Free SC-100 Exam Braindumps

Pass your Microsoft Cybersecurity Architect exam with these free Questions and Answers

Page 3 of 29
QUESTION 6

- (Exam Topic 3)
You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.
The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019.
You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application.
Which security control should you recommend?

  1. A. app discovery anomaly detection policies in Microsoft Defender for Cloud Apps
  2. B. adaptive application controls in Defender for Cloud
  3. C. Azure Security Benchmark compliance controls m Defender for Cloud
  4. D. app protection policies in Microsoft Endpoint Manager

Correct Answer: B
https://docs.microsoft.com/en-us/azure/defender-for-cloud/recommendations-reference#compute-recommendati

QUESTION 7

- (Exam Topic 3)
You have an Azure subscription that has Microsoft Defender for Cloud enabled. You have an Amazon Web Services (AWS) implementation.
You plan to extend the Azure security strategy to the AWS implementation. The solution will NOT use Azure Arc. Which three services can you use to provide security for the AWS resources? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

  1. A. Azure Active Directory (Azure AD) Privileged Identity Management (PIM)
  2. B. Azure Active Directory (Azure AD) Conditional Access
  3. C. Microsoft Defender for servers
  4. D. Azure Policy
  5. E. Microsoft Defender for Containers

Correct Answer: BDE
https://docs.microsoft.com/en-us/azure/defender-for-cloud/supported-machines-endpoint-solutions-clouds-conta

QUESTION 8

- (Exam Topic 3)
You have a customer that has a Microsoft 365 subscription and uses the Free edition of Azure Active Directory (Azure AD)
The customer plans to obtain an Azure subscription and provision several Azure resources. You need to evaluate the customer's security environment.
What will necessitate an upgrade from the Azure AD Free edition to the Premium edition?

  1. A. role-based authorization
  2. B. Azure AD Privileged Identity Management (PIM)
  3. C. resource-based authorization
  4. D. Azure AD Multi-Factor Authentication

Correct Answer: B
(https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure) https://www.microsoft.com/en-us/security/business/identity-access/azure-active-directory-pricing?rtc=1

QUESTION 9

- (Exam Topic 3)
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription that has Microsoft Defender for Cloud enabled. You are evaluating the Azure Security Benchmark V3 report.
In the Secure management ports controls, you discover that you have 0 out of a potential 8 points.
You need to recommend configurations to increase the score of the Secure management ports controls. Solution: You recommend enabling the VMAccess extension on all virtual machines.
Does this meet the goal?

  1. A. Yes
  2. B. No

Correct Answer: B
https://docs.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-privileged-access#pa-2-avoid-s Adaptive Network Hardening:
https://docs.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-network-security#ns-7-simplify

QUESTION 10

- (Exam Topic 2)
To meet the application security requirements, which two authentication methods must the applications support? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

  1. A. Security Assertion Markup Language (SAML)
  2. B. NTLMv2
  3. C. certificate-based authentication
  4. D. Kerberos

Correct Answer: AD
https://docs.microsoft.com/en-us/azure/active-directory/app-proxy/application-proxy-configure-single-sign-on-o https://docs.microsoft.com/en-us/azure/active-directory/app-proxy/application-proxy-configure-single-sign-on-w https://docs.microsoft.com/en-us/azure/active-directory/app-proxy/application-proxy-configure-custom-domain

Page 3 of 29

Post your Comments and Discuss Microsoft SC-100 exam with other Community members: