Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Cybersecurity Architect Expert

Domain 2Objective 1

Design Solutions for Security Operations SC-100 Practice Questions (Page 4)

Part of the Design security operations, identity, and compliance capabilities domain, which accounts for 25–30% of the SC-100 exam. Microsoft does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–24 in this domain), expect 3–6 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
7concepts
25–30%of the exam

Questions 16–20

  1. 16foundation · easy

    A security team needs a central platform to aggregate security logs from firewalls, servers, and cloud workloads, and to run queries for threat detection. Which Microsoft solution is designed for this purpose?

    Select an answer first
  2. 17expert · hard

    A company operates industrial control systems (ICS) and wants to improve threat detection coverage for their OT environment. They plan to map detections to the MITRE ATT&CK for ICS framework. Which Microsoft solution should they use to collect and analyze OT security events?

    Select an answer first
  3. 18application · medium

    A multinational company has offices in the US and Europe and uses Azure, AWS, and on-premises servers. The security team needs a single dashboard to correlate security alerts from all environments and meet a regulatory requirement to retain audit logs for 7 years. Which solution should they implement?

    Select an answer first
  4. 19application · medium

    A security operations center (SOC) wants to standardize its incident response process. They currently use Microsoft Sentinel and Microsoft Defender XDR. They want to ensure that every new incident is automatically assigned to the correct analyst team based on the type of attack, and that the incident is updated with relevant playbook steps. What should you implement?

    Select an answer first
  5. 20application · medium

    A security operations center (SOC) receives hundreds of low-severity alerts daily. They want to automatically triage and respond to common alerts (e.g., impossible travel) without manual intervention, while escalating complex incidents to analysts. Which solution should they implement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-100” is a trademark of its owner, used for identification only.