Courseiva
Free · No account needed · No credit card

Microsoft Cybersecurity Architect Practice Test

605 questions with instant explanations, domain breakdown, and wrong-answer analysis. Built for the real exam.

Instant feedback after each answer
Full explanations included
Domain score breakdown
Real exam: 120 min
Pass mark: 700/1000

Sample questions with explanations

This is exactly what you see during practice — question, options, and a full explanation after you answer.

Q1Design security solutions for infrastructurehard
Full explanation →

Which THREE components are required to implement a Zero Trust network architecture using Microsoft Entra Internet Access (formerly Microsoft 365 Network Connectivity)?

Conditional Access policiesCorrect
BMicrosoft Entra application proxy
CSite-to-site VPN
Microsoft Intune device compliance policiesCorrect

Option A (Conditional Access policies) is correct because Entra Internet Access relies on Conditional Access to evaluate signals such as user identity, device state, and risk before granting access to internet and SaaS resources, enforcing the "never trust, always verify" princip…Read full explanation

Q2Design security solutions for infrastructurehard
Full explanation →

You are designing a network security architecture for an Azure application that uses Azure Front Door and Azure Application Gateway. The application must be protected from DDoS attacks and common web exploits. Application traffic should be inspected by a web application firewall (WAF) before reaching the backend. What is the recommended deployment order?

AAzure Front Door with WAF only, no Application Gateway.
BAzure Front Door without WAF in front of Azure Application Gateway without WAF.
CAzure Application Gateway with WAF in front of Azure Front Door.
Azure Front Door with WAF in front of Azure Application Gateway with WAF.Correct

The recommended architecture places Azure Front Door with WAF at the global edge to absorb DDoS and block common web exploits close to the client, then routes traffic to Azure Application Gateway with WAF for regional, path-based, and application-layer protection before reaching …Read full explanation

Q3Design solutions that align with security best practices and prioritieshard
Full explanation →

You are designing a Microsoft Purview data security solution for a multinational organization subject to GDPR and CCPA. Which THREE Purview capabilities should you include to meet regulatory requirements?

Data Loss Prevention (DLP) policiesCorrect
BAdvanced eDiscovery
Microsoft Purview Audit (Premium) and Activity ExplorerCorrect
Data classification and sensitivity labelsCorrect

Data Loss Prevention (DLP) policies are correct because they allow the organization to detect and prevent the accidental or intentional sharing of sensitive data—such as personally identifiable information (PII) covered under GDPR and CCPA—across email, SharePoint, OneDrive, and …Read full explanation

Untimed Practice

Answer at your own pace. Explanation and domain tag shown immediately after each answer.

Timed Practice

Countdown timer starts immediately. Results and domain scores shown at the end — just like the real exam.

Why practice here?

Full explanations on every question

Not just the right answer — you get exactly why each wrong option is wrong, so you learn the concept, not the answer.

Domain score breakdown

After each session see your score by exam domain so you know exactly where to focus study time.

100% free, forever

No subscription, no trial, no email wall. Start a session in under 10 seconds.

Exam-style questions

Scenario-based, precise wording, realistic distractors — written to match what you actually see on exam day.

← All SC-100 questionsSC-100 exam guideStudy guidePractice by domain