究極のガイド準備SC-100認証試験Microsoft Certified: Cybersecurity Architect Expertは2024年更新
リアルSC-100問題集でMicrosoft正確なアンサーは最新問題は2024年更新
Microsoft SC-100認定試験は、サイバーセキュリティアーキテクチャにおける専門知識を証明するための優れた方法です。この認定は、世界的に認められ、熟練したサイバーセキュリティの専門家を求める雇用主に高く評価されています。この認定を持つ個人は、就職市場で競争力があり、高収入のサイバーセキュリティのポジションに採用される可能性が高くなります。さらに、この認定は、個人がサイバーセキュリティの分野でスキルと知識を向上させ、最新の業界動向やベストプラクティスについて最新情報を得るための素晴らしい方法です。
質問 # 45
You need to recommend a solution to meet the AWS requirements.
What should you include in the recommendation? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
正解:
解説:
質問 # 46
You have an Azure subscription that contains several storage accounts. The storage accounts are accessed by legacy applications that are authenticated by using access keys.
You need to recommend a solution to prevent new applications from obtaining the access keys of the storage accounts. The solution must minimize the impact on the legacy applications.
What should you include in the recommendation?
- A. Configure automated key rotation.
- B. Apply read-only locks on the storage accounts.
- C. Set the AllowBlobPublicAcccss property to false.
- D. Set the AllowSharcdKeyAccess property to false.
正解:B
質問 # 47
You need to recommend a solution to meet the AWS requirements.
What should you include in the recommendation? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
正解:
解説:
質問 # 48
Your company has a Microsoft 365 E5 subscription.
The company wants to identify and classify data in Microsoft Teams, SharePoint Online, and Exchange Online.
You need to recommend a solution to identify documents that contain sensitive information.
What should you include in the recommendation?
- A. Information Governance
- B. data loss prevention (DLP)
- C. eDiscovery
- D. data classification content explorer
正解:B
質問 # 49
Your company uses Microsoft Defender for Cloud and Microsoft Sentinel. The company is designing an application that will have the architecture shown in the following exhibit.
You are designing a logging and auditing solution for the proposed architecture. The solution must meet the following requirements-.
* Integrate Azure Web Application Firewall (WAF) logs with Microsoft Sentinel.
* Use Defender for Cloud to review alerts from the virtual machines.
What should you include in the solution? To answer, select the appropriate options in the answer are a. NOTE: Each correct selection is worth one point.
正解:
解説:
質問 # 50
You have an on-premises server that runs Windows Server and contains a Microsoft SQL Server database named DB1.
You plan to migrate DB1 to Azure.
You need to recommend an encrypted Azure database solution that meets the following requirements:
* Minimizes the risks of malware that uses elevated privileges to access sensitive data
* Prevents database administrators from accessing sensitive data
* Enables pattern matching for server-side database operations
* Supports Microsoft Azure Attestation
* Uses hardware-based encryption
What should you include in the recommendation?
- A. Azure SQL Database with Intel Software Guard Extensions (Intel SGX) enclaves
- B. Azure SQL Managed Instance that has Always Encrypted configured
- C. Azure SQL Database with virtualization-based security (VBS) enclaves
- D. SQL Server on Azure Virtual Machines with virtualization-based security (VBS) enclaves
正解:A
質問 # 51
You are evaluating the security of ClaimsApp.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE; Each correct selection is worth one point.
正解:
解説:
質問 # 52
Your company plans to evaluate the security of its Azure environment based on the principles of the Microsoft Cloud Adoption Framework for Azure.
You need to recommend a cloud-based service to evaluate whether the Azure resources comply with the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF).
What should you recommend?
- A. Microsoft Defender for Cloud Apps
- B. Compliance Manager in Microsoft Purview
- C. Microsoft Sentinel
- D. Microsoft Defender for Cloud
正解:D
質問 # 53
You plan to deploy a dynamically scaling, Linux-based Azure Virtual Machine Scale Set that will host jump servers. The jump servers will be used by support staff who connect f personal and kiosk devices via the internet. The subnet of the jump servers will be associated to a network security group (NSG) You need to design an access solution for the Azure Virtual Machine Scale Set. The solution must meet the following requirements:
* Ensure that each time the support staff connects to a jump server; they must request access to the server.
* Ensure that only authorized support staff can initiate SSH connections to the jump servers.
