SC-100 Exam Expected Questions and
Answers
What does MCRA stand for? - ANSWER✔✔-Microsoft Cybersecurity Reference Architectures
Why would you reference MCRA? - ANSWER✔✔-The diagrams describe how Microsoft security
capabilities integrate with Microsoft platforms and 3rd party platforms like Microsoft 365, Microsoft
Azure, 3rd party apps like ServiceNow and salesforce, and 3rd party platforms like Amazon Web Services
(AWS) and Google Cloud Platform (GCP).
What is MCRA composed of? - ANSWER✔✔-The reference architectures are primarily composed of
detailed technical diagrams on Microsoft cybersecurity capabilities, zero trust user access, security
operations, operational technology (OT), multi-cloud and cross-platform capabilities, attack chain
coverage, azure native security controls, and security organizational functions.
The key tenets of success for governance are? - ANSWER✔✔-- Continuous discovery of assets and asset
types
- Continuous improvement of asset security posture
- Policy-driven governance (provides consistent execution by fixing something once in policy that's
automatically applied at scale across resource)
Copyright © Stuvia International BV 2010-2024 Page 1/20
, Copyright © KAYLIN 2024/2025 ACADEMIC YEAR. ALL RIGHTS RESERVED FIRST PUBLISH NOVEMBER, 2024
What do Security operations provide? - ANSWER✔✔-Insight into the immediate risk of active attacks
What does Security Governance provide? - ANSWER✔✔-A broad or long view of risk from potential
future attacks and attack vectors
What do Governance teams do? - ANSWER✔✔-Provide oversight and monitoring to sustain and improve
security posture over time. These teams also report compliance as required by regulating bodies.
What provides the best direction for security? - ANSWER✔✔-Business goals and risk. Informs risk owners
using familiar language and processes in the risk management framework.
What is the first step of managing organizational alignment? - ANSWER✔✔-Determine how the
organizational structures will be fulfilled
What are the organizational structures for organizational alignment? - ANSWER✔✔-- Org chart
alignment: Management hierarchies, manager responsibilities, and staff alignment will align to
organizational structures.
- Virtual teams: Management structures and org charts remain unchanged. Instead, virtual teams will be
created and tasked with the required functions.
- Mixed model: More commonly, a mixture of org chart and virtual team alignment will be required to
deliver on transformation goals.
List the functions required to succeed at cloud adoption and longer-term operating models -
ANSWER✔✔-- Cloud strategy: Align technical change to business needs.
Copyright © Stuvia International BV 2010-2024 Page 2/20
, Copyright © KAYLIN 2024/2025 ACADEMIC YEAR. ALL RIGHTS RESERVED FIRST PUBLISH NOVEMBER, 2024
- Cloud adoption: Deliver technical solutions.
- Cloud governance: Manage risk.
- Central IT team: Support from existing IT staff.
- Cloud operations: Support and operate adopted solutions.
- Cloud center of excellence: Improve quality, speed, and resiliency of adoption.