Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Contoso is a financial services company migrating critical workloads to Azure. They must comply with PCI DSS and have a Security Operations Center (SOC) team that uses Microsoft Sentinel. The CISO wants to ensure that the security posture aligns with Microsoft's cybersecurity reference architecture (MCRA). You need to design a solution that includes the following requirements: 1) All Azure subscriptions must be managed under a single management group hierarchy with consistent policies. 2) The SOC must have a centralized view of security alerts across all resources, including on-premises servers and multi-cloud environments. 3) Privileged access to Azure resources must be protected using just-in-time (JIT) access and Privileged Identity Management (PIM). 4) Compliance with PCI DSS must be continuously monitored and reported. 5) The solution must minimize operational overhead. What should you include in the design?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy a single management group containing all subscriptions. Enable Microsoft Defender for Cloud with the 'PCI DSS v3.2.1' regulatory compliance dashboard on the management group. Configure Azure Policy to enforce security standards. Enable PIM and configure JIT VM access. Use Microsoft Sentinel as the SIEM, connecting it to Defender for Cloud and on-premises security sources.

Option B is correct because it directly satisfies all five requirements with minimal operational overhead: a single management group with inherited Azure Policy enforces consistent PCI DSS controls across all subscriptions, and enabling Microsoft Defender for Cloud's 'PCI DSS v3.2.1' regulatory compliance dashboard on the management group provides continuous compliance monitoring and reporting. Microsoft Sentinel, connected to Defender for Cloud and on-premises security sources, gives the SOC a centralized SIEM view spanning Azure, on-premises, and multi-cloud, while PIM with JIT VM access secures privileged access as required. Option A fails because it fragments governance into separate management groups per business unit, uses a third-party SIEM instead of the existing Microsoft Sentinel, and applies Defender for Cloud per subscription, increasing overhead. Option C is wrong because it omits JIT access, limits Sentinel to cloud workloads only, and relies on manual secure score review rather than continuous PCI DSS reporting. Option D is incorrect because it disables Defender for Cloud (losing regulatory compliance monitoring) and uses Azure Monitor rather than Sentinel for SOC alerting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create separate management groups per business unit. Enable Microsoft Defender for Cloud on each subscription individually. Use Azure Policy to assign PCI DSS policies per subscription. Configure PIM at the tenant root management group. Use a third-party SIEM to aggregate alerts.

    Why it's wrong here

    Fragmented management across separate management groups and per-subscription Defender for Cloud deployment prevents a unified view of compliance and security posture. Individually assigning PCI DSS policies per subscription creates configuration drift and duplicated effort, while a third-party SIEM adds integration complexity without native ingestion of Defender for Cloud alerts. This approach lacks a centralized regulatory compliance dashboard and makes continuous monitoring across the enterprise impractical.

  • ✓

    Deploy a single management group containing all subscriptions. Enable Microsoft Defender for Cloud with the 'PCI DSS v3.2.1' regulatory compliance dashboard on the management group. Configure Azure Policy to enforce security standards. Enable PIM and configure JIT VM access. Use Microsoft Sentinel as the SIEM, connecting it to Defender for Cloud and on-premises security sources.

    Why this is correct

    This design centralizes subscription management under a single management group, allowing Azure Policy and Defender for Cloud regulatory compliance dashboards to span the entire environment consistently. The PCI DSS v3.2.1 dashboard continuously assesses all resources, PIM combined with JIT VM access reduces standing privilege and exposed attack surface, and Microsoft Sentinel ingests both cloud and on-premises security data for a unified SOC. It provides an integrated, continuous compliance monitoring and threat detection solution that scales across the organization.

  • ✗

    Deploy a management group hierarchy with policies inherited. Use Microsoft Defender for Cloud's secure score to monitor compliance manually. Implement PIM without JIT. Use Microsoft Sentinel but only for cloud workloads.

    Why it's wrong here

    Manually monitoring the secure score for compliance is not equivalent to a regulatory compliance dashboard; the secure score reflects security posture, not PCI DSS control status, and manual review is neither continuous nor auditable. PIM without JIT leaves VM management ports open, increasing the risk of brute-force attacks, while limiting Sentinel to cloud workloads ignores on-premises signals that could indicate a breach path. This configuration leaves significant visibility and control gaps for a financial services organization.

  • ✗

    Use a single management group with Azure Policy to enforce PCI DSS controls. Rely on Azure Monitor for security alerts. Do not enable Defender for Cloud to reduce costs. Use PIM for privileged roles. Connect on-premises logs to a Log Analytics workspace for the SOC.

    Why it's wrong here

    Solely relying on Azure Monitor for security alerts is insufficient because it is an operational telemetry service, not a security analytics platform, and it lacks the threat detection and compliance assessment capabilities of Defender for Cloud. Skipping Defender for Cloud to reduce costs eliminates continuous compliance evaluation against PCI DSS and critical security recommendations, leaving the organization exposed despite Azure Policy enforcement. Even with PIM and Log Analytics connectivity, the absence of Defender for Cloud means the SOC lacks automated security monitoring and a centralized compliance dashboard.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.