dc dotCreds
Microsoft Cybersecurity Architect

SC-100 Practice Test

Start today’s free 10-question SC-100 set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 12, 2026, 3:38 PM CDT

Go Pro - One Time Unlock

Unlock the full SC-100 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 SC-100 questions

Use this SC-100 practice test to review Microsoft Cybersecurity Architect. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Design modern identity, authentication, authorization, and external access Design security operations, identity, and compliance capabilities

A report-only Conditional Access pilot shows that a policy would block the emergency access account. How should the architect proceed?

Concept tested:
Question 2 of 10
Objective Align security and governance with CAF, WAF, landing zones, and DevSecOps Design solutions that align with security best practices and priorities

A platform team must apply identity, connectivity, management, policy, and security foundations consistently before workload subscriptions are created. What should it implement?

Concept tested:
Question 3 of 10
Objective Design secure backup and restore for business continuity and disaster recovery Design solutions that align with security best practices and priorities

Backup monitoring reports mass deletion attempts, and the restore runbook starts applications before identity, DNS, networking, and keys. What should the response and recovery design require?

Concept tested:
Question 4 of 10
Objective Secure local administrator passwords with Windows LAPS Design security solutions for infrastructure

LAPS generates unique passwords, but they are backed up to an unapproved location, many help-desk users can retrieve them, and rotation is not audited. What should be redesigned?

Concept tested:
Question 5 of 10
Objective Design centralized logging, auditing, and activity investigation Design security operations, identity, and compliance capabilities

Help-desk staff need no investigative role but can search all Microsoft 365 user and administrator activity. What should the architect change?

Concept tested:
Question 6 of 10
Objective Evaluate Microsoft 365 security posture and protection Design security solutions for applications and data

Copilot reveals overshared data, and management responds by chasing Secure Score points with no assigned remediation owners. What should the architect do?

Concept tested:
Question 7 of 10
Objective Align solutions with the Microsoft Cloud Security Benchmark Design solutions that align with security best practices and priorities

A team marks an MCSB recommendation complete because a policy is assigned, but no evidence shows the control operates effectively. What should governance require?

Concept tested:
Question 8 of 10
Objective Specify security requirements for cloud workloads and containers Design security solutions for infrastructure

A team moves from VMs to containers and plans to patch production containers manually while leaving identity and network controls unchanged. What should the architect require?

Concept tested:
Question 9 of 10
Objective Design data discovery, classification, and threat priorities Design security solutions for applications and data

A data catalog locates files but assigns no sensitivity or business meaning, so every file receives the same access and retention. What should the architect add?

Concept tested:
Question 10 of 10
Objective Specify endpoint baselines and Windows LAPS requirements Design security solutions for infrastructure

A piloted Windows baseline deployed successfully, but six months later many endpoints have drifted from its settings. What should the program add?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
SC-100 Pro $4.99 one-time

Best if you only need this one certification.

50 Exam Practice Test $1.99 one-time

A 50-question SC-100 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Microsoft Security Bundle $9.99 one-time

Unlock all 6 active Microsoft Security Bundle practice banks in one permanent purchase.

What’s includedSC-900, SC-200, SC-300, SC-401, SC-500, SC-100
All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full SC-100 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily SC-100 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily SC-100 set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A report-only Conditional Access pilot shows that a policy would block the emergency access account. How should the architect proceed?

Answer choices

  1. A. Remove all monitoring from the emergency identity without replacement protection
  2. B. Narrowly exclude, protect and monitor emergency access; validate policy scope.
  3. C. Exclude every administrator permanently without scope controls
  4. D. Enable the policy and hope the account is unnecessary without owner or exception governance

Correct answer

Narrowly exclude, protect and monitor emergency access; validate policy scope.

Safe rollout uses report-only evidence, while emergency access needs a deliberate governed exclusion, protected credentials, and monitoring rather than accidental blockage.

Wrong-answer review

  • A. Remove all monitoring from the emergency identity without replacement protection: Emergency use is highly sensitive and should receive stronger, not weaker, monitoring.
  • C. Exclude every administrator permanently without scope controls: A universal administrator exclusion defeats the policy’s privileged-access protection.
  • D. Enable the policy and hope the account is unnecessary without owner or exception governance: Blocking the recovery identity can make the tenant inaccessible during control failure.

Extra learning features

Why this matters

Failure to exclude the emergency account from Conditional Access could render the tenant inaccessible during a control failure, severely disrupting business operations and potentially leading to prolonged downtime. This highlights the critical need for careful governance of emergency access policies.

Objective/domain: Design security operations, identity, and compliance capabilities

Source: Microsoft Entra Conditional Access overview

Question 2 A platform team must apply identity, connectivity, management, policy, and security foundations consistently before workload subscriptions are created. What should it implement?

Answer choices

  1. A. A separate manually configured platform for every workload
  2. B. An application threat model only without scope controls
  3. C. A Secure Score improvement plan without owner or exception governance
  4. D. Use an Azure landing-zone foundation with shared platform controls.

