Courseiva

SC-100 · topic practice

Scenario practice questions

Practise Microsoft Cybersecurity Architect Scenario practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Scenario

What the exam tests

What to know about Scenario

Scenario questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Scenario exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Practice set

Scenario questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full Scenario explanation →

Refer to the exhibit. A KQL query is used in Microsoft Sentinel to detect brute-force attacks. The query returns no results despite known brute-force attempts. What is the most likely issue?

Exhibit

SecurityEvent
| where EventID == 4625
| summarize FailureCount = count() by Account, IPAddress
| where FailureCount > 10
| project Account, IPAddress, FailureCount
Question 2easymultiple choice
Read the full Scenario explanation →

You need to design a solution to synchronize on-premises Active Directory users to Microsoft Entra ID for hybrid identity. Which tool should you use?

Question 3mediummultiple choice
Read the full Scenario explanation →

A company is designing a data protection strategy for Azure SQL Database. They need to ensure that backups are retained for 7 years to meet regulatory compliance. Which Azure feature should they use?

Question 4hardmultiple choice
Read the full Scenario explanation →

A multinational corporation uses Microsoft Entra ID for identity and Microsoft Defender for Cloud Apps for SaaS app governance. The security team wants to deploy a conditional access policy that blocks access from untrusted locations for all cloud apps except Microsoft 365, which should only be blocked if the device is not compliant. How should you configure the policy?

Question 5hardmultiple choice
Read the full Scenario explanation →

Your company uses Microsoft Entra ID for identity management. You need to implement a solution that allows external partners to access a specific application using their own identity providers, while ensuring that their accounts are automatically deprovisioned when removed from their home organization. Which feature should you use?

Question 6mediummultiple choice
Read the full Scenario explanation →

A company is implementing Microsoft Priva to manage subject rights requests. Users submit requests to access their personal data stored in Exchange Online, SharePoint, and Teams. The privacy team needs to automate the retrieval of data from these sources. Which Priva capability should they use?

Question 7mediummulti select
Read the full Scenario explanation →

A company uses Microsoft Purview to classify and label sensitive data. They want to automatically apply a sensitivity label to documents containing a specific custom sensitive information type. Which TWO components are required for this?

Question 8hardmulti select
Read the full Scenario explanation →

Which THREE Microsoft security solutions can be used to detect and respond to threats across hybrid cloud environments? (Choose three.)

Question 9mediummultiple choice
Read the full Scenario explanation →

A company uses Microsoft Sentinel for security operations. They want to collect logs from a custom application running on Azure Virtual Machines. The application writes logs to a local file. Which data connector should they use?

Question 10mediummultiple choice
Read the full Scenario explanation →

Your organization uses Microsoft Sentinel to monitor hybrid workloads. You need to design a solution to detect lateral movement attempts from compromised on-premises servers to Azure VMs. Which data connector should you prioritize?

Question 11hardmultiple choice
Read the full Scenario explanation →

Refer to the exhibit. A security administrator is reviewing a Conditional Access policy JSON. They want to ensure that users with medium risk level are prompted for multi-factor authentication (MFA), while high-risk users are blocked. The policy is not working as expected. Which issue is present in the policy?

Exhibit

{
  "properties": {
    "policyMode": "default",
    "rules": [
      {
        "name": "BlockHighRisk",
        "conditions": {
          "userRiskLevels": ["high"],
          "signInRiskLevels": ["high"]
        },
        "grantControls": {
          "builtInControls": ["block"]
        }
      },
      {
        "name": "RequireMFAForMedium",
        "conditions": {
          "userRiskLevels": ["medium"],
          "signInRiskLevels": ["medium"]
        },
        "grantControls": {
          "builtInControls": ["mfa"]
        }
      }
    ]
  }
}
Question 12mediummultiple choice
Read the full Scenario explanation →

Your organization uses Microsoft Sentinel for security information and event management (SIEM). You need to create an analytics rule that detects when a user account is created outside of business hours from an unusual IP address. Which type of rule should you use?

