SC-100 Zero Trust & Threat Protection Solutions 4 — Questions and Answers
Question 1: Which Microsoft solution provides Secure Access Service Edge (SASE) capabilities by combining network security and SD-WAN, aligning with Zero Trust network access principles?
- Azure ExpressRoute
- Microsoft Entra Internet Access (Global Secure Access) (Correct answer)
- Azure Virtual WAN with Firewall
- Azure AD Application Proxy
Correct answer: Microsoft Entra Internet Access (Global Secure Access)
Microsoft Entra Internet Access (part of Global Secure Access) delivers identity-centric, Zero Trust network access controls aligned with SASE architecture principles.
Question 2: An organization wants to detect when an attacker uses a compromised service account to perform pass-the-ticket attacks in Active Directory. Which solution detects this?
- Microsoft Defender for Endpoint
- Microsoft Defender for Identity (Correct answer)
- Microsoft Defender for Cloud
- Microsoft Defender for Office 365
Correct answer: Microsoft Defender for Identity
Microsoft Defender for Identity monitors Kerberos ticket activity on domain controllers to detect pass-the-ticket and other credential-based attacks.
Question 3: In the Zero Trust 'assume breach' mindset, which practice involves proactively searching for threats that evade automated detection controls?
- Security baseline enforcement
- Threat hunting (Correct answer)
- Vulnerability scanning
- Patch management
Correct answer: Threat hunting
Threat hunting is a proactive security practice where analysts search for hidden threats within the environment assuming that attackers may already be present.
Question 4: A company must enforce Zero Trust for third-party contractors accessing internal web apps without requiring VPN. Which solution provides identity-based app access?
- Azure Bastion
- Microsoft Entra Private Access (Global Secure Access) (Correct answer)
- Azure VPN Gateway
- Azure Firewall DNAT rules
Correct answer: Microsoft Entra Private Access (Global Secure Access)
Microsoft Entra Private Access provides identity-aware, Zero Trust access to internal applications without requiring a traditional VPN tunnel.
Question 5: Which Microsoft Defender for Cloud feature continuously assesses Azure resources against security benchmarks and assigns a quantified security posture score?
- Just-in-time VM access
- Secure Score (Correct answer)
- Adaptive application controls
- Regulatory compliance dashboard
Correct answer: Secure Score
Secure Score in Microsoft Defender for Cloud quantifies an organization's security posture and prioritizes recommendations to improve it.
Question 6: An architect is designing threat protection for Azure SQL databases. Which Microsoft service detects anomalous database activities like SQL injection attempts?
- Microsoft Defender for Cloud Apps
- Microsoft Defender for SQL (Correct answer)
- Azure Monitor Diagnostic Logs
- Azure Firewall
Correct answer: Microsoft Defender for SQL
Microsoft Defender for SQL provides advanced threat protection that detects anomalous activities including SQL injection, brute force, and suspicious access patterns.
Question 7: Which Zero Trust control ensures that even if an attacker compromises network access, they cannot move laterally to access sensitive data stores without re-authenticating?
- Network perimeter firewalls
- Microsegmentation with identity-based access controls (Correct answer)
- VPN split tunneling
- SSL/TLS inspection
Correct answer: Microsegmentation with identity-based access controls
Microsegmentation combined with identity-based controls enforces per-resource authentication, preventing lateral movement even after network access is gained.
Which Microsoft solution provides Secure Access Service Edge (SASE) capabilities by combining network security and SD-WAN, aligning with Zero Trust network access principles?