Courseiva

SC-100 · topic practice

Design security solutions for infrastructure practice questions

This domain covers designing Azure infrastructure security: Microsoft Sentinel SIEM/SOAR ingestion and automation, Microsoft Defender for Cloud posture and workload protection, network segmentation with Azure Firewall and NSGs, and identity/privilege controls for hybrid workloads. Questions present a business scenario and ask you to choose the architecture, connector, or control that meets the stated requirement with least effort.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Design security solutions for infrastructure

What the exam tests

What to know about Design security solutions for infrastructure

Be able to map a scenario to the right Sentinel connector, automation rule or playbook, Defender for Cloud plan, and network control. The single most important thing: pick the native, least-effort integration that satisfies the stated requirement rather than a custom build.

Selecting Microsoft Sentinel data connectors, including Azure Activity and Windows Security Events via AMA

Designing automation rules and playbooks for incident triage and remediation in Microsoft Sentinel

Configuring Microsoft Defender for Cloud plans, secure score, and regulatory compliance dashboards

Applying Azure Firewall, NSG, and private endpoint designs for network segmentation

Watch out for

Common Design security solutions for infrastructure exam traps

  • ▸Choosing a custom log pipeline or diagnostic setting when the native Azure Activity connector already ingests subscription logs with less effort.
  • ▸Confusing automation rules with playbooks: rules handle triage and assignment, playbooks run the Logic Apps remediation logic.
  • ▸Assuming Defender for Cloud alone detects on-premises brute-force activity instead of connecting the Windows Security Events data source to Sentinel.

Practice set

Design security solutions for infrastructure questions

20 questions · select your answer, then reveal the explanation

You are designing a secure DevOps pipeline using GitHub Advanced Security and Microsoft Defender for Cloud. The development team uses a mix of Python and JavaScript. Which tool should you integrate to detect secrets (e.g., API keys) committed to the repository?

Refer to the exhibit. You are deploying an ARM template for a network security group. What is the security implication of this configuration?

Exhibit

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {},
  "resources": [
    {
      "type": "Microsoft.Network/networkSecurityGroups",
      "apiVersion": "2020-06-01",
      "name": "nsg-frontend",
      "properties": {
        "securityRules": [
          {
            "name": "AllowHTTPS",
            "properties": {
              "protocol": "Tcp",
              "sourcePortRange": "*",
              "destinationPortRange": "443",
              "sourceAddressPrefix": "Internet",
              "destinationAddressPrefix": "10.0.1.0/24",
              "access": "Allow",
              "priority": 100,
              "direction": "Inbound"
            }
          }
        ]
      }
    }
  ]
}

You need to design a solution to protect Azure VMs from malware and vulnerabilities. Which Microsoft service should you use?

Your organization uses Microsoft Sentinel for security operations. You need to design a solution to automatically respond to a confirmed compromise of a domain controller by isolating the affected VM. Which automation feature should you use?

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You need to design a solution that automatically creates an incident in Sentinel when a Defender XDR alert fires. Which integration should you configure?

Your organization uses Microsoft Purview to classify data assets. You need to design a solution that automatically scans data sources in Azure SQL Database for sensitive information. Which Purview scanner should you configure?

Which TWO actions should you take to secure an Azure Kubernetes Service (AKS) cluster using Microsoft Defender for Cloud?

Which THREE components are required to implement a Zero Trust network architecture using Microsoft Entra Internet Access (formerly Microsoft 365 Network Connectivity)?

Your organization is deploying Azure Kubernetes Service (AKS) and plans to use Azure Policy to enforce security controls on the cluster. The security team wants to automatically audit and deny the creation of privileged containers. Which Azure Policy initiative should you assign?

You are designing a security solution for a critical Azure SQL Database that must be protected against data exfiltration by a compromised admin account. The solution must ensure that even a database administrator cannot copy data to an external storage account. Which Azure service should you configure?

Your organization is planning to use Microsoft Sentinel for security information and event management (SIEM). The security team wants to ensure that Sentinel can ingest logs from on-premises servers that are not connected to the internet. The solution must use Azure Arc for management. Which data connector should you use?

Which THREE components are required to implement a Microsoft Sentinel solution that collects security logs from a multi-cloud environment including AWS and Azure? (Choose three.)

Which TWO of the following are valid methods to enforce multifactor authentication (MFA) for users accessing Microsoft 365 services? (Choose two.)

