SC-100 Security Posture Management 1 — Questions and Answers
Question 1: Which Microsoft service provides Cloud Security Posture Management (CSPM) capabilities to assess and improve security configurations across Azure, AWS, and GCP?
- Microsoft Sentinel
- Microsoft Defender for Cloud (Correct answer)
- Microsoft Entra ID Protection
- Microsoft Defender for Endpoint
Correct answer: Microsoft Defender for Cloud
Microsoft Defender for Cloud provides CSPM capabilities including Secure Score, recommendations, and multi-cloud posture assessment across Azure, AWS, and GCP.
Question 2: What does Microsoft Secure Score measure?
- The number of active threats detected in the environment
- An organization's security posture based on completed security recommendations (Correct answer)
- The compliance percentage against a regulatory framework
- The patch level of all devices in the organization
Correct answer: An organization's security posture based on completed security recommendations
Microsoft Secure Score measures an organization's security posture by assigning points for completing recommended security actions across Microsoft 365 and Azure services.
Question 3: In Microsoft Defender for Cloud, what is the purpose of the 'Regulatory Compliance' dashboard?
- To assign security policies to management groups
- To compare your environment against specific compliance standards such as CIS, PCI-DSS, and NIST (Correct answer)
- To generate incident reports for auditors automatically
- To enforce Azure Policy definitions on all subscriptions
Correct answer: To compare your environment against specific compliance standards such as CIS, PCI-DSS, and NIST
The Regulatory Compliance dashboard in Defender for Cloud maps your security controls to specific compliance standards and shows your compliance percentage against each framework.
Question 4: What is the primary difference between Microsoft Defender for Cloud's Foundational CSPM (free) tier and Defender CSPM (paid) tier?
- The free tier only monitors Azure while the paid tier monitors AWS and GCP
- The paid tier adds agentless scanning, attack path analysis, and data-aware security posture (Correct answer)
- The free tier does not provide Secure Score
- The paid tier includes Microsoft Sentinel integration
Correct answer: The paid tier adds agentless scanning, attack path analysis, and data-aware security posture
Defender CSPM (paid) adds advanced capabilities such as agentless vulnerability scanning, attack path analysis, cloud security explorer, and data-aware security posture over the free foundational tier.
Question 5: A cybersecurity architect wants to identify lateral movement paths attackers could use across cloud resources. Which Defender for Cloud feature should they use?
- Secure Score improvement actions
- Attack path analysis (Correct answer)
- Just-in-time VM access
- Adaptive application controls
Correct answer: Attack path analysis
Attack path analysis in Defender CSPM uses a graph-based algorithm to identify exploitable paths attackers could take across cloud resources, highlighting the most critical risks.
Question 6: Which Azure construct allows a cybersecurity architect to apply a consistent set of security policies across multiple subscriptions simultaneously?
- Resource Groups
- Management Groups with Azure Policy initiatives (Correct answer)
- Azure Blueprints only
- Subscription-level RBAC assignments
Correct answer: Management Groups with Azure Policy initiatives
Management Groups allow policies and Azure Policy initiatives to be applied hierarchically across multiple subscriptions, enabling consistent governance at scale.
Question 7: What is 'cloud security explorer' in Microsoft Defender for Cloud used for?
- Browsing Azure Marketplace for security solutions
- Running graph-based queries to proactively identify security risks across cloud assets (Correct answer)
- Monitoring real-time alerts from connected cloud environments
- Managing security agent deployments to virtual machines
Correct answer: Running graph-based queries to proactively identify security risks across cloud assets
Cloud Security Explorer lets security teams run graph-based queries on the cloud security graph to proactively find security risks, misconfigurations, and relationships across resources.
Which Microsoft service provides Cloud Security Posture Management (CSPM) capabilities to assess and improve security configurations across Azure, AWS, and GCP?