Question 13hardmulti select
Read the full VPN explanation →

Which THREE components are required to implement a secure hybrid network architecture using Azure VPN Gateway? (Choose three.)

Question 14hardmulti select
Read the full Scenario explanation →

Your organization is implementing Microsoft Entra ID governance. Which THREE capabilities should you include to manage the identity lifecycle and access reviews?

Question 15mediummultiple choice
Read the full Scenario explanation →

Your company uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. You need to prevent users from sharing credit card numbers via email in Outlook on the web. The policy should notify users when they try to send such data and allow them to override with a business justification. What should you configure?

Question 16hardmultiple choice
Read the full Scenario explanation →

Your organization uses Microsoft Intune to manage devices. You need to deploy a line-of-business (LOB) app to iOS devices that is not available in the public App Store. The app is signed with an enterprise certificate. Which app deployment method should you use?

Question 17hardmulti select
Read the full Scenario explanation →

Your organization is implementing a secure DevOps pipeline for Azure. You need to ensure that secrets (e.g., API keys) are not stored in source code and that access to production resources is controlled. Which THREE practices should you implement?

Question 18hardmultiple choice
Read the full Scenario explanation →

You are analyzing a custom detection rule in Microsoft 365 Defender. Based on the exhibit, what is a potential operational issue with this rule?

Exhibit

Refer to the exhibit.

{
    "alertRuleTemplate": "Suspicious process execution",
    "displayName": "Custom Rule - Suspicious PowerShell",
    "description": "Detects suspicious PowerShell commands",
    "query": "DeviceProcessEvents | where FileName in~ ('powershell.exe', 'pwsh.exe') | where ProcessCommandLine has_any ('-EncodedCommand', '-e ', 'Invoke-Expression')",
    "severity": "High",
    "queryFrequency": "PT1H",
    "queryPeriod": "PT1H",
    "triggerOperator": "GreaterThan",
    "triggerThreshold": 5
}
Question 19hardmultiple choice
Read the full Scenario explanation →

Refer to the exhibit. A security administrator needs to ensure that the storage account 'securestore' is compliant with the company policy that requires encryption at rest using customer-managed keys and network access restricted to a specific virtual network. Which of the following statements is correct?

Exhibit

Consider the following Azure CLI command output for a storage account:

{
  "id": "/subscriptions/.../storageAccounts/securestore",
  "kind": "StorageV2",
  "properties": {
    "supportsHttpsTrafficOnly": true,
    "encryption": {
      "keySource": "Microsoft.Keyvault",
      "keyvaultproperties": {
        "keyvaulturi": "https://myvault.vault.azure.net/keys/mykey/abc123"
      },
      "services": {
        "blob": {
          "enabled": true
        },
        "file": {
          "enabled": true
        }
      }
    },
    "networkAcls": {
      "defaultAction": "Deny",
      "virtualNetworkRules": [
        {
          "id": "/subscriptions/.../virtualNetworks/vnet1/subnets/subnet1",
          "action": "Allow"
        }
      ],
      "ipRules": []
    }
  }
}
Question 20easymultiple choice
Read the full Scenario explanation →

Your company plans to migrate on-premises servers to Azure. You need to ensure that the migrated servers are protected against malware and vulnerabilities. Which Microsoft Defender for Cloud plan should you enable for the Azure VMs?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Scenario sessions

Start a Scenario only practice session

Every question in these sessions is drawn from the Scenario domain — nothing else.

Related practice questions

Related SC-100 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SC-100 exam test about Scenario?
Scenario questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Scenario questions in a focused session?
Yes — the session launcher on this page draws every question from the Scenario domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SC-100 topics?
Use the topic links above to move to related areas, or go back to the SC-100 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SC-100 exam covers. They are not copied from any real exam or dump site.