ExamGecko
Home Home / Microsoft / SC-100

Microsoft SC-100 Practice Test - Questions Answers, Page 6

Question list
Search
Search

List of questions

Search

Related questions











You have a Microsoft 365 E5 subscription.

You need to recommend a solution to add a watermark to email attachments that contain sensitive dat a. What should you include in the recommendation?

A.

Microsoft Defender for Cloud Apps

A.

Microsoft Defender for Cloud Apps

Answers
B.

insider risk management

B.

insider risk management

Answers
C.

Microsoft Information Protection

C.

Microsoft Information Protection

Answers
D.

Azure Purview

D.

Azure Purview

Answers
Suggested answer: C

Explanation:

https://docs.microsoft.com/en-us/microsoft-365/compliance/sensitivity-labels?view=o365-worldwide

You can use sensitivity labels to: Provide protection settings that include encryption and content markings. For example, apply a "Confidential" label to a document or email, and that label encrypts the content and applies a "Confidential" watermark. Content markings include headers and footers as well as watermarks, and encryption can also restrict what actions authorized people can take on the content. Protect content in Office apps across different platforms and devices. Supported by Word, Excel, PowerPoint, and Outlook on the Office desktop apps and Office on the web. Supported on Windows, macOS, iOS, and Android. Protect content in third-party apps and services by using Microsoft Defender for Cloud Apps. With Defender for Cloud Apps, you can detect, classify, label, and protect content in third-party apps and services, such as SalesForce, Box, or DropBox, even if the third-party app or service does not read or support sensitivity labels.

Your company has a hybrid cloud infrastructure.

The company plans to hire several temporary employees within a brief period. The temporary employees will need to access applications and data on the company' premises network. The company's security policy prevents the use of personal devices for accessing company data and applications. You need to recommend a solution to provide the temporary employee with access to company resources. The solution must be able to scale on demand. What should you include in the recommendation?

A.

Migrate the on-premises applications to cloud-based applications.

A.

Migrate the on-premises applications to cloud-based applications.

Answers
B.

Redesign the VPN infrastructure by adopting a split tunnel configuration.

B.

Redesign the VPN infrastructure by adopting a split tunnel configuration.

Answers
C.

Deploy Microsoft Endpoint Manager and Azure Active Directory (Azure AD) Conditional Access.

C.

Deploy Microsoft Endpoint Manager and Azure Active Directory (Azure AD) Conditional Access.

Answers
D.

Deploy Azure Virtual Desktop, Azure Active Directory (Azure AD) Conditional Access, and Microsoft Defender for Cloud Apps.

D.

Deploy Azure Virtual Desktop, Azure Active Directory (Azure AD) Conditional Access, and Microsoft Defender for Cloud Apps.

Answers
Suggested answer: D

Explanation:

https://docs.microsoft.com/en-us/azure/architecture/example-scenario/wvd/windows-virtual- desktop https://docs.microsoft.com/en-us/azure/virtual-desktop/security-guide https://techcommunity.microsoft.com/t5/security-compliance-and-identity/announcing-microsoft- defender-for-cloud-apps/ba-p/2835842

You have an Azure subscription that contains virtual machines, storage accounts, and Azure SQL databases. All resources are backed up multiple times a day by using Azure Backup. You are developing a strategy to protect against ransomware attacks.

You need to recommend which controls must be enabled to ensure that Azure Backup can be used to restore the resources in the event of a successful\ ransonvware attack. Which two controls should you include in the recommendation? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

A.

Use Azure Monitor notifications when backup configurations change.

A.

Use Azure Monitor notifications when backup configurations change.

Answers
B.

Require PINs for critical operations.

B.

Require PINs for critical operations.

Answers
C.

Perform offline backups to Azure Data Box.

C.

Perform offline backups to Azure Data Box.

Answers
D.

Encrypt backups by using customer-managed keys (CMKs).

D.

Encrypt backups by using customer-managed keys (CMKs).

Answers
E.

Enable soft delete for backups.

E.

Enable soft delete for backups.

Answers
Suggested answer: A, B

Explanation:

https://docs.microsoft.com/en-us/azure/security/fundamentals/backup-plan-to-protect-against- ransomware'You need to recommend which CONTROLS must be enabled to ENSURE that Azure Backup can be used to RESTORE the resources in the event of a successful ransomware attack.' Whilst helpful for auditing purposes and detection of a malicious attack, monitoring configuration changes and alerting after a change is made does not represent a CONTROL which ENSURES Azure Backup can be used to RESTORE the resources.

Your company develops several applications that are accessed as custom enterprise applications in Azure Active Directory (Azure AD). You need to recommend a solution to prevent users on a specific list of countries from connecting to the applications. What should you include in the recommendation?

A.

activity policies in Microsoft Defender for Cloud Apps

A.

activity policies in Microsoft Defender for Cloud Apps

Answers
B.

sign-in risk policies in Azure AD Identity Protection

B.

sign-in risk policies in Azure AD Identity Protection

Answers
C.

device compliance policies in Microsoft Endpoint Manager

C.

device compliance policies in Microsoft Endpoint Manager

Answers
D.

Azure AD Conditional Access policies

D.

Azure AD Conditional Access policies

Answers
E.

user risk policies in Azure AD Identity Protection

E.

user risk policies in Azure AD Identity Protection

Answers
Suggested answer: A

Explanation:

https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional- access-policy-location https://docs.microsoft.com/en-us/power-platform/admin/restrict-access-online-trusted-ip-rules

Your company has a Microsoft 365 subscription and uses Microsoft Defender for Identity. You are informed about incidents that relate to compromised identities. You need to recommend a solution to expose several accounts for attackers to exploit. When the attackers attempt to exploit the accounts, an alert must be triggered. Which Defender for Identity feature should you include in the recommendation?

A.

standalone sensors

A.

standalone sensors

Answers
B.

honeytoken entity tags

B.

honeytoken entity tags

Answers
C.

sensitivity labels

C.

sensitivity labels

Answers
D.

custom user tags

D.

custom user tags

Answers
Suggested answer: B

Explanation:

https://docs.microsoft.com/en-us/advanced-threat-analytics/suspicious-activity-guide#honeytoken- activityThe Sensitive tag is used to identify high value assets.(user / devices / groups)Honeytoken entities are used as traps for malicious actors. Any authentication associated with these honeytoken entities triggers an alert. and Defender for Identity considers Exchange servers as high-value assets and automatically tags them as Sensitive

You have a Microsoft 365 E5 subscription and an Azure subscription. You are designing a Microsoft Sentinel deployment. You need to recommend a solution for the security operations team. The solution must include custom views and a dashboard for analyzing security events. What should you recommend using in Microsoft Sentinel?

A.

playbooks

A.

playbooks

Answers
B.

workbooks

B.

workbooks

Answers
C.

notebooks

C.

notebooks

Answers
D.

threat intelligence

D.

threat intelligence

Answers
Suggested answer: B

Explanation:

https://docs.microsoft.com/en-us/azure/azure-monitor/visualize/workbooks-overview

Your company has an on-premise network in Seattle and an Azure subscription. The on-premises network contains a Remote Desktop server. The company contracts a third-party development firm from France to develop and deploy resources to the virtual machines hosted in the Azure subscription. Currently, the firm establishes an RDP connection to the Remote Desktop server. From the Remote Desktop connection, the firm can access the virtual machines hosted in Azure by using custom administrative tools installed on the Remote Desktop server. All the traffic to the Remote Desktop server is captured by a firewall, and the firewall only allows specific connections from France to the server. You need to recommend a modern security solution based on the Zero Trust model. The solution must minimize latency tor developers. Which three actions should you recommend? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.

Configure network security groups (NSGs) to allow access from only specific logical groupings of IP address ranges.

A.

Configure network security groups (NSGs) to allow access from only specific logical groupings of IP address ranges.

Answers
B.

Implement Azure Firewall to restrict host pool outbound access.

B.

Implement Azure Firewall to restrict host pool outbound access.

Answers
C.

Configure Azure Active Directory (Azure AD) Conditional Access with multi-factor authentication

(MFA) and named locations.

C.

Configure Azure Active Directory (Azure AD) Conditional Access with multi-factor authentication

(MFA) and named locations.

Answers
D.

Migrate from the Remote Desktop server to Azure Virtual Desktop.

D.

Migrate from the Remote Desktop server to Azure Virtual Desktop.

Answers
E.

Deploy a Remote Desktop server to an Azure region located in France.

E.

Deploy a Remote Desktop server to an Azure region located in France.

Answers
Suggested answer: B, C, D

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/firewall/protect-azure-virtual-desktop

Your company is moving all on-premises workloads to Azure and Microsoft 365. Vou need to design a security orchestration, automation, and response (SOAR) strategy in Microsoft Sentinel that meets the following requirements:

• Minimizes manual intervention by security operation analysts

• Supports Waging alerts within Microsoft Teams channels

What should you include in the strategy?

A.

data connectors

A.

data connectors

Answers
B.

playbooks

B.

playbooks

Answers
C.

workbooks

C.

workbooks

Answers
D.

KQL

D.

KQL

Answers
Suggested answer: B

Explanation:


Your company plans to provision blob storage by using an Azure Storage account The blob storage will be accessible from 20 application sewers on the internet. You need to recommend a solution to ensure that only the application servers can access the storage account. What should you recommend using to secure the blob storage?

A.

service tags in network security groups (NSGs)

A.

service tags in network security groups (NSGs)

Answers
B.

managed rule sets in Azure Web Application Firewall (WAF) policies

B.

managed rule sets in Azure Web Application Firewall (WAF) policies

Answers
C.

inbound rules in network security groups (NSGs)

C.

inbound rules in network security groups (NSGs)

Answers
D.

firewall rules for the storage account

D.

firewall rules for the storage account

Answers
E.

inbound rules in Azure Firewall

E.

inbound rules in Azure Firewall

Answers
Suggested answer: D

Your company has a Microsoft 365 E5 subscription.

The company plans to deploy 45 mobile self-service kiosks that will run Windows

10. You need to provide recommendations to secure the kiosks. The solution must meet the following requirements:

• Ensure that only authorized applications can run on the kiosks.

• Regularly harden the kiosks against new threats.

Which two actions should you include in the recommendations? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

A.

Onboard the kiosks to Azure Monitor.

A.

Onboard the kiosks to Azure Monitor.

Answers
B.

Implement Privileged Access Workstation (PAW) for the kiosks.

B.

Implement Privileged Access Workstation (PAW) for the kiosks.

Answers
C.

Implement Automated Investigation and Remediation (AIR) in Microsoft Defender for Endpoint.

C.

Implement Automated Investigation and Remediation (AIR) in Microsoft Defender for Endpoint.

Answers
D.

Implement threat and vulnerability management in Microsoft Defender for Endpoint.

D.

Implement threat and vulnerability management in Microsoft Defender for Endpoint.

Answers
E.

Onboard the kiosks to Microsoft Intune and Microsoft Defender for Endpoint.

E.

Onboard the kiosks to Microsoft Intune and Microsoft Defender for Endpoint.

Answers
Suggested answer: D, E

Explanation:

(https://docs.microsoft.com/en-us/microsoft-365/security/defender-vulnerability- management/defender-vulnerability-management?view=o365-worldwide)

Total 177 questions
Go to page: of 18