SC-100 practice questions

20 free SC-100 practice questions with answers and explanations, covering Zero Trust and Microsoft security best practices, security operations and identity, infrastructure security, and application and data security.

Study the full SC-100 course, free to start.

SC-100 exam at a glance

Skills measured from 21 October 2026

Official SC-100 study guide on Microsoft Learn

20 free SC-100 practice questions

Design solutions that align with security best practices and priorities

Question 1. Leadership asks whether to use the CAF or the WAF to guide an organisation-wide cloud adoption and governance programme spanning strategy, landing zones and ongoing management. Which framework fits, and why?

  1. The WAF, because it is organisation-scoped and covers governance
  2. The CAF, because it reviews a single workload across five pillars
  3. The WAF, because it provisions landing zones
  4. The CAF, because it is organisation-scoped and covers the full adoption journey and governance
Show answer

Answer: D, The CAF, because it is organisation-scoped and covers the full adoption journey and governance. The Cloud Adoption Framework is organisation-scoped and covers the whole journey (Strategy, Plan, Ready, Adopt, Govern, Manage, Secure). The Well-Architected Framework is workload-scoped and reviews one architecture across five quality pillars, so it does not drive an org-wide programme.

Question 2. A stakeholder says 'we bought a Zero Trust product, so we are done'. What is the most accurate architect response?

  1. Zero Trust means trusting everything inside the corporate network
  2. Zero Trust only applies to the network firewall
  3. Zero Trust is a strategy applied across identity, endpoints, data, apps, infrastructure and network, not a single product
  4. Correct, one product fully implements Zero Trust
Show answer

Answer: C, Zero Trust is a strategy applied across identity, endpoints, data, apps, infrastructure and network, not a single product. Zero Trust is an end-to-end strategy built on verify explicitly, least privilege and assume breach, applied across all six pillars. No single product delivers it, and it explicitly rejects trusting the internal network by default.

Question 3. A team wants to add security to the software delivery process, covering design, code, pipeline and operations. Which approach and example controls should the architect recommend?

  1. A single annual manual security review after release
  2. Security only at the operations stage, once live
  3. DevSecOps: threat modelling in design, dependency and secret scanning in code, automated checks in the pipeline, posture management and pen testing in operations
  4. Relying on developers to remember to check security
Show answer

Answer: C, DevSecOps: threat modelling in design, dependency and secret scanning in code, automated checks in the pipeline, posture management and pen testing in operations. DevSecOps shifts security left, adding controls at design, code, pipeline and operations so issues are caught early and consistently. A single late review, operations-only security, or ad hoc developer effort all leave gaps that shifting left is designed to close.

Question 4. An architect is defining the recovery plan for ransomware resilience. Which pair of measures sets how much data loss and how much downtime are acceptable, and so drives the backup design?

  1. Mean time between failures (MTBF) and mean time to detect (MTTD)
  2. Recovery point objective (RPO) and recovery time objective (RTO)
  3. Service level agreement (SLA) and key performance indicator (KPI)
  4. Attack surface reduction (ASR) and multifactor authentication (MFA)
Show answer

Answer: B, Recovery point objective (RPO) and recovery time objective (RTO). RPO sets the maximum acceptable data loss (how far back you must be able to restore) and RTO sets the maximum acceptable downtime (how quickly you must restore). Together they drive backup frequency, immutability and restore testing. The other pairs are unrelated reliability, contract or preventive-control terms.

Question 5. An architect is threat modelling a new generative AI copilot using STRIDE, but a colleague argues STRIDE alone is enough and no AI-specific guidance is needed. Following CAF guidance for secure AI adoption, how should the architect respond?

  1. Agree, because STRIDE alone fully covers generative AI risks
  2. Supplement STRIDE with AI-specific frameworks such as MITRE ATLAS and the OWASP Top 10 for Generative AI, since these cover risks like prompt injection and model manipulation that STRIDE does not name
  3. Skip threat modelling entirely for AI workloads since they are still new
  4. Replace STRIDE entirely, since it does not apply to any cloud workload
Show answer

Answer: B, Supplement STRIDE with AI-specific frameworks such as MITRE ATLAS and the OWASP Top 10 for Generative AI, since these cover risks like prompt injection and model manipulation that STRIDE does not name. CAF's discover-AI-security-risks discipline supplements general threat modelling like STRIDE with AI-specific guidance such as MITRE ATLAS and the OWASP Top 10 for Generative AI, which name risks (prompt injection, model manipulation, training data poisoning) that STRIDE alone does not capture. Dropping STRIDE or skipping modelling both leave the design unassessed.

Design security operations, identity, and compliance capabilities

Question 6. Security wants even a Global Administrator to be forced through phishing-resistant MFA from a compliant device before they can modify Conditional Access policies, so a stolen token alone cannot weaken the controls. What should the architect use?

  1. A break-glass account
  2. A named location policy
  3. Password protection
  4. Protected actions
Show answer

Answer: D, Protected actions. Protected actions attach a step-up Conditional Access requirement to specific high-impact permission operations, such as editing Conditional Access policies, protecting the controls themselves. Named locations and password protection do not gate individual sensitive operations this way.

Question 7. Contoso must let partner organisations access a shared application using their own corporate identities, with the trust relationship governed centrally. Which design should the architect choose?

  1. A shared username and password for all partners
  2. Microsoft Entra External ID B2B collaboration with cross-tenant access settings
  3. Creating internal Entra accounts for every partner user
  4. Federating the partners into on-premises Active Directory
Show answer

Answer: B, Microsoft Entra External ID B2B collaboration with cross-tenant access settings. B2B collaboration lets external users bring their own identities as guests, governed by cross-tenant access settings that centrally define inbound and outbound trust. Creating internal accounts or sharing credentials increases risk and administrative burden and abandons the partner's own identity lifecycle.

Question 8. A design must respond automatically when a sign-in looks risky, for example from an anonymising proxy, by requiring MFA. Which capability provides the risk signal and response, and what licence is needed?

  1. Microsoft Entra ID Protection with risk-based Conditional Access, requiring Entra ID P2
  2. Azure Policy with a deny effect, no licence needed
  3. Microsoft Purview DLP, requiring E3
  4. A network security group, requiring no licence
Show answer

Answer: A, Microsoft Entra ID Protection with risk-based Conditional Access, requiring Entra ID P2. Entra ID Protection scores sign-in and user risk, and risk-based Conditional Access responds (for example requiring MFA); risk-based policies require Microsoft Entra ID P2. Azure Policy, DLP and NSGs do not evaluate identity risk.

Question 9. An architect wants to prevent a misconfigured Conditional Access policy from locking every administrator out of the tenant. What should the design include?

  1. Disabling Conditional Access entirely
  2. One shared admin password written down
  3. Two or more cloud-only break-glass accounts, excluded from the lockout-capable policies, strongly protected and alerting on any use
  4. Making every user a Global Administrator
Show answer

Answer: C, Two or more cloud-only break-glass accounts, excluded from the lockout-capable policies, strongly protected and alerting on any use. Break-glass (emergency access) accounts that are cloud-only and excluded from the policies that could cause a lockout, protected with strong credentials and monitored, restore access safely. Disabling Conditional Access, shared passwords or universal admin rights all weaken security.

Question 10. An architect wants to audit, across every subscription, alignment with a recognised standard such as ISO 27001 using built-in content. Which capability provides this?

  1. Azure Policy built-in regulatory compliance initiatives assigned at a management group
  2. A manually maintained checklist
  3. Microsoft Entra access reviews
  4. Microsoft Defender for Endpoint device inventory
Show answer

Answer: A, Azure Policy built-in regulatory compliance initiatives assigned at a management group. Azure Policy provides built-in regulatory initiatives (ISO 27001, NIST, PCI and more) that group the required policies; assigned at a management group they audit alignment across all subscriptions. Checklists, access reviews and endpoint inventory do not assess resource configuration against a standard.

Design security solutions for infrastructure

Question 11. Security wants to eliminate the risk that one stolen local administrator password can be reused to move laterally across every workstation. Which capability should the design include?

  1. Granting all users local administrator rights
  2. A single strong local admin password documented in a shared vault
  3. Disabling MFA to simplify admin logins
  4. Windows LAPS to randomise and rotate each device's local admin password, stored in Entra ID
Show answer

Answer: D, Windows LAPS to randomise and rotate each device's local admin password, stored in Entra ID. Windows LAPS gives every device a unique, automatically rotated local admin password stored securely in Entra ID or AD, so a credential stolen from one machine cannot be reused elsewhere. A shared password, weaker auth or broad local admin rights all increase lateral-movement risk.

Question 12. A design must keep traffic to an Azure SQL database and a storage account entirely off the public internet while still reachable from the application subnet. Which should the architect use?

  1. A site-to-site VPN to Microsoft's datacentre
  2. A public endpoint restricted by a weak firewall rule
  3. Private endpoints (Azure Private Link) with public network access disabled
  4. Exposing the services with a public IP and NSG
Show answer

Answer: C, Private endpoints (Azure Private Link) with public network access disabled. Private endpoints give the PaaS services a private IP inside the virtual network and, with public network access disabled, keep traffic off the public internet while remaining reachable privately. Public endpoints or public IPs leave the services internet-exposed.

Question 13. A team runs Kubernetes on AKS and needs image scanning, control-plane hardening and runtime threat detection. Which Microsoft solution should the architect specify?

  1. Windows LAPS
  2. Microsoft Defender for Containers
  3. Azure DDoS Protection
  4. Microsoft Purview Compliance Manager
Show answer

Answer: B, Microsoft Defender for Containers. Defender for Containers provides registry image vulnerability assessment, environment and control-plane hardening, and runtime threat detection for Kubernetes. LAPS, DDoS Protection and Compliance Manager do not secure containers.

Question 14. An architect must inspect outbound TLS-encrypted traffic and detect intrusions at the network edge for a regulated workload. Which should be specified?

  1. A standard network security group
  2. Azure DDoS Protection alone
  3. A public IP with no filtering
  4. Azure Firewall Premium (with TLS inspection and IDPS)
Show answer

Answer: D, Azure Firewall Premium (with TLS inspection and IDPS). Azure Firewall Premium adds TLS inspection and an intrusion detection and prevention system for deep inspection of encrypted egress. NSGs filter by IP and port without payload inspection, DDoS Protection addresses volumetric attacks, and an unfiltered public IP is insecure.

Question 15. An architect must extend Defender for Cloud posture and workload protection to on-premises servers and a GCP project. Which onboarding approach is correct?

  1. Only Azure resources can be protected, so nothing can be done
  2. Rebuild all workloads in Azure first
  3. Onboard on-premises servers via Azure Arc and connect the GCP project with the multicloud connector
  4. Install a separate, unintegrated tool in each environment
Show answer

Answer: C, Onboard on-premises servers via Azure Arc and connect the GCP project with the multicloud connector. Azure Arc projects on-premises servers into Azure for governance and Defender coverage, and the multicloud connector brings GCP (and AWS) into Defender for Cloud, giving one posture and protection view. Defender for Cloud is not Azure-only, and separate tools lose the unified view.

Design security solutions for applications and data

Question 16. A regulated bank must ensure that even its own database administrators cannot read customers' card numbers stored in Azure SQL, while the rest of the database uses standard at-rest protection. Which combination fits?

  1. Only network security groups on the database subnet
  2. TDE alone for the whole database
  3. Disabling auditing to reduce exposure of the data
  4. Always Encrypted for the card columns, with transparent data encryption (TDE) for the database at rest
Show answer

Answer: D, Always Encrypted for the card columns, with transparent data encryption (TDE) for the database at rest. Always Encrypted protects specific sensitive columns end to end so administrators cannot see the plaintext, while TDE provides transparent at-rest encryption for the whole database and backups. TDE alone still lets admins read the data, and NSGs or disabling auditing do not protect the column values.

