SC-100 Risk Assessment 3 — Questions and Answers
Question 1: Which NIST framework function focuses specifically on identifying and understanding cybersecurity risks to systems, people, assets, and data?
- Protect
- Detect
- Identify (Correct answer)
- Respond
Correct answer: Identify
The NIST CSF 'Identify' function establishes the organizational understanding needed to manage cybersecurity risk to systems, assets, data, and capabilities.
Question 2: A cybersecurity architect is designing a risk assessment process for a hybrid Azure environment. Which Azure-native service provides continuous assessment of security configurations against benchmarks?
- Azure Monitor Logs
- Microsoft Defender for Cloud (Correct answer)
- Azure Network Watcher
- Microsoft Entra ID Protection
Correct answer: Microsoft Defender for Cloud
Microsoft Defender for Cloud continuously assesses resource configurations against the Microsoft Cloud Security Benchmark and other standards, surfacing risks as recommendations.
Question 3: In risk management terminology, what is the difference between a threat and a vulnerability?
- A threat is a weakness; a vulnerability is a potential attacker
- A threat is a potential harmful event; a vulnerability is a weakness that could be exploited (Correct answer)
- A threat is the impact of a breach; a vulnerability is the likelihood of attack
- A threat is a technical flaw; a vulnerability is a business risk
Correct answer: A threat is a potential harmful event; a vulnerability is a weakness that could be exploited
A threat is any potential event that could harm an asset, while a vulnerability is a weakness that makes an asset susceptible to that threat.
Question 4: An SC-100 candidate is reviewing a risk treatment plan. Which option involves paying a premium to shift financial risk to another party?
- Risk avoidance
- Risk mitigation
- Risk transfer (Correct answer)
- Risk acceptance
Correct answer: Risk transfer
Risk transfer shifts the financial consequence of a risk to a third party, typically through cyber insurance or contractual liability clauses.
Question 5: During threat modeling for a new SaaS application on Azure, which methodology uses attack trees and stride categories to systematically identify threats?
- PASTA (Process for Attack Simulation and Threat Analysis)
- STRIDE (Correct answer)
- OCTAVE
- FAIR (Factor Analysis of Information Risk)
Correct answer: STRIDE
STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) is Microsoft's threat modeling methodology used to categorize threats systematically.
Question 6: Which Azure service should a cybersecurity architect recommend to assess risk posed by identities with excessive permissions across Azure subscriptions?
- Microsoft Entra Privileged Identity Management (PIM) (Correct answer)
- Azure AD B2C
- Microsoft Defender for Cloud Apps
- Azure Key Vault
Correct answer: Microsoft Entra Privileged Identity Management (PIM)
Microsoft Entra PIM provides visibility into privileged role assignments, enables just-in-time access, and helps reduce risk from standing excessive permissions.
Question 7: A risk assessment reveals that a critical data processing system has no documented business continuity plan. This finding maps to which risk domain?
- Information security risk
- Operational resilience risk (Correct answer)
- Regulatory compliance risk
- Reputational risk
Correct answer: Operational resilience risk
The absence of a business continuity plan represents an operational resilience risk, meaning the organization cannot recover normal operations after a disruption.
Which NIST framework function focuses specifically on identifying and understanding cybersecurity risks to systems, people, assets, and data?