Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Microsoft Microsoft Certified: Cybersecurity Architect Expert SC-100 Questions and answers with CertsForce

Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions
Questions # 31:

For a Microsoft cloud environment, you are designing a security architecture based on the Microsoft Cloud Security Benchmark.

What are three best practices for identity management based on the Azure Security Benchmark? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

Options:

A.

Manage application identities securely and automatically.


B.

Manage the lifecycle of identities and entitlements


C.

Protect identity and authentication systems.


D.

Enable threat detection for identity and access management.


E.

Use a centralized identity and authentication system.


Expert Solution
Questions # 32:

You have an Azure environment that contains multiple workloads deployed across multiple subscriptions.

You need to recommend a solution to assess and improve the security posture of the workloads. The solution must meet the following requirements:

• Use the Microsoft Cloud Adoption Framework for Azure to evaluate compliance with cloud governance policies.

• Use the Azure Well-Architected Framework to secure individual workloads.

What should you include in the recommendation for each requirement? To answer, drag the appropriate recommendations to the correct requirements. Each recommendation may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content

NOTE: Each correct selection is worth one point.

Question # 32


Expert Solution
Questions # 33:

Your company has a third-party security information and event management (SIEM) solution that uses Splunk and Microsoft Sentinel. You plan to integrate Microsoft Sentinel with Splunk.

You need to recommend a solution to send security events from Microsoft Sentinel to Splunk. What should you include in the recommendation?

Options:

A.

Azure Event Hubs


B.

Azure Data Factor


C.

a Microsoft Sentinel workbook


D.

a Microsoft Sentinel data connector


Expert Solution
Questions # 34:

Your company, named Contoso. Ltd... has an Azure AD tenant namedcontoso.com. Contoso has a partner company named Fabrikam. Inc. that has an Azure AD tenant named fabrikam.com. You need to ensure that helpdesk users at Fabrikam can reset passwords for specific users at Contoso. The solution must meet the following requirements:

• Follow the principle of least privilege.

• Minimize administrative effort.

What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Question # 34


Expert Solution
Questions # 35:

You have a Microsoft Entra tenant named contoso.com that is linked to an Azure subscription named Sub! and a Microsoft 365 subscription. Sub! contains a publicly accessible Azure App Service web app named App1.

You have an external partner that has a Microsoft Entra tenant named fabrikam.com.

You need to recommend a solution that meets the following requirements:

• Ensures that the users in fabrikam.com can be granted permissions to specific Microsoft Teams channels in contoso.com

• Ensures that the users of App1 can authenticate by using social media accounts

• Minimizes administrative effort

Which authentication method should you recommend for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 35


Expert Solution
Questions # 36:

Your on-premises network contains an e-commerce web app that was developed in Angular and Nodejs. The web app uses a MongoDB database. You plan to migrate the web app to Azure. The solution architecture team proposes the following architecture as an Azure landing zone.

Question # 36

You need to provide recommendations to secure the connection between the web app and the database. The solution must follow the Zero Trust model.

Solution: You recommend implementing Azure Key Vault to store credentials.

Options:

A.

Yes


B.

No


Expert Solution
Questions # 37:

You need to recommend a solution to secure the MedicalHistory data in the ClaimsDetail table. The solution must meet the Contoso developer requirements.

What should you include in the recommendation?

Options:

A.

Transparent Data Encryption (TDE)


B.

Always Encrypted


C.

row-level security (RLS)


D.

dynamic data masking


E.

data classification


Expert Solution
Questions # 38:

To meet the application security requirements, which two authentication methods must the applications support? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

Options:

A.

Security Assertion Markup Language (SAML)


B.

NTLMv2


C.

certificate-based authentication


D.

Kerberos


Expert Solution
Questions # 39:

You need to recommend a solution for securing the landing zones. The solution must meet the landing zone requirements and the business requirements.

What should you configure for each landing zone?

Options:

A.

Azure DDoS Protection Standard


B.

an Azure Private DNS zone


C.

Microsoft Defender for Cloud


D.

an ExpressRoute gateway


Expert Solution
Questions # 40:

You need to design a strategy for securing the SharePoint Online and Exchange Online data. The solution must meet the application security requirements.

Which two services should you leverage in the strategy? Each correct answer presents part of the solution. NOTE; Each correct selection is worth one point.

Options:

A.

Azure AD Conditional Access


B.

Microsoft Defender for Cloud Apps


C.

Microsoft Defender for Cloud


D.

Microsoft Defender for Endpoint


E.

access reviews in Azure AD


Expert Solution
Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions