Courseiva
← Back to Microsoft Cybersecurity Architect questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise Microsoft Cybersecurity Architect practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

15
scenario questions
SC-100
exam code
Microsoft
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related SC-100 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummultiple choice
Full question →

Refer to the exhibit. A KQL query is used in Microsoft Sentinel to detect brute-force attacks. The query returns no results despite known brute-force attempts. What is the most likely issue?

Exhibit

SecurityEvent
| where EventID == 4625
| summarize FailureCount = count() by Account, IPAddress
| where FailureCount > 10
| project Account, IPAddress, FailureCount
Question 2mediummultiple choice
Full question →

Refer to the exhibit. You are investigating a security incident in Microsoft Sentinel. The KQL query above is used to identify potential brute-force attacks. What does the query return?

Exhibit

Log Analytics query:
SecurityEvent
| where TimeGenerated > ago(24h)
| where AccountType == "User"
| summarize FailedLogins = count() by Account, Computer
| where FailedLogins > 5
Question 3easymultiple choice
Full question →

Refer to the exhibit. A security analyst runs the following KQL query in Microsoft Sentinel. What is the purpose of this query?

Exhibit

Refer to the exhibit.
```kql
SecurityEvent
| where TimeGenerated > ago(1h)
| where EventID == 4625
| where AccountType == "User"
| summarize Count = count() by Account, Computer, IpAddress
| where Count > 10
| project Account, Computer, IpAddress, Count
```
Question 4mediummultiple choice
Full question →

A security administrator applies the Azure Policy definition shown in the exhibit to a management group containing multiple subscriptions. After the policy is assigned, a development team reports they cannot create a new storage account in their subscription. What is the most likely cause?

Exhibit

Refer to the exhibit.

{
  "policyRule": {
    "if": {
      "allOf": [
        {
          "field": "type",
          "equals": "Microsoft.Storage/storageAccounts"
        },
        {
          "field": "Microsoft.Storage/storageAccounts/supportsHttpsTrafficOnly",
          "equals": "false"
        }
      ]
    },
    "then": {
      "effect": "deny"
    }
  }
}
Question 5hardmultiple choice
Full question →

Refer to the exhibit. You are reviewing a Conditional Access policy in Microsoft Entra ID. Based on the JSON snippet, what is the most likely outcome when a user with high user risk attempts to sign in?

Exhibit

Refer to the exhibit.
```json
{
  "properties": {
    "displayName": "Block high-risk sign-ins",
    "conditions": {
      "userRiskLevels": ["high"],
      "signInRiskLevels": []
    },
    "grantControls": {
      "builtInControls": ["block"]
    }
  }
}
```
Question 6mediummultiple choice
Full question →

Refer to the exhibit. What is the effect of this Azure Policy definition?

Exhibit

Consider the following Azure Policy definition:

{
  "if": {
    "allOf": [
      {
        "field": "type",
        "equals": "Microsoft.Storage/storageAccounts"
      },
      {
        "field": "Microsoft.Storage/storageAccounts/supportsHttpsTrafficOnly",
        "equals": "false"
      }
    ]
  },
  "then": {
    "effect": "deny"
  }
}
Question 7mediummultiple choice
Full question →

Refer to the exhibit. You are analyzing a Microsoft Sentinel analytics rule. What does this rule detect?

Exhibit

Refer to the exhibit.
```json
{
  "properties": {
    "displayName": "Microsoft Sentinel Analytics Rule",
    "query": "SecurityEvent
| where EventID == 4625
| summarize Count = count() by Account, bin(TimeGenerated, 5m)
| where Count > 10",
    "frequency": "PT5M",
    "period": "PT10M",
    "triggerOperator": "GreaterThan",
    "triggerThreshold": 0
  }
}
```
Question 8mediummultiple choice
Full question →

The exhibit shows a KQL query in Microsoft Sentinel. What is the primary purpose of this query?

Exhibit

Refer to the exhibit.
```kusto
SecurityAlert
| where TimeGenerated > ago(7d)
| where AlertSeverity == "High"
| summarize AlertCount = count() by AlertName, bin(TimeGenerated, 1d)
| order by AlertCount desc
```
Question 9hardmultiple choice
Full question →

Refer to the exhibit. You run the PowerShell command against an Azure SQL Database. The command returns a baseline object for rule VA2108. What does this indicate about the database's vulnerability assessment configuration?

Exhibit

Get-AzSqlDatabaseVulnerabilityAssessmentRuleBaseline -ResourceGroupName 'rg-sql' -ServerName 'sqlsrv01' -DatabaseName 'sqldb01' -BaselineName 'default' -RuleId 'VA2108'
Question 10hardmultiple choice
Full question →

Refer to the exhibit. A security administrator is reviewing a Conditional Access policy JSON. They want to ensure that users with medium risk level are prompted for multi-factor authentication (MFA), while high-risk users are blocked. The policy is not working as expected. Which issue is present in the policy?

Exhibit

{
  "properties": {
    "policyMode": "default",
    "rules": [
      {
        "name": "BlockHighRisk",
        "conditions": {
          "userRiskLevels": ["high"],
          "signInRiskLevels": ["high"]
        },
        "grantControls": {
          "builtInControls": ["block"]
        }
      },
      {
        "name": "RequireMFAForMedium",
        "conditions": {
          "userRiskLevels": ["medium"],
          "signInRiskLevels": ["medium"]
        },
        "grantControls": {
          "builtInControls": ["mfa"]
        }
      }
    ]
  }
}
Question 11mediummultiple choice
Full question →

Refer to the exhibit. You are reviewing an ARM template that deploys a network security group (NSG) for a web application. The NSG allows inbound HTTP traffic from any source and then denies all other inbound traffic. However, after deployment, you find that HTTP traffic is being blocked. What is the most likely cause?

Exhibit

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "resources": [
    {
      "type": "Microsoft.Network/networkSecurityGroups",
      "apiVersion": "2020-06-01",
      "name": "nsg-web",
      "properties": {
        "securityRules": [
          {
            "name": "AllowHTTP",
            "properties": {
              "protocol": "Tcp",
              "sourcePortRange": "*",
              "destinationPortRange": "80",
              "sourceAddressPrefix": "*",
              "destinationAddressPrefix": "*",
              "access": "Allow",
              "priority": 100,
              "direction": "Inbound"
            }
          },
          {
            "name": "DenyAll",
            "properties": {
              "protocol": "*",
              "sourcePortRange": "*",
              "destinationPortRange": "*",
              "sourceAddressPrefix": "*",
              "destinationAddressPrefix": "*",
              "access": "Deny",
              "priority": 200,
              "direction": "Inbound"
            }
          }
        ]
      }
    }
  ]
}
Question 12hardmultiple choice
Full question →

Refer to the exhibit. You are an Azure security engineer reviewing a custom Azure Policy definition. The policy is intended to audit virtual machines to ensure they have the Azure Security extension installed. However, the policy is not triggering on any resources. What is the most likely reason?

Exhibit

{
  "policyRule": {
    "if": {
      "allOf": [
        {
          "field": "type",
          "equals": "Microsoft.Compute/virtualMachines"
        },
        {
          "field": "Microsoft.Compute/virtualMachines/storageProfile.osDisk.managedDisk",
          "exists": "true"
        }
      ]
    },
    "then": {
      "effect": "auditIfNotExists",
      "details": {
        "type": "Microsoft.Compute/virtualMachines/extensions",
        "existenceCondition": {
          "field": "Microsoft.Compute/virtualMachines/extensions/publisher",
          "equals": "Microsoft.Azure.Security"
        }
      }
    }
  }
}
Question 13hardmultiple choice
Full question →

Contoso is a large enterprise with a complex Azure environment. They have multiple management groups, subscriptions, and a hub-spoke network topology. The security team wants to implement a consistent security baseline across all subscriptions using Azure Policy. They need to ensure that: 1) All resources must be deployed in approved regions only. 2) Network security groups must have specific rules to block high-risk ports. 3) All storage accounts must enforce HTTPS traffic. 4) The policies must be applied at the management group level to ensure inheritance. 5) Non-compliant resources must be automatically remediated where possible. What should you do?

Question 14mediummultiple choice
Full question →

Refer to the exhibit. You are reviewing an ARM template for an Azure storage account. Which security best practice is implemented?

Exhibit

resourceGroup: myResourceGroup
parameters:
  - name: location
    type: string
    defaultValue: eastus
resources:
  - type: Microsoft.Storage/storageAccounts
    name: mystorageaccount
    properties:
      supportsHttpsTrafficOnly: true
      minimumTlsVersion: TLS1_2
      networkAcls:
        defaultAction: Deny
        ipRules: []
        virtualNetworkRules: []
Question 15hardmultiple choice
Full question →

Refer to the exhibit. A security architect reviews the Azure AD Conditional Access policy JSON. The policy is intended to require MFA for all users accessing Azure management (Microsoft Azure Management app ID 797f4846-ba77-4853-9e6f-4433c3e1d1c5), except for the BreakGlassAdmin account and from trusted locations. However, some users report being prompted for MFA even when connecting from the corporate office (which is marked as a trusted location). What is the most likely cause?

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "displayName": "Require MFA for Azure management",
    "state": "Enabled",
    "conditions": {
      "userRiskLevels": [],
      "signInRiskLevels": [],
      "clientAppTypes": ["all"],
      "applications": {
        "includeApplications": ["797f4846-ba77-4853-9e6f-4433c3e1d1c5"],
        "excludeApplications": []
      },
      "users": {
        "includeUsers": ["All"],
        "excludeUsers": ["BreakGlassAdmin@contoso.com"]
      },
      "locations": {
        "includeLocations": ["All"],
        "excludeLocations": ["AllTrusted"]
      }
    },
    "grantControls": {
      "builtInControls": ["mfa"],
      "termsOfUse": [],
      "operator": "OR"
    }
  }
}
```

These SC-100 practice questions are part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style SC-100 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.