Free Microsoft SC-100 practice questions

10 free Microsoft SC-100 practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 360 questions. Work through them, then open each answer to check your reasoning.

Question 1

Your company has a Microsoft 365 ES subscription.

The Chief Compliance Officer plans to enhance privacy management in the working environment.

You need to recommend a solution to enhance the privacy management. The solution must meet the following requirements:

• Identify unused personal data and empower users to make smart data handling decisions.

• Provide users with notifications and guidance when a user sends personal data in Microsoft Teams.

• Provide users with recommendations to mitigate privacy risks.

What should you include in the recommendation?

  1. communication compliance in insider risk management
  2. Microsoft Viva Insights
  3. Privacy Risk Management in Microsoft Priva
  4. Advanced eDiscovery
Show answer and explanation

Correct answer: C. Privacy Risk Management in Microsoft Priva

Microsoft Priva's Privacy Risk Management feature is specifically designed to identify unused personal data, provide users with notifications and guidance when personal data is shared in Teams, and offer recommendations to mitigate privacy risks. This directly addresses all three requirements mentioned in the question.

Why the other options are wrong

  • A. Communication compliance focuses on detecting policy violations and inappropriate communications, not privacy data handling decisions.
  • B. Microsoft Viva Insights provides workplace analytics and wellbeing insights, not privacy risk management capabilities.
  • D. Advanced eDiscovery is for legal discovery and compliance investigations, not for identifying unused personal data or real-time guidance.

Question 2

You have an Azure subscription that has Microsoft Defender for Cloud enabled.

Suspicious authentication activity alerts have been appearing in the Workload protections dashboard.

You need to recommend a solution to evaluate and remediate the alerts by using workflow automation. The solution must minimize development effort.

What should you include in the recommendation?

  1. Azure Monitor webhooks
  2. Azure Event Hubs
  3. Azure Functions apps
  4. Azure Logics Apps
Show answer and explanation

Correct answer: D. Azure Logics Apps

Azure Logic Apps provide a low-code, no-code solution for workflow automation that can integrate with Microsoft Defender for Cloud to evaluate and remediate alerts. Logic Apps minimize development effort compared to other options and support complex conditional logic for alert response automation.

Why the other options are wrong

  • A. Azure Monitor webhooks are for notifications only and do not provide workflow automation capabilities for evaluation and remediation.
  • B. Azure Event Hubs is a data streaming platform for ingesting events, not for automation and remediation workflows.
  • C. Azure Functions requires more development effort than Logic Apps and is cod-ased rather than low-code/no-code.

Question 3

Your company is moving a big data solution to Azure.

The company plans to use the following storage workloads:

• Azure Storage blob containers

• Azure Data Lake Storage Gen2

Azure Storage file shares –

• Azure Disk Storage

Which two storage workloads support authentication by using Azure Active Directory (Azure AD)? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

  1. Azure Storage file shares
  2. Azure Disk Storage
  3. Azure Storage blob containers
  4. Azure Data Lake Storage Gen2 ✅Correct Answer: A, C
  5. Azure Storage file shares
  6. Azure Storage blob containers Azure Storage blob containers and Azure Storage file shares both support Azure AD (Microsoft Entra ID) authentication. Blob storage accepts Entra ID tokens for data plane requests with RBAC, and Azure Files supports identity-based authentication over SMB using on-premises AD DS, Microsoft Entra Domain Services, or Microsoft Entra Kerberos.
Show answer and explanation

Answer and explanation for question 3

Question 4

You have a Microsoft 365 E5 subscription and an Azure subscription.

You are designing a Microsoft deployment.

You need to recommend a solution for the security operations team. The solution must include custom views and a dashboard for analyzing security events.

What should you recommend using in Microsoft Sentinel?

  1. notebooks
  2. playbooks
  3. workbooks
  4. threat intelligence
Show answer and explanation

Correct answer: C. workbooks

Microsoft Sentinel workbooks provide customizable dashboards and visualizations for analyzing security events. Workbooks allow security teams to create custom views, display KPIs, and present data in an organized manner tailored to their operational needs.

Why the other options are wrong

  • A. Notebooks are for interactive investigation and data analysis using KQL, not for building dashboards.
  • B. Playbooks are for automation and response actions, not for analyzing security events through dashboards.
  • D. Threat intelligence provides threat data and indicators, not custom dashboards for event analysis.

Question 5

Your company has a Microsoft 365 subscription and uses Microsoft Defender for Identity.

You are informed about incidents that relate to compromised identities.

You need to recommend a solution to expose several accounts for attackers to exploit.

When the attackers attempt to exploit the accounts, an alert must be triggered.

Which Defender for Identity feature should you include in the recommendation?

  1. sensitivity labels
  2. custom user tags
  3. standalone sensors
  4. honeytoken entity tags
Show answer and explanation

Correct answer: D. honeytoken entity tags

In Microsoft Defender for Identity, a honeytoken entity tag is applied to existing dormant or decoy accounts that are deliberately left exposed. Those accounts should see no legitimate activity, so any authentication or use of them immediately raises an alert, exposing attackers who try to exploit them.

Why the other options are wrong

  • A. Sensitivity labels classify and protect data. They do not mark accounts as decoys or alert on their use.
  • B. Custom user tags group and categorize entities for filtering and reporting, and do not generate decoy alerts.
  • C. Standalone sensors are a deployment option for collecting domain controller traffic, not a decoy account feature.

Question 6

Your company is moving all on-premises workloads to Azure and Microsoft 365.

You need to design a security orchestration, automation, and response (SOAR) strategy in Microsoft Sentinel that meets the following requirements:

• Minimizes manual intervention by security operation analysts

• Supports triaging alerts within Microsoft Teams channels

What should you include in the strategy?

