✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Domain 1: Design solutions that align with security best practices and priorities
A company wants to design a ransomware resilience strategy following Microsoft recommendations. The design must ensure that critical backup data cannot be deleted or encrypted by an attacker who compromises an administrator account. Which solution BEST meets this requirement?
Immutable vault settings combined with resource guard and multi-user authorization (MUA) require approval from a separate management scope before critical backup operations like deletion or reduced retention can be performed, preventing a single compromised administrator from destroying backup data — aligning with Microsoft ransomware resilience guidance.
Question 2 of 12 · Domain 2: Design security operations, identity, and compliance capabilities
A global enterprise runs Microsoft Sentinel as its SIEM alongside on-premises Active Directory, Azure workloads, and AWS EC2 instances. The security team wants unified incident correlation, fusion-based detection, and automated response for identity-based threats spanning all these environments, without duplicating alert triage across multiple consoles. Which design BEST meets these requirements?
The Defender XDR-Sentinel native connector synchronizes incidents bidirectionally and feeds Defender's correlated signals into Sentinel's fusion engine, while the AWS connector ingests CloudTrail/GuardDuty data so Sentinel becomes the single pane of glass for cross-cloud, cross-identity correlation and automated SOAR playbooks.
Question 3 of 12 · Domain 3: Design security solutions for infrastructure
Fabrikam operates an OT network running SCADA systems for its manufacturing plants. The OT network is segmented from IT using the Purdue model, and the security team must design a monitoring solution that provides visibility into OT device communications and detects anomalous ICS protocol traffic without installing any software on the OT devices themselves. Which solution should be included in the design?
Defender for IoT OT sensors passively monitor traffic mirrored via SPAN/TAP, using deep packet inspection of ICS/SCADA protocols (Modbus, DNP3, etc.) to build an asset inventory and detect anomalies without touching the OT devices, which is the required agentless, non-intrusive approach.
Question 4 of 12 · Domain 4: Design security solutions for applications and data
A company uses GitHub Actions to deploy infrastructure to Azure. The security architect must eliminate long-lived credentials stored as GitHub secrets while still allowing the pipeline to authenticate to Azure and deploy resources. Which solution BEST meets this requirement?
Workload identity federation lets GitHub Actions present an OIDC token that Azure AD exchanges for a short-lived access token, removing the need to store any client secret or certificate — the recommended Zero Trust pattern for CI/CD workload identities.
Question 5 of 12 · Domain 1: Design solutions that align with security best practices and priorities
A company has a legacy line-of-business web application hosted on-premises that does not support modern authentication protocols. Employees need secure remote access to the application without exposing it directly to the internet via VPN. As part of a Zero Trust access strategy, which solution BEST meets this requirement?
Microsoft Entra Application Proxy publishes individual applications with per-app, identity-based Conditional Access enforcement, satisfying the Zero Trust principles of verify explicitly and least-privilege access without granting broad network-level connectivity.
Question 6 of 12 · Domain 2: Design security operations, identity, and compliance capabilities
An architect must design a control that allows a small group of engineers to elevate to the Global Administrator role only when needed, requiring a business justification, manager approval, and automatic time-bound expiration of the elevated role. Which capability should be specified in the design?
PIM provides eligible (just-in-time) role assignments with configurable approval, justification, MFA enforcement, and automatic expiration — exactly matching the time-bound, approval-gated elevation requirement for privileged roles like Global Administrator.
Question 7 of 12 · Domain 3: Design security solutions for infrastructure
Contoso has a secure score of 42% across dozens of subscriptions in Microsoft Defender for Cloud. The security team has a limited remediation budget and wants to design a governance process that maximizes secure score improvement while ensuring accountability for remediation. Which approach should the design include?
Governance rules in Defender for Cloud let architects assign owners, set SLAs (due dates), and prioritize remediation based on each recommendation's score impact and whether a quick fix is available, maximizing score improvement efficiently under budget constraints.
Question 8 of 12 · Domain 4: Design security solutions for applications and data
A global organization stores sensitive data across Azure, AWS, on-premises file shares, and SaaS apps like Salesforce. The security architect needs a single strategy to automatically discover, classify, and apply sensitivity labels to this data across all these locations. Which service should be the foundation of this strategy?
Microsoft Purview provides a unified data map with scanning connectors for Azure, AWS, on-premises, and SaaS sources, enabling automated discovery, classification, and consistent sensitivity labeling — the recommended cross-estate data classification strategy in SC-100 guidance.
Question 9 of 12 · Domain 1: Design solutions that align with security best practices and priorities
A company must continuously assess its compliance posture against frameworks such as ISO 27001 and NIST 800-53 across its Microsoft 365 and Azure environment, and generate a prioritized list of improvement actions with a compliance score. Which tool should be included in the design?
Microsoft Purview Compliance Manager provides cross-Microsoft 365 and Azure compliance assessments mapped to regulatory templates such as ISO 27001 and NIST 800-53, producing a compliance score and prioritized improvement actions.
Question 10 of 12 · Domain 2: Design security operations, identity, and compliance capabilities
A design requires all users to complete MFA when accessing a sensitive SharePoint site, and additionally must prevent document downloads when the user connects from an unmanaged (non-compliant, non-domain-joined) device. Which Conditional Access configuration achieves BOTH requirements?
Grant controls (Require MFA) and session controls (Conditional Access App Control) can be combined in a single Conditional Access policy. App-enforced or Defender for Cloud Apps session control can block downloads specifically for sessions originating from unmanaged devices while still permitting authenticated, MFA-verified access.
Question 11 of 12 · Domain 3: Design security solutions for infrastructure
A company runs workloads on Azure, AWS EC2, and GCP Compute Engine. The security architect must design a unified cloud security posture and workload protection solution that provides recommendations and threat detection for all three cloud providers from a single console. Which solution should be included in the design?
Defender for Cloud's native multicloud connectors auto-provision Azure Arc and Defender plans (such as Defender for Servers) on AWS and GCP resources, delivering unified CSPM recommendations and CWPP threat protection in a single console.
Question 12 of 12 · Domain 4: Design security solutions for applications and data
An architecture team is redesigning Key Vault access for a Zero Trust posture. They need granular, auditable permissions on secret and key operations that integrate with Azure AD Conditional Access and Privileged Identity Management, and they want to retire the legacy vault-level access model. What should they configure?
Switching the vault to the Azure RBAC permission model allows fine-grained, Azure AD–integrated role assignments that support Conditional Access, PIM just-in-time elevation, and full activity logging — the recommended modern access model over vault access policies.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.
The exam fee is approximately $165 and varies by region — confirm current pricing with the certification vendor before you book.
What topics are on the exam?
It covers 4 domains: Design solutions that align with security best practices and priorities (20-25%), Design security operations, identity, and compliance capabilities (25-30%), Design security solutions for infrastructure (20-25%), Design security solutions for applications and data (20-25%). The full course has a dedicated chapter, lab and practice-test coverage for each.
Is this practice test really free?
Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.
Will this prepare me for the real exam?
The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.