[2026年07月29日] 合格率取得する秘訣はSC-100日本語認定試験エンジンPDF
SC-100日本語試験問題集合格できるには更新された2026年07月テスト問題集
質問 # 51
Active Directory ドメイン サービス (AD DS) と同期する Microsoft 365 サブスクリプションがあります。
サブスクリプション内のデータを暗号化したランサムウェア攻撃に対する回復手順を定義する必要があります。ソリューションは、Microsoft セキュリティのベスト プラクティスに従う必要があります。
復旧計画の最初のステップは何ですか?
- A. 法執行機関に連絡してください。
- B. Microsoft OneDrive 同期と Exchange ActiveSync を無効にします。
- C. クリーンアップされたコンピューターまたはデバイスにファイルを復元します。
- D. Microsoft Defender for Endpoint からセキュリティ スキャンを実行します。
正解:B
質問 # 52
ホットスポットに関する質問
さまざまな開発者グループがランダムな時間と速度でさまざまな API セットにアクセスできるようにする Azure API Management ソリューションをデプロイする予定です。
購入すべき価格帯と、レート制限ポリシーを適用する範囲を推奨する必要があります。ソリューションは以下の要件を満たす必要があります。
- 各開発者グループが特定の API セットのみにアクセスできるようにします。
- 各APIセットが特定のレートで設定できることを確認する
制限。
- 開発と管理の労力とコストを最小限に抑えます。
何を推奨しますか? 回答するには、回答エリアで適切なオプションを選択してください。
注意: 正しい選択ごとに 1 ポイントが付与されます。
正解:
解説:
Explanation:
Box 1: Standard V2
Standard v2 - Standard v2 is a production-ready tier with support for network-isolated backends.
Box 2: Product
API Management allows you to define policies at the following scopes, from most broad to most narrow:
Global (all APIs)
Workspace (all APIs associated with a selected workspace)
*-> Product (all APIs associated with a selected product)
API (all operations in an API)
Operation (single operation in an API)
When configuring a policy, you must first select the scope at which the policy applies.
Reference:
https://learn.microsoft.com/en-us/azure/api-management/api-management-features
https://learn.microsoft.com/en-us/azure/api-management/api-management-howto-policies
質問 # 53
ドラッグアンドドロップの質問
あなたの会社は、ランサムウェア インシデント調査を最適化したいと考えています。
Microsoft 検出および対応チーム (DART) のアプローチに基づいて、ランサムウェア インシデントを調査するための計画を推奨する必要があります。
計画の中で順番に実行することを推奨する 3 つのアクションはどれですか。回答するには、適切なアクションをアクション リストから回答領域に移動し、正しい順序に並べます。
正解:
解説:
Explanation:
https://learn.microsoft.com/en-us/security/compass/incident-response-playbook-dart- ransomware-approach
質問 # 54
貴社はハイブリッドクラウドインフラストラクチャを採用しています。
データとアプリケーションは、クラウド環境間で定期的に移動されます。
同社のオンプレミスネットワークは、以下の図に示すように管理されています。
ハイブリッドクラウドインフラストラクチャをサポートするセキュリティ運用を設計しています。ソリューションは以下の要件を満たす必要があります。
複数の環境にわたる仮想マシンとサーバーを管理します。
* Azure ポリシー全体にわたって、すべての環境のすべてのリソースに対して標準を適用します。
オンプレミスネットワークには、どの2つのコンポーネントを推奨すべきでしょうか?それぞれの正解は、ソリューションの一部を示しています。
注:正解ごとに1ポイントが加算されます。
- A. アジュールバスティオン
- B. Azure Arc
- C. Azure Policy のゲスト構成
- D. オンプレミスデータゲートウェイ
- E. Azure VPN ゲートウェイ
正解:B、C
解説:
https://docs.micros oft.com/en-us/azure/governance/machine-c onfiguration/overview
質問 # 55
お客様のネットワークには、Domain1 という名前の Active Directory ドメインサービス (AD DS) ドメインが含まれています。
お客様はMicrosoft Entraテナントをお持ちです。
Domain1は、Microsoft Entra Connectを使用してテナントと同期します。
Microsoft Entraのスマートロックアウトを評価するには、以下のアカウントロックアウトに関する考慮事項をテストする必要があります。
ログインに失敗した回数。この回数を超えるとアカウントがロックされます。
正解:
解説:
Explanation:
質問 # 56
Microsoft 365 Defender を使用して保護された Microsoft 365 サブスクリプションがある。 Microsoft Sentinel を使用して Microsoft 365 および Microsoft 365 Defender からのイベントを監視するセキュリティ運用戦略を設計している。 次の要件を満たすソリューションを推奨する必要があります。
* Microsoft Sentinel をサードパーティのセキュリティ ベンダーと統合して、既知のマルウェアに関する情報にアクセスします
