Courseiva

SC-100 · topic practice

Design security operations, identity, and compliance capabilities practice questions

This domain covers designing Microsoft Sentinel deployments, analytics rules, automation, and integration with Defender XDR workloads, plus identity protection and compliance capabilities in Microsoft Purview. Questions present operational scenarios—missing detections, automated response, data loss prevention, risk-based signals—and ask you to select the correct configuration or diagnose why a control fails.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Design security operations, identity, and compliance capabilities

What the exam tests

What to know about Design security operations, identity, and compliance capabilities

You must be able to map a security operations requirement to the right Microsoft tool—Sentinel, Defender XDR, Defender for Cloud Apps, or Purview—and explain the configuration that makes it work. The most important thing: verify the data source and connector before trusting any detection or automated response.

Configuring Microsoft Sentinel analytics rules, KQL query logic, and incident creation from Defender XDR signals

Designing automation with Sentinel playbooks, automation rules, and Logic Apps for incident response

Applying Defender for Cloud Apps policies, session controls, and DLP to block sensitive uploads

Using Microsoft Purview compliance, sensitivity labels, and Insider Risk Management for data governance

Watch out for

Common Design security operations, identity, and compliance capabilities exam traps

  • ▸Assuming a Sentinel analytics rule fires without checking entity mapping, data connector health, or whether the required table actually receives logs.
  • ▸Confusing Defender for Cloud Apps file policies with Purview DLP policies; each applies at different layers and requires different licensing.
  • ▸Believing automation rules and playbooks are interchangeable; automation rules orchestrate, while playbooks contain the actual response logic.

Practice set

Design security operations, identity, and compliance capabilities questions

20 questions · select your answer, then reveal the explanation

Your organization uses Microsoft Purview to classify sensitive data. You need to automatically apply a sensitivity label to documents that contain personally identifiable information (PII). Which TWO components should you configure?

Your company uses Microsoft Defender for Cloud to manage security posture across hybrid workloads. You need to ensure that critical vulnerabilities found on Azure VMs are automatically remediated without manual intervention. Which feature should you enable?

Your organization uses Microsoft Sentinel to centralize security logs from multiple clouds. The security team needs a solution that automatically investigates low-fidelity alerts and creates incidents only when confirmed malicious. Which Microsoft Sentinel feature should you configure?

Your organization uses Microsoft Defender XDR to detect and respond to threats. The SOC team wants to automatically isolate a device when a high-severity incident is confirmed. Which automation feature should you configure?

Your company is migrating from on-premises Active Directory to Microsoft Entra ID. You need to ensure that users can authenticate using their existing on-premises credentials while gradually moving to cloud-only authentication. Which authentication method should you implement first?

Your organization needs to enforce multi-factor authentication (MFA) for all users accessing sensitive applications. You plan to use Microsoft Entra ID Conditional Access. Which grant control should you configure?

Your organization is implementing a privileged access strategy using Microsoft Entra ID. You need to provide just-in-time (JIT) access to Azure resources for administrators. Which TWO features should you use?

Your organization is using Microsoft Sentinel to detect advanced threats. You need to ensure that alerts from Microsoft Defender XDR are automatically synchronized with Sentinel and that incidents are created. Which THREE components are required?

Refer to the exhibit. You are reviewing a Conditional Access policy JSON. The policy is intended to block legacy authentication. However, users are still able to access email using Outlook (modern auth). What is the most likely reason?

Exhibit

{
  "properties": {
    "displayName": "Block legacy authentication",
    "state": "enabled",
    "conditions": {
      "applications": {
        "includeApplications": ["All"]
      },
      "users": {
        "includeUsers": ["All"]
      },
      "clientAppTypes": ["exchangeActiveSync", "otherClients"]
    },
    "grantControls": {
      "builtInControls": ["block"]
    }
  }
}

Refer to the exhibit. You are reviewing an ARM template for an Azure storage account. The security team requires that only HTTPS traffic is allowed and that TLS 1.2 is enforced. Does this template meet the requirements?

