Microsoft SC-100 Practice Exam Questions & Answers

6 Free Questions · Last reviewed: September 30, 2026 · Prepared & Reviewed by the ValidExamDumps Editorial Team

Exam Facts

Microsoft SC-100 Exam Details

Key details for this exam, checked against the published exam outline

279 Practice Questions (Our Bank)
100 minutes Exam Duration
700 out of 1000 Passing Score
USD 165 Official Exam Fee
Exam Code
SC-100
Full Name
Microsoft Certified: Cybersecurity Architect Expert (SC-100)
Issuing Body
Microsoft
Question Format (Our Bank)
Multiple Choice, Hotspot, Drag & Drop, Order List, Case Studies
Delivery
Online proctored or at a Pearson VUE test centre
Eligibility
Must hold at least one associate-level prerequisite certification: Microsoft Certified Azure Security Engineer Associate, Microsoft Certified Identity and Access Administrator Associate, Microsoft Certified Security Operations Analyst Associate, Microsoft
Validity
1 year from the date the exam is passed. Renewal requires completing a free online renewal assessment annually through Microsoft Learn
Practice Questions

Free SC-100 Practice Questions

Each question shows the correct answer and an explanation of why it is right

VA
ValidExamDumps Editorial Team Every question and its answer is checked by our SC-100 exam preparation team, who also write the explanation shown with each one. How we research and review these pages

You have an Azure subscription and an Azure DevOps organization.

You need to recommend a solution for connecting Azure DevOps pipelines to the resources in the subscription by using Azure Resource Manager (ARM) service connections. The solution must align with Microsoft Cloud Adoption Framework for Azure best practices, including the principle of least privilege.

What should you include in the recommendation?

Correct Answer: C
Explanation Endpoint Privilege Management in Microsoft Intune allows standard users to run applications that require admin rights without giving them full administrative access to their devices. This is managed through a security context that elevates only specific applications as needed. The key advantage is that Group1 members can assist users while maintaining the security posture of keeping regular user accounts unprivileged. This directly addresses identity and access management within the security operations domain.

Your company plans to follow DevSecOps best practices of the Microsoft Cloud Adoption Framework for Azure.

You need to perform threat modeling by using a top-down approach based on the Microsoft Cloud Adoption Framework for Azure.

What should you use to start the threat modeling process?

Correct Answer: C
Explanation

For threat modeling using a top-down approach based on the Microsoft Cloud Adoption Framework, you should start with: Define business goals, critical assets, and organizational risk tolerance first, then map architecture and data flows, and finally identify threats at each layer. More specifically, begin with STRIDE methodology (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) applied to your cloud architecture components, or use Microsoft's threat modeling tool in conjunction with the Azure Security Architecture reference. The top-down approach starts with high-level business and architecture context before drilling down into technical threat scenarios.

Your company is moving all on-premises workloads to Azure and Microsoft 365. You need to design a security orchestration, automation, and response (SOAR) strategy in Microsoft Sentinel that meets the following requirements:

* Minimizes manual intervention by security operation analysts

* Supports Waging alerts within Microsoft Teams channels

What should you include in the strategy?

Correct Answer: B

You need to recommend a strategy for routing internet-bound traffic from the landing zones. The solution must meet the landing zone requirements.

What should you recommend as part of the landing zone deployment?

Correct Answer: A

You have an Azure subscription that is used as an Azure landing zone for an application. You need to evaluate the security posture of all the workloads in the landing zone. What should you do first?

Correct Answer: C
Explanation

To evaluate the security posture of workloads in an Azure landing zone, the first step should be to run Microsoft Defender for Cloud's security assessment or use Azure Security Benchmark assessment tools in Microsoft Defender for Cloud. You should first enable Microsoft Defender for Cloud (Defender CSPM plan) to establish a baseline security posture assessment. This provides comprehensive visibility into security vulnerabilities, compliance status, and security recommendations across all resources in the landing zone before implementing remediation steps.

You have an on-premises server that runs Windows Server and contains a Microsoft SQL Server database named DB1.

You plan to migrate DB1 to Azure.

You need to recommend an encrypted Azure database solution that meets the following requirements:

* Minimizes the risks of malware that uses elevated privileges to access sensitive data

* Prevents database administrators from accessing sensitive data

* Enables pattern matching for server-side database operations

* Supports Microsoft Azure Attestation

* Uses hardware-based encryption

What should you include in the recommendation?

Correct Answer: D
Explanation

The requirements specify a sophisticated encryption solution with specific security properties:

  • Minimizes malware risks from elevated privileges: Always Encrypted encrypts data at the application level before it reaches the database, preventing even DBAs with elevated privileges from accessing sensitive data in plaintext.
  • Prevents DBA access to sensitive data: Always Encrypted keys are managed outside the database (in Key Vault or application), ensuring database administrators cannot decrypt sensitive columns even if they access the database directly.
  • Enables server-side pattern matching: Always Encrypted with randomized encryption supports deterministic encryption for pattern matching operations on the server side.
  • Supports Azure Attestation: SQL Server with Always Encrypted can be configured with Azure Attestation to prove that keys are only accessed by authorized code.
  • Uses hardware-based encryption: When configured with Azure Key Vault in a Dedicated HSM or using SQL Server's Transparent Data Encryption with hardware security modules, encryption is hardware-backed.
  • Why SQL Server vs. SQL Database: The migration from on-premises SQL Server makes SQL Server on Azure VMs (with Always Encrypted) the most appropriate solution, though SQL Database with Always Encrypted is also viable.

