Courseiva

SC-100 · topic practice

Design security solutions for applications and data practice questions

This domain covers securing applications and data across Azure and Microsoft 365. You must design controls for APIs, storage, databases, and identity, then map them to Defender for Cloud, Microsoft Sentinel, and Purview. Questions present scenarios—like an Azure Function App calling Cosmos DB—and ask you to choose the correct security service, configuration, or remediation workflow.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Design security solutions for applications and data

What the exam tests

What to know about Design security solutions for applications and data

You must be able to select and configure the right Microsoft security service for a given application or data scenario, then explain how it integrates with Sentinel or Defender for Cloud. The most important thing is matching the control to the layer—identity, network, application, or data—without over-engineering.

Securing Azure Functions and APIs using managed identities, API Management, and Defender for APIs

Choosing encryption, key management, and access controls for Azure Storage, SQL, and Cosmos DB

Configuring Microsoft Sentinel data connectors, analytics rules, and automated remediation playbooks

Applying Microsoft Purview sensitivity labels, DLP policies, and data discovery to protect data

Watch out for

Common Design security solutions for applications and data exam traps

  • ▸Confusing Microsoft Defender for Cloud recommendations with Microsoft Sentinel detection and response capabilities when the scenario asks for automated threat remediation.
  • ▸Assuming Azure Storage or Cosmos DB encryption at rest requires customer-managed keys, when platform-managed keys are the default and sufficient unless compliance demands otherwise.
  • ▸Selecting Azure Firewall or NSG rules for application-layer API protection instead of using Azure Web Application Firewall or API Management policies.

Practice set

Design security solutions for applications and data questions

20 questions · select your answer, then reveal the explanation

Your company uses Microsoft Defender for Cloud to protect Azure resources. A critical application uses an Azure SQL Database. You need to ensure that all queries to the database are encrypted in transit and that the encryption protocol is the most secure version available. Which configuration should you enforce?

A company uses Microsoft Entra ID to authenticate users for a web application. They want to enable self-service password reset (SSPR) for users. What is the minimum licensing requirement?

Your organization uses Microsoft Defender for Cloud to protect Azure SQL databases. You notice that a particular database is flagged with a high-severity recommendation to enable 'Advanced Data Security'. What does enabling Advanced Data Security provide?

Your company is designing a solution to store sensitive documents in Azure Files. The files must be encrypted at rest and in transit. Which two configurations are required? (Each correct answer presents part of the solution.)

A company uses Azure API Management to expose backend APIs. They need to implement OAuth 2.0 authorization with Microsoft Entra ID. The APIs are called by a SPA application. Which OAuth 2.0 grant type should be used?

Your company is developing a microservices application that will run on Azure Kubernetes Service (AKS). The application must authenticate to Azure SQL Database using managed identities. Which type of managed identity should you assign to the AKS cluster?

Your organization uses Azure Cosmos DB with SQL API. You need to implement data encryption at rest and control access to the encryption keys. Which two actions should you take? (Choose two.)

Your company uses Microsoft Intune to manage mobile devices. You need to protect corporate data on mobile devices by ensuring that work files are encrypted and not accessible by personal apps. What three configurations should you implement? (Choose three.)

Your company uses Microsoft Defender for Cloud Apps to discover and control shadow IT. You need to block the use of a newly discovered unsanctioned cloud storage app that poses a high risk. What should you configure?

You are designing an API management solution using Azure API Management. The security team requires that all API calls must be authenticated using OAuth 2.0 and that only specific Azure AD applications can access the APIs. Additionally, the solution must support rate limiting and IP filtering. What should you configure?

Your organization uses Microsoft Defender for Endpoint (MDE) for endpoint detection and response. You need to protect sensitive data on Windows 10 devices from being exfiltrated via USB drives. The solution must be able to audit file copy operations to USB and block them for high-risk users. What should you configure?

Refer to the exhibit. You are reviewing an Azure Policy definition. What does this policy do?

Exhibit

{
  "properties": {
    "policyRule": {
      "if": {
        "field": "type",
        "equals": "Microsoft.Compute/virtualMachines"
      },
      "then": {
        "effect": "deny",
        "details": {
          "field": "Microsoft.Compute/virtualMachines/networkProfile.networkInterfaces[*].id",
          "exists": "false"
        }
      }
    }
  },
  "name": "Deny-VM-Without-NIC"
}

Refer to the exhibit. You run the PowerShell command shown in the exhibit. The command returns the secret value in plain text. The Key Vault has soft-delete and purge protection enabled. What is the most likely reason that the command succeeded?

Exhibit

PS C:\> Get-AzKeyVaultSecret -VaultName 'ContosoKeyVault' -Name 'DbPassword' -AsPlainText
Contoso123!

Refer to the exhibit. You are analyzing a KQL query in Microsoft Sentinel. What is the purpose of this query?

Exhibit

SecurityAlert
| where AlertName == "Suspicious process execution"
| where TimeGenerated > ago(1h)
| project Computer, AlertName, TimeGenerated

Your organization is designing a data protection strategy using Microsoft Purview. You need to classify and label all sensitive data stored in Azure SQL Database. The solution must automatically detect credit card numbers and apply a sensitivity label. Which three actions should you take? (Choose three.)

Your organization uses Microsoft Defender for Cloud Apps. You need to detect and prevent the use of unsanctioned cloud apps. The solution should generate alerts when users access high-risk apps and block access to very high-risk apps. Which three actions should you take? (Choose three.)

A company uses Microsoft Defender for Cloud Apps to control data exfiltration from sanctioned SaaS apps. Security admins want to block downloading sensitive files from SharePoint Online to unmanaged devices. Which method should be used?

Question 18hardmultiple choice
Review the full subnetting walkthrough →

Refer to the exhibit. A security architect is reviewing an ARM template for an Azure Key Vault. The vault must be accessible from a backend subnet via private endpoint. What is the missing configuration component?

Exhibit

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "resources": [
    {
      "type": "Microsoft.KeyVault/vaults",
      "apiVersion": "2021-10-01",
      "name": "kv-prod-001",
      "properties": {
        "tenantId": "[subscription().tenantId]",
        "sku": {
          "family": "A",
          "name": "Standard"
        },
        "enableSoftDelete": true,
        "enablePurgeProtection": true,
        "networkAcls": {
          "defaultAction": "Deny",
          "bypass": "AzureServices",
          "virtualNetworkRules": [
            {
              "id": "/subscriptions/.../subnets/backend-subnet"
            }
          ]
        },
        "accessPolicies": []
      }
    }
  ]
}

A company stores sensitive customer data in Azure SQL Database. They need to encrypt the data at rest and control access to encryption keys. Which solution should they use?

A company deploys a line-of-business application on Azure App Service. The application uses a managed identity to access Azure SQL Database. Security policy requires that the database connection string must not contain credentials. How should the connection string be configured?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Design security solutions for applications and data sessions

Start a Design security solutions for applications and data only practice session

Every question in these sessions is drawn from the Design security solutions for applications and data domain — nothing else.

Related practice questions

Related SC-100 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SC-100 exam test about Design security solutions for applications and data?
You must be able to select and configure the right Microsoft security service for a given application or data scenario, then explain how it integrates with Sentinel or Defender for Cloud. The most important thing is matching the control to the layer—identity, network, application, or data—without over-engineering.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Design security solutions for applications and data questions in a focused session?
Yes — the session launcher on this page draws every question from the Design security solutions for applications and data domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SC-100 topics?
Use the topic links above to move to related areas, or go back to the SC-100 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SC-100 exam covers. They are not copied from any real exam or dump site.