exam questions

Exam SC-100 All Questions

View all questions & answers for the SC-100 exam

Exam SC-100 topic 2 question 9 discussion

Actual exam question from Microsoft's SC-100
Question #: 9
Topic #: 2
[All SC-100 Questions]

Your company is preparing for cloud adoption.
You are designing security for Azure landing zones.
Which two preventative controls can you implement to increase the secure score? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

  • A. Azure Web Application Firewall (WAF)
  • B. Azure Active Directory (Azure AD) Privileged Identity Management (PIM)
  • C. Microsoft Sentinel
  • D. Azure Firewall
  • E. Microsoft Defender for Cloud alerts
Show Suggested Answer Hide Answer
Suggested Answer: AD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
PlumpyTumbler
Highly Voted 2 years, 7 months ago
Selected Answer: AD
This question is to increase secure score. Here is a long reference page from Microsoft of security recommendations that can increase your secure score. Sentinel & PIM are not on it. The explanation makes a great point about alerts not being preventive, which is a key aspect of the required solution. https://docs.microsoft.com/en-us/azure/defender-for-cloud/recommendations-reference Which leads me to believe that only firewalls fit the bill.
upvoted 51 times
grimrodd
5 months, 2 weeks ago
The below article also confirms the answers being A and D https://learn.microsoft.com/en-us/azure/defender-for-cloud/secure-score-security-controls
upvoted 3 times
...
jarihd1
2 years, 6 months ago
What if - there is no application gateway / traffic manager / CDN etc configured - how you will configure WAF ? CAF needs basic things for the security readiness! Do not confuse people.
upvoted 4 times
...
mikenyga
2 years, 7 months ago
Why defender for cloud? Question about landing zone, (CAF) answer correct. Onboard Microsoft Sentinel. Azure Identity Management and access control security best practices. https://docs.microsoft.com/en-us/azure/cloud-adoption-framework/ready/considerations/landing-zone-security
upvoted 2 times
alpars
2 years, 7 months ago
Sentinel does not increase security score and it is used widely for detection and correlation.
upvoted 7 times
...
...
PeteNZ
2 years, 2 months ago
Well, disagree. This is about landing zones and if you scroll down here, I'd say PIM would definitely be an answer. https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/landing-zone/design-area/security
upvoted 7 times
NinjaSchoolProfessor
1 year, 9 months ago
ABCD are correct. All items except "Defender for Cloud alerts" are tools that improve security and are available for use with Azure Landing Zone.
upvoted 3 times
...
Ramkid
2 years, 1 month ago
I agree with you. https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/landing-zone/design-area/identity-access-landing-zones#privileged-identity-management-pim
upvoted 1 times
...
meelaran
1 year, 3 months ago
it does not increase security score
upvoted 1 times
...
...
...
HardcodedCloud
Highly Voted 2 years, 7 months ago
Selected Answer: AD
Preventative controls are WAF & Firewall
upvoted 21 times
Ramye
1 year, 3 months ago
Certainly, but does it improve the security score? No. So these can’t be score…
upvoted 1 times
Ramye
1 year, 3 months ago
Sorry meant to say these can’t be answers
upvoted 1 times
...
...
...
dsatizabal
Most Recent 3 months, 1 week ago
Selected Answer: BC
For me, being this about ALZ, I definitely go for BC, firewall and WAF are for applications, not for the zone where those lands, I mean, what if you have a private cluster with no public access? Besides, this article already shared: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/landing-zone/design-area/security mentiones that: "Make use of the recommendations, alerting, and remediation capabilities of Microsoft Defender for Cloud. Your security team can also integrate Microsoft Defender for Cloud into Microsoft Sentinel if they need a more robust, centrally managed hybrid and multicloud Security Information Event Management (SIEM)/Security Orchestration and Response (SOAR) solution." So, sentinel definitely helps increasing the ALZ security.
upvoted 1 times
...
JuicyLinux
6 months, 2 weeks ago
Selected Answer: AD
A good reference from Microsoft Learn on how to improve the security score in Microsoft Defender for Cloud: https://learn.microsoft.com/en-us/azure/defender-for-cloud/secure-score-security-controls#improving-a-secure-score
upvoted 1 times
...
Tony416
7 months ago
Selected Answer: BE
Tricky question. Reading the CAF, and based on the following TOPIC: "Design area overview," https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/landing-zone/design-area/security#design-area-overview However, I recommend everyone expand the research...
upvoted 1 times
...
JAGUDERO
1 year ago