* イベント内でコマンド アンド コントロール サーバーの IP アドレスが検出されると、インシデントが自動的に生成されます。各要件を満たすには、Microsoft Sentinel で何を構成する必要がありますか? 回答するには、回答領域で適切なオプションを選択してください。
注: 正しく選択するたびに 1 ポイントの価値があります。
正解:
解説:
質問 # 57
あなたは、Azure にオンボードされたコンテナー化されたアプリケーションのセキュリティ標準を設計しています。Microsoft Defender for Containers の使用を評価しています。
Defender for Containers を使用して既知の脆弱性をスキャンできるのは、どの 2 つの環境ですか? それぞれの正解は完全な解決策を示します。注: 正しく選択するたびに 1 ポイントの価値があります。
- A. Azure Kubernetes Service (AKS) にデプロイされた Windows コンテナー
- B. Azure Container Registry にデプロイされた Linux コンテナー
- C. Azure Container Instances にデプロイされた Linux コンテナー
- D. Azure Container Registry にデプロイされた Windows コンテナー
- E. Azure Kubernetes Service (AKS) にデプロイされた Linux コンテナー
正解:B、E
解説:
https://docs.microsoft.com/en-us/learn/modules/design-strategy-for-secure-paas-iaas-saas-services/9-specify-security-requirements-for-containers
https://docs.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-introduction#view-vulnerabilities-for-running-images
Topic 2, Fabrikam, Inc
On-premises Environment
The on-premises network contains a single Active Directory Domain Services (AD DS) domain named corp.fabrikam.com.
Azure Environment
Fabrikam has the following Azure resources:
* An Azure Active Directory (Azure AD) tenant named fabrikam.onmicrosoft.com that syncs with corp.fabnkam.com
* A single Azure subscription named Sub1
* A virtual network named Vnet1 in the East US Azure region
* A virtual network named Vnet2 in the West Europe Azure region
* An instance of Azure Front Door named FD1 that has Azure Web Application Firewall (WAR enabled
* A Microsoft Sentinel workspace
* An Azure SQL database named ClaimsDB that contains a table named ClaimDetails
* 20 virtual machines that are configured as application servers and are NOT onboarded to Microsoft Defender for Cloud
* A resource group named TestRG that is used for testing purposes only
* An Azure Virtual Desktop host pool that contains personal assigned session hosts All the resources in Sub1 are in either the East US or the West Europe region.
Partners
Fabrikam has contracted a company named Contoso, Ltd. to develop applications. Contoso has the following infrastructure-.
* An Azure AD tenant named contoso.onmicrosoft.com
* An Amazon Web Services (AWS) implementation named ContosoAWS1 that contains AWS EC2 instances used to host test workloads for the applications of Fabrikam Developers at Contoso will connect to the resources of Fabrikam to test or update applications. The developers will be added to a security Group named Contoso Developers in fabrikam.onmicrosoft.com that will be assigned to roles in Sub1.
The ContosoDevelopers group is assigned the db.owner role for the ClaimsDB database.
Compliance Event
Fabrikam deploys the following compliance environment:
* Defender for Cloud is configured to assess all the resources in Sub1 for compliance to the HIPAA HITRUST standard.
* Currently, resources that are noncompliant with the HIPAA HITRUST standard are remediated manually.
