[2026年03月07日] 完全版最新の問題集でPDFで最新SC-100試験問題と解答 [Q96-Q114]

Share

[2026年03月07日] 完全版最新の問題集でPDFで最新SC-100試験問題と解答

無料で使えるSC-100試験問題集で100%合格できる試験簡単に合格させるGoShiken

質問 # 96
Hotspot Question
You have an Azure subscription that contains an Azure Kubernetes Service (AKS) cluster named AKS1. AKS1 hosts a Windows node pool named Pool1 and a Linux node pool named Pool2.
You are designing a pool update strategy for AKS1.
You need to recommend how often to replace the operating system images deployed to the nodes. The solution must meet the following requirements:
- Minimize how long it takes to apply operating system updates once the updates are released.
- Minimize administrative effort.
What should you recommend for each pool? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

解説:

Explanation:
Box 1: Monthly
Windows supports monthly node image version upgrades.
Box 2: Weekly
Linux supports weekly node image version upgrades.
Note: Azure Kubernetes Service patch and upgrade guidance
This section of the Azure Kubernetes Service (AKS) day-2 operations guide describes patching and upgrading strategies for AKS worker nodes and Kubernetes versions. As a cluster operator, you need to have a plan for keeping your clusters up to date and monitoring Kubernetes API changes and deprecations over time.
Reference:
https://learn.microsoft.com/en-us/azure/architecture/operator-guides/aks/aks-upgrade-practices


質問 # 97
Hotspot Question
You have an Azure subscription that contains a Microsoft Sentinel workspace named MWS1 and an Azure Data Lake Storage account named lake1. Firewall log data is ingested into MWS1.
You plan to export historical firewall log data from MWS1 to lake1.
You need to ensure that security analysts can perform threat hunting from MWS1. The solution must ensure that the firewall logs stored in lake1 can be included in threat hunting queries.
What should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

解説:

Explanation:
Box 1: A notebook
To export historical firewall log data from a Microsoft Sentinel workspace to Azure Data Lake Storage (ADLS) for threat hunting, you can utilize the "Export Historical Data" notebook or a scheduled data export using Log Analytics. The notebook approach allows for more granular control over the export process, including the ability to filter and transform data before exporting it to ADLS, while the scheduled data export offers a more automated and continuous approach.
Box 2: An Azure Synapse workspace
The new historical data export notebook uses Azure Synapse to work with data at scale.
Reference:
https://techcommunity.microsoft.com/blog/microsoftsentinelblog/export-historical-log-data-from- microsoft-sentinel/3413418


質問 # 98
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
You have a Microsoft 365 subscription that uses Microsoft Defender XDR. The subscription contains 500 devices that are enrolled in Microsoft Intune. The subscription contains 500 users that connect to external software as a service (SaaS) apps by using the devices.
You need to implement a solution that meets the following requirements:
- Allows user access to SaaS apps that Microsoft has identified as low
risk
- Blocks user access to SaaS apps that Microsoft has identified as high risk Solution: You configure app protection policies in Intune, and you create a Conditional Access policy.
Does this meet the goal?

  • A. No
  • B. Yes

正解:B


質問 # 99
You have an Azure SQL database named DB1 that contains customer information.
A team of database administrators has full access to DB1.
To address customer inquiries, operators in the customer service department use a custom web app named App1 to view the customer information.
You need to design a security strategy for D81. The solution must meet the following requirements:
* When the database administrators access DB1 by using SQL management tools, they must be prevented from viewing the content of the Credit Card attribute of each customer record.
* When the operators view customer records in App1, they must view only the last four digits of the Credit Card attribute.
What should you include in the design? To answer, select the appropriate options in the answer area. NOTE:
Each correct selection is worth one point.

正解:

解説:

Explanation:


質問 # 100
For a Microsoft cloud environment, you are designing a security architecture based on the Microsoft Cybersecurity Reference Architectures (MCRA). You need to protect against the following external threats of an attack chain:
* An attacker attempts to exfiltrate data to external websites.
* An attacker attempts lateral movement across domain-joined computers.
What should you include in the recommendation for each threat? To answer, select the appropriate options in the answer area.

正解:

解説:


質問 # 101
You need to recommend a strategy for securing the litware.com forest. The solution must meet the identity requirements. What should you include in the recommendation? To answer, select the appropriate options in the answer are a. NOTE; Each correct selection is worth one point.

