10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.
The SC-100 exam has 60 questions and runs 2 hours.
These 10 free SC-100 questions are organized by exam domain, so you can see how each part of the Microsoft Cybersecurity Architect (SC-100) blueprint is tested. Reveal the answer and explanation under each question.
Domain 1: Design solutions that align with security best practices and priorities (20-25%)
Question 1
A financial services firm allows engineers to access a production database server only after an approval workflow completes, for a maximum of four hours, and only for the single server they are troubleshooting. Which Zero Trust guiding principle does this design MOST directly implement?
Show answer & explanation
Correct answer: A - Use least privilege access
Question 2
An architect is asked to review one customer-facing payment application and advise on the trade-offs between its reliability, cost, operational, and security design decisions. The review is explicitly not concerned with the organization's landing zones, subscription structure, or overall governance model. Which Microsoft framework is intended for this scope?
Show answer & explanation
Correct answer: B - Azure Well-Architected Framework
Question 3
Contoso is building a ransomware resiliency program based on Microsoft's recommended guidance. Four workstreams have been proposed and must be sequenced. Which workstream should be prioritized FIRST?
Show answer & explanation
Correct answer: D - Ensure backups cannot be deleted or encrypted by an attacker holding administrative credentials
Domain 2: Design security operations, identity, and compliance capabilities (25-30%)
Question 4
A security operations team must ingest logs from an on-premises third-party firewall and from AWS CloudTrail, correlate them with Microsoft Entra ID sign-in activity, and retain the combined data set for seven years to satisfy an external audit obligation. Which solution should you recommend?
Show answer & explanation
Correct answer: D - Microsoft Sentinel
Question 5
An organization requires that sign-ins scored as high risk be blocked automatically. An architect must document which service produces the risk score and which service enforces the block. Which statement is correct?
Show answer & explanation
Correct answer: C - Microsoft Entra ID Protection produces the risk score, and a Conditional Access policy enforces the block
Question 6
Project managers must be able to request a bundle containing one security group, three SaaS applications, and a SharePoint site in a single request. The request must be approved by the project sponsor, and all access in the bundle must be removed automatically after 90 days. Which Microsoft Entra capability should you recommend?
Show answer & explanation
Correct answer: B - Entitlement management
Domain 3: Design security solutions for infrastructure (25-30%)
Question 7
A company operates 400 physical servers in its own datacenter and 150 virtual machines in AWS, in addition to its Azure workloads. Security leadership requires that Microsoft Defender for Cloud recommendations and Azure Policy guest configuration apply consistently to every one of these servers. What should you include in the recommendation?
Show answer & explanation
Correct answer: C - Onboard the servers and virtual machines to Azure Arc
Question 8
A manufacturer must inventory the programmable logic controllers and human-machine interfaces on its plant network and detect threats against them. The operations team will not permit software agents on these devices, nor any active scanning of the plant network. What should you include in the recommendation?
Show answer & explanation
Correct answer: C - Microsoft Defender for IoT network sensors using traffic mirroring
Domain 4: Design security solutions for applications and data (20-25%)
Question 9
A regulator requires that a column of national identity numbers in an Azure SQL Database remain unreadable to database administrators, including accounts that hold full server-level permissions. Which capability should you recommend?
Show answer & explanation
Correct answer: A - Always Encrypted, with the column master key stored in Azure Key Vault
Question 10
Before deploying Microsoft 365 Copilot, a governance team is concerned that employees will be able to summarize documents they were never intended to open. Which action MOST reduces this risk?
Show answer & explanation
Correct answer: D - Remediate existing oversharing in SharePoint and OneDrive before rollout
That's 10 of 1,030
The full bank has 1,020 more SC-100 questions with explanations.