* Qualys is used as the standard vulnerability assessment tool for servers.
Problem Statements
The secure score in Defender for Cloud shows that all the virtual machines generate the following recommendation-. Machines should have a vulnerability assessment solution.
All the virtual machines must be compliant in Defender for Cloud.
ClaimApp Deployment
Fabrikam plans to implement an internet-accessible application named ClaimsApp that will have the following specification
* ClaimsApp will be deployed to Azure App Service instances that connect to Vnetl and Vnet2.
* Users will connect to ClaimsApp by using a URL of https://claims.fabrikam.com.
* ClaimsApp will access data in ClaimsDB.
* ClaimsDB must be accessible only from Azure virtual networks.
* The app services permission for ClaimsApp must be assigned to ClaimsDB.
Application Development Requirements
Fabrikam identifies the following requirements for application development:
* Azure DevTest labs will be used by developers for testing.
* All the application code must be stored in GitHub Enterprise.
* Azure Pipelines will be used to manage application deployments.
* All application code changes must be scanned for security vulnerabilities, including application code or configuration files that contain secrets in clear text. Scanning must be done at the time the code is pushed to a repository.
Security Requirement
Fabrikam identifies the following security requirements:
* Internet-accessible applications must prevent connections that originate in North Korea.
* Only members of a group named InfraSec must be allowed to configure network security groups (NSGs} and instances of Azure Firewall, VJM. And Front Door in Sub1.
* Administrators must connect to a secure host to perform any remote administration of the virtual machines. The secure host must be provisioned from a custom operating system image.
AWS Requirements
Fabrikam identifies the following security requirements for the data hosted in ContosoAWSV.
* Notify security administrators at Fabrikam if any AWS EC2 instances are noncompliant with secure score recommendations.
* Ensure that the security administrators can query AWS service logs directly from the Azure environment.
Contoso Developer Requirements
Fabrikam identifies the following requirements for the Contoso developers;
* Every month, the membership of the ContosoDevelopers group must be verified.
* The Contoso developers must use their existing contoso.onmicrosoft.com credentials to access the resources in Sub1.
* The Comoro developers must be prevented from viewing the data in a column named MedicalHistory in the ClaimDetails table.
Compliance Requirement
Fabrikam wants to automatically remediate the virtual machines in Sub1 to be compliant with the HIPPA HITRUST standard. The virtual machines in TestRG must be excluded from the compliance assessment.
質問 # 58
Azure サブスクリプションとアマゾン ウェブ サービス (AWS) アカウントを含むマルチクラウド環境があります。
両方のサブスクリプションのリソースを管理するには、Azure にセキュリティ サービスを実装する必要があります。ソリューションは次の要件を満たす必要があります。
* AWS CloudTrail イベントで見つかった脅威を自動的に識別します。
* Azure ポリシーを使用して、AWS 仮想マシンにセキュリティ設定を適用します。
各要件のソリューションには何を含める必要がありますか? 回答するには、回答内の適切な選択肢を選択してください。注: 正しく選択するたびに 1 ポイントの価値があります。
正解:
解説:
Explanation:
質問 # 59
ClaimsDB への接続要件を満たすソリューションを推奨する必要があります。
それぞれの要件に対して何を使用することを推奨しますか? 回答するには、回答領域で適切なオプションを選択してください。
注: 正しく選択するたびに 1 ポイントの価値があります。
正解:
解説:
質問 # 60
Microsoft Defender for Cloud が有効になっている Azure サブスクリプションがあります。
次の図に示すように、Azure Security Benchmark V3 レポートを評価しています。

Windows を実行するすべての仮想マシンにサーバー用 Microsoft Defender がインストールされているかどうかを確認する必要があります。どのコンプライアンス管理を評価する必要がありますか?
- A. インシデント対応
- B. 体制と脆弱性の管理
- C. データ保護
- D. 資産管理
- E. エンドポイントセキュリティ
正解:A
解説:
https://docs.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-endpoint-security
質問 # 61
ジャンプサーバーをホストする、動的にスケーリング可能なLinuxベースのAzure仮想マシンスケールセットをデプロイする予定です。ジャンプサーバーは、インターネット経由で個人用デバイスやキオスク端末を接続するサポートスタッフが使用します。ジャンプサーバーのサブネットは、ネットワークセキュリティグループ(NSG)に関連付けられます。Azure仮想マシンスケールセットのアクセスソリューションを設計する必要があります。ソリューションは、次の要件を満たす必要があります。
* サポートスタッフがジャンプサーバーに接続するたびに、サーバーへのアクセスを要求する必要があることを確認してください。
* 許可されたサポートスタッフのみがジャンプサーバーへのSSH接続を開始できるようにしてください。
* 内部ネットワークおよびインターネットからの総当たり攻撃に対する保護を最大限に強化する。
* ユーザーがジャンプサーバーに接続できるのはインターネット経由のみであることを確認してください。
管理業務の手間を最小限に抑える
解答には何を含めるべきでしょうか?回答するには、回答欄で適切な選択肢を選んでください。
注:正解ごとに1ポイントが加算されます。
正解:
解説:
Explanation:
質問 # 62
あなたの会社は、新しい Azure App Service Web アプリを開発しています。あなたは、Web アプリのセキュリティを検証するための設計支援を提供しています。
安全でないサーバー構成、クロスサイト スクリプティング (XSS)、SQL インジェクションなどの脆弱性について Web アプリをテストするためのソリューションを推奨する必要があります。推奨事項には何を含めるべきですか?
- A. 静的アプリケーション セキュリティ テスト (SAST)
- B. 動的アプリケーション セキュリティ テスト (DAST)
- C. 対話型アプリケーション セキュリティ テスト (IAST)
- D. ランタイム アプリケーション SE/F 保護 (RASP)
正解:B
解説:
DAST tools analyze programs while they are executing to find security vulnerabilities such as memory corruption, insecure server configuration, cross-site scripting, user privilege issues, SQL injection, and other critical security concerns.
Reference:
https://docs.microsoft.com/en-us/azure/security/develop/secure-develop
質問 # 63
Azure リソースの保存データの暗号化標準を設計している場合、保存データが AES-256 キーを使用して暗号化されるようにするための推奨事項を提供する必要があります。ソリューションは、暗号化キーの毎月のローテーションをサポートする必要があります。
解決策: Azure SQL データベースの場合は、カスタマー マネージド キー (CMK) を使用する透過的データ暗号化 (TDE) をお勧めします。
これは目標を達成していますか?
- A. はい
- B. いいえ
正解:B
質問 # 64
あなたの会社は、ランサムウェア インシデントの調査を最適化したいと考えています。
Microsoft Detection and Response Team (DART) のアプローチに基づいてランサムウェア インシデントを調査する計画を推奨する必要があります。
計画内で順番に実行することを推奨する 3 つのアクションはどれですか? 回答するには、アクションのリストから適切なアクションを回答領域に移動し、正しい順序で並べます。
正解:
解説:
1 - Assess the current situation and identify the scope.
2 - Identify which line-of-business (LOB) apps are unavailable due to a ransomware incident.
3 - Identify the compromise recovery process.