正解:

解説:


質問 # 102
Your company has a Microsoft 365 E5 subscription, an Azure subscription, on-premises applications, and Active Directory Domain Services (AD DS).
You need to recommend an identity security strategy that meets the following requirements:
* Ensures that customers can use their Facebook credentials to authenticate to an Azure App Service website
* Ensures that partner companies can access Microsoft SharePoint Online sites for the project to which they are assigned The solution must minimize the need to deploy additional infrastructure components. What should you include in the recommendation? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

解説:

Explanation:
Graphical user interface, application Description automatically generated

Box 1 --> https://docs.microsoft.com/en-us/azure/active-directory-b2c/overview Box 2 -- > https://docs.microsoft.com/en-us/azure/active-directory/external-identities/identity-providers


質問 # 103
You have a hybrid cloud infrastructure.
You plan to deploy the Azure applications shown in the following table.

What should you use to meet the requirement of each app? To answer, select the appropriate options in the answer are a. NOTE: Each correct selection is worth one point.

正解:

解説:


質問 # 104
You are designing a new Azure environment based on the security best practices of the Microsoft Cloud Adoption Framework for Azure. The environment will contain one subscription for shared infrastructure components and three separate subscriptions for applications.
You need to recommend a deployment solution that includes network security groups (NSGs), Azure Firewall, Azure Key Vault, and Azure Bastion. The solution must minimize deployment effort and follow security best practices of the Microsoft Cloud Adoption Framework for Azure.
What should you include in the recommendation?

  • A. the Azure landing zone accelerator
  • B. Azure Security Benchmark v3
  • C. Azure Advisor
  • D. the Azure Well-Architected Framework

正解:A

解説:
The most simple solution is to host a jumpbox on the virtual network of the data management landing zone or data landing zone to connect to the data services through private endpoints.
Azure Bastion provides a few other core security benefits, including:
* The service integrates with native security appliances for an Azure virtual network, such as Azure Firewall.
Note:
* Platform landing zones: Subscriptions deployed to provide centralized services, often operated by a central team, or a number of central teams split by function (e.g. networking, identity), which will be used by various workloads and applications. Platform landing zones represent key services that often benefit from being consolidated for efficiency and ease of operations.
Examples include networking, identity, and management services.
* The Azure App Service landing zone accelerator is an open-source collection of architectural guidance and reference implementation to accelerate deployment of Azure App Service at scale.
It can provide a specific architectural approach and reference implementation via infrastructure as code templates to prepare your landing zones. The landing zones adhere to the architecture and best practices of the Cloud Adoption Framework.
Reference:
https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/scenarios/cloud-scale- analytics/architectures/connect-to-environments-privately
https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/landing-zone/
https://learn.microsoft.com/en-us/security/benchmark/azure/overview-v3
https://learn.microsoft.com/en-us/azure/architecture/framework/


質問 # 105
You are a security administrator for Microsoft 365; you implemented Microsoft Defender for Identity You have created several test accounts with specific configurations for the purpose of vulnerability testing, When attackers try to exploit these accounts, you would like to be alerted to see what areas in the configuration needs improvements.
What features in Microsoft Defender for Identity can you use to meet your objective?

  • A. Honeytoken entity tags
  • B. Sensitivity labels
  • C. System user tags
  • D. Confidential label

正解:A

解説:
Option A is incorrect because a sensitivity label is a tag applied to content containing sensitive data, whether text documents, spreadsheets, or emails. This will not meet the objective.
Option B is incorrect because User tags are identifiers for specific groups of users in Microsoft Defender for Office 365 and will not meet the objective.
Option C is incorrect because a confidential label is a sensitivity label you can use to add a layer of security to your files or emails.
Option D is correct because Honeytoken entities are used as traps for malicious actors. Any authentication associated with these honeytoken entities triggers an alert.
Reference:
https://docs.microsoft.com/en-us/advanced-threat-analytics/suspicious-activity- guide#honeytoken-activity


質問 # 106
Hotspot Question
You have 500 Windows 11 devices and 200 macOS devices. The devices are managed by using Microsoft Intune and are subject to compliance policies.
You plan to deploy the following Intune features:
- Security baselines
- Remote lock of noncompliant devices
Which feature will be supported by each platform? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point

正解:

解説:

Explanation:
Box 1: Windows only
Security baselines in Microsoft Intune are primarily designed for Windows devices and not supported on macOS devices. While Intune supports managing both Windows and macOS devices, security baselines, which are preconfigured groups of settings with best practice recommendations, are specifically for Windows. macOS devices can be secured using other Intune features like device restrictions, OS and software updates, and compliance policies.
Box 2: Windows and macOS
The "Remote lock" device action in Microsoft Intune is supported for both Windows and macOS devices, as part of compliance policies. When a device is deemed noncompliant based on the configured compliance policies, the "Remote lock" action can be initiated to lock the device, preventing unauthorized access.
Reference:
https://learn.microsoft.com/en-us/intune/intune-service/protect/security-baselines
https://learn.microsoft.com/en-us/intune/intune-service/protect/actions-for-noncompliance


質問 # 107
You have a Microsoft 365 tenant. Your company uses a third-party software as a service (SaaS) app named App1. App1 supports authenticating users by using Microsoft Entra credentials.
You need to recommend a solution to enable users to authenticate to App1 by using their Microsoft Entra credentials.
What should you include in the recommendation?

  • A. Microsoft Entra Application Proxy
  • B. a Microsoft Entra enterprise application
  • C. Microsoft Entra External ID
  • D. a relying party trust in Active Directory Federation Services (AD FS)

正解:B

解説:
Note: Users in Microsoft 365 can use their Microsoft Entra credentials to authenticate to third- party SaaS applications through the Microsoft Entra enterprise application feature. This is achieved by configuring the SaaS application to use Microsoft Entra ID as its identity provider and enabling single sign-on (SSO).
Reference:
https://learn.microsoft.com/en-us/microsoft-365/enterprise/integrated-apps-and-azure-ads


質問 # 108
You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.
The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019.
You need to recommend a solution to ensure that only authorized applications can run on the virtual machines.
If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application.
Which security control should you recommend?

  • A. Azure Security Benchmark compliance controls m Defender for Cloud
  • B. app protection policies in Microsoft Endpoint Manager
  • C. app discovery anomaly detection policies in Microsoft Defender for Cloud Apps
  • D. adaptive application controls in Defender for Cloud

正解:D

解説:
https://docs.microsoft.com/en-us/azure/defender-for-cloud/recommendations-reference#compute-recommendatio


質問 # 109
You open Microsoft Defender for Cloud as shown in the following exhibit.

Use the drop-down menus to select the answer choice that complete each statements based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

正解:

解説:


質問 # 110
Hotspot Question
You have an Azure SQL database named DB1 that contains customer information.
A team of database administrators has full access to DB1.
To address customer inquiries, operators in the customer service department use a custom web app named App1 to view the customer information.
You need to design a security strategy for DB1. The solution must meet the following requirement:
- When the database administrators access DB1 by using SQL management
tools, they must be prevented from viewing the content of the
CreditCard attribute of each customer record.
- When the operators view customer records in App1, they must view only the last four digits of the CreditCard attribute.
What should you include in the design? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

解説:


質問 # 111
You have an Azure subscription that contains a Microsoft Sentinel workspace named MSW1. MSW1 includes
50 scheduled analytics rules.
You need to design a security orchestration automated response (SOAR) solution by using Microsoft Sentinel playbooks. The solution must meet the following requirements:
* Ensure that expiration dates can be configured when a playbook runs.
* Minimize the administrative effort required to configure individual analytics rules.
What should you use to invoke the playbooks, and which type of Microsoft Sentinel trigger should you use?
To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

解説:

Explanation:


質問 # 112
Your company uses Microsoft Defender for Cloud and Microsoft Sentinel. The company is designing an application that will have the architecture shown in the following exhibit.

You are designing a logging and auditing solution for the proposed architecture. The solution must meet the following requirements-.
* Integrate Azure Web Application Firewall (WAF) logs with Microsoft Sentinel.
* Use Defender for Cloud to review alerts from the virtual machines.
What should you include in the solution? To answer, select the appropriate options in the answer area. NOTE:
Each correct selection is worth one point.

正解:

解説:


質問 # 113
You are evaluating the security of ClaimsApp.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE; Each correct selection is worth one point.

正解:

解説:


質問 # 114
......

無料で試せるSC-100試験問題SC-100実際の無料試験問題:https://www.goshiken.com/Microsoft/SC-100-mondaishu.html

検証済みのSC-100問題集と325格別な問題:https://drive.google.com/open?id=1H67u6nTEjpq484hh8NUK_gbD-3waDnJZ