Summer Sale Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple75

Pass the Microsoft Certified: Cybersecurity Architect Expert SC-100 Questions and answers with Dumpstech

Exam SC-100 Premium Access

View all detail and faqs for the SC-100 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 8 out of 10 pages
Viewing questions 71-80 out of questions
Questions # 71:

You have a Microsoft 365 tenant that uses Microsoft SharePoint Online and Microsoft Purview. Microsoft Purview has a sensitivity label named Label1 that is applied to the files stored on SharePoint Online sites.

You need to recommend a Microsoft Purview Data Loss Prevention (DLP) policy that meets the following requirements:

• Prevents users from uploading the files to third-party external websites

• Allows users to upload the files to Microsoft OneDrive for Business

To which location should you apply the DLP policy?

Options:

A.

Devices

B.

OneDrive accounts

C.

SharePoint sites

D.

Microsoft Defender for Cloud Apps

Questions # 72:

You have the Azure subscriptions shown in the following table.

Question # 72

The tenants contain the groups shown in the following table.

Question # 72

You perform the following actions:

• Configure multi-user authorization (MUA) for Vault1 by using a resource guard deployed to Sub2.

• Enable all available MUA controls for Vault1.

• In contoso.com, create a Privileged Identity Management (PIM) assignment named Assignment1.

• Configure Assignment1 to enable Group! to activate the Contributor role for Vault1.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Question # 72

Options:

Questions # 73:

You have an Azure Storage account named storage1.

You plan to secure storage1 by using a Bring Your Own Key (BYOK) strategy.

You create an Azure key vault named AKV1 and upload a compatible key.

You need to configure storage1 to use the key stored in AKV1 for encryption.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Question # 73

Options:

Questions # 74:

You have an Azure subscription.

You have an on-premises datacenter that contains Microsoft SQL Server instances. Each instance contains multiple databases.

You have a Microsoft 365 subscription.

You plan to implement a solution to scan the databases for vulnerabilities that compromise data security.

You need to recommend what to configure before the databases can be scanned.

What should you recommend?

Options:

A.

Microsoft Defender for Cloud

B.

Microsoft Defender Vulnerability Management

C.

Microsoft Purview data governance

D.

Microsoft Purview data loss prevention (DLP)

Questions # 75:

You have an Azure subscription that has Microsoft Defender for Cloud enabled.

You are evaluating the Azure Security Benchmark V3 report.

In the Secure management ports controls, you discover that you have 0 out of a potential 8 points.

You need to recommend configurations to increase the score of the Secure management ports controls.

Solution: You recommend enabling just-in-time (JIT) VM access on all virtual machines.

Does this meet the goal?

Options:

A.

Yes

B.

No

Questions # 76:

You have a Microsoft Entra tenant named contoso.com.

You have a partner company that has a multi-tenant application named App1. App1 is registered to a Microsoft Entra tenant named fabnkam.com.

You need to ensure that the users in contoso.com can authenticate to App1.

What should you recommend creating in contoso.com?

Options:

A.

a service principal

B.

a system-assigned managed identity

C.

an application object

D.

a user-assigned managed identity

Questions # 77:

Your company has a main office and 10 branch offices. Each branch office contains an on-premises file server that runs Windows Server and multiple devices that run either Windows 11 or macOS. The devices are enrolled in Microsoft Intune.

You have a Microsoft Entra tenant.

You need to deploy Global Secure Access to implement web filtering for device traffic to the internet The solution must ensure that all the web traffic from the devices in the branch offices is controlled by using Global Secure Access.

What should you do first in each branch office?

Options:

A.

Configure an Intune policy to deploy the Global Secure Access client to each device.

B.

Configure an IPsec tunnel on the router.

C.

Install the Microsoft Entra private network connector on the file server.

D.

Configure an Intune policy to onboard Microsoft Defender for Endpoint to each device.

Questions # 78:

Your company has on-premises Microsoft SQL Server databases.

The company plans to move the databases to Azure.

You need to recommend a secure architecture for the databases that will minimize operational requirements for patching and protect sensitive data by using dynamic data masking. The solution must minimize costs.

What should you include in the recommendation?

Options:

A.

Azure SQL Managed Instance

B.

Azure Synapse Analytics dedicated SQL pools

C.

Azure SQL Database

D.

SQL Server on Azure Virtual Machines

Questions # 79:

A customer has a hybrid cloud infrastructure that contains a Microsoft 365 E5 subscription and an Azure subscription.

All on-premises Windows servers in the perimeter network are prevented from connecting directly to the internet.

The customer recently recovered from a tansomware attack.

The customer plans to deploy Microsoft Sentinel.

You need to recommend solutions to meet the following requirements:

• Ensure that the security operations team can access the security logs and the operation logs.

• Ensure that the IT operations team can access only the operations logs, including the event logs of the servers in the perimeter network.

Which two solutions should you include in the recommendation? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Options:

A.

the Azure Monitor agent

B.

Microsoft Entra Conditional Access policies

C.

Windows Server event subscription

D.

resource-based role-based access control (RBAC)

Questions # 80:

What should you create in Azure AD to meet the Contoso developer requirements?

Question # 80

Options:

Viewing page 8 out of 10 pages
Viewing questions 71-80 out of questions