Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

New Release SC-100 Microsoft Certified: Cybersecurity Architect Expert Questions

Page: 6 / 12
Total 296 questions

Microsoft Cybersecurity Architect Questions and Answers

Question 21

You have a Microsoft 365 tenant.

You need to recommend a Microsoft 365 Defender solution to enhance security for the tenant. The solution must meet the following requirements:

• Identify users that are downloading an unusually high number of files from Microsoft SharePoint Online sites and are possibly involved in a data exfiltration attempt.

• Block Microsoft Teams messages that contain potentially malicious content by using zero-hour auto purge (ZAP).

What should you recommend for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Options:

Question 22

Your network contains an on-premises Active Directory Domain Services (ADDS) domain that syncs with a Microsoft Entra tenant. You need to assess the domain to identify potential credential exposure risks. The solution must meet the following requirements:

• Provide actionable recommendations to mitigate the risks.

• Minimize administrative effort

What should you use?

Options:

A.

Microsoft Defender for Cloud Apps

B.

Microsoft Secure Score

C.

Microsoft Assessment and Planning (MAP) Toolkit

D.

Microsoft Defender for Identity

Question 23

You have an Azure subscription that contains multiple Azure Storage blobs and Azure Files shares.

You need to recommend a security solution for authorizing access to the blobs and shares. The solution must meet the following requirements:

• Support access to the shares by using the SMB protocol.

• Limit access to the blobs to specific periods of time.

• Include authentication support when possible.

What should you recommend for each resource? To answer, select the options in the answer area.

NOTE: Each correct answer is worth one point.

Options:

Question 24

Your company is developing an invoicing application that will use Azure Active Directory (Azure AD) B2C. The application will be deployed as an App Service web app. You need to recommend a solution to the application development team to secure the application from identity related attacks. Which two configurations should you recommend? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options:

A.

Azure AD Conditional Access integration with user flows and custom policies

B.

Azure AD workbooks to monitor risk detections

C.

custom resource owner password credentials (ROPC) flows in Azure AD B2C

D.

access packages in Identity Governance

E.

smart account lockout in Azure AD B2C

Page: 6 / 12
Total 296 questions