B is wrong because Azure Policy can enforce agent deployment, but auto-provisioning is simpler and more direct.

Option D is wrong because enabling Defender for Cloud at the subscription level does not automatically install the agent.

602
MCQmedium

A healthcare organization is using Microsoft Purview to govern its data estate. They have multiple Azure Data Lake Storage accounts and Azure SQL Databases. They need to classify sensitive data such as patient health information (PHI) and apply protection automatically when data is exported from these sources to an external location. The organization also wants to prevent unauthorized users from accessing sensitive data in Azure SQL Database by using built-in security features. The compliance team requires that any access to sensitive data be logged and auditable. You need to design a solution that meets these requirements. What should you implement?

A.Use Microsoft Purview to scan and classify data. Auto-apply sensitivity labels. Implement Azure AD authentication and row-level security in Azure SQL Database. Enable auditing and send to Log Analytics.
B.Use Microsoft Purview to scan and classify data. Apply sensitivity labels manually. Configure Azure SQL Database firewall to block all but admin. Use Azure SQL auditing.
C.Use Microsoft Defender for Cloud to identify sensitive data. Implement Azure SQL Database always encrypted. Use Azure Monitor to log queries.
D.Use Microsoft Purview to classify data. Apply data masking in Azure SQL Database for PHI columns. Use Azure SQL Database threat detection.
AnswerA

This option is correct because it combines Purview's scanning with auto-applied sensitivity labels, ensuring consistent classification without manual effort. Azure AD authentication replaces SQL logins with identity-based access, and row-level security (RLS) filters PHI at the query level so authorized users only see rows they are permitted to access. Enabling auditing to Log Analytics creates an immutable, queryable record of all data access and label changes, satisfying auditability requirements that are essential for healthcare compliance.

Why this answer

Microsoft Purview can scan data sources like Azure Data Lake Storage and Azure SQL Database, classify sensitive data such as PHI, and auto-apply sensitivity labels. Azure SQL Database supports Azure AD authentication and row-level security (RLS) to restrict access to sensitive data based on user identity. Auditing logs can be sent to Log Analytics for compliance.

Option B is incorrect because it requires manual labeling and does not use row-level security. Option C uses Defender for Cloud (not Purview) and Always Encrypted (which does not prevent access to authorized users). Option D uses data masking (obfuscation) rather than access control and lacks auto-labeling and auditing integration.

603
MCQeasy

A company wants to protect sensitive email data from being exfiltrated by malicious insiders. They need a solution that can detect and block anomalous outbound email traffic in real time. Which Microsoft solution should they use?

A.Microsoft Purview Information Protection
B.Microsoft Defender for Cloud Apps
C.Microsoft Defender for Office 365
D.Microsoft Sentinel
AnswerC

Microsoft Defender for Office 365 is the correct choice because it is the email security service built into Exchange Online Protection and Microsoft 365. It inspects every inbound and outbound message in near real time with anti-phishing, anti-spam, anti-malware, Safe Links, and Safe Attachments, and can quarantine suspicious messages before they reach mailboxes. Its outbound spam and mail-flow rules also allow administrators to block or restrict internal users from sending messages containing sensitive content, directly preventing data exfiltration.

Why this answer

Microsoft Defender for Office 365 (MDO) is the correct solution because it provides real-time detection and blocking of anomalous outbound email traffic through its outbound spam filtering and anti-phishing policies. MDO uses machine learning models to analyze email sending patterns, such as sudden spikes in volume or unusual recipient domains, and can automatically quarantine or block suspicious outbound messages to prevent data exfiltration by malicious insiders.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps (a CASB for cloud app activity monitoring) with Defender for Office 365, which is specifically built to protect email traffic at the transport layer, including outbound anomaly detection.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Information Protection focuses on classifying, labeling, and encrypting data at rest or in transit, but it does not provide real-time detection or blocking of anomalous outbound email traffic. Option B is wrong because Microsoft Defender for Cloud Apps is a CASB that monitors cloud app usage and can detect anomalous behavior, but it is not designed to inspect and block outbound email traffic in real time at the email transport layer. Option D is wrong because Microsoft Sentinel is a SIEM/SOAR solution that aggregates and analyzes security logs for threat detection and response, but it does not natively perform real-time email traffic inspection or blocking at the mail flow level.

604
MCQhard

Refer to the exhibit. A security architect is reviewing the network configuration of an Azure App Service app named 'finance-app'. The app needs to be accessible from a backend subnet via private endpoint. Which additional configuration is required?

A.Set publicNetworkAccess to Enabled
B.Configure regional VNet integration for the app
C.Create a private endpoint and associate it with the App Service
D.Enable IP-based SSL for the app
AnswerC

A private endpoint creates a network interface with a private IP address in the virtual network, allowing clients inside the VNet (or connected via peering/VPN) to reach the App Service without traversing the public internet. Simply associating the private endpoint with the App Service, however, does not automatically remove the public endpoint; you must also set publicNetworkAccess to Disabled and apply access restrictions to block all public traffic. This combination gives true private inbound connectivity and satisfies the requirement.

Why this answer

The correct option is C: Create a private endpoint and associate it with the App Service. For an Azure App Service app to be reachable from a backend subnet over a private IP, a private endpoint must be created and linked to the app, which provisions a private IP in the target subnet via Azure Private Link. Option A is wrong because setting publicNetworkAccess to Enabled exposes the app publicly rather than providing private access.

Option B is wrong because regional VNet integration enables outbound traffic from the app into a VNet, not inbound private access to the app. Option D is wrong because IP-based SSL only binds a certificate to an IP address and does not create private connectivity.

605
Multi-Selecthard

Your organization uses Microsoft Entra ID and needs to implement a Zero Trust identity strategy. Which THREE principles should you apply?

Select 3 answers
A.Use least privilege access
B.Verify explicitly
C.Trust implicitly
D.Use a single authentication method
E.Assume breach
AnswersA, B, E

In Microsoft Entra ID, least privilege means assigning identities only the permissions required for their specific job, using built-in roles like Global Reader or custom roles instead of broad Global Administrator. Privileged Identity Management (PIM) provides time-bound, just-in-time role activation, further reducing standing access and the attack surface. This principle directly limits the blast radius if an account is compromised, making it a correct answer for Zero Trust.

Why this answer

The Zero Trust identity model in Microsoft Entra ID is built on three core principles, and option B (Verify explicitly) is correct because every access request must be authenticated and authorized based on all available signals—user identity, device health, location, and risk—rather than trusting based on network location. Option A (Use least privilege access) is correct because Zero Trust requires granting just-enough, just-in-time access using tools like Privileged Identity Management (PIM) and conditional access so users only get the permissions needed for the task. Option E (Assume breach) is correct because Zero Trust assumes the network is already compromised and therefore uses micro-segmentation, end-to-end encryption, and analytics to minimize blast radius and detect threats.

Option C (Trust implicitly) is incorrect because it is the opposite of Zero Trust—implicit trust based on being inside the corporate network is exactly what Zero Trust eliminates. Option D (Use a single authentication method) is incorrect because Zero Trust favors strong, phishing-resistant multi-factor authentication (such as FIDO2 or Windows Hello for Business) rather than relying on a single authentication factor.

Exam trap

The trap here is that candidates often confuse 'Trust implicitly' with the legacy perimeter-based security model and select it as a valid principle, or mistakenly think a single authentication method simplifies management, but Zero Trust explicitly rejects both for continuous verification and defense-in-depth.

Page 8

Page 9 of 9

All pages