Correct answer

Use an Azure landing-zone foundation with shared platform controls.

Objective/domain: Design solutions that align with security best practices and priorities

Source: Security in the Cloud Adoption Framework

Question 3 Backup monitoring reports mass deletion attempts, and the restore runbook starts applications before identity, DNS, networking, and keys. What should the response and recovery design require?

Answer choices

  1. A. Investigate the alert and restore dependencies in a tested sequence.
  2. B. Use the same sequence for every service without dependency analysis
  3. C. Ignore backup alerts during incidents without replacement protection
  4. D. Restore applications first because they are customer-facing

Correct answer

Investigate the alert and restore dependencies in a tested sequence.

Objective/domain: Design solutions that align with security best practices and priorities

Source: Azure Backup security features

Question 4 LAPS generates unique passwords, but they are backed up to an unapproved location, many help-desk users can retrieve them, and rotation is not audited. What should be redesigned?

Answer choices

  1. A. Disable rotation to simplify access without replacement protection
  2. B. Publish the passwords in device inventory without owner or exception governance
  3. C. Return to one shared local password with broad access
  4. D. Define backup location, least-privileged retrieval, rotation and auditing.

Correct answer

Define backup location, least-privileged retrieval, rotation and auditing.

Objective/domain: Design security solutions for infrastructure

Source: Windows Local Administrator Password Solution overview

Question 5 Help-desk staff need no investigative role but can search all Microsoft 365 user and administrator activity. What should the architect change?

Answer choices

  1. A. Restrict audit access to authorized least-privileged roles and monitor use.
  2. B. Export all audit records to a public share without scope controls
  3. C. Disable Purview Audit entirely without replacement protection
  4. D. Give every employee the same access without scope controls

Correct answer

Restrict audit access to authorized least-privileged roles and monitor use.

Objective/domain: Design security operations, identity, and compliance capabilities

Source: Search the Microsoft Purview audit log

Question 6 Copilot reveals overshared data, and management responds by chasing Secure Score points with no assigned remediation owners. What should the architect do?

Answer choices

  1. A. Increase the score through unrelated low-impact actions without owner or exception governance
  2. B. Remediate permissions, sensitivity, retention, audit and DLP by risk.
  3. C. Assume Copilot caused the underlying permissions without owner or exception governance
  4. D. Disable all posture reporting without replacement protection

Correct answer

Remediate permissions, sensitivity, retention, audit and DLP by risk.

Objective/domain: Design security solutions for applications and data

Source: Microsoft Secure Score

Question 7 A team marks an MCSB recommendation complete because a policy is assigned, but no evidence shows the control operates effectively. What should governance require?

Answer choices

  1. A. Count the recommendation twice to improve reporting without owner or exception governance
  2. B. Validate evidence, monitoring, ownership and exceptions against risk.
  3. C. Remove the benchmark from governance without replacement protection
  4. D. Accept the assignment as conclusive implementation proof without owner or exception governance

Correct answer

Validate evidence, monitoring, ownership and exceptions against risk.

Objective/domain: Design solutions that align with security best practices and priorities

Source: Microsoft Cloud Security Benchmark overview

Question 8 A team moves from VMs to containers and plans to patch production containers manually while leaving identity and network controls unchanged. What should the architect require?

Answer choices

  1. A. Use trusted rebuilt images; retain customer identity, network, data and app controls.
  2. B. Patch each running container and keep it indefinitely without owner or exception governance
  3. C. Assume the orchestrator owns every customer security decision without scope controls
  4. D. Disable image scanning because the platform is managed without replacement protection

Correct answer

Use trusted rebuilt images; retain customer identity, network, data and app controls.

Objective/domain: Design security solutions for infrastructure

Source: Azure security best practices and patterns

Question 9 A data catalog locates files but assigns no sensitivity or business meaning, so every file receives the same access and retention. What should the architect add?

Answer choices

  1. A. Delete the catalog because location is insufficient without replacement protection
  2. B. Use file size as the only security label without scope controls
  3. C. Apply one maximum restriction to all data permanently without scope controls
  4. D. Classify by content/context; apply proportional access, protection, retention and monitoring.

Correct answer

Classify by content/context; apply proportional access, protection, retention and monitoring.

Objective/domain: Design security solutions for applications and data

Source: Data discovery and classification

Question 10 A piloted Windows baseline deployed successfully, but six months later many endpoints have drifted from its settings. What should the program add?

Answer choices

  1. A. Reimage every endpoint without investigating drift without scope controls
  2. B. Assume the initial deployment remains effective without owner or exception governance
  3. C. Monitor baseline compliance and remediate or govern exceptions.
  4. D. Stop versioning the baseline to avoid future changes without owner or exception governance

Correct answer

Monitor baseline compliance and remediate or govern exceptions.

Objective/domain: Design security solutions for infrastructure

Source: Windows security baselines

Where to go after the daily web set

How are SC-100 questions generated?

dotCreds builds SC-100 practice questions from public exam objectives and Microsoft Learn and exam-objective references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start SC-100 practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.