Question 17. An architect must measure and improve the security posture of Microsoft 365 collaboration and productivity workloads with prioritised, points-based actions. Which should be used?

  1. The Azure pricing calculator
  2. Microsoft Entra entitlement management only
  3. Microsoft Secure Score, alongside Microsoft Defender for Office 365
  4. Azure Advisor cost recommendations
Show answer

Answer: C, Microsoft Secure Score, alongside Microsoft Defender for Office 365. Microsoft Secure Score measures posture across Microsoft 365 and provides prioritised, points-based improvement actions, complemented by Defender for Office 365 for email and collaboration protection. Cost tools and entitlement management do not measure M365 security posture.

Question 18. A regulated organisation must control the rotation and revocation of the keys that encrypt its Azure Storage data. Which design meets this?

  1. Rely on the default platform-managed keys
  2. Customer-managed keys (CMK) in Azure Key Vault Premium or Managed HSM, optionally with infrastructure encryption
  3. Disable encryption to simplify key handling
  4. Store the key in the application configuration
Show answer

Answer: B, Customer-managed keys (CMK) in Azure Key Vault Premium or Managed HSM, optionally with infrastructure encryption. Customer-managed keys in Key Vault Premium or Managed HSM give the customer control over the key lifecycle, and infrastructure (double) encryption can add a second layer. Platform-managed keys do not give customer control, and disabling encryption or storing keys in config are insecure.

Question 19. An organisation must protect email against weaponised links that are clean at delivery but malicious when clicked, and against malicious attachments. Which Microsoft 365 capability should the architect evaluate?

  1. Azure Firewall Premium
  2. Microsoft Defender for Storage
  3. Windows LAPS
  4. Microsoft Defender for Office 365 (Safe Links and Safe Attachments)
Show answer

Answer: D, Microsoft Defender for Office 365 (Safe Links and Safe Attachments). Defender for Office 365 provides Safe Links (time-of-click URL scanning) and Safe Attachments (sandbox detonation), which address exactly these email threats. Azure Firewall, Defender for Storage and LAPS do not protect email and collaboration.

Question 20. A design must protect specific card-number columns in Azure SQL so that even database administrators cannot read the plaintext, while the rest of the database is encrypted at rest transparently. Which combination fits?

  1. Dynamic data masking plus a network security group
  2. Transparent data encryption alone
  3. Always Encrypted for the card columns plus transparent data encryption for the database
  4. Deleting the columns and storing them in a spreadsheet
Show answer

Answer: C, Always Encrypted for the card columns plus transparent data encryption for the database. Always Encrypted protects specific columns end to end so administrators cannot see the plaintext, while TDE encrypts the whole database at rest. Masking only obscures results (admins can still read), TDE alone leaves admins able to read the data, and spreadsheets are less secure.

A 4-week SC-100 study plan

Frequently asked questions

How hard is SC-100?

It's an expert-level exam about judgement rather than configuration. Most options in a question would technically work; you have to pick the one an architect would recommend for that organisation's priorities, often inside a case study.

How long should I study for SC-100?

Most people studying part-time plan four to eight weeks, building on the associate-level knowledge they already have. Reading the Microsoft frameworks the exam references is worth the time.

Are these real SC-100 exam questions?

No. Microsoft exam questions are confidential, and sharing them breaks the agreement every candidate accepts. These are original questions written to the published skills outline, so they test the same knowledge in the same style.

Is CertBuddi free?

You can enrol free with no card. Free accounts get the opening modules of every course; Pro (£9.99 a month, or £79.99 a year) unlocks every module, the full timed mock exam and an adaptive study plan.

How should I use these practice questions?

Answer each one before you look at the explanation, and keep a list of the ones you get wrong. That list is your study plan: it's made of exactly the things you don't know yet.

CertBuddi is an independent study aid, not affiliated with or endorsed by Microsoft. These are original practice questions, not real exam questions.