* Maximize protection against brute-force attacks from internal networks and the internet.
* Ensure that users can only connect to the jump servers from the internet.
* Minimize administrative effort
What should you include in the solution? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
正解:
解説:
質問 # 54
You have a Microsoft 365 E5 subscription and an Azure subscription. You are designing a Microsoft Sentinel deployment.
You need to recommend a solution for the security operations team. The solution must include custom views and a dashboard for analyzing security events. What should you recommend using in Microsoft Sentinel?
- A. threat intelligence
- B. playbooks
- C. notebooks
- D. workbooks
正解:C
質問 # 55
Your company has a Microsoft 365 E5 subscription, an Azure subscription, on-premises applications, and Active Directory Domain Services (AD DSV You need to recommend an identity security strategy that meets the following requirements:
* Ensures that customers can use their Facebook credentials to authenticate to an Azure App Service website
* Ensures that partner companies can access Microsoft SharePoint Online sites for the project to which they are assigned The solution must minimize the need to deploy additional infrastructure components. What should you include in the recommendation? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
正解:
解説:
質問 # 56
You have a customer that has a Microsoft 365 subscription and an Azure subscription.
The customer has devices that run either Windows, iOS, Android, or macOS. The Windows devices are deployed on-premises and in Azure.
You need to design a security solution to assess whether all the devices meet the customer's compliance rules.
What should you include in the solution?
- A. Microsoft Defender for Endpoint
- B. Microsoft Information Protection
- C. Microsoft Sentinel
- D. Microsoft Endpoint Manager
正解:D
解説:
Explanation
https://docs.microsoft.com/en-us/mem/intune/protect/compliance-policy-monitor#open-the-compliance-dashboar
質問 # 57
You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.
The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019.
You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application.
Which security control should you recommend?
- A. Azure Active Directory (Azure AD) Conditional Access App Control policies
- B. OAuth app policies in Microsoft Defender for Cloud Apps
- C. app protection policies in Microsoft Endpoint Manager
- D. application control policies in Microsoft Defender for Endpoint
正解:B
解説:
https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create#windows-defender-application-control-policy-rules
質問 # 58
Your network contains an on-premises Active Directory Domain Services (AO DS) domain. The domain contains a server that runs Windows Server and hosts shared folders The domain syncs with Azure AD by using Azure AD Connect Azure AD Connect has group writeback enabled.
You have a Microsoft 365 subscription that uses Microsoft SharePoint Online.
You have multiple project teams. Each team has an AD DS group that syncs with Azure AD Each group has permissions to a unique SharePoint Online site and a Windows Server shared folder for its project. Users routinely move between project teams.
You need to recommend an Azure AD identity Governance solution that meets the following requirements:
* Project managers must verify that their project group contains only the current members of their project team
* The members of each project team must only have access to the resources of the project to which they are assigned
* Users must be removed from a project group automatically if the project manager has MOT verified the group s membership for 30 days.
* Administrative effort must be minimized.
What should you include in the recommendation? To answer select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
正解:
解説:
Explanation:
質問 # 59
You have a Microsoft 365 E5 subscription.
You are designing a solution to protect confidential data in Microsoft SharePoint Online sites that contain more than one million documents.
You need to recommend a solution to prevent Personally Identifiable Information (Pll) from being shared.
Which two components should you include in the recommendation? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
- A. sensitivity label policies
- B. retention label policies
- C. eDiscovery cases
- D. data loss prevention (DLP) policies
正解:A、C
質問 # 60
You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.
The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019.
You need to recommend a solution to ensure that only authorized applications can run on the virtual machines.
If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application.
Which security control should you recommend?
- A. Azure Security Benchmark compliance controls m Defender for Cloud
- B. app protection policies in Microsoft Endpoint Manager
- C. adaptive application controls in Defender for Cloud
- D. app discovery anomaly detection policies in Microsoft Defender for Cloud Apps
正解:C
解説:
https://docs.microsoft.com/en-us/azure/defender-for-cloud/recommendations-reference#compute-recommendatio
質問 # 61
You need to recommend a solution to meet the security requirements for the virtual machines. What should you include in the recommendation?
