SC-100 Zero Trust & Threat Protection Solutions 2 — Questions and Answers
Question 1: An organization wants to enforce Zero Trust for all remote users accessing corporate apps. Which Microsoft solution provides continuous access evaluation (CAE) to revoke sessions in near real-time?
- Microsoft Defender for Cloud Apps
- Azure Active Directory Conditional Access with CAE (Correct answer)
- Azure Firewall Premium
- Microsoft Sentinel
Correct answer: Azure Active Directory Conditional Access with CAE
Azure AD Conditional Access with CAE allows resource providers to revoke tokens near-instantly when risk conditions change, rather than waiting for token expiry.
Question 2: Which Microsoft Defender for Endpoint capability uses machine learning to detect advanced persistent threats that evade signature-based detection?
- Attack surface reduction rules
- Endpoint detection and response (EDR) (Correct answer)
- Network protection
- Tamper protection
Correct answer: Endpoint detection and response (EDR)
EDR in Microsoft Defender for Endpoint uses behavioral analytics and ML to detect and investigate sophisticated threats beyond signature-based methods.
Question 3: A cybersecurity architect needs to segment a flat network to support Zero Trust principles. Which Azure service provides microsegmentation for workloads in Azure Virtual Networks?
- Azure DDoS Protection
- Azure Network Security Groups (NSGs) with Application Security Groups (Correct answer)
- Azure Bastion
- Azure Private Link
Correct answer: Azure Network Security Groups (NSGs) with Application Security Groups
NSGs combined with Application Security Groups enable microsegmentation by controlling traffic flow at a granular workload level within Azure Virtual Networks.
Question 4: An architect is designing threat protection for Microsoft 365 email. Which feature in Microsoft Defender for Office 365 detonates suspicious attachments in a sandbox before delivery?
- Spoof intelligence
- Safe Attachments (Correct answer)
- Mail flow rules
- DKIM signing
Correct answer: Safe Attachments
Safe Attachments in Defender for Office 365 opens email attachments in a virtual detonation environment to detect malware before delivery to the recipient.
Question 5: Under the Zero Trust model, which principle requires verifying that a device meets security posture requirements before granting access to corporate resources?
- Assume breach
- Use least privilege access
- Verify explicitly — device health (Correct answer)
- Network perimeter defense
Correct answer: Verify explicitly — device health
Zero Trust's 'verify explicitly' pillar includes evaluating device compliance and health signals alongside user identity before granting access.
Question 6: Which Microsoft service provides unified XDR capabilities by correlating signals from endpoints, identities, email, and cloud apps into a single incident view?
- Microsoft Sentinel
- Microsoft 365 Defender (Microsoft Defender XDR) (Correct answer)
- Azure Security Center
- Microsoft Intune
Correct answer: Microsoft 365 Defender (Microsoft Defender XDR)
Microsoft Defender XDR (formerly Microsoft 365 Defender) is an extended detection and response platform that correlates cross-domain signals into unified incidents.
Question 7: An organization wants to apply Zero Trust to SaaS applications and enforce session controls even after successful authentication. Which capability achieves this?
- Azure AD Password Protection
- Microsoft Defender for Cloud Apps with Conditional Access App Control (Correct answer)
- Azure AD Identity Protection
- Microsoft Purview Information Protection
Correct answer: Microsoft Defender for Cloud Apps with Conditional Access App Control
Conditional Access App Control in Microsoft Defender for Cloud Apps routes sessions through a reverse proxy to enforce real-time session policies on SaaS apps.
An organization wants to enforce Zero Trust for all remote users accessing corporate apps.
Which Microsoft solution provides continuous access evaluation (CAE) to revoke sessions in near real-time?