Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Cybersecurity Architect Expert

Domain 1Objective 2

Design Solutions That Align with the Microsoft Cybersecurity Reference Architectures (MCRA) and Microsoft Cloud Security Benchmark (MCSB) SC-100 Practice Questions (Page 1)

Part of the Design solutions that align with security best practices and priorities domain, which accounts for 20–25% of the SC-100 exam. Microsoft does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–20 in this domain), expect 3–7 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
6concepts
20–25%of the exam

Questions 1–5

  1. 1application · medium

    A retail company is migrating its on-premises applications to Azure. The security architect must design a solution that aligns with the Zero Trust adoption framework and the MCRA. The company wants to implement a phased approach that starts with identity and then expands to other pillars. Which initial step should the architect recommend?

    Select an answer first
  2. 2foundation · easy

    A cybersecurity architect is reviewing the Microsoft Cybersecurity Reference Architectures (MCRA) to plan a security strategy. Which statement best describes the primary purpose of the MCRA?

    Select an answer first
  3. 3application · medium

    A government agency is deploying an AI-based document classification system that handles sensitive information. The security architect must ensure the solution aligns with the Microsoft Cloud Security Benchmark (MCSB). The agency is concerned about data residency and the potential for the AI model to be compromised. Which set of controls should the architect prioritize?

    Select an answer first
  4. 4foundation · easy

    Which tool or service is commonly used in the Microsoft ecosystem to help secure the software supply chain by scanning for vulnerabilities in container images?

    Select an answer first
  5. 5expert · hard

    A software-as-a-service (SaaS) provider is designing defenses against external attacks aligned with the MCRA. The provider's application is built on microservices and uses a CI/CD pipeline that pulls open-source libraries. The security architect must protect the application from external attacks and supply chain risks. Which combination of controls should be implemented?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-100” is a trademark of its owner, used for identification only.