Expert-level certification covering the design of Zero Trust security strategy, security operations, identity, infrastructure, and application and data protection across Microsoft and hybrid multicloud environments.
Free sample questions
No account needed. Every question has a worked explanation, just like the full bank.
lock_openFree sampleDesign Solutions that Align with Security Best Practices and Prioritieshard
A financial services organisation wants its backup design to survive a ransomware operator who has already gained Global Administrator rights in Microsoft Entra ID and intends to delete or encrypt all backups before detonating. Which backup design property most directly satisfies this resiliency requirement?
- ABackups are written to immutable, time-locked storage that no administrator role can delete or alter until the retention period expires.check_circle Correct
- BBackups are replicated to a second Azure region so that a regional outage cannot make the restore points unavailable.
- CBackups are encrypted at rest with customer-managed keys held in an Azure Key Vault that the backup service can read automatically.
- DBackups run more frequently so that the recovery point objective is reduced to under fifteen minutes for every protected workload.
Ransomware-resilient backups must be immutable and retention-locked so that even a fully compromised privileged identity cannot destroy the restore points. Ransomware actors specifically target backups using stolen privileged credentials before encrypting production, so the design must make restore points undeletable by any role. Immutable, time-locked storage enforces this at the platform level rather than relying on access control that the attacker already holds.
Why A is correct: Immutability with a retention lock enforces the assume-breach principle so that even a fully compromised privileged identity cannot delete or encrypt the protected restore point, which is exactly what the requirement demands.
Why B is wrong: Geo-replication defends against a datacentre or regional failure and seems resilient, but a privileged attacker can issue deletion against replicated copies just as easily, so it does not counter a malicious insider-level identity.
Why C is wrong: Encryption at rest protects backup confidentiality and is tempting because it sounds like hardening, but it does nothing to stop a Global Administrator from deleting the backups outright, so it misses the stated threat.
Why D is wrong: A tighter recovery point objective improves data freshness and is appealing for resilience metrics, but more frequent copies in deletable storage are equally destroyable by the compromised admin, so the threat is unaddressed.
lock_openFree sampleDesign Security Solutions for Applications and Datahard
A product team is about to begin building a new customer-facing payments service and asks a security architect when, in the application lifecycle, design-level security flaws such as missing authorisation boundaries and unsafe trust assumptions should be identified. The architect wants the practice that surfaces these flaws before code is written, by reasoning about the system's data flows and trust boundaries. Which practice best meets this requirement?
- APerform threat modeling during the design phase, enumerating data flows and trust boundaries to identify and rank design weaknesses before any code exists.check_circle Correct
- BRun dynamic application security testing against a deployed staging build so that exploitable runtime weaknesses are discovered before the service reaches production traffic.
- CAdd static application security testing to the build pipeline so that insecure coding patterns are flagged automatically every time a developer commits source.
- DSchedule an external penetration test ahead of launch so that an independent team validates the service's defences against realistic attacker techniques first.
Threat modeling is the design-phase practice that reveals architectural and trust-boundary flaws before code exists, unlike testing that runs against built software. Threat modeling reasons about a system's data flows, trust boundaries, and assets to enumerate how it could be attacked while the design is still on paper. Because it precedes implementation, it catches authorisation, trust, and exposure flaws when they are cheapest to fix, which testing techniques that need running or committed code cannot do.
Why A is correct: Threat modeling is the design-phase activity that maps data flows and trust boundaries to expose architectural weaknesses such as missing authorisation, so it identifies and ranks design flaws exactly when the requirement demands, before implementation begins.
Why B is wrong: Dynamic testing is valuable and tempting because it finds real exploitable issues, but it runs against built, deployed code and so cannot surface the design-level trust-boundary flaws the requirement targets before code is written.
Why C is wrong: Static analysis catches insecure code patterns and feels like the earliest control, but it operates on committed source rather than the architecture, so it misses design flaws that exist before code and that no scanner reads from a diagram.
Why D is wrong: A penetration test gives independent assurance and is appealing as a gate, but it happens against a near-complete system late in the lifecycle, so it finds design flaws only after they are expensively built rather than before code is written.
lock_openFree sampleDesign Solutions that Align with Security Best Practices and Prioritieshard
While designing a ransomware resiliency strategy, an architect is asked to identify the single highest-leverage protection to prioritise first according to Microsoft Security Best Practices, because most large-scale ransomware incidents pivot through one common control failure. Which priority should the design address first?
- ADeploying Microsoft Defender for Endpoint to every workstation and server so that malicious binaries are blocked at execution time.
- BSecuring privileged access by isolating administrative identities and enforcing just-in-time elevation through Microsoft Entra Privileged Identity Management.check_circle Correct
- CImplementing immutable backups so that encrypted production data can always be restored after a successful detonation.
- DEnabling Microsoft Sentinel analytics rules tuned to detect lateral movement and mass file-encryption behaviour across the estate.
Microsoft prioritises securing privileged access as the first ransomware defence because operators depend on escalating to admin rights to spread and destroy. Human-operated ransomware almost always escalates to high-privilege accounts to move laterally, disable defences, and delete backups. Eliminating standing privilege with just-in-time elevation removes the dependency the campaign relies on, which is why Microsoft ranks it ahead of detection and recovery controls.
Why A is wrong: Endpoint protection is essential and tempting as a first move, but it is a detection and prevention layer that attackers routinely evade, whereas removing standing privileged access denies the escalation the campaign relies on, so it is not the first priority.
Why B is correct: Microsoft guidance ranks protecting privileged access as the top ransomware priority because operators escalate to admin rights to spread payloads and destroy backups, so removing standing privilege closes the path the attack depends on.
Why C is wrong: Recoverable backups are a critical pillar and appealing because recovery is the visible outcome, but they assume the attack has already succeeded, so prioritising them before privileged access leaves the breach path open.
Why D is wrong: SIEM analytics improve detection speed and are attractive for visibility, but detection alerts after compromise has begun, so it does not prevent the privileged-access escalation that Microsoft ranks as the leading priority.
More free SC-100 practice questions with worked answersFrequently asked questions
- How many questions are on the SC-100 exam?
- The Microsoft Cybersecurity Architect (SC-100) exam has Typically 40 to 60 questions questions and runs for 120 minutes. The format is multiple choice, multiple response, and case studies, at a pearson vue testing center or online proctored.
- What score do I need to pass SC-100?
- The pass mark is 700 / 1000. Examworthy gives you a per-domain readiness score so you can see which domains are holding you back before you book.
- How much does the SC-100 exam cost?
- The exam costs 165 USD to sit. Practising on Examworthy is free to start, with a worked explanation on every question.
- Is there a SC-100 practice exam?
- Yes. Examworthy's exam mode runs a timed SC-100 practice exam (mock) paced to match the real exam, scored per domain so you can see exactly where you stand against the blueprint. Timed mocks are free with an account.
- How does Examworthy help me prepare for SC-100?
- Every practice question carries a worked explanation and a per-distractor rationale, mapped to the official blueprint domains. You learn why each answer is right or wrong, not just the letter.
- Is Examworthy affiliated with Microsoft?
- No. Examworthy is not affiliated with or endorsed by Microsoft. Our questions are original, blueprint-aligned practice material; we never reproduce live exam items.
Examworthy is not affiliated with or endorsed by Microsoft. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. SC-100 and related marks belong to their respective owners.