Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Cybersecurity Architect Expert

Domain 2Objective 1

Design Solutions for Security Operations SC-100 Practice Questions (Page 3)

Part of the Design security operations, identity, and compliance capabilities domain, which accounts for 25–30% of the SC-100 exam. Microsoft does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–24 in this domain), expect 3–6 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
7concepts
25–30%of the exam

Questions 11–15

  1. 11application · medium

    A SOC wants to automatically block a user's account when Microsoft Defender for Endpoint detects a high-confidence ransomware attack on their device. They also want to create an incident in Sentinel for tracking. Which approach should they use?

    Select an answer first
  2. 12foundation · easy

    What is the primary purpose of Security Orchestration, Automation, and Response (SOAR) in a security operations center?

    Select an answer first
  3. 13application · medium

    A multinational company is deploying Microsoft Sentinel as its central SIEM. They need to collect security logs from AWS CloudTrail, Google Cloud Platform (GCP) Audit Logs, and on-premises Windows servers. The security team wants a single data connector per source and minimal administrative overhead for log ingestion. What should you configure?

    Select an answer first
  4. 14application · medium

    A company wants to centralize logging and auditing for all Microsoft 365 services, Azure resources, and on-premises Active Directory. They want to use Microsoft Sentinel for analysis and Microsoft Purview for compliance auditing. What should they configure?

    Select an answer first
  5. 15application · medium

    A company runs workloads in Azure, on-premises, and in AWS. They want to use Microsoft Sentinel as their single security monitoring platform. They need to ensure that security events from all environments are collected and correlated, and they want to use MITRE ATT&CK coverage to identify gaps. What should you implement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-100” is a trademark of its owner, used for identification only.