- A. Azure Virtual Desktop
- B. an Azure Bastion host
- C. just-in-time (JIT) VM access
- D. a network security group (NSG)
正解:B
質問 # 62
Your company has a multi-cloud environment that contains a Microsoft 365 subscription, an Azure subscription, and Amazon Web Services (AWS) implementation. You need to recommend a security posture management solution for the following components:
* Azure loT Edge devices
* AWS EC2 instances
Which services should you include in the recommendation? To answer, select the appropriate options in the answer are
a. NOTE: Each correct selection is worth one point.
正解:
解説:
質問 # 63
You need to recommend a solution to meet the compliance requirements.
What should you recommend? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
正解:
解説:
質問 # 64
Your company is migrating data to Azure. The data contains Personally Identifiable Information (Pll). The company plans to use Microsoft Information Protection for the Pll data store in Azure. You need to recommend a solution to discover Pll data at risk in the Azure resources.
What should you include in the recommendation? To answer, select the appropriate options in the answer are
a. NOTE: Each correct selection is worth one point.
正解:
解説:
質問 # 65
You have an Azure subscription that contains virtual machines, storage accounts, and Azure SQL databases. All resources are backed up multiple times a day by using Azure Backup. You are developing a strategy to protect against ransomware attacks.
You need to recommend which controls must be enabled to ensure that Azure Backup can be used to restore the resources in the event of a successtu\ ransonvwaTe attack.
Which two controls should you include in the recommendation? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
- A. Encrypt backups by using customer-managed keys (CMKs).
- B. Use Azure Monitor notifications when backup configurations change.
- C. Enable soft delete for backups.
- D. Require PINs for critical operations.
- E. Perform offline backups to Azure Data Box.
正解:D、E
質問 # 66
You are designing an auditing solution for Azure landing zones that will contain the following components:
* SQL audit logs for Azure SQL databases
* Windows Security logs from Azure virtual machines
* Azure App Service audit logs from App Service web apps
You need to recommend a centralized logging solution for the landing zones. The solution must meet the following requirements:
* Log all privileged access.
* Retain logs for at least 365 days.
* Minimize costs.
What should you include in the recommendation? To answer, select the appropriate options in the answer are a. NOTE: Each correct selection is worth one point.
正解:
解説:
質問 # 67
Your company uses Microsoft Defender for Cloud and Microsoft Sentinel. The company is designing an application that will have the architecture shown in the following exhibit.
You are designing a logging and auditing solution for the proposed architecture. The solution must meet the following requirements-.
* Integrate Azure Web Application Firewall (WAF) logs with Microsoft Sentinel.
* Use Defender for Cloud to review alerts from the virtual machines.
What should you include in the solution? To answer, select the appropriate options in the answer are a. NOTE: Each correct selection is worth one point.
正解:
解説:
質問 # 68
You have a Microsoft 365 E5 subscription and an Azure subscripts You need to evaluate the existing environment to increase the overall security posture for the following components:
* Windows 11 devices managed by Microsoft Intune
* Azure Storage accounts
* Azure virtual machines
What should you use to evaluate the components? To answer, select the appropriate options in the answer area.
正解:
解説:
質問 # 69
You are designing the security standards for a new Azure environment.
You need to design a privileged identity strategy based on the Zero Trust model.
Which framework should you follow to create the design?
- A. Enhanced Security Admin Environment (ESAE)
- B. Rapid Modernization Plan (RaMP)
- C. Microsoft Operational Security Assurance (OSA)
- D. Microsoft Security Development Lifecycle (SDL)
正解:A
質問 # 70
......
マイクロソフトのSC-100認定試験は、サイバーセキュリティ業界で非常に認められた認定資格です。この認証は、プロフェッショナルがMicrosoft環境を保護するスキルと知識を証明する機会を提供します。適切な準備とトレーニングを行えば、候補者は試験に合格し、サイバーセキュリティアーキテクチャのキャリアを進めることができます。
Microsoft SC-100試験は、脅威管理、アイデンティティとアクセス管理、セキュリティオペレーション、データとアプリケーション保護など、サイバーセキュリティに関連する幅広いトピックをカバーしています。試験は、Azure、Microsoft 365、Windows 10などのMicrosoftテクノロジーを使用して安全なソリューションを設計および実装する能力を評価するように設計されています。
Microsoft Certified: Cybersecurity Architect Expert SC-100試験練習問題集:https://jp.fast2test.com/SC-100-premium-file.html
SC-100プレミアム資料テストPDFで無料問題集お試しセット:https://drive.google.com/open?id=1LIso0OLVqFWYBkLZLKGeMvxfQ9G_jgMX