Microsoft Certified:Cybersecurity Architect Expert
Domain 2Objective 1
Design Solutions for Security Operations SC-100 Practice Questions (Page 6)
Part of the Design security operations, identity, and compliance capabilities domain, which accounts for 25–30% of the SC-100 exam. Microsoft does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–24 in this domain), expect 3–6 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
7concepts
25–30%of the exam
Questions 26–30
- 26
A global organization has a hybrid environment with Azure, on-premises, and mobile devices. They want to use MITRE ATT&CK to evaluate their threat detection coverage across all platforms. They have Microsoft Defender for Endpoint, Defender for Office 365, and Defender for Cloud Apps. They want to identify gaps in their coverage for mobile devices and ICS/OT environments, which they are just starting to deploy. What should they do?
Select an answer first - 27
A company wants to improve their threat detection coverage by integrating Microsoft Defender XDR with Microsoft Sentinel. They want to use MITRE ATT&CK to evaluate their coverage. They also want to ensure that high-severity incidents are automatically escalated to the SOC manager. What should they do?
Select an answer first - 28
A security operations team wants to automate responses to common alerts, such as disabling a compromised user account, without manual intervention. Which Microsoft solution provides SOAR capabilities that integrate with Microsoft Sentinel and Microsoft Defender XDR?
Select an answer first - 29
A company wants to improve its threat detection coverage by using MITRE ATT&CK techniques. They have Microsoft Defender for Endpoint and Microsoft Defender for Office 365. They want to see which techniques are covered by their current detections and identify gaps. They also want to automate the creation of incidents for high-confidence detections. What should they use?
Select an answer first - 30
A security architect is designing a detection and response solution to provide unified visibility across endpoints, email, identity, and cloud apps. Which Microsoft capability is specifically designed to correlate signals across these domains and enable automated response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-100” is a trademark of its owner, used for identification only.