Free Microsoft SC-100 Practice Test Questions MCQs
Stop wondering if you're ready. Our Microsoft SC-100 practice test is designed to identify your exact knowledge gaps. Validate your skills with Microsoft Cybersecurity Architect questions that mirror the real exam's format and difficulty. Build a personalized study plan based on your free SC-100 exam questions mcqs performance, focusing your effort where it matters most.
Targeted practice like this helps candidates feel significantly more prepared for Microsoft Cybersecurity Architect exam day.
21710+ already prepared
Updated On : 25-May-2026171 Questions
Microsoft Cybersecurity Architect
4.9/5.0
Topic 1: Fabrikam, Inc Case Study 1
OverView
Fabrikam, Inc. is an insurance company that has a main office in New York and a branch
office in Paris.
On-premises Environment
The on-premises network contains a single Active Directory Domain Services (AD DS)
domain named corp.fabrikam.com.
Azure Environment
Fabrikam has the following Azure resources:
• An Azure Active Directory (Azure AD) tenant named fabrikam.onmicrosoft.com that syncs
with corp.fabnkam.com
• A single Azure subscription named Sub1
• A virtual network named Vnet1 in the East US Azure region
• A virtual network named Vnet2 in the West Europe Azure region
• An instance of Azure Front Door named FD1 that has Azure Web Application Firewall
(WAR enabled)
• A Microsoft Sentinel workspace
• An Azure SQL database named ClaimsDB that contains a table named ClaimDetails
• 20 virtual machines that are configured as application servers and are NOT onboarded to
Microsoft Defender for Cloud
• A resource group named TestRG that is used for testing purposes only
• An Azure Virtual Desktop host pool that contains personal assigned session hosts
All the resources in Sub1 are in either the East US or the West Europe region.
Partners
Fabrikam has contracted a company named Contoso, Ltd. to develop applications.
Contoso has the following infrastructure-.
• An Azure AD tenant named contoso.onmicrosoft.com
• An Amazon Web Services (AWS) implementation named ContosoAWS1 that contains
AWS EC2 instances used to host test workloads for the applications of Fabrikam
Developers at Contoso will connect to the resources of Fabrikam to test or update
applications. The developers will be added to a security Group named Contoso Developers
in fabrikam.onmicrosoft.com that will be assigned to roles in Sub1.
The ContosoDevelopers group is assigned the db.owner role for the ClaimsDB database.
Compliance Event
Fabrikam deploys the following compliance environment:
• Defender for Cloud is configured to assess all the resources in Sub1 for compliance to the
HIPAA HITRUST standard.
• Currently, resources that are noncompliant with the HIPAA HITRUST standard are
remediated manually.
• Qualys is used as the standard vulnerability assessment tool for servers.
Problem Statements
The secure score in Defender for Cloud shows that all the virtual machines generate the
following recommendation-. Machines should have a vulnerability assessment solution.
All the virtual machines must be compliant in Defender for Cloud.
ClaimApp Deployment
Fabrikam plans to implement an internet-accessible application named ClaimsApp that will
have the following specification
• ClaimsApp will be deployed to Azure App Service instances that connect to Vnetl and
Vnet2.
• Users will connect to ClaimsApp by using a URL of https://claims.fabrikam.com.
• ClaimsApp will access data in ClaimsDB.
• ClaimsDB must be accessible only from Azure virtual networks.
• The app services permission for ClaimsApp must be assigned to ClaimsDB.
Application Development Requirements
Fabrikam identifies the following requirements for application development:
• Azure DevTest labs will be used by developers for testing.
• All the application code must be stored in GitHub Enterprise.
• Azure Pipelines will be used to manage application deployments.
• All application code changes must be scanned for security vulnerabilities, including
application code or configuration files that contain secrets in clear text. Scanning must be
done at the time the code is pushed to a repository.
Security Requirement
Fabrikam identifies the following security requirements:
• Internet-accessible applications must prevent connections that originate in North Korea.
• Only members of a group named InfraSec must be allowed to configure network security
groups (NSGs} and instances of Azure Firewall, VJM. And Front Door in Sub1.
• Administrators must connect to a secure host to perform any remote administration of the
virtual machines. The secure host must be provisioned from a custom operating system
image.
AWS Requirements
Fabrikam identifies the following security requirements for the data hosted in
ContosoAWSV.
• Notify security administrators at Fabrikam if any AWS EC2 instances are noncompliant
with secure score recommendations.
• Ensure that the security administrators can query AWS service logs directly from the
Azure environment.
Contoso Developer Requirements
Fabrikam identifies the following requirements for the Contoso developers;
• Every month, the membership of the ContosoDevelopers group must be verified.
• The Contoso developers must use their existing contoso.onmicrosoft.com credentials to
access the resources in Sub1.
• The Comoro developers must be prevented from viewing the data in a column named
MedicalHistory in the ClaimDetails table.
Compliance Requirement
Fabrikam wants to automatically remediate the virtual machines in Sub1 to be compliant
with the HIPPA HITRUST standard. The virtual machines in TestRG must be excluded
from the compliance assessment.
| Page 1 out of 18 Pages |
Microsoft Cybersecurity Architect Practice Exam Questions
These SC-100 practice questions with explanations help candidates prepare for cybersecurity architect roles. Topics include zero trust strategy, security architecture design, risk management, and compliance. Each explanation provides insight into decision-making and best practices, helping learners understand complex security frameworks. This approach enhances strategic thinking and practical knowledge. By practicing these questions, candidates can improve their ability to design secure solutions and confidently handle architect-level challenges in the certification exam.SC-100 - Microsoft Cybersecurity Architect Official Exam Blueprint and Weight:
1. Design Solutions That Align with Security Best Practices and Priorities
Official Exam Weight: 20-25%
Subtopics: Design security strategy to support business
resiliency goals including identifying and prioritizing threats to
business-critical assets, design solutions for business continuity and
disaster recovery (BCDR) including secure backup and restore for hybrid
and multicloud environments, design solutions for mitigating ransomware
attacks including prioritization of BCDR and privileged access, evaluate
solutions for security updates, design solutions that align with best
practices for cybersecurity capabilities and controls, design solutions
that align with best practices for protecting against insider external
and supply chain attacks, design solutions that align with best
practices for Zero Trust security including A Rapid modernization plan
for Zero Trust (RaMP), design new or evaluate existing strategy for
security and governance based on Microsoft Cloud Adoption Framework for
Azure (CAF) and Azure Well-Architected Framework (WAF), recommend
solutions for security and governance based on Microsoft Cloud Adoption
Framework for Azure (CAF) and Microsoft Azure Well-Architected
Framework, design solutions for implementing and governing security
using Azure landing zones, design DevSecOps process that aligns with
best practices in Microsoft Cloud Adoption Framework for Azure (CAF).
2. Design Security Operations, Identity, and Compliance Capabilities
Official Exam Weight: 25-30%
Subtopics: Design solution for detection and response
that includes extended detection and response (XDR) and security
information and event management (SIEM), design solution for centralized
logging and auditing including Microsoft Purview Audit, design
monitoring to support hybrid and multicloud environments, design
solution for security orchestration and automated response (SOAR)
including Microsoft Sentinel and Microsoft Defender XDR, design and
evaluate security workflows including incident response threat hunting
and incident management, design and evaluate threat detection coverage
using MITRE ATT&CK matrices including Enterprise Mobile and
industrial control systems (ICS), design solution for access to software
as service (SaaS) platform as service (PaaS) infrastructure as service
(IaaS) hybrid/on-premises and multicloud resources including identity
networking and application controls, design solution for Microsoft Entra
ID including hybrid and multi-cloud environments, design solution for
external identities including business-to-business (B2B) and
decentralized identity, design modern authentication and authorization
strategy including Conditional Access continuous access evaluation risk
scoring and protected actions, validate alignment of Conditional Access
policies with Zero Trust strategy, specify requirements to harden Active
Directory Domain Services (AD DS), design solution to manage secrets
keys and certificates, design solution for assigning and delegating
privileged roles using enterprise access model, evaluate security and
governance of Microsoft Entra ID including Microsoft Entra Privileged
Identity Management (PIM) entitlement management and access reviews,
evaluate security and governance of Active Directory Domain Services (AD
DS) including resilience to common attacks, design solution for
securing administration of cloud tenants including SaaS and multicloud
infrastructure and platforms, design solution for cloud infrastructure
entitlement management, evaluate access review management solution,
design solution for secure workstations for privileged access including
remote access, translate compliance requirements into security controls,
design solution to address compliance requirements using Microsoft
Purview, design solution to address privacy requirements including
Microsoft Priva, design Azure Policy solutions to address security and
compliance requirements, evaluate and validate alignment with regulatory
standards and benchmarks using Microsoft Defender for Cloud.
3. Design Security Solutions for Infrastructure
Official Exam Weight: 25-30%
Subtopics: Evaluate security posture using Microsoft
Defender for Cloud including Microsoft cloud security benchmark (MCSB),
evaluate security posture using Microsoft Secure Score, design
integrated security posture management solutions that include Microsoft
Defender for Cloud in hybrid and multi-cloud environments, select cloud
workload protection solutions in Microsoft Defender for Cloud, design
solution for integrating hybrid and multicloud environments using Azure
Arc, design solution for Microsoft Defender External Attack Surface
Management (Defender EASM), specify requirements and priorities for
posture management process that uses Microsoft Security Exposure
Management attack paths attack surface reduction security insights and
initiatives, specify security requirements for servers including
multiple platforms and operating systems, specify security requirements
for mobile devices and clients including endpoint protection hardening
and configuration, specify security requirements for IoT devices and
embedded systems, evaluate solutions for securing operational technology
(OT) and industrial control systems (ICS) using Microsoft Defender for
IoT, specify security baselines for server and client endpoints,
evaluate Windows Local Administrator Password Solution (Windows LAPS)
solution, specify security baselines for SaaS PaaS and IaaS services,
specify security requirements for IoT workloads, specify security
requirements for web workloads, specify security requirements for
containers, specify security requirements for container orchestration,
evaluate solutions that include Azure AI services security, evaluate
network designs to align with security requirements and best practices,
evaluate solutions that use Microsoft Entra Internet Access as secure
web gateway, evaluate solutions that use Microsoft Entra Internet Access
for Microsoft Services including cross-tenant configurations, evaluate
solutions that use Microsoft Entra Private Access.
4. Design Security Solutions for Applications and Data
Official Exam Weight: 20-25%
Subtopics: Evaluate security posture for productivity
and collaboration workloads using metrics including Microsoft Secure
Score, evaluate solutions that include Microsoft Defender for Office 365
and Microsoft Defender for Cloud Apps, evaluate device management
solutions that include Microsoft Intune, evaluate solutions for securing
data in Microsoft 365 using Microsoft Purview, evaluate data security
and compliance controls in Microsoft Copilot for Microsoft 365 services,
evaluate security posture of existing application portfolios, evaluate
threats to business-critical applications using threat modeling, design
and implement full lifecycle strategy for application security, design
and implement standards and practices for securing application
development process, map technologies to application security
requirements, design solution for workload identities to authenticate
and access Azure resources, design solution for API management and
security, design solutions that secure applications using Azure Web
Application Firewall (WAF), evaluate solutions for data discovery and
classification, specify priorities for mitigating threats to data,
evaluate solutions for encryption of data at rest and in transit
including Azure Key Vault and infrastructure encryption, design security
solution for data in Azure workloads including Azure SQL Azure Synapse
Analytics and Azure Cosmos DB, design security solution for data in
Azure Storage, design security solution that includes Microsoft Defender
for Storage and Microsoft Defender for Databases.
| Domain | Title | Exam Weight |
|---|---|---|
| 1 | Design Solutions That Align with Security Best Practices and Priorities | 20-25% |
| 2 | Design Security Operations, Identity, and Compliance Capabilities | 25-30% |
| 3 | Design Security Solutions for Infrastructure | 25-30% |
| 4 | Design Security Solutions for Applications and Data | 20-25% |
Results That Speak for Themselves
Preparing for Microsoft Certified: Cybersecurity Architect Expert became far more strategic with MSmcqs.com. The SC-100 practice exam covered zero trust, governance, and enterprise security architecture scenarios.
Hannah Cohen | Israel
