SC-100 Exam Question 11

You are designing a security operations strategy based on the Zero Trust framework.
You need to minimize the operational load on Tier 1 Microsoft Security Operations Center (SOC) analysts.
What should you do?
  • SC-100 Exam Question 12

    You are a security administrator for Microsoft 365; you implemented Microsoft Defender for Identity You have created several test accounts with specific configurations for the purpose of vulnerability testing, When attackers try to exploit these accounts, you would like to be alerted to see what areas in the configuration needs improvements.
    What features in Microsoft Defender for Identity can you use to meet your objective?
  • SC-100 Exam Question 13

    Hotspot Question
    You have an Azure subscription and an on-premises datacenter. The datacenter contains 100 servers that run Windows Server. All the servers are backed up to a Recovery Services vault by using Azure Backup and the Microsoft Azure Recovery Services (MARS) agent.
    You need to design a recovery solution for ransomware attacks that encrypt the on-premises servers. The solution must follow Microsoft Security Best Practices and protect against the following risks:
    - A compromised administrator account used to delete the backups from
    Azure Backup before encrypting the servers
    - A compromised administrator account used to disable the backups on
    the MARS agent before encrypting the servers
    What should you use for each risk? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-100 Exam Question 14

    You have a Microsoft 365 E5 subscription and an Azure subscription.
    You need to recommend a solution to enforce the Zero Trust principle of explicit verification for the subscriptions. The solution must be based on Zero Trust guidance in the Microsoft Cybersecurity Reference Architectures (MCRA).
    What should you include in the recommendation?
  • SC-100 Exam Question 15

    You are designing the security standards for containerized applications onboarded to Azure.
    You are evaluating the use of Microsoft Defender for Containers.
    In which two environments can you use Defender for Containers to scan for known vulnerabilities? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.