dc dotCreds
Microsoft Cybersecurity Architect

SC-100 Practice Test

Start today’s free 10-question SC-100 set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 7, 2026, 9:59 AM CDT

Go Pro - One Time Unlock

Unlock the full SC-100 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 SC-100 questions

Use this SC-100 practice test to review Microsoft Cybersecurity Architect. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Discover external attack surface with Defender EASM Design security solutions for infrastructure

Internal inventory omits a supplier-hosted portal using the company domain, but EASM discovers it. What should the organization do?

Concept tested:
Question 2 of 10
Objective Design centralized logging, auditing, and activity investigation Design security operations, identity, and compliance capabilities

A central log record shows an operation name but omits actor, target, result, timestamp normalization, and source. Why must the architecture change?

Concept tested:
Question 3 of 10
Objective Align security and governance with CAF, WAF, landing zones, and DevSecOps Design solutions that align with security best practices and priorities

A landing-zone policy is assigned everywhere, and leadership reports success without checking whether workloads comply or business risk declined. What should governance measure?

Concept tested:
Question 4 of 10
Objective Design privileged access and identity governance Design security operations, identity, and compliance capabilities

Administrators use a break-glass account for routine changes because it is always available. What should the privileged-access design require?

Concept tested:
Question 5 of 10
Objective Design secure backup and restore for business continuity and disaster recovery Design solutions that align with security best practices and priorities

Production and backup administrators currently use the same permanent account. Which change best protects recovery operations?

Concept tested:
Question 6 of 10
Objective Evaluate application threats with threat modeling Design security solutions for applications and data

A threat model contains many categories but no owner has implemented or tested the mitigation for a likely account-takeover path. What should be prioritized?

Concept tested:
Question 7 of 10
Objective Design access for agent and workload identities Design security operations, identity, and compliance capabilities

An employee sponsoring several agents leaves the company. What should identity governance do?

Concept tested:
Question 8 of 10
Objective Align solutions with the Microsoft Cloud Security Benchmark Design solutions that align with security best practices and priorities

A regulator cites one framework, while the cloud team wants to implement every MCSB recommendation identically across all workloads. What should the architect do?

Concept tested:
Question 9 of 10
Objective Design a full-lifecycle application security strategy Design security solutions for applications and data

A build uses an untracked library and writes a deployment secret into logs. Which SDL controls are required?

Concept tested:
Question 10 of 10
Objective Specify security requirements for cloud workloads and containers Design security solutions for infrastructure

A Kubernetes program trusts any public image and focuses only on scanning, leaving secrets, admission, workload identity, and network policy undesigned. What should the architect require?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
SC-100 Pro $4.99 one-time

Best if you only need this one certification.

50 Exam Practice Test $1.99 one-time

A 50-question SC-100 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Microsoft Access $6.99/month

Unlock Microsoft, Azure, Power Platform, Copilot, and AI practice exams.

Why it fitsUnlock Microsoft, Azure, Power Platform, Copilot, and AI practice exams, Includes current and future Microsoft practice banks on dotCreds, Best for learners taking more than one Microsoft exam, PDF downloads sold separately where available

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full SC-100 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily SC-100 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily SC-100 set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 Internal inventory omits a supplier-hosted portal using the company domain, but EASM discovers it. What should the organization do?

Answer choices

  1. A. Validate the external asset, identify its owner and dependency, then assign remediation based on evidence
  2. B. Ignore anything absent from the internal CMDB
  3. C. Shut down the supplier connection without verification
  4. D. Treat EASM discovery as proof the portal is malicious

Correct answer

Validate the external asset, identify its owner and dependency, then assign remediation based on evidence

External discovery complements internal inventory by revealing unknown dependencies, but ownership and context must be validated before remediation.

Wrong-answer review

  • B. Ignore anything absent from the internal CMDB: The inventory gap is the reason the EASM finding is important.
  • C. Shut down the supplier connection without verification: Immediate disruption can harm a legitimate business dependency.
  • D. Treat EASM discovery as proof the portal is malicious: Internet exposure is not itself proof of malicious ownership or activity.

Extra learning features

Why candidates miss this

The distractors 'Ignore anything absent from the internal CMDB' and 'Treat EASM discovery as proof the portal is malicious' are tempting because they represent immediate, reactive responses. The decisive clue that eliminates them is the emphasis on ‘validation,’ requiring a deeper investigation to determine the true nature of the external asset and its potential impact.

Objective/domain: Design security solutions for infrastructure

Source: Microsoft Defender External Attack Surface Management overview

Question 2 A central log record shows an operation name but omits actor, target, result, timestamp normalization, and source. Why must the architecture change?

Answer choices

  1. A. Operation name alone uniquely proves the full incident
  2. B. Retention will reconstruct the missing fields automatically
  3. C. Preserve time, identity, source, operation, target, result, and correlation context for reliable investigation
  4. D. Remove all fields except severity

Correct answer

Preserve time, identity, source, operation, target, result, and correlation context for reliable investigation

Objective/domain: Design security operations, identity, and compliance capabilities

Source: Search the Microsoft Purview audit log

Question 3 A landing-zone policy is assigned everywhere, and leadership reports success without checking whether workloads comply or business risk declined. What should governance measure?

