SC-100 Security Strategy & Risk Management 5 — Questions and Answers
Question 1: An SC-100 architect is evaluating an organization's security posture using the MITRE ATT&CK framework. What is the PRIMARY purpose of mapping security controls to ATT&CK techniques?
- To satisfy regulatory audit requirements by demonstrating control coverage documentation
- To identify gaps where adversary techniques are not covered by existing defenses and prioritize control improvements (Correct answer)
- To generate automated threat intelligence reports for executive dashboards
- To classify all security incidents by technique ID for SIEM correlation rules
Correct answer: To identify gaps where adversary techniques are not covered by existing defenses and prioritize control improvements
Mapping controls to ATT&CK techniques reveals defensive gaps where attackers can operate undetected, enabling risk-informed prioritization of security investments.
Question 2: When advising on a security strategy for a highly regulated organization, which approach to security policy management best balances agility with governance?
- Implementing immutable policies that never change to ensure regulatory stability
- Adopting a living policy management lifecycle with scheduled reviews, exception processes, and change control (Correct answer)
- Delegating all policy decisions to individual business units to maximize agility
- Implementing only the minimum policies required by regulators to reduce overhead
Correct answer: Adopting a living policy management lifecycle with scheduled reviews, exception processes, and change control
A living policy lifecycle with formal reviews, exceptions, and change control allows policies to evolve with the threat landscape while maintaining governance accountability.
Question 3: A cybersecurity architect is assessing an organization's security culture. Which indicator best demonstrates that a positive security culture has been successfully embedded?
- 100% completion rate on mandatory annual security awareness training modules
- Employees proactively reporting suspicious emails and security anomalies without fear of reprisal (Correct answer)
- Zero security incidents reported in the past fiscal year
- All security policies have been reviewed and signed off by every employee
Correct answer: Employees proactively reporting suspicious emails and security anomalies without fear of reprisal
Proactive voluntary reporting indicates employees understand their security role and trust the organization's response, which are hallmarks of a genuine security culture versus surface compliance.
Question 4: Which risk management approach does Microsoft recommend when an organization cannot immediately remediate a high-severity vulnerability due to business constraints?
- Accepting the risk indefinitely and removing it from the risk register
- Applying compensating controls, documenting the exception with a time-bound remediation plan, and monitoring continuously (Correct answer)
- Immediately taking the affected system offline until the vulnerability is patched
- Escalating to regulators to negotiate an extended compliance deadline
Correct answer: Applying compensating controls, documenting the exception with a time-bound remediation plan, and monitoring continuously
Compensating controls with time-bound exception management and continuous monitoring maintains risk visibility and accountability while accommodating business constraints.
Question 5: An organization is designing its security strategy to address emerging AI-powered threats. Which capability is MOST critical for detecting AI-generated phishing and social engineering attacks?
- Blocking all AI-generated content at the email gateway using keyword filtering
- Implementing behavioral analytics that detect anomalous communication patterns combined with advanced email authentication (DMARC/DKIM/SPF) (Correct answer)
- Requiring all emails to be manually reviewed by security analysts before delivery
- Deploying a separate AI detection model for every communication channel
Correct answer: Implementing behavioral analytics that detect anomalous communication patterns combined with advanced email authentication (DMARC/DKIM/SPF)
Behavioral analytics identify unusual patterns that AI-generated attacks exhibit, while email authentication prevents domain spoofing used in AI-crafted spear-phishing campaigns.
Question 6: When developing a cloud security strategy, which principle ensures that security requirements are built into workloads from the beginning rather than added after deployment?
- Security Operations Center (SOC) post-deployment review
- Shift-Left Security integrating security into the DevSecOps pipeline (Correct answer)
- Penetration testing of all new applications before go-live
- Reactive security patching through a vulnerability management program
Correct answer: Shift-Left Security integrating security into the DevSecOps pipeline
Shift-Left Security embeds security requirements, testing, and validation into the development pipeline so vulnerabilities are caught early when they are least costly to remediate.
Question 7: A security architect is designing a security strategy for an organization undergoing digital transformation. Which framework component from the Microsoft Security Adoption Framework (SAF) addresses how to sequence security capabilities for maximum risk reduction?
- Security Posture Management, which tracks current vulnerability counts across all assets
- Security Modernization Roadmap, which prioritizes security capabilities based on attack pattern likelihood and business impact (Correct answer)
- Compliance Management Dashboard, which shows regulatory adherence scores by control domain
- Threat Intelligence Platform, which provides real-time feeds of emerging threats and indicators of compromise
Correct answer: Security Modernization Roadmap, which prioritizes security capabilities based on attack pattern likelihood and business impact
The Microsoft SAF Security Modernization Roadmap helps organizations sequence security investments by aligning capability development with the most likely attack patterns and highest business risk.
An SC-100 architect is evaluating an organization's security posture using the MITRE ATT&CK framework.
What is the PRIMARY purpose of mapping security controls to ATT&CK techniques?