質問 # 65
あなたはMicrosoft 365のサブスクリプションをお持ちです。
Microsoft Purview Information Protection を構成すると、機密ラベルが自動的に適用されます。
Microsoft Purview分類器によって機密情報と定義されたコンテンツを含むファイルの場合、ユーザーがラベル付けされていないファイルをMicrosoft SharePoint Onlineにアップロードできないようにするソリューションを推奨する必要があります。
推薦状には何を含めるべきでしょうか?回答するには、回答欄で適切な選択肢を選んでください。
注:正解ごとに1ポイントが加算されます。
正解:
解説:
Explanation:
質問 # 66
Microsoft 365 E5 サブスクリプションをお持ちです。
Global Secure Access ユニバーサル テナント制限 v2 を展開する予定です。
どの認証プレーン リソースとどのデータ プレーン リソースが保護されますか? 回答するには、回答領域で適切なオプションを選択してください。
注意: 正しい選択ごとに 1 ポイントが付与されます。
正解:
解説:
Explanation:
質問 # 67
ドラッグアンドドロップの質問
お客様は、クラウドベースのセキュリティ情報・イベント管理(SIEM)としてMicrosoft Sentinelを導入しました。お客様は投資価値を最大化したいと考えており、脅威が損害や業務の中断を引き起こす前に、コスト効率の高い方法で脅威を検知・対応することで、インシデント管理ライフサイクルを強化する方法を尋ねています。
クライアントがこの目標を達成するのに役立つ Sentinel コンポーネントを特定する必要があります。
各シナリオにどのSentinelツールを推奨すべきでしょうか?適切なツールを適切なインシデント管理アクティビティにドラッグしてください。各ツールは1回、複数回、または全く使用しない場合があります。
正解:
解説:
Explanation:
The client should use a playbook to automatically isolate an infected machine. A Sentinel playbook is a reusable set of steps to perform common security-related tasks, such as investigating and responding to incidents. Playbooks can be created using Logic Apps Designer in Sentinel and can be triggered manually or automatically in response to security events.
Microsoft Sentinel allows you to create custom playbooks that are tailored to your organization's specific needs. For example, you could create a playbook that automatically responds to alerts about suspicious logins by obtaining more information about the user and their activity.
The client should use a workbook to visualize and monitor threat data. Microsoft Sentinel Workbooks, which is based on Azure Monitor Workbooks, is a reusable tool that you can use to visualize and analyze data from your Azure monitoring metrics. You can create workbooks containing multiple visuals and then save them so you can access them later. Workbooks are stored in JavaScript Object Notation (JSON) format and can be exported and imported from one Azure tenant to another.
The client should use a notebook to analyze data with Python machine learning. A Jupyter notebook is an interactive, web-based environment for code execution commonly used to develop machine learning tasks. Jupyter notebooks in Sentinel enable you to interactively analyze and visualize data in your workspace.
With Jupyter notebooks in Microsoft Sentinel, you can:
- Query and analyze data interactively.
- Visualize data to gain insights and better understand relationships.
- Build and share machine learning models.
The client should not use a runbook. A runbook is used in Azure Automation to define process automation. Runbooks can be written in PowerShell or Python or created using graphical tools.
質問 # 68
Microsoft 365 テナントを所有しています。会社では、App1 というサードパーティ製の SaaS (Software as a Service) アプリを使用しています。App1 は、Microsoft Entra 資格情報を使用したユーザー認証をサポートしています。
ユーザーが Microsoft Entra 資格情報を使用して App1 に認証できるようにするソリューションを推奨する必要があります。
推薦書には何を含めるべきでしょうか?
- A. Microsoft Entra 外部 ID
- B. Active Directory フェデレーション サービス (AD FS) の証明書利用者信頼
- C. Microsoft Entra エンタープライズ アプリケーション
- D. Microsoft Entra アプリケーション プロキシ
正解:C
解説:
Note: Users in Microsoft 365 can use their Microsoft Entra credentials to authenticate to third- party SaaS applications through the Microsoft Entra enterprise application feature. This is achieved by configuring the SaaS application to use Microsoft Entra ID as its identity provider and enabling single sign-on (SSO).