A company is planning to deploy a multi-tier application in Azure. The web tier must be accessible from the internet, while the database tier must be accessible only from the web tier and management jump boxes. The solution should minimize exposure to the internet. Which Azure architecture should you recommend?

Your company uses Microsoft Sentinel as its SIEM. You need to design a solution to detect lateral movement attempts within the corporate network using Windows Event Logs collected from domain controllers and workstations. Which data source and analytic rule type should you use?

You need to secure Azure Kubernetes Service (AKS) clusters by ensuring that only approved container images from a private Azure Container Registry (ACR) can be deployed. The solution should enforce this at admission time. Which Azure Policy effect should you use?

You are designing a secure access strategy for Azure SQL Database. The solution must use Microsoft Entra authentication and ensure that only specific client IP addresses can connect. Additionally, all connections must be encrypted in transit. Which THREE components should you configure?

Your company uses Microsoft Defender for Endpoint and Microsoft Intune to manage endpoints. You need to ensure that devices are healthy before they can access corporate resources. Which TWO settings should you configure in Microsoft Intune compliance policies to enforce device health?

Refer to the exhibit. You are reviewing a PowerShell script that configures network security. What is the effect of the NSG rule created in this script?

Exhibit

Refer to the exhibit.

$rg = 'rg-network'
$vnet = 'vnet-prod'
$subnet = 'snet-app'
$nic = 'nic-app1'
$nsg = 'nsg-app'

# Create NSG
$nsgParams = @{
    ResourceGroupName = $rg
    Name = $nsg
    Location = 'eastus'
}
$nsgObj = New-AzNetworkSecurityGroup @nsgParams

# Add rule to deny inbound from internet
$ruleParams = @{
    Name = 'DenyInternetInbound'
    Access = 'Deny'
    Priority = 100
    Direction = 'Inbound'
    Protocol = '*' 
    SourceAddressPrefix = 'Internet'
    SourcePortRange = '*'
    DestinationAddressPrefix = '*' 
    DestinationPortRange = '*'
    NetworkSecurityGroup = $nsgObj
}
Add-AzNetworkSecurityRuleConfig @ruleParams | Set-AzNetworkSecurityGroup

# Associate NSG with subnet
$vnetObj = Get-AzVirtualNetwork -ResourceGroupName $rg -Name $vnet
$subnetObj = $vnetObj.Subnets | Where-Object {$_.Name -eq $subnet}
$subnetObj.NetworkSecurityGroup = $nsgObj
Set-AzVirtualNetwork -VirtualNetwork $vnetObj
Question 20hardmultiple choice
Read the full VPN explanation →

Refer to the exhibit. You are reviewing an ARM template for an Azure App Service configuration. What is the effect of the ipSecurityRestrictions array?

Exhibit

Refer to the exhibit.

{
  "type": "Microsoft.Web/sites/config",
  "apiVersion": "2022-03-01",
  "name": "webapp-config",
  "properties": {
    "ftpsState": "FtpsOnly",
    "minTlsVersion": "1.2",
    "http20Enabled": true,
    "siteAuthSettings": {
      "enabled": true,
      "defaultProvider": "AzureActiveDirectory",
      "clientId": "12345-abcde-..."
    },
    "ipSecurityRestrictions": [
      {
        "ipAddress": "192.168.0.0/24",
        "action": "Allow",
        "priority": 100,
        "name": "AllowCorporateNetwork",
        "description": "Allow corporate IP range"
      },
      {
        "ipAddress": "Any",
        "action": "Deny",
        "priority": 200,
        "name": "DenyAll",
        "description": "Deny all other traffic"
      }
    ]
  }
}

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Design security solutions for infrastructure sessions

Start a Design security solutions for infrastructure only practice session

Every question in these sessions is drawn from the Design security solutions for infrastructure domain — nothing else.

Related practice questions

Related SC-100 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SC-100 exam test about Design security solutions for infrastructure?
Be able to map a scenario to the right Sentinel connector, automation rule or playbook, Defender for Cloud plan, and network control. The single most important thing: pick the native, least-effort integration that satisfies the stated requirement rather than a custom build.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Design security solutions for infrastructure questions in a focused session?
Yes — the session launcher on this page draws every question from the Design security solutions for infrastructure domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SC-100 topics?
Use the topic links above to move to related areas, or go back to the SC-100 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SC-100 exam covers. They are not copied from any real exam or dump site.