Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Cybersecurity Architect Expert

Domain 2Objective 1

Design Solutions for Security Operations SC-100 Practice Questions (Page 2)

Part of the Design security operations, identity, and compliance capabilities domain, which accounts for 25–30% of the SC-100 exam. Microsoft does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–24 in this domain), expect 3–6 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
7concepts
25–30%of the exam

Questions 6–10

  1. 6expert · hard

    A company has a security operations center that uses Microsoft Sentinel. They want to improve their incident response by using threat intelligence. They have a paid threat intelligence feed that provides indicators of compromise (IOCs). They want to use these IOCs to detect threats and automate the response. What should they do?

    Select an answer first
  2. 7foundation · easy

    Which capability is essential for a monitoring solution to support a multicloud environment?

    Select an answer first
  3. 8application · medium

    A company's incident response team wants to use threat hunting to proactively search for indicators of compromise (IOCs) across their endpoints and email. They want to use a single query language. Which tool should they use?

    Select an answer first
  4. 9application · medium

    Contoso Pharmaceuticals has Microsoft 365 E5 and Microsoft Defender for Endpoint deployed. The security team wants to automate the initial triage of high-severity alerts from Defender for Endpoint, including enrichment with user risk data from Microsoft Entra ID Protection, and then create an incident in Microsoft Sentinel for further investigation. The team wants to minimize the number of separate tools and manual steps. What should you recommend?

    Select an answer first
  5. 10expert · hard

    A company is deploying Microsoft Sentinel in a new Azure region to meet data residency requirements. They have existing on-premises security tools that generate logs in a proprietary format. They want to ingest these logs into Sentinel without building custom parsers. They also need to retain logs for six years for compliance. What should they do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-100” is a trademark of its owner, used for identification only.