Exhibit

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "resources": [
    {
      "type": "Microsoft.Storage/storageAccounts",
      "apiVersion": "2021-02-01",
      "name": "[parameters('storageName')]",
      "location": "[resourceGroup().location]",
      "kind": "StorageV2",
      "properties": {
        "supportsHttpsTrafficOnly": true,
        "minimumTlsVersion": "TLS1_2",
        "networkAcls": {
          "bypass": "AzureServices",
          "defaultAction": "Deny"
        }
      }
    }
  ]
}

A company uses Microsoft Defender for Cloud to assess the security posture of their hybrid environment. They need to ensure that all Azure subscriptions are evaluated against the same set of regulatory compliance standards. What should they configure?

Question 12easymultiple choice
Study the full multicast explanation →

Your organization has Microsoft Entra ID (Azure AD) and uses Privileged Identity Management (PIM). You need to ensure that when a user activates a privileged role, they must provide a reason and a ticket number. What should you configure?

Refer to the exhibit. You are configuring a Microsoft Purview sensitivity label. When a user applies this label to an email, what happens?

Exhibit

Refer to the exhibit.
```json
{
  "properties": {
    "displayName": "Sensitivity label: Confidential",
    "encryption": {
      "encryptionEnabled": true,
      "protectWithDoNotForward": true
    }
  }
}
```

Which TWO configurations are required to enable Microsoft Defender for Cloud Apps to monitor cloud app usage?

Your organization uses Microsoft Sentinel as a SIEM. You need to reduce the cost of data ingestion while ensuring that security-relevant events are retained. You have identified that Windows Event ID 4624 (successful logon) produces a high volume of logs. What should you do?

Your organization uses Microsoft Defender for Cloud to manage the security posture of Azure resources. You need to receive alerts when a virtual machine is deployed without just-in-time (JIT) access enabled. What should you do?

A company uses Microsoft Sentinel for security operations. The security team wants to automatically create an incident in Microsoft Sentinel when Microsoft Defender for Cloud detects a high-severity vulnerability on a virtual machine. What should the security team configure?

A global organization uses Microsoft Entra ID with Conditional Access policies. They want to enforce multifactor authentication (MFA) for all users accessing sensitive apps from outside the corporate network, but allow access without MFA from trusted IPs. What should they configure?

A company uses Microsoft Purview to enforce Data Loss Prevention (DLP) policies. They want to prevent users from sharing credit card numbers via email. Which action should they configure in the DLP policy?

Refer to the exhibit. An organization uses Microsoft Entra ID Governance. This access review policy is intended to review guest users created after January 1, 2025. The reviewers are users with job title 'Manager'. However, the review is not starting automatically. What is the most likely cause?

Exhibit

JSON policy snippet:
```json
{
  "policyType": "AccessReview",
  "displayName": "Review guest access",
  "scope": {
    "@odata.type": "#microsoft.graph.accessReviewScope",
    "query": "/users?$filter=userType eq 'Guest' and createdDateTime ge 2025-01-01",
    "queryType": "MicrosoftGraph"
  },
  "reviewers": [
    {
      "query": "/users?$filter=jobTitle eq 'Manager'",
      "queryType": "MicrosoftGraph"
    }
  ],
  "settings": {
    "mailNotificationsEnabled": true,
    "reminderNotificationsEnabled": true,
    "autoReviewEnabled": false,
    "autoApplyReviewEnabled": false,
    "instanceDurationInDays": 30
  }
}
```

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Design security operations, identity, and compliance capabilities sessions

Start a Design security operations, identity, and compliance capabilities only practice session

Every question in these sessions is drawn from the Design security operations, identity, and compliance capabilities domain — nothing else.

Related practice questions

Related SC-100 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SC-100 exam test about Design security operations, identity, and compliance capabilities?
You must be able to map a security operations requirement to the right Microsoft tool—Sentinel, Defender XDR, Defender for Cloud Apps, or Purview—and explain the configuration that makes it work. The most important thing: verify the data source and connector before trusting any detection or automated response.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Design security operations, identity, and compliance capabilities questions in a focused session?
Yes — the session launcher on this page draws every question from the Design security operations, identity, and compliance capabilities domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SC-100 topics?
Use the topic links above to move to related areas, or go back to the SC-100 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SC-100 exam covers. They are not copied from any real exam or dump site.