Courseiva

SC-100 · topic practice

Design solutions that align with security best practices and priorities practice questions

This domain covers designing security that follows Microsoft best practices and priorities across identity, data, and cloud workloads. Questions present a business scenario and ask you to choose the Microsoft solution that best aligns with Zero Trust, least privilege, and defense in depth — typically Microsoft Entra ID, Purview, Defender for Cloud, and GitHub Advanced Security.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Design solutions that align with security best practices and priorities

What the exam tests

What to know about Design solutions that align with security best practices and priorities

A candidate must map business requirements to the correct Microsoft security control and justify it with Zero Trust and least privilege. The single most important thing: pick the service that enforces the control automatically, not one that only reports or recommends it.

Designing Zero Trust identity with Microsoft Entra ID Conditional Access and phishing-resistant passwordless methods like FIDO2 and Windows Hello for Business.

Configuring Microsoft Purview sensitivity labels with auto-labeling and trainable classifiers for data classification.

Enabling Defender for Cloud DevOps security and GitHub Advanced Security to scan IaC templates for misconfigurations pre-deployment.

Applying least privilege through Privileged Identity Management, Entra ID Governance, and Azure RBAC role assignments.

Watch out for

Common Design solutions that align with security best practices and priorities exam traps

  • ▸Choosing passwordless authentication as a standalone fix instead of pairing it with Conditional Access authentication strength policies that actually enforce it.
  • ▸Assuming Purview auto-labeling applies labels instantly; it requires published labels, client-side or service-side scanning, and simulation before enforcement.
  • ▸Confusing Defender for Cloud posture recommendations with workload protection plans, or expecting IaC scanning to run without connecting the repository first.

Practice set

Design solutions that align with security best practices and priorities questions

20 questions · select your answer, then reveal the explanation

A company is designing a hybrid identity solution with Microsoft Entra ID. They need to ensure that users can access resources from unmanaged devices while maintaining security. The security team requires that all access from unmanaged devices must be limited to browser-only access to web apps and must block native client apps. Which conditional access grant control should you configure?

Your organization is using Microsoft Defender for Cloud to assess the security posture of Azure resources. You need to ensure that the highest severity recommendations are addressed first. Which dashboard or feature in Defender for Cloud should you use to view the most critical security issues?

Which TWO actions should you take to implement a defense-in-depth strategy for an Azure application? (Choose two.)

Which THREE components are part of the Microsoft Zero Trust architecture? (Choose three.)

Your enterprise uses Microsoft Defender for Cloud to secure a hybrid cloud environment spanning Azure and AWS. You need to design a solution that prioritizes remediation of the most critical vulnerabilities across both clouds based on Common Vulnerability Scoring System (CVSS) scores, exploitability, and business impact. Which Defender for Cloud feature should you use?

Your company is deploying Microsoft Defender XDR and wants to use automated investigation and response (AIR) to remediate confirmed threats. However, you need to ensure that high-impact actions like deleting email messages or isolating devices require manual approval from the security operations team. Which configuration should you set?

Your organization uses Microsoft Intune to manage mobile devices. You need to design a policy that ensures corporate data on personally owned devices is protected, but does not allow IT to wipe the entire device if it is lost or stolen. Which Intune policy type should you configure?

Your company is implementing Microsoft Copilot for Security to assist the security operations team. You need to ensure that prompts and responses from Copilot do not expose sensitive internal information to unauthorized users. Which configuration should you apply?

Your organization is designing a security strategy for Microsoft 365 Copilot. You need to ensure that Copilot does not generate responses based on sensitive data that users are not authorized to access. Which TWO configurations should you implement?

Your organization uses Microsoft Defender for Cloud to protect a multi-cloud environment (Azure, AWS, GCP). You need to ensure that security configurations are assessed against industry benchmarks like CIS and PCI DSS. Which THREE actions should you take?

Your company is using Microsoft Entra ID and wants to implement passwordless authentication to improve security. Which THREE authentication methods should you consider?

Refer to the exhibit. You are evaluating an Azure Policy definition that checks whether a web app redirects HTTP to HTTPS. The policy uses 'auditIfNotExists' effect. After assigning this policy to a subscription, you notice that a web app that does not redirect HTTP to HTTPS is marked as 'Healthy'. What is the most likely cause?

Exhibit

{
  "policy": {
    "if": {
      "field": "Microsoft.Security/customAssessment.name",
      "equals": "Ensure web app redirects HTTP to HTTPS"
    },
    "then": {
      "effect": "auditIfNotExists",
      "details": {
        "type": "Microsoft.Security/assessments",
        "name": "web-app-http-redirect",
        "existenceCondition": {
          "field": "Microsoft.Security/assessments/status.code",
          "equals": "Healthy"
        }
      }
    }
  }
}

Your organization uses Microsoft Defender for Cloud Apps. You need to detect anomalous behavior such as impossible travel. What should you configure?

Question 14hardmultiple choice
Read the full Ansible explanation →

A company uses Microsoft Sentinel and wants to implement a security orchestration, automation, and response (SOAR) solution. They need a playbook that automatically blocks a user in Microsoft Entra ID when a high-severity incident is created. What should they use?

Your organization is adopting a Zero Trust network strategy. Which Microsoft solution should you use to implement micro-segmentation and enforce identity-based access controls for on-premises and cloud resources?

Which TWO Microsoft Purview solutions are used to discover and protect sensitive data across Microsoft 365, Azure, and on-premises environments?

A company uses Microsoft Sentinel with a workspace in the East US region. They want to ingest logs from Azure resources in West Europe. To minimize data transfer costs, what should they do?

Which TWO actions are part of the Microsoft Cybersecurity Reference Architecture (MCRA) for a Zero Trust implementation?

Which TWO are best practices for securing Microsoft Entra ID?

A manufacturing company wants to secure its IoT devices that run on Azure IoT Hub. They need to ensure that only authorized devices can connect and that firmware updates are signed. Which combination of Azure services should they use?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Design solutions that align with security best practices and priorities sessions

Start a Design solutions that align with security best practices and priorities only practice session

Every question in these sessions is drawn from the Design solutions that align with security best practices and priorities domain — nothing else.

Related practice questions

Related SC-100 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SC-100 exam test about Design solutions that align with security best practices and priorities?
A candidate must map business requirements to the correct Microsoft security control and justify it with Zero Trust and least privilege. The single most important thing: pick the service that enforces the control automatically, not one that only reports or recommends it.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Design solutions that align with security best practices and priorities questions in a focused session?
Yes — the session launcher on this page draws every question from the Design solutions that align with security best practices and priorities domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SC-100 topics?
Use the topic links above to move to related areas, or go back to the SC-100 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SC-100 exam covers. They are not copied from any real exam or dump site.