Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Cybersecurity Architect Expert

Domain 1Objective 3

Design Solutions That Align with the Microsoft Cloud Adoption Framework for Azure (CAF) and the Azure Well-Architected Framework SC-100 Practice Questions (Page 4)

Part of the Design solutions that align with security best practices and priorities domain, which accounts for 20–25% of the SC-100 exam. Microsoft does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–20 in this domain), expect 3–7 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
7concepts
20–25%of the exam

Questions 16–20

  1. 16expert · hard

    A large enterprise is adopting Azure and has established a CAF-based governance strategy. The security team wants to enforce a security baseline across all subscriptions, but the business units have different compliance requirements. The architect must balance centralized governance with business unit autonomy. Which approach should the architect recommend?

    Select an answer first
  2. 17expert · hard

    A company is adopting a DevSecOps approach for a critical application. The security architect needs to ensure that security checks are integrated into the CI/CD pipeline without slowing down development. The company has a strict release deadline. Which approach should the architect recommend?

    Select an answer first
  3. 18application · medium

    A company is planning to adopt Azure AI services for a customer-facing chatbot. The security architect must design a strategy that aligns with the organization's security requirements. Which approach should the architect recommend?

    Select an answer first
  4. 19foundation · easy

    What is the primary purpose of an Azure landing zone in the context of security and governance?

    Select an answer first
  5. 20application · medium

    A company is deploying an Azure landing zone to support a new application. The security team requires that all virtual machines (VMs) in the landing zone have disk encryption enabled and that no public IP addresses are assigned to VMs. The application team wants to deploy VMs using infrastructure as code (IaC) templates. What should the security architect configure to enforce these requirements?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-100” is a trademark of its owner, used for identification only.