SC-100 Practice Question: Design solutions that align with security best practices and priorities
You are a security architect for a large multinational organization that uses Microsoft 365, Azure, and third-party SaaS applications. The organization has recently experienced a breach where an attacker compromised a user account via a phishing email and then used that account to access sensitive data in SharePoint Online and exfiltrate it via email. The security team wants to implement a comprehensive solution that aligns with the Zero Trust principles of 'verify explicitly', 'use least privilege', and 'assume breach'. You need to design a solution that includes identity protection, conditional access, data protection, and continuous monitoring. You have the following requirements: 1. Block phishing attacks in real time. 2. Enforce least privilege access to sensitive data. 3. Detect and respond to anomalous user behavior. 4. Protect data at rest and in transit. 5. Enable automated response to incidents. Which combination of Microsoft security services and configurations should you recommend?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement Microsoft Defender for Office 365 to block phishing emails. Use Conditional Access policies with session risk to enforce access controls. Deploy Microsoft Purview DLP and sensitivity labels to protect data. Use Microsoft Sentinel with automation rules and playbooks to detect and respond to incidents.
It directly maps to all five requirements: Defender for Office 365 provides real-time anti-phishing protection, Conditional Access with session risk enforces least-privilege and adaptive access, Microsoft Purview DLP and sensitivity labels protect data at rest and in transit, and Microsoft Sentinel with automation rules and playbooks delivers continuous monitoring plus automated incident response. This combination also aligns with Zero Trust by verifying explicitly through risk-based Conditional Access, applying least privilege via DLP and labels, and assuming breach through Sentinel detection and automated response. Option A lacks identity risk detection and phishing blocking, and Azure Sentinel alone does not provide the required automated response without playbooks. Option B omits phishing protection and automated response, and Azure Monitor is not a SIEM/SOAR platform for incident automation. Option D focuses on on-premises identity threats, which does not address the cloud-based phishing and SaaS exfiltration scenario, and Azure Security Center is not the right tool for Microsoft 365 data protection and automated response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement Microsoft Defender for Cloud Apps to discover and control SaaS apps. Use Conditional Access with app control. Deploy Microsoft Purview Data Lifecycle Management. Use Azure Sentinel for monitoring.
Why it's wrong here
Microsoft Defender for Cloud Apps and Conditional Access app control are valuable for SaaS shadow IT discovery and session policies, but they do not block email-based phishing attacks. Purview Data Lifecycle Management only manages retention and deletion, not classification-based protection like sensitivity labels. While Sentinel is included, it is used only for monitoring without automation rules or playbooks, and the solution omits Entra ID Protection to detect identity-based risks, leaving phishing and automated response gaps.
- ✗
Implement Microsoft Entra ID Protection to detect and block risky sign-ins. Use Conditional Access policies to require MFA and block legacy authentication. Use Microsoft Purview sensitivity labels to classify data and Azure Monitor to collect logs.
Why it's wrong here
This option strengthens authentication with Entra ID Protection and Conditional Access (MFA, blocking legacy auth), but it completely overlooks email phishing protection provided by Defender for Office 365. Sensitivity labels alone cannot enforce data loss prevention without Purview DLP. Azure Monitor is a log-collection service, not a SIEM, so it lacks Sentinel's detection and automated response capabilities. Consequently, phishing and incident-response automation requirements remain unmet.
- ✓
Implement Microsoft Defender for Office 365 to block phishing emails. Use Conditional Access policies with session risk to enforce access controls. Deploy Microsoft Purview DLP and sensitivity labels to protect data. Use Microsoft Sentinel with automation rules and playbooks to detect and respond to incidents.
Why this is correct
Defender for Office 365 blocks phishing emails at the mail gateway using threat intelligence and safe attachments/links. Conditional Access with session risk enforces least-privilege access based on real-time risk, while Purview DLP and sensitivity labels protect data across workloads. Sentinel integrates these signals and uses automation rules and playbooks for rapid, automated incident response, fulfilling all stated requirements. This layered approach covers email security, identity, data protection, and security operations.
- ✗
Implement Microsoft Defender for Identity to detect on-premises threats. Use Conditional Access with device compliance policies. Deploy Microsoft Purview Information Protection. Use Azure Security Center for monitoring.
Why it's wrong here
Defender for Identity focuses on detecting on-premises AD attacks, not email-borne phishing, and device compliance policies do not address session-level risk. Purview Information Protection is a legacy name; the current solution uses sensitivity labels and DLP, which this option lacks. Azure Security Center (now Defender for Cloud) is a CSPM tool, not a SIEM, and there is no automated response orchestration, leaving phishing and incident-response requirements unfulfilled.
Go deeper
Related to this question
Learn chapter
Securing Azure IaaS and Containerized Workloads
Key term
Microsoft 365 Security Design
Microsoft 365 Security Design is the process of planning and configuring built-in security features in Microsoft 365 to protect data, identities, and devices from cyber threats.
Key term
SOC Architecture
SOC Architecture is the structured design of people, processes, and technology in a Security Operations Center to detect, analyze, and respond to cyber threats.
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.