COPILOT RESPONSE B. Azure Active Directory (Azure AD) Privileged Identity Management (PIM): Este servicio ayuda a gestionar, controlar y supervisar el acceso a recursos importantes en la organización. Puede ayudar a reducir los riesgos asociados con los privilegios de acceso al proporcionar acceso justo a tiempo y acceso justo lo suficiente. E. Microsoft Defender for Cloud alerts: Estas alertas proporcionan notificaciones en tiempo real sobre actividades sospechosas y violaciones de políticas en tu entorno de nube. Pueden ayudarte a detectar y responder rápidamente a amenazas de seguridad.
upvoted 1 times
...
Cleggs
1 year, 3 months ago
Selected Answer: AD
The only two that show up in the secure score metrics are A and D. PIM is mentioned to increase score but I cant find anything in MDC that shows that.
upvoted 2 times
...
ayadmawla
1 year, 3 months ago
Selected Answer: BC
Answers given are correct and are inline with the Security design component of an Azure landing zone: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/landing-zone/design-area/security
upvoted 2 times
...
Azerty1313
1 year, 4 months ago
Here you find the list: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/landing-zone/design-area/security The question to answer which ones are preventative? According to me WAF, Firewall & PIM. Next question which does improve the score? Not sure there.
upvoted 1 times
...
rahulnair
1 year, 6 months ago
Selected Answer: BC
Improve SS for landing zone explicitly calls out sentinel and PIM. WAF and FW are not classified as basic controls "Azure native controls. Azure Firewall and Azure Web Application Firewall offer basic security advantages. Advantages are a fully stateful firewall as a service, built-in high availability, unrestricted cloud scalability, FQDN filtering, support for OWASP core rule sets, and simple setup and configuration."
upvoted 2 times
...
yyYPpp
1 year, 6 months ago
Selected Answer: AB
The two preventative controls that can be implemented to increase the secure score in Azure landing zones are: A. Azure Web Application Firewall (WAF) B. Azure Active Directory (Azure AD) Privileged Identity Management (PIM) while C. Microsoft Sentinel, D. Azure Firewall, and E. Microsoft Defender for Cloud alerts are all valuable tools for enhancing security in Azure, they are not specifically categorized as preventative controls for increasing the secure score.
upvoted 1 times
...
calotta1
1 year, 8 months ago
WAF is only required for specific scenario, so many ALZ do not have a requirement for WAF but will PIM is a must for any deployment. AFW is similar, must have on any secure ALZ.
upvoted 1 times
...
celomomo
1 year, 8 months ago
Selected Answer: AD
Both Azure WAF and Azure Firewall are preventative controls that enhance the security posture of your Azure environment by protecting against unauthorized access, threats, and attacks. These controls help in securing your applications and network traffic, contributing to an improved secure score.
upvoted 1 times
...
Ario
1 year, 9 months ago
A and D are correct
upvoted 1 times
...
rhylos
1 year, 10 months ago
Selected Answer: AD
chatgpt: A. Azure Web Application Firewall (WAF): Azure WAF helps protect your web applications from common exploits and vulnerabilities by providing centralized protection, monitoring, and logging for your web traffic. It can prevent attacks such as SQL injection, cross-site scripting (XSS), and other malicious activities targeted at web applications. D. Azure Firewall: Azure Firewall is a managed, cloud-based network security service that provides network traffic filtering and protection for Azure resources. It acts as a preventive control by allowing you to define and enforce network and application-level policies to secure your Azure landing zones. Azure Firewall provides inbound and outbound traffic filtering, application-level inspection, and threat intelligence integration to protect against unauthorized access and threats. Both Azure WAF and Azure Firewall help increase the secure score by providing essential security controls to protect your Azure landing zones.
upvoted 1 times
...
Itu2022
1 year, 10 months ago
was on exam 15/06/23
upvoted 2 times
...
zellck
1 year, 11 months ago
Selected Answer: AD
AD is the answer. https://learn.microsoft.com/en-us/azure/defender-for-cloud/secure-score-security-controls#security-controls-and-their-recommendations - Restrict unauthorized network access Azure offers a suite of tools designed to ensure accesses across your network meet the highest security standards. Use these recommendations to manage Defender for Cloud's adaptive network hardening settings, ensure you’ve configured Azure Private Link for all relevant PaaS services, enable Azure Firewall on your virtual networks, and more. - Protect applications against DDoS attacks Azure’s advanced networking security solutions include Azure DDoS Protection, Azure Web Application Firewall, and the Azure Policy Add-on for Kubernetes. Use these recommendations to ensure your applications are protected with these tools and others.
upvoted 4 times
zellck
1 year, 11 months ago
Gotten this in May 2023 exam.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago