Cause all that matters here is passing the Microsoft SC-100 exam. Cause all that you need is a high score of SC-100 Microsoft Cybersecurity Architect exam. The only one thing you need to do is downloading Exambible SC-100 exam study guides now. We will not let you down with our money-back guarantee.

Online Microsoft SC-100 free dumps demo Below:

NEW QUESTION 1

Your company plans to provision blob storage by using an Azure Storage account The blob storage will be accessible from 20 application sewers on the internet. You need to recommend a solution to ensure that only the application servers can access the storage account. What should you recommend using to secure the blob storage?

  • A. service tags in network security groups (NSGs)
  • B. managed rule sets in Azure Web Application Firewall (WAF) policies
  • C. inbound rules in network security groups (NSGs)
  • D. firewall rules for the storage account
  • E. inbound rules in Azure Firewall

Answer: C

NEW QUESTION 2

You need to recommend a solution to meet the security requirements for the InfraSec group. What should you use to delegate the access?

  • A. a subscription
  • B. a custom role-based access control (RBAC) role
  • C. a resource group
  • D. a management group

Answer: D

NEW QUESTION 3

You have an Azure subscription that has Microsoft Defender for Cloud enabled. You need to enforce ISO 2700V2013 standards for the subscription. The solution must ensure that noncompliant resources are remediated automatical
What should you use?

  • A. the regulatory compliance dashboard in Defender for Cloud
  • B. Azure Policy
  • C. Azure Blueprints
  • D. Azure role-based access control (Azure RBAC)

Answer: D

NEW QUESTION 4

You have an Azure subscription that is used as an Azure landing zone for an application. You need to evaluate the security posture of all the workloads in the landing zone. What should you do first?

  • A. Add Microsoft Sentinel data connectors.
  • B. Configure Continuous Integration/Continuous Deployment (CI/CD) vulnerability scanning.
  • C. Enable the Defender plan for all resource types in Microsoft Defender for Cloud.
  • D. Obtain Azure Active Directory Premium Plan 2 licenses.

Answer: A

NEW QUESTION 5

You are designing an auditing solution for Azure landing zones that will contain the following components:
• SQL audit logs for Azure SQL databases
• Windows Security logs from Azure virtual machines
• Azure App Service audit logs from App Service web apps
You need to recommend a centralized logging solution for the landing zones. The solution must meet the following requirements:
• Log all privileged access.
• Retain logs for at least 365 days.
• Minimize costs.
What should you include in the recommendation? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
SC-100 dumps exhibit


Solution:
SC-100 dumps exhibit

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 6

Your company has a Microsoft 365 subscription and uses Microsoft Defender for Identity. You are informed about incidents that relate to compromised identities.
You need to recommend a solution to expose several accounts for attackers to exploit. When the attackers attempt to exploit the accounts, an alert must be triggered. Which Defender for Identity feature should you include in the recommendation?

  • A. standalone sensors
  • B. honeytoken entity tags
  • C. sensitivity labels
  • D. custom user tags

Answer: D

NEW QUESTION 7

You are creating the security recommendations for an Azure App Service web app named App1. App1 has the following specifications:
• Users will request access to App1 through the My Apps portal. A human resources manager will approve the requests.
• Users will authenticate by using Azure Active Directory (Azure AD) user accounts. You need to recommend an access security architecture for App1.
What should you include in the recommendation? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
SC-100 dumps exhibit


Solution:
SC-100 dumps exhibit

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 8

You have an Azure subscription that has Microsoft Defender for Cloud enabled. You are evaluating the Azure Security Benchmark V3 report.
In the Secure management ports controls, you discover that you have 0 out of a potential 8 points. You need to recommend configurations to increase the score of the Secure management ports controls. Solution: You recommend enabling adaptive network hardening. Does this meet the goal?

  • A. Yes
  • B. No

Answer: A

NEW QUESTION 9

You have a hybrid cloud infrastructure.
You plan to deploy the Azure applications shown in the following table.
SC-100 dumps exhibit
What should you use to meet the requirement of each app? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
SC-100 dumps exhibit


Solution:
SC-100 dumps exhibit

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 10

You have a Microsoft 365 E5 subscription and an Azure subscription. You are designing a Microsoft Sentinel deployment.
You need to recommend a solution for the security operations team. The solution must include custom views and a dashboard for analyzing security events. What should you recommend using in Microsoft Sentinel?

  • A. playbooks
  • B. workbooks
  • C. notebooks
  • D. threat intelligence

Answer: C

NEW QUESTION 11

Your company is developing an invoicing application that will use Azure Active Directory (Azure AD) B2C. The application will be deployed as an App Service web app. You need to recommend a solution to the application development team to secure the application from identity related attacks. Which two configurations should you recommend? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  • A. Azure AD Conditional Access integration with user flows and custom policies
  • B. Azure AD workbooks to monitor risk detections
  • C. custom resource owner password credentials (ROPC) flows in Azure AD B2C
  • D. access packages in Identity Governance
  • E. smart account lockout in Azure AD B2C

Answer: BE

NEW QUESTION 12

Your company has the virtual machine infrastructure shown in the following table.
SC-100 dumps exhibit
The company plans to use Microsoft Azure Backup Server (MABS) to back up the virtual machines to Azure. You need to provide recommendations to increase the resiliency of the backup strategy to mitigate attacks
such as ransomware.
What should you include in the recommendation?

  • A. Use geo-redundant storage (GRS).
  • B. Use customer-managed keys (CMKs) for encryption.
  • C. Require PINs to disable backups.
  • D. Implement Azure Site Recovery replication.

Answer: C

NEW QUESTION 13

A customer follows the Zero Trust model and explicitly verifies each attempt to access its corporate applications.
The customer discovers that several endpoints are infected with malware. The customer suspends access attempts from the infected endpoints.
The malware is removed from the end point.
Which two conditions must be met before endpoint users can access the corporate applications again? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. Microsoft Defender for Endpoint reports the endpoints as compliant.
  • B. Microsoft Intune reports the endpoints as compliant.
  • C. A new Azure Active Directory (Azure AD) Conditional Access policy is enforced.
  • D. The client access tokens are refreshed.

Answer: CD

NEW QUESTION 14

A customer is deploying Docker images to 10 Azure Kubernetes Service (AKS) resources across four Azure subscriptions. You are evaluating the security posture of the customer.
You discover that the AKS resources are excluded from the secure score recommendations. You need to produce accurate recommendations and update the secure score.
Which two actions should you recommend in Microsoft Defender for Cloud? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  • A. Configure auto provisioning.
  • B. Assign regulatory compliance policies.
  • C. Review the inventory.
  • D. Add a workflow automation.
  • E. Enable Defender plans.

Answer: BD

NEW QUESTION 15

You have a Microsoft 365 E5 subscription.
You need to recommend a solution to add a watermark to email attachments that contain sensitive data. What should you include in the recommendation?

  • A. Microsoft Defender for Cloud Apps
  • B. insider risk management
  • C. Microsoft Information Protection
  • D. Azure Purview

Answer: A

NEW QUESTION 16

You have an Azure subscription that contains several storage accounts. The storage accounts are accessed by legacy applications that are authenticated by using access keys.
You need to recommend a solution to prevent new applications from obtaining the access keys of the storage accounts. The solution must minimize the impact on the legacy applications.
What should you include in the recommendation?

  • A. Apply read-only locks on the storage accounts.
  • B. Set the AllowSharcdKeyAccess property to false.
  • C. Set the AllowBlobPublicAcccss property to false.
  • D. Configure automated key rotation.

Answer: A

NEW QUESTION 17

You are designing security for an Azure landing zone. Your company identifies the following compliance and privacy requirements:
• Encrypt cardholder data by using encryption keys managed by the company.
• Encrypt insurance claim files by using encryption keys hosted on-premises.
Which two configurations meet the compliance and privacy requirements? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  • A. Store the insurance claim data in Azure Blob storage encrypted by using customer-provided keys.
  • B. Store the cardholder data in an Azure SQL database that is encrypted by using keys stored in Azure Key Vault Managed HSM
  • C. Store the insurance claim data in Azure Files encrypted by using Azure Key Vault Managed HSM.
  • D. Store the cardholder data in an Azure SQL database that is encrypted by using Microsoft-managed Keys.

Answer: CD

NEW QUESTION 18
......

Recommend!! Get the Full SC-100 dumps in VCE and PDF From Dumps-hub.com, Welcome to Download: https://www.dumps-hub.com/SC-100-dumps.html (New 105 Q&As Version)