SC-100 - Design Solutions that Align with Security Best Practices and Priorities - Section 1.2

Design solutions that align with the Microsoft Cybersecurity Reference Architectures (MCRA) and Microsoft cloud security benchmark (MCSB).

Use the Microsoft Cybersecurity Reference Architectures (MCRA) and Microsoft cloud security benchmark (MCSB) as authoritative frameworks for mapping cybersecurity capabilities and controls to a Zero Trust posture. Apply the Rapid Modernization Plan (RaMP) to sequence improvements that reduce exposure to insider, external, and supply chain attacks.

Microsoft Cybersecurity Reference Architectures (MCRA)Microsoft cloud security benchmark (MCSB)Zero TrustRapid Modernization Plan (RaMP)insider, external, and supply chain attackscybersecurity capabilities and controls

Practice question for this objective

Free sampleDesign Solutions that Align with Security Best Practices and Prioritiesmedium

An architect wants the security governance design to measure the Azure estate against a consistent, Microsoft-authored set of security controls that map to industry frameworks, and to surface where the environment falls short so teams can remediate. Which combination correctly identifies the benchmark and the service that assesses the estate against it?

  • AThe Azure Well-Architected Framework, assessed continuously by Microsoft Sentinel analytics rules that score the estate against each pillar.
  • BThe Microsoft cloud security benchmark, assessed by Microsoft Purview, which scores the estate against the benchmark and recommends data-protection remediations.
  • CThe Microsoft cloud security benchmark, assessed by Microsoft Defender for Cloud, which evaluates the estate against the benchmark controls and reports gaps through secure score. Correct
  • DThe enterprise access model, assessed by Microsoft Entra Privileged Identity Management, which scores the estate against the model and reports privileged-access gaps.
Measure Azure security posture against the Microsoft cloud security benchmark using Microsoft Defender for Cloud, which reports control gaps through secure score. The Microsoft cloud security benchmark provides a prescriptive, Microsoft-authored set of security controls mapped to frameworks such as those from industry standards bodies, and Microsoft Defender for Cloud continuously assesses the estate against it. Defender for Cloud expresses the resulting gaps as secure score recommendations, which is the governance feedback loop the requirement describes.

Why A is wrong: The Well-Architected Framework is real guidance and Microsoft Sentinel is a real service, so the pairing is tempting, but the framework is a workload design review rather than a control benchmark and Sentinel is a security information and event management tool, so neither role fits.

Why B is wrong: Naming the correct benchmark makes this tempting, but Microsoft Purview governs data classification, compliance and information protection rather than evaluating cloud workload security posture, so it is the wrong assessing service.

Why C is correct: The Microsoft cloud security benchmark is the Microsoft-authored control set mapped to industry frameworks, and Microsoft Defender for Cloud assesses the estate against it and surfaces shortfalls through secure score, which exactly matches the requirement.

Why D is wrong: The enterprise access model and Privileged Identity Management are genuine privileged-access design tools and sound authoritative, but the model addresses administrative tiers rather than a broad control benchmark, so this pairing does not satisfy the requirement.

See more SC-100 practice questions, answers explained.

More in this domain

Back to all Design Solutions that Align with Security Best Practices and Priorities objectives, or the SC-100 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.