  1. KQL
  2. playbooks
  3. data connectors
  4. workbooks
Show answer and explanation

Correct answer: B. playbooks

Playbooks are Microsoft Sentinel's SOAR automation feature that minimizes manual intervention by automating response actions. Playbooks can be triggered by alerts and integrated with Microsoft Teams channels to enable triage and response workflows directly within Teams.

Why the other options are wrong

  • A. KQL is a query language for data analysis, not a SOAR automation mechanism.
  • C. Data connectors ingest data into Sentinel but do not provide automation or response capabilities.
  • D. Workbooks are for visualization and analysis, not for automating security responses or Teams integration.

Question 7

You have an Azure subscription that contains virtual machines, storage accounts, and Azure SQL databases.

All resources are backed up multiple times a day by using Azure Backup.

You are developing a strategy to protect against ransomware attacks.

You need to recommend which controls must be enabled to ensure that Azure Backup can be used to restore the resources in the event of a successful ransomware attack.

Which two controls should you include in the recommendation? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

  1. Enable soft delete for backups.
  2. Require PINs for critical operations.
  3. Encrypt backups by using customer-managed keys (CMKs).
  4. Perform offline backups to Azure Data Box.
  5. Use Azure Monitor notifications when backup configurations change.
Show answer and explanation

Correct answer: A, B

A. Enable soft delete for backups. B. Require PINs for critical operations. Soft delete for backups prevents accidental or malicious deletion of backup data by recovering deleted backups within a retention period, which is critical for ransomware recovery. Requiring PINs for critical operations adds an additional security layer to prevent unauthorized deletion or modification of backup configurations that attackers might attempt during a ransomware attack.

Why the other options are wrong

  • C. While encryption with CMKs is valuable for security, it does not specifically prevent ransomware from destroying backup data or restore points.
  • D. Offline backups to Azure Data Box are a good practice but are not real-time controls that prevent ransomware during an active attack.
  • E. Monitoring notifications after configuration changes are helpful for awareness but do not prevent ransomware attacks or ensure recovery capability.

Question 8

Your company has a third-party security information and event management (SIEM) solution that uses Splunk and Microsoft Sentinel.

You plan to integrate Microsoft Sentinel with Splunk.

You need to recommend a solution to send security events from Microsoft Sentinel to Splunk.

What should you include in the recommendation?

  1. a Microsoft Sentinel data connector
  2. Azure Event Hubs
  3. a Microsoft Sentinel workbook
  4. Azure Data Factory
Show answer and explanation

Correct answer: B. Azure Event Hubs

Azure Event Hubs is the recommended solution for exporting security events from Microsoft Sentinel to third-party SIEM solutions like Splunk. Event Hubs provides a scalable, reliable streaming platform that can receive and forward data from Sentinel to external systems using connectors and integrations.

Why the other options are wrong

  • A. Microsoft Sentinel data connectors are for ingesting data into Sentinel, not for exporting data to external systems.
  • C. Workbooks are for visualization and analysis within Sentinel, not for exporting data to external SIEM solutions.
  • D. Azure Data Factory is for data integration and ETL processes but is not the standard solution for Sentinel-to-Splunk integration.

Question 9

A customer follows the Zero Trust model and explicitly verifies each attempt to access its corporate applications.

The customer discovers that several endpoints are infected with malware.

The customer suspends access attempts from the infected endpoints.

The malware is removed from the endpoints.

Which two conditions must be met before endpoint users can access the corporate applications again? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

  1. The client access tokens are refreshed.
  2. Microsoft Intune reports the endpoints as compliant.
  3. A new Azure Active Directory (Azure AD) Conditional Access policy is enforced.
  4. Microsoft Defender for Endpoint reports the endpoints as compliant.
Show answer and explanation

Correct answer: A, D

A. The client access tokens are refreshed. D. Microsoft Defender for Endpoint reports the endpoints as compliant. Zero Trust verifies explicitly at every access attempt. First, Microsoft Defender for Endpoint must report the remediated endpoints as clean and compliant, which clears the device risk signal used in the access decision. Second, the client access tokens must be refreshed so that the new device state is evaluated. Existing tokens still carry the old non-compliant status, so access remains blocked until fresh tokens are issued after re-evaluation.

Why the other options are wrong

  • B. Intune compliance reporting is not the signal that clears this block; the malware verdict and the token state are.
  • C. A new Conditional Access policy is not required; the existing policies re-evaluate the endpoints when new tokens are requested.

Question 10

You have a customer that has a Microsoft 365 subscription and uses the Free edition of Azure Active Directory (Azure AD).

The customer plans to obtain an Azure subscription and provision several Azure resources.

You need to evaluate the customer's security environment.

What will necessitate an upgrade from the Azure AD Free edition to the Premium edition?

  1. Azure AD Privileged Identity Management (PIM)
  2. role-based authorization
  3. resource-based authorization
  4. Azure AD Multi-Factor Authentication
Show answer and explanation

Correct answer: A. Azure AD Privileged Identity Management (PIM)

Azure AD Privileged Identity Management (PIM) is an Azure AD Premium feature that enables just-in-time privileged access and role activation workflows. This is essential for managing admin access to Azure resources and adhering to Zero Trust principles. The Free edition does not include PIM capabilities, making this upgrade necessary for proper privileged identity management in Azure deployments.

Why the other options are wrong

  • B. Role-based authorization (RBAC) is available in Azure AD Free edition.
  • C. Resource-based authorization is a general authorization concept available in the Free tier.
  • D. Azure AD Multi-Factor Authentication is available in Azure AD Free edition.

That was 10 of 360.

The full Microsoft SC-100 pack has all 360 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.

Get the full pack