SC-100 Security Strategy & Risk Management 3 — Questions and Answers
Question 1: An SC-100 candidate is advising a board on cybersecurity governance. Which structure best positions security as a strategic business enabler rather than a cost center?
- Reporting security metrics only during breach incidents to avoid alarm
- Establishing a security governance committee with C-suite participation and quarterly business risk reporting (Correct answer)
- Delegating all security decisions to the IT department to reduce board burden
- Focusing governance solely on regulatory compliance checklists
Correct answer: Establishing a security governance committee with C-suite participation and quarterly business risk reporting
A security governance committee with C-suite participation elevates security to a strategic function and ensures risk decisions are made with full business context.
Question 2: Which Microsoft security concept describes the practice of continuously validating that users, devices, and applications meet security requirements before granting access to resources?
- Defense in Depth
- Continuous Access Evaluation (CAE) (Correct answer)
- Privileged Identity Management (PIM)
- Conditional Access Policy Enforcement
Correct answer: Continuous Access Evaluation (CAE)
Continuous Access Evaluation enables real-time revocation of access tokens when user or device conditions change, implementing continuous validation rather than point-in-time checks.
Question 3: A security architect is assessing the risk of a proposed cloud migration. Which threat modeling methodology is MOST appropriate for identifying architectural risks in complex distributed systems?
- STRIDE, focusing on Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege (Correct answer)
- OWASP Top 10, focusing on the most common web application vulnerabilities
- Kill Chain analysis, focusing on attacker progression stages
- CVE scoring using CVSS to rank known vulnerabilities by severity
Correct answer: STRIDE, focusing on Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege
STRIDE is Microsoft's recommended threat modeling methodology for systematically identifying threats across system components and data flows in architectural designs.
Question 4: When designing a security operations strategy, which metric best measures the effectiveness of an organization's incident detection capability?
- Number of security alerts generated per day
- Mean Time to Detect (MTTD) correlated with alert fidelity rate (Correct answer)
- Total number of security tools deployed in the SOC
- Percentage of endpoints covered by EDR solutions
Correct answer: Mean Time to Detect (MTTD) correlated with alert fidelity rate
MTTD combined with alert fidelity (signal-to-noise ratio) provides a meaningful measure of detection effectiveness, balancing speed with accuracy.
Question 5: An organization must demonstrate security program maturity to a regulator. Which framework provides a standardized model for measuring and communicating security capability maturity levels?
- CIS Controls Implementation Groups
- CMMI for Security (Capability Maturity Model Integration) (Correct answer)
- NIST SP 800-53 Control Families
- Microsoft Secure Score benchmarking
Correct answer: CMMI for Security (Capability Maturity Model Integration)
CMMI provides a structured model with defined maturity levels (Initial through Optimizing) that organizations use to assess and communicate security program maturity.
Question 6: A cybersecurity architect is defining risk appetite for an organization. Which statement correctly distinguishes risk appetite from risk tolerance?
- Risk appetite is the maximum acceptable risk level; risk tolerance is the desired target risk level
- Risk appetite is the broad amount of risk an organization is willing to pursue; risk tolerance is the acceptable deviation from that appetite (Correct answer)
- Risk appetite applies to financial risks only; risk tolerance applies to operational risks
- Risk appetite is set by regulators; risk tolerance is set internally by the security team
Correct answer: Risk appetite is the broad amount of risk an organization is willing to pursue; risk tolerance is the acceptable deviation from that appetite
Risk appetite is the high-level strategic statement of acceptable risk, while risk tolerance defines the specific acceptable variation around that appetite for operational decisions.
Question 7: When designing a security strategy for an organization subject to multiple overlapping regulations (HIPAA, PCI-DSS, SOC 2), which approach minimizes compliance cost while maximizing security coverage?
- Implementing each framework independently with separate control sets and audits
- Creating a unified control framework that maps to all applicable regulations using a single control to satisfy multiple requirements (Correct answer)
- Selecting only the most stringent regulation and implementing solely those controls
- Outsourcing compliance to a managed security service provider for each regulation
Correct answer: Creating a unified control framework that maps to all applicable regulations using a single control to satisfy multiple requirements
A unified control framework with cross-regulation mapping allows one control to satisfy requirements from multiple frameworks simultaneously, reducing duplication and audit costs.
An SC-100 candidate is advising a board on cybersecurity governance.
Which structure best positions security as a strategic business enabler rather than a cost center?