Answer choices

  1. A. Platform and workload ownership plus control effectiveness and business outcomes, not policy assignment counts alone
  2. B. Only the number of policy objects
  3. C. Only workload-team security work
  4. D. Only platform-team activity

Correct answer

Platform and workload ownership plus control effectiveness and business outcomes, not policy assignment counts alone

Objective/domain: Design solutions that align with security best practices and priorities

Source: Security in the Cloud Adoption Framework

Question 4 Administrators use a break-glass account for routine changes because it is always available. What should the privileged-access design require?

Answer choices

  1. A. Add the account to more daily workflows
  2. B. Reserve emergency access for resilience, use governed scoped roles for routine work, and monitor all emergency-account use
  3. C. Share its password with every operations engineer
  4. D. Remove all emergency access capability

Correct answer

Reserve emergency access for resilience, use governed scoped roles for routine work, and monitor all emergency-account use

Objective/domain: Design security operations, identity, and compliance capabilities

Source: Microsoft Entra Privileged Identity Management overview

Question 5 Production and backup administrators currently use the same permanent account. Which change best protects recovery operations?

Answer choices

  1. A. Add more permissions to the shared account
  2. B. Use separate least-privileged backup identities and protect recovery points with soft delete or immutability
  3. C. Store the shared password in a team document
  4. D. Disable backup-operation alerts

Correct answer

Use separate least-privileged backup identities and protect recovery points with soft delete or immutability

Objective/domain: Design solutions that align with security best practices and priorities

Source: Azure Backup security features

Question 6 A threat model contains many categories but no owner has implemented or tested the mitigation for a likely account-takeover path. What should be prioritized?

Answer choices

  1. A. The category with the most entries
  2. B. The plausible high-impact path, with a mitigation owner and verification plan
  3. C. Additional documentation without implementation
  4. D. Every low-impact threat before the likely takeover

Correct answer

The plausible high-impact path, with a mitigation owner and verification plan

Objective/domain: Design security solutions for applications and data

Source: Threat modeling for drivers

Question 7 An employee sponsoring several agents leaves the company. What should identity governance do?

Answer choices

  1. A. Use the agent inventory to review ownership, purpose, permissions, and activity, then reassign or retire dependent agents
  2. B. Leave every agent active indefinitely
  3. C. Transfer all agents to a shared anonymous sponsor
  4. D. Delete inventory records but preserve permissions

Correct answer

Use the agent inventory to review ownership, purpose, permissions, and activity, then reassign or retire dependent agents

Objective/domain: Design security operations, identity, and compliance capabilities

Source: Microsoft Entra Agent ID overview

Question 8 A regulator cites one framework, while the cloud team wants to implement every MCSB recommendation identically across all workloads. What should the architect do?

Answer choices

  1. A. Ignore MCSB because it is not the cited regulation
  2. B. Treat every benchmark item as equally mandatory
  3. C. Use only the regulatory wording and no technical benchmark
  4. D. Map relevant MCSB controls to applicable risks and obligations, documenting ownership, evidence, exceptions, and validation

Correct answer

Map relevant MCSB controls to applicable risks and obligations, documenting ownership, evidence, exceptions, and validation

Objective/domain: Design solutions that align with security best practices and priorities

Source: Microsoft Cloud Security Benchmark overview

Question 9 A build uses an untracked library and writes a deployment secret into logs. Which SDL controls are required?

Answer choices

  1. A. Inventory and verify the component, monitor and update it, and remove embedded secrets from source, logs, and artifacts
  2. B. Retain the secret in logs but shorten log retention
  3. C. Trust the library indefinitely because the build succeeded
  4. D. Replace the component inventory with a penetration test

Correct answer

Inventory and verify the component, monitor and update it, and remove embedded secrets from source, logs, and artifacts

Objective/domain: Design security solutions for applications and data

Source: Microsoft Security Development Lifecycle

Question 10 A Kubernetes program trusts any public image and focuses only on scanning, leaving secrets, admission, workload identity, and network policy undesigned. What should the architect require?

Answer choices

  1. A. Patch compromised running containers manually
  2. B. Use trusted scanned and rebuilt images plus secured orchestrator control plane, secrets, admission, identities, and network policies
  3. C. Disable the image registry
  4. D. Grant every workload the cluster administrator identity

Correct answer

Use trusted scanned and rebuilt images plus secured orchestrator control plane, secrets, admission, identities, and network policies

Objective/domain: Design security solutions for infrastructure

Source: Azure security best practices and patterns

Where to go after the daily web set

How are SC-100 questions generated?

dotCreds builds SC-100 practice questions from public exam objectives and Microsoft Learn and exam-objective references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start SC-100 practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.