Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Your company uses Microsoft Azure to host a critical application that processes credit card payments. The application must comply with PCI DSS. You need to ensure that all access to cardholder data is logged and monitored, and that any unauthorized access attempts trigger an alert. Which combination of services should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Monitor and Microsoft Sentinel

Azure Monitor and Microsoft Sentinel (option D) are the right combination because Azure Monitor collects and retains the logs and metrics from the application and its Azure resources, while Microsoft Sentinel ingests those logs to correlate events, detect unauthorized access attempts to cardholder data, and generate alerts via analytics rules and incident creation, satisfying PCI DSS logging and monitoring requirements. Azure Monitor provides the telemetry pipeline (Log Analytics workspace, diagnostic settings) and Sentinel adds SIEM/SOAR detection and alerting on top of it. Option A is wrong because Azure Policy enforces configuration compliance and Defender for Cloud Apps is a CASB for SaaS discovery/control, not a log-monitoring and alerting SIEM. Option B is wrong because Azure Policy and Defender for Cloud provide posture management and threat protection but do not deliver the centralized log correlation and custom alerting on access to cardholder data that Sentinel does. Option C is wrong because Azure Key Vault only manages secrets, keys, and certificates, and Defender for Cloud alone does not provide the required log aggregation and alerting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Policy and Microsoft Defender for Cloud Apps

    Why it's wrong here

    Azure Policy is a governance service that enforces resource compliance rules, but it captures neither user access logs nor runtime telemetry—it only evaluates configuration state. Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) focused on shadow IT discovery and conditional access for SaaS applications like Microsoft 365, not Azure infrastructure workloads. Together these tools address compliance and SaaS app risk, but they cannot provide the centralized logging or suspicious activity alerting needed for a critical Azure-hosted application's detection capability.

  • ✗

    Azure Policy and Microsoft Defender for Cloud

    Why it's wrong here

    Azure Policy enforces organizational standards on resource configurations (e.g., requiring TLS or tagging), but it does not log individual access events to an application or its data plane. Microsoft Defender for Cloud provides security posture management, vulnerability assessments, and recommendation-based hardening, alongside some workload protections, but its alerts target misconfigurations and known attack paths rather than acting as a SIEM that aggregates and analyzes all logs. This combination is strong for proactive hardening but lacks the detective telemetry pipeline and real-time alerting against suspicious user behavior that a critical application requires.

  • ✗

    Azure Key Vault and Microsoft Defender for Cloud

    Why it's wrong here

    Azure Key Vault is a secret and key management service—it securely stores certificates, secrets, and cryptographic keys, but it does not log application-level user access or broad infrastructure telemetry; its own diagnostics are limited to secret operations. Microsoft Defender for Cloud, as noted, offers recommendations and security posture insights but does not ingest or centralize application logs, nor does it provide SIEM-style alerting on anomalous sign-in or data-access patterns. Relying on these would leave you with secret protection and hardening advice, but no effective logging/alerting mechanism for detecting and responding to threats against the application.

  • ✓

    Azure Monitor and Microsoft Sentinel

    Why this is correct

    Azure Monitor collects diagnostic logs, metrics, and activity data from Azure resources—such as App Service or virtual machines—into a Log Analytics workspace, forming the foundational telemetry pipeline for the critical application. Microsoft Sentinel then ingests those logs, uses built-in analytics rules and threat-intelligence correlation to detect suspicious behavior, and provides incident management and automated response (SOAR). This pairing directly satisfies the requirement to both log access/activity and alert on potential threats, making it the correct combination for detective security monitoring.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.