This combination provides defense-in-depth encryption protecting against privileged account abuse while maintaining necessary database functionality.

Full Access

Get the complete SC-100 question set

  • 279 questions covering all exam domains
  • Correct answers with explanations, like the free questions above
  • PDF and online practice test
  • 90 days of free updates
Starting from 50% OFF
$20 $40
Get Full Access

One-time payment · Instant download

Study Guide

What the Microsoft SC-100 Exam Covers

Exam domains verified against: Official Microsoft SC-100 exam guide, last checked September 2026.

Domain 1: Design solutions that align with security best practices and priorities 20% - 25%

Design security architectures following Microsoft Cybersecurity Reference Architectures and cloud security benchmarks. Develop resilience strategies for ransomware and other attacks based on Microsoft Security Best Practices, and align solutions with the Microsoft Cloud Adoption Framework and Azure Well-Architected Framework.

Sample question from this domain above: Q6

Domain 2: Design security operations, identity, and compliance capabilities 25% - 30%

Develop strategies for security operations monitoring and response. Design identity and access management solutions that enforce secure authentication and authorization. Implement compliance frameworks that ensure adherence to regulatory requirements and governance standards.

Sample questions from this domain above: Q1Q4

Domain 3: Design security solutions for infrastructure 25% - 30%

Create comprehensive security architectures for networks, servers, and cloud environments. Design controls to protect physical and virtual infrastructure from cyber threats. Develop strategies to mitigate risks in hybrid and multicloud infrastructures while maintaining business continuity.

Sample question from this domain above: Q2

Domain 4: Design security solutions for applications and data 20% - 25%

Specify application security requirements and implement encryption mechanisms throughout the application lifecycle. Design data security strategies that enforce access controls, classification, and protection of sensitive information against cyber threats.

Sample questions from this domain above: Q3Q5

FAQ

SC-100 Exam FAQ

Common questions about the exam itself

What background do I need before attempting SC-100?
You must hold one of five associate-level certifications: Azure Security Engineer Associate, Identity and Access Administrator Associate, Security Operations Analyst Associate, Security Administrator Associate, or Information Protection Administrator Associate. You should also have practical experience implementing security solutions in identity and access, platform protection, security operations, data and AI security, application security, and hybrid or multicloud infrastructure.
Is SC-100 harder than the associate-level Microsoft security exams?
Yes. SC-100 is an expert-level exam that requires strategic architectural thinking rather than tactical implementation skills. It focuses on designing end-to-end security strategies and translating business needs into comprehensive security architectures, which is substantially more complex than the technical implementation tested at the associate level.
How long does it typically take to prepare for SC-100?
Preparation time varies widely depending on your background. If you hold a prerequisite certification and have practical security experience, expect 2 to 4 months of focused study. If you need to refresh foundational knowledge from your associate certification, plan for 3 to 6 months. Most candidates benefit from combining Microsoft Learn modules with hands-on lab experience and practice exams.
What makes infrastructure security the hardest domain in SC-100?
The infrastructure security domain requires you to design across multiple complex environments including on-premises, Azure, multicloud, and hybrid setups. The exam tests your ability to assess vulnerabilities at scale, design layered security controls, ensure business continuity, and align technical solutions with business risk tolerance, which demands both breadth and depth of knowledge.
Can I take SC-100 online from home?
Yes. The exam is available as online proctored through Pearson VUE, which allows you to take it from home with a proctor monitoring via webcam. You can also take it at a physical Pearson VUE test centre if you prefer an in-person environment.
What is the passing score for SC-100 and how is it calculated?
The passing score is 700 out of 1000. Your score is calculated based on the number and difficulty of questions you answer correctly. The exam uses adaptive scoring where harder questions are weighted more heavily if answered correctly.
How long is the SC-100 certification valid and what does renewal require?
Your certification is valid for one year from the date you pass the exam. To renew, you must complete a free online renewal assessment through Microsoft Learn before the certification expires. This assessment confirms you have maintained your knowledge of current security strategies and technologies.
What job role does SC-100 prepare me for?
SC-100 is designed for cybersecurity architects who translate business security strategy into technical capabilities and secure architectures. The certification validates your ability to plan and implement enterprise-wide cybersecurity strategies that protect organizational assets, business processes, and operations across hybrid and multicloud environments.
How does SC-100 relate to other Microsoft security certifications?
SC-100 is the expert-level pinnacle of Microsoft's security certification track. You must first earn one of five associate-level certifications such as SC-200 (Security Operations Analyst), SC-300 (Identity and Access Administrator), or AZ-500 (Azure Security Engineer). These provide the foundation you need before attempting the architectural thinking required at the expert level.
What happens if I fail SC-100 on my first attempt?
You can retake the exam up to 5 times within a 12-month period. After each failure, Microsoft recommends reviewing the exam score report to identify weak areas, then using Microsoft Learn modules and practice exams to address those gaps before your next attempt. Each retake costs the standard exam fee of USD 165.