Microsoft Cybersecurity Architect (SC-100) Exam Prep
Free practice questions

Free SC-100 Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The SC-100 exam has 60 questions and runs 2 hours.

These 10 free SC-100 questions are organized by exam domain, so you can see how each part of the Microsoft Cybersecurity Architect (SC-100) blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Design solutions that align with security best practices and priorities (20-25%)

Question 1

A financial services firm allows engineers to access a production database server only after an approval workflow completes, for a maximum of four hours, and only for the single server they are troubleshooting. Which Zero Trust guiding principle does this design MOST directly implement?

Show answer & explanation

Correct answer: A - Use least privilege access

Question 2

An architect is asked to review one customer-facing payment application and advise on the trade-offs between its reliability, cost, operational, and security design decisions. The review is explicitly not concerned with the organization's landing zones, subscription structure, or overall governance model. Which Microsoft framework is intended for this scope?

Show answer & explanation

Correct answer: B - Azure Well-Architected Framework

Question 3

Contoso is building a ransomware resiliency program based on Microsoft's recommended guidance. Four workstreams have been proposed and must be sequenced. Which workstream should be prioritized FIRST?

Show answer & explanation

Correct answer: D - Ensure backups cannot be deleted or encrypted by an attacker holding administrative credentials

Domain 2: Design security operations, identity, and compliance capabilities (25-30%)

Question 4

A security operations team must ingest logs from an on-premises third-party firewall and from AWS CloudTrail, correlate them with Microsoft Entra ID sign-in activity, and retain the combined data set for seven years to satisfy an external audit obligation. Which solution should you recommend?

Show answer & explanation

Correct answer: D - Microsoft Sentinel

Question 5

An organization requires that sign-ins scored as high risk be blocked automatically. An architect must document which service produces the risk score and which service enforces the block. Which statement is correct?

Show answer & explanation

Correct answer: C - Microsoft Entra ID Protection produces the risk score, and a Conditional Access policy enforces the block

Question 6

Project managers must be able to request a bundle containing one security group, three SaaS applications, and a SharePoint site in a single request. The request must be approved by the project sponsor, and all access in the bundle must be removed automatically after 90 days. Which Microsoft Entra capability should you recommend?

Show answer & explanation

Correct answer: B - Entitlement management

Domain 3: Design security solutions for infrastructure (25-30%)

Question 7

A company operates 400 physical servers in its own datacenter and 150 virtual machines in AWS, in addition to its Azure workloads. Security leadership requires that Microsoft Defender for Cloud recommendations and Azure Policy guest configuration apply consistently to every one of these servers. What should you include in the recommendation?

Show answer & explanation

Correct answer: C - Onboard the servers and virtual machines to Azure Arc

Question 8

A manufacturer must inventory the programmable logic controllers and human-machine interfaces on its plant network and detect threats against them. The operations team will not permit software agents on these devices, nor any active scanning of the plant network. What should you include in the recommendation?

Show answer & explanation

Correct answer: C - Microsoft Defender for IoT network sensors using traffic mirroring

Domain 4: Design security solutions for applications and data (20-25%)

Question 9

A regulator requires that a column of national identity numbers in an Azure SQL Database remain unreadable to database administrators, including accounts that hold full server-level permissions. Which capability should you recommend?

Show answer & explanation

Correct answer: A - Always Encrypted, with the column master key stored in Azure Key Vault

Question 10

Before deploying Microsoft 365 Copilot, a governance team is concerned that employees will be able to summarize documents they were never intended to open. Which action MOST reduces this risk?

Show answer & explanation

Correct answer: D - Remediate existing oversharing in SharePoint and OneDrive before rollout

That's 10 of 1,030

The full bank has 1,020 more SC-100 questions with explanations.

Continue in the free practice test →

View plans