Skip to content

Design security operations, identity, and compliance capabilities Questions

Practice questions for Design security operations, identity, and compliance capabilities topic in Microsoft Certified: Cybersecurity Architect Expert. 58 questions covering this domain.

58 questions16 easy29 medium13 hard
Q1
medium

A security architect needs a design for recurring access attestation across groups, applications, and privileged roles. Which Microsoft capability is ...

Q2
medium

A cybersecurity architect needs to design a detection and response capability that combines cross-signal investigation with centralized log analytics ...

Q3
medium

A security architect is modernizing identity and wants strong controls across SaaS, PaaS, IaaS, hybrid, and multicloud resources by combining identity...

Q4
easy

Which Microsoft product provides cloud-native SIEM capabilities in the SC-100 exam scope?

Q5
hard

An architect must design centralized logging and auditing for Microsoft 365 activities as part of a larger SecOps and compliance architecture. Which M...

Q6
easy

Which Microsoft identity governance capability makes privileged role assignments eligible and time-bound instead of permanently active?

Q7
easy

Which Microsoft product is the unified XDR service referenced for designing detection and response solutions?

Q8
medium

A privacy office needs a Microsoft solution specifically aimed at privacy management requirements and data subject rights processes. Which product sho...

Q9
medium

A compliance program must translate regulatory obligations into controls and then monitor alignment inside Azure. Which Microsoft combination best sup...

Q10
easy

Which Microsoft service should be used to centrally manage secrets, keys, and certificates in Azure designs?

Q11
medium

A company must design external user access for partners and also support modern identity scenarios with verifiable credentials. Which combination best...

Q12
hard

A business requires identity policies that immediately react to changing session conditions instead of waiting for long token lifetimes, while also pr...

Q13
medium

An organization wants access decisions to evaluate user context, device state, risk, and sensitive actions in a Zero Trust design. Which capability sh...

Q14
hard

A company has a fragmented privileged access model with standing admin roles across cloud tenants and on-premises systems. Which redesign best aligns ...

Q15
easy

Which Microsoft product detects on-premises Active Directory threats like lateral movement and DCSync attacks via sensors on domain controllers?

Q16
medium

An architect needs to centrally manage entitlements (access packages, lifecycle, reviews) for employees and partners. Which Microsoft Entra capability...

Q17
easy

Which Microsoft solution provides Cloud Infrastructure Entitlement Management (CIEM) across Azure, AWS, and GCP?

Q18
medium

An organization wants to enforce session controls (block download, paste, watermark) for risky sessions to SaaS apps. Which Microsoft service supports...

Q19
medium

Which Microsoft Entra capability provides phishing-resistant authentication using FIDO2 security keys or platform credentials (passkeys)?

Q20
medium

Which Microsoft Sentinel feature uses User and Entity Behavior Analytics (UEBA) to detect anomalous user behavior?

Sign in to see all 58 questions

Create a free account to browse all questions — completely free during our launch phase.