Free SC-100 Mock Exam – Practice Online Confidently

Increase your chances of passing the Microsoft SC-100 exam questions on your first try. Practice with our free online SC-100 exam mock test designed to help you prepare effectively and confidently.

Exam Code: SC-100
Exam Questions: 296
Microsoft Cybersecurity Architect
Updated: 25 Aug, 2026
Question 1

Your on-premises network contains an Active Directory Domain Services (AD DS) domain named

corpxontoso.com and an AD DS-integrated application named App1.

Your perimeter network contains a server named Server1 that runs Windows Server.

You have a Microsoft Entra tenant named contoso.com that syncs with corp.contoso.com.

You plan to implement a security solution that will include the following configurations:

Manage access to App1 by using Microsoft Entra Private Access.

Deploy a Microsoft Entra application proxy connector to Server1.

Implement single sign-on (SSO) for App1 by using Kerberos constrained delegation.  

For Server1, configure the following rules in Windows Defender Firewall with Advanced Security:

o Rule1: Allow TCP 443 inbound from a designated set of Azure URLs.

o Rule2: Allow TCP 443 outbound to a designated set of Azure URLs.

o Rule3: Allow TCP 80 outbound to a designated set of Azure URLs.

o Rule4: Allow TCP 389 outbound to the domain controllers on corp.contoso.com.

You need to maximize security for the planned implementation. The solution must minimize the

impact on the connector.

Which rule should you remove?

Options :
Answer: C

Question 2

You have a Microsoft 365 tenant that contains 5,000 users and 5,000 Windows 11 devices. All users

are assigned Microsoft 365 £5 licenses and the Microsoft Defender Vulnerability Management addon.

The Windows 11 devices are managed by using Microsoft Intune and Microsoft Defender for

Endpoint. The Windows 11 devices are configured during deployment to comply with Center for

Internet Security (CIS) benchmarks for Windows 11.

You need to recommend a compliance solution for the Windows 11 devices. The solution must

identify devices that were modified and no longer comply with the CIS benchmarks.

What should you include in the recommendation?

Options :
Answer: D

Question 3

You have an Azure subscription that has Microsoft Defender for Cloud enabled. You are evaluating the Azure Security Benchmark V3 report as shown in the following exhibit.

You need to verify whether Microsoft Defender for servers is installed on all the virtual machines that run Windows. Which compliance control should you evaluate? 

Options :
Answer: E

Question 4

You are evaluating an Azure environment for compliance.

You need to design an Azure Policy implementation that can be used to evaluate compliance without

changing any resources.

Which effect should you use in Azure Policy? 

Options :
Answer: B

Question 5

You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and

Microsoft Defender for Cloud are enabled.

The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications

on Windows Server 2019.

You need to recommend a solution to ensure that only authorized applications can run on the virtual

machines. If an unauthorized application attempts to run or be installed, the application must be

blocked automatically until an administrator authorizes the application.

Which security control should you recommend? 

Options :
Answer: D

Viewing Page : 1 - 30
Practicing : 1 - 5 of 296 Questions

© Copyrights FreeMockExams 2026. All Rights Reserved

We use cookies to ensure that we give you the best experience on our website (FreeMockExams). If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the FreeMockExams.