Weekend Special Sale 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale75best

Free Microsoft SC-100 Practice Exam with Questions & Answers | Set: 2

Questions 11

You have a Microsoft Entra tenant that contains 800 Microsoft Entra joined devices and 700 users. Each user is assigned a single device. All the devices are onboarded to Global Secure Access.

You use a software as a service (SaaS) app named App1 that is hosted by a third party. Users access App1 through the internet.

You need to ensure that all the devices access App1 by using the Global Secure Access client.

What should you use?

Options:
A.

a Conditional Access policy

B.

a Quick Access app

C.

a traffic forwarding profile

D.

a security profile

Microsoft SC-100 Premium Access
Questions 12

You have a multicloud environment that contains an Azure subscription, an Amazon Web Services (AWS) subscription, and a Google Cloud Platform (GCP) subscription.

You plan to assess data security and compliance.

You need to design a Compliance Manager solution that meets the following requirements:

• Provides recommended improvement actions that include detailed implementation guidance

• Automatically monitors regulatory compliance

• Minimizes administrative effort

What should you include in the solution?

Options:
A.

Microsoft Defender for Cloud

B.

Microsoft Defender for Cloud Apps

C.

Microsoft Sentinel

D.

Compliance Manager connectors

Questions 13

You have an on-premises network and a Microsoft 365 subscription.

You are designing a Zero Trust security strategy.

Which two security controls should you include as part of the Zero Trust solution? Each correct answer part of the solution.

NOTE: Each correct answer is worth one point.

Options:
A.

Block sign-attempts from unknown location.

B.

Always allow connections from the on-premises network.

C.

Disable passwordless sign-in for sensitive account.

D.

Block sign-in attempts from noncompliant devices.

Questions 14

You have a Microsoft 365 subscription that contains a Microsoft SharePoint Online site named Site1.

You have a Conditional Access policy named Policy1 that only allows workload identities from trusted locations to access SharePoint Online.

You plan to move all business-sensitive information to Site1.

You need to ensure that Policy1 applies to Site1 only.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

NOTE: More than one order of answer choices is correct. You will receive credit for any of the correct orders you select.

SC-100 Question 14

Options:
Questions 15

You have an Azure subscription. The subscription contains five Azure App Service instances that host public web apps Each instance is deployed across three Azure regions.

The web apps handle sensitive customer data and must be protected from common web exploits and malicious bots.

You need to recommend a security solution that meets the following requirements:

• Provides centralized management and updates for protection rules

• Protects all the web apps without modifying the application code

• Minimizes costs

What should you include in the recommendation?

Options:
A.

Azure Application Gateway

B.

Azure Front Door

C.

Azure DDoS Protection

D.

Azure Firewall

Questions 16

Your company has an on-premises network, an Azure subscription, and a Microsoft 365 E5 subscription. The company uses the following devices:

• Computers that run either Windows 10 or Windows 11

• Tablets and phones that run either Android or iOS

You need to recommend a solution to classify and encrypt sensitive Microsoft Office 365 data regardless of where the data is stored. What should you include in the recommendation?

Options:
A.

eDiscovery

B.

retention policies

C.

Compliance Manager

D.

Microsoft Information Protection

Questions 17

You have an Azure subscription and a Microsoft 365 subscription. All users are assigned Microsoft 365 E5 licenses. All computers run Windows 11 and are Microsoft Entra joined.

You need to recommend a solution to prevent computers that run early builds of Windows 11 from connecting to Microsoft 365 services.

Which two types of policies should you include in the recommendation? Each correct answer presents part of the solution.

Options:
A.

Microsoft Defender for Cloud regulatory compliance policy

B.

Microsoft Defender for Endpoint endpoint security policy

C.

Microsoft Entra ID Protection sign-in risk policy

D.

Microsoft Entra Conditional Access policy

E.

Microsoft Intune compliance policy

Questions 18

Your network contains an on-premises Active Directory Domain Services (AD DS) domain.

You have a Microsoft 365 subscription.

You need to recommend a solution to evaluate the security and governance of the domains. The solution must meet the following requirements:

• identify configuration issues and administrative vulnerabilities.

• Minimize effort.

What should you include in the recommendation?

Options:
A.

Microsoft Entra ID Protection

B.

Microsoft Defender for Servers

C.

Microsoft Defender for Identity

D.

Microsoft Sentinel

Questions 19

You have an Azure subscription

You plan to deploy multiple containerized microservice-based apps to Azure Kubemetes Service (AKS)

You need to recommend a solution that meets the following requirements:

• Manages secrets

• Provides encryption

• Secures service-to-service communication by using mTLS encryption

• Minimizes administrative effort

What should you include in the recommendation?

Options:
A.

Flux

B.

Envoy

C.

Dapr

D.

Istio

Questions 20

You have a Microsoft Entra tenant and an Azure subscription.

You are evaluating the use of a risk-based Conditional Access policy to control the access of workload identities to resources.

To which type of identity should you apply the policy, and which signal source can you use as part of the policy? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-100 Question 20

Options: