20 free SC-100 practice questions with answers and explanations, covering Zero Trust and Microsoft security best practices, security operations and identity, infrastructure security, and application and data security.
Study the full SC-100 course, free to start.
Official SC-100 study guide on Microsoft Learn
Question 1. Leadership asks whether to use the CAF or the WAF to guide an organisation-wide cloud adoption and governance programme spanning strategy, landing zones and ongoing management. Which framework fits, and why?
Answer: D, The CAF, because it is organisation-scoped and covers the full adoption journey and governance. The Cloud Adoption Framework is organisation-scoped and covers the whole journey (Strategy, Plan, Ready, Adopt, Govern, Manage, Secure). The Well-Architected Framework is workload-scoped and reviews one architecture across five quality pillars, so it does not drive an org-wide programme.
Question 2. A stakeholder says 'we bought a Zero Trust product, so we are done'. What is the most accurate architect response?
Answer: C, Zero Trust is a strategy applied across identity, endpoints, data, apps, infrastructure and network, not a single product. Zero Trust is an end-to-end strategy built on verify explicitly, least privilege and assume breach, applied across all six pillars. No single product delivers it, and it explicitly rejects trusting the internal network by default.
Question 3. A team wants to add security to the software delivery process, covering design, code, pipeline and operations. Which approach and example controls should the architect recommend?
Answer: C, DevSecOps: threat modelling in design, dependency and secret scanning in code, automated checks in the pipeline, posture management and pen testing in operations. DevSecOps shifts security left, adding controls at design, code, pipeline and operations so issues are caught early and consistently. A single late review, operations-only security, or ad hoc developer effort all leave gaps that shifting left is designed to close.
Question 4. An architect is defining the recovery plan for ransomware resilience. Which pair of measures sets how much data loss and how much downtime are acceptable, and so drives the backup design?
Answer: B, Recovery point objective (RPO) and recovery time objective (RTO). RPO sets the maximum acceptable data loss (how far back you must be able to restore) and RTO sets the maximum acceptable downtime (how quickly you must restore). Together they drive backup frequency, immutability and restore testing. The other pairs are unrelated reliability, contract or preventive-control terms.
Question 5. An architect is threat modelling a new generative AI copilot using STRIDE, but a colleague argues STRIDE alone is enough and no AI-specific guidance is needed. Following CAF guidance for secure AI adoption, how should the architect respond?
Answer: B, Supplement STRIDE with AI-specific frameworks such as MITRE ATLAS and the OWASP Top 10 for Generative AI, since these cover risks like prompt injection and model manipulation that STRIDE does not name. CAF's discover-AI-security-risks discipline supplements general threat modelling like STRIDE with AI-specific guidance such as MITRE ATLAS and the OWASP Top 10 for Generative AI, which name risks (prompt injection, model manipulation, training data poisoning) that STRIDE alone does not capture. Dropping STRIDE or skipping modelling both leave the design unassessed.
Question 6. Security wants even a Global Administrator to be forced through phishing-resistant MFA from a compliant device before they can modify Conditional Access policies, so a stolen token alone cannot weaken the controls. What should the architect use?
Answer: D, Protected actions. Protected actions attach a step-up Conditional Access requirement to specific high-impact permission operations, such as editing Conditional Access policies, protecting the controls themselves. Named locations and password protection do not gate individual sensitive operations this way.
Question 7. Contoso must let partner organisations access a shared application using their own corporate identities, with the trust relationship governed centrally. Which design should the architect choose?
Answer: B, Microsoft Entra External ID B2B collaboration with cross-tenant access settings. B2B collaboration lets external users bring their own identities as guests, governed by cross-tenant access settings that centrally define inbound and outbound trust. Creating internal accounts or sharing credentials increases risk and administrative burden and abandons the partner's own identity lifecycle.
Question 8. A design must respond automatically when a sign-in looks risky, for example from an anonymising proxy, by requiring MFA. Which capability provides the risk signal and response, and what licence is needed?
Answer: A, Microsoft Entra ID Protection with risk-based Conditional Access, requiring Entra ID P2. Entra ID Protection scores sign-in and user risk, and risk-based Conditional Access responds (for example requiring MFA); risk-based policies require Microsoft Entra ID P2. Azure Policy, DLP and NSGs do not evaluate identity risk.
Question 9. An architect wants to prevent a misconfigured Conditional Access policy from locking every administrator out of the tenant. What should the design include?
Answer: C, Two or more cloud-only break-glass accounts, excluded from the lockout-capable policies, strongly protected and alerting on any use. Break-glass (emergency access) accounts that are cloud-only and excluded from the policies that could cause a lockout, protected with strong credentials and monitored, restore access safely. Disabling Conditional Access, shared passwords or universal admin rights all weaken security.
Question 10. An architect wants to audit, across every subscription, alignment with a recognised standard such as ISO 27001 using built-in content. Which capability provides this?
Answer: A, Azure Policy built-in regulatory compliance initiatives assigned at a management group. Azure Policy provides built-in regulatory initiatives (ISO 27001, NIST, PCI and more) that group the required policies; assigned at a management group they audit alignment across all subscriptions. Checklists, access reviews and endpoint inventory do not assess resource configuration against a standard.
Question 11. Security wants to eliminate the risk that one stolen local administrator password can be reused to move laterally across every workstation. Which capability should the design include?
Answer: D, Windows LAPS to randomise and rotate each device's local admin password, stored in Entra ID. Windows LAPS gives every device a unique, automatically rotated local admin password stored securely in Entra ID or AD, so a credential stolen from one machine cannot be reused elsewhere. A shared password, weaker auth or broad local admin rights all increase lateral-movement risk.
Question 12. A design must keep traffic to an Azure SQL database and a storage account entirely off the public internet while still reachable from the application subnet. Which should the architect use?
Answer: C, Private endpoints (Azure Private Link) with public network access disabled. Private endpoints give the PaaS services a private IP inside the virtual network and, with public network access disabled, keep traffic off the public internet while remaining reachable privately. Public endpoints or public IPs leave the services internet-exposed.
Question 13. A team runs Kubernetes on AKS and needs image scanning, control-plane hardening and runtime threat detection. Which Microsoft solution should the architect specify?
Answer: B, Microsoft Defender for Containers. Defender for Containers provides registry image vulnerability assessment, environment and control-plane hardening, and runtime threat detection for Kubernetes. LAPS, DDoS Protection and Compliance Manager do not secure containers.
Question 14. An architect must inspect outbound TLS-encrypted traffic and detect intrusions at the network edge for a regulated workload. Which should be specified?
Answer: D, Azure Firewall Premium (with TLS inspection and IDPS). Azure Firewall Premium adds TLS inspection and an intrusion detection and prevention system for deep inspection of encrypted egress. NSGs filter by IP and port without payload inspection, DDoS Protection addresses volumetric attacks, and an unfiltered public IP is insecure.
Question 15. An architect must extend Defender for Cloud posture and workload protection to on-premises servers and a GCP project. Which onboarding approach is correct?
Answer: C, Onboard on-premises servers via Azure Arc and connect the GCP project with the multicloud connector. Azure Arc projects on-premises servers into Azure for governance and Defender coverage, and the multicloud connector brings GCP (and AWS) into Defender for Cloud, giving one posture and protection view. Defender for Cloud is not Azure-only, and separate tools lose the unified view.
Question 16. A regulated bank must ensure that even its own database administrators cannot read customers' card numbers stored in Azure SQL, while the rest of the database uses standard at-rest protection. Which combination fits?
Answer: D, Always Encrypted for the card columns, with transparent data encryption (TDE) for the database at rest. Always Encrypted protects specific sensitive columns end to end so administrators cannot see the plaintext, while TDE provides transparent at-rest encryption for the whole database and backups. TDE alone still lets admins read the data, and NSGs or disabling auditing do not protect the column values.
Question 17. An architect must measure and improve the security posture of Microsoft 365 collaboration and productivity workloads with prioritised, points-based actions. Which should be used?
Answer: C, Microsoft Secure Score, alongside Microsoft Defender for Office 365. Microsoft Secure Score measures posture across Microsoft 365 and provides prioritised, points-based improvement actions, complemented by Defender for Office 365 for email and collaboration protection. Cost tools and entitlement management do not measure M365 security posture.
Question 18. A regulated organisation must control the rotation and revocation of the keys that encrypt its Azure Storage data. Which design meets this?
Answer: B, Customer-managed keys (CMK) in Azure Key Vault Premium or Managed HSM, optionally with infrastructure encryption. Customer-managed keys in Key Vault Premium or Managed HSM give the customer control over the key lifecycle, and infrastructure (double) encryption can add a second layer. Platform-managed keys do not give customer control, and disabling encryption or storing keys in config are insecure.
Question 19. An organisation must protect email against weaponised links that are clean at delivery but malicious when clicked, and against malicious attachments. Which Microsoft 365 capability should the architect evaluate?
Answer: D, Microsoft Defender for Office 365 (Safe Links and Safe Attachments). Defender for Office 365 provides Safe Links (time-of-click URL scanning) and Safe Attachments (sandbox detonation), which address exactly these email threats. Azure Firewall, Defender for Storage and LAPS do not protect email and collaboration.
Question 20. A design must protect specific card-number columns in Azure SQL so that even database administrators cannot read the plaintext, while the rest of the database is encrypted at rest transparently. Which combination fits?
Answer: C, Always Encrypted for the card columns plus transparent data encryption for the database. Always Encrypted protects specific columns end to end so administrators cannot see the plaintext, while TDE encrypts the whole database at rest. Masking only obscures results (admins can still read), TDE alone leaves admins able to read the data, and spreadsheets are less secure.
It's an expert-level exam about judgement rather than configuration. Most options in a question would technically work; you have to pick the one an architect would recommend for that organisation's priorities, often inside a case study.
Most people studying part-time plan four to eight weeks, building on the associate-level knowledge they already have. Reading the Microsoft frameworks the exam references is worth the time.
No. Microsoft exam questions are confidential, and sharing them breaks the agreement every candidate accepts. These are original questions written to the published skills outline, so they test the same knowledge in the same style.
You can enrol free with no card. Free accounts get the opening modules of every course; Pro (£9.99 a month, or £79.99 a year) unlocks every module, the full timed mock exam and an adaptive study plan.
Answer each one before you look at the explanation, and keep a list of the ones you get wrong. That list is your study plan: it's made of exactly the things you don't know yet.
CertBuddi is an independent study aid, not affiliated with or endorsed by Microsoft. These are original practice questions, not real exam questions.