SC-100 - Design Solutions that Align with Security Best Practices and Priorities (23% of the exam) - Section 1.2

Design solutions that align with the Microsoft Cybersecurity Reference Architectures (MCRA) and Microsoft cloud security benchmark (MCSB).

Use the Microsoft Cybersecurity Reference Architectures (MCRA) and Microsoft cloud security benchmark (MCSB) as authoritative frameworks for mapping cybersecurity capabilities and controls to a Zero Trust posture. Apply the Rapid Modernization Plan (RaMP) to sequence improvements that reduce exposure to insider, external, and supply chain attacks.

Microsoft Cybersecurity Reference Architectures (MCRA)Microsoft cloud security benchmark (MCSB)Zero TrustRapid Modernization Plan (RaMP)insider, external, and supply chain attackscybersecurity capabilities and controls

Practice question for this objective

Free sampleDesign Solutions that Align with Security Best Practices and Prioritiesmedium

An architect wants the security governance design to measure the Azure estate against a consistent, Microsoft-authored set of security controls that map to industry frameworks, and to surface where the environment falls short so teams can remediate. Which combination correctly identifies the benchmark and the service that assesses the estate against it?

  • AThe Azure Well-Architected Framework, assessed continuously by Microsoft Sentinel analytics rules that score the estate against each pillar.
  • BThe Microsoft cloud security benchmark, assessed by Microsoft Purview, which scores the estate against the benchmark and recommends data-protection remediations.
  • CThe Microsoft cloud security benchmark, assessed by Microsoft Defender for Cloud, which evaluates the estate against the benchmark controls and reports gaps through secure score. Correct
  • DThe enterprise access model, assessed by Microsoft Entra Privileged Identity Management, which scores the estate against the model and reports privileged-access gaps.
Measure Azure security posture against the Microsoft cloud security benchmark using Microsoft Defender for Cloud, which reports control gaps through secure score. The Microsoft cloud security benchmark provides a prescriptive, Microsoft-authored set of security controls mapped to frameworks such as those from industry standards bodies, and Microsoft Defender for Cloud continuously assesses the estate against it. Defender for Cloud expresses the resulting gaps as secure score recommendations, which is the governance feedback loop the requirement describes.

Why A is wrong: The Well-Architected Framework is real guidance and Microsoft Sentinel is a real service, so the pairing is tempting, but the framework is a workload design review rather than a control benchmark and Sentinel is a security information and event management tool, so neither role fits.

Why B is wrong: Naming the correct benchmark makes this tempting, but Microsoft Purview governs data classification, compliance and information protection rather than evaluating cloud workload security posture, so it is the wrong assessing service.

Why C is correct: The Microsoft cloud security benchmark is the Microsoft-authored control set mapped to industry frameworks, and Microsoft Defender for Cloud assesses the estate against it and surfaces shortfalls through secure score, which exactly matches the requirement.

Why D is wrong: The enterprise access model and Privileged Identity Management are genuine privileged-access design tools and sound authoritative, but the model addresses administrative tiers rather than a broad control benchmark, so this pairing does not satisfy the requirement.

See more SC-100 practice questions, answers explained.

Exam traps in Design Solutions that Align with Security Best Practices and Priorities

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-100 bank for this domain.

  • The Cloud Adoption Framework for Azure, designated as the control-mapped security baseline whose technical controls drive Defender for Cloud posture scoring and recommendations across the multicloud estate.

    Why it is wrong: The Cloud Adoption Framework is tempting because it guides secure cloud adoption, but it is governance and migration guidance rather than the prescriptive, control-mapped benchmark that powers Defender for Cloud posture scoring.

  • Place a web application firewall in front of the production endpoint to inspect and block layer-7 exploits such as injection and cross-site scripting from external callers.

    Why it is wrong: A web application firewall is a sound runtime control, but it defends against external request-borne attacks, not the upstream tampering of dependencies or artefacts that defines a supply chain attack.

  • The Microsoft Cybersecurity Reference Architectures, whose purpose is to sequence the initial high-impact reduction in breach risk for resource-constrained teams before the full Zero Trust programme follows.

    Why it is wrong: The MCRA are tempting because they cover the whole estate, but they are descriptive control-placement diagrams of the target architecture, not a prioritised sequencing plan for rapid initial risk reduction.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.