Reference:
https://learn.microsoft.com/en-us/microsoft-365/enterprise/integrated-apps-and-azure-ads
質問 # 69
あなたの会社には、コンテナー化された Web アプリをデプロイするために使用される Azure App Service プランがあります。Web アプリを App Service プランにデプロイするための安全な DevOps 戦略を設計しています。コード スキャン ツールを安全なソフトウェア開発ライフサイクルに統合する戦略を推奨する必要があります。コードは次の 2 つのフェーズでスキャンする必要があります。
コードをリポジトリにアップロードする コンテナを構築する
各フェーズのコード スキャンをどこに統合する必要がありますか? 回答するには、回答領域で適切なオプションを選択してください。
正解:
解説:
質問 # 70
contoso.com という名前の Microsoft Entra テナントがあり、Microsoft Intune を使用しています。contoso.com の各ユーザーは、Microsoft Entra ID P1 ライセンスと、グローバル セキュア アクセス クライアントが展開された Windows 11 デバイスを所有しています。
Microsoft Entra Internet Access の以下の構成を展開する予定です。
* ベースラインプロファイルを有効にします。
* 優先度300のセキュリティプロファイル「Profile」を作成し、WCFPolicyという名前の単一のWebコンテンツフィルタリングポリシーを格納します。WCFPolicy1を次のように構成します。
o アクションを許可に設定します。
o 完全修飾ドメイン名 (FQDN) の宛先が '.adatum.com' である単一のルールを含めます。
* Profile1 を CAPolicy1 という名前の条件付きアクセス ポリシーにリンクし、CAPolicy1 をすべてのユーザーに適用し、ユーザーのデバイスが準拠していない場合を除きアクセスを許可します。計画されている展開が次のリソースへのトラフィックに与える影響を評価する必要があります。
* https://www.adatum.com:8433
* https://www.fabrikam.com
どのような2つの交通状況が発生するでしょうか?それぞれの正解は、完全な解決策を示しています。
注:正解ごとに1ポイント獲得できます。
- A. https://www.adatumxom:8433 へのトラフィックは、すべてのデバイスから許可されます。
- B. https://www.adatum.com:8433 へのトラフィックは、すべてのデバイスからブロックされます。
- C. https://www.fabrikam.com へのアクセスは、準拠デバイスからのみ許可されます。
- D. https://www.fabrikam.com へのトラフィックは、すべてのデバイスから許可されます。
- E. https://www.adatum.com:8433 へのトラフィックは、準拠デバイスからのみ許可されます。
- F. https://www.fabrikam.com へのアクセスは、準拠していないデバイスからのみブロックされます。
正解:D、E
質問 # 71
Azure Automation アカウントで Runbook のセキュリティを設計しています。Runbook はデータを Azure Data Lake Storage Gen2 にコピーします。
コピー プロセスのコンポーネントを保護するソリューションを推奨する必要があります。
各コンポーネントの推奨事項には何を含める必要がありますか? 回答するには、回答内の適切な選択肢を選択してください。注: 正しく選択するたびに 1 ポイントの価値があります。
正解:
解説:
質問 # 72
貴社には、従来型の運用技術(OT)機器とIoT機器があります。
Microsoft Cybersecurity Reference Architectures (MCRA) に基づき、OTおよびIoTデバイスにゼロトラスト原則を適用するためのベストプラクティスを推奨する必要があります。このソリューションは、業務運営の中断リスクを最小限に抑えるものでなければなりません。
推奨事項に含めるべきセキュリティ手法はどれですか?正解はそれぞれ解決策の一部を示しています。
注:正解ごとに1ポイント獲得できます。
- A. 脅威監視
- B. アクティブスキャン
- C. ソフトウェアパッチ適用
- D. 受動的なトラフィック監視
正解:A、C
質問 # 73
あなたは、クラウド専用環境向けのセキュリティアーキテクチャを設計しています。
あなたは、Microsoft サイバーセキュリティ参照アーキテクチャ (MCRA) に基づいて、Microsoft 365 Defender と他の Microsoft クラウド サービスとの統合ポイントを確認しています。
Microsoft 365 Defenderと直接統合でき、以下の要件を満たすMicrosoftクラウドサービスを推奨する必要があります。
* Microsoft 365 Defender ポータルから直接管理できるデータ損失防止 (DLP) ポリシーを適用します。
* ユーザーおよびエンティティ行動分析(UEBA)に基づき、統合アラート機能を使用してセキュリティ脅威を検知し、対応します。
各要件に対する推奨事項には何を含めるべきでしょうか?回答するには、回答欄で適切な選択肢を選んでください。注:正解ごとに1ポイントが加算されます。
正解:
解説:
Explanation:
質問 # 74
......
SC-100日本語テスト問題練習は2026年最新のに更新された298問あります:https://www.goshiken.com/Microsoft/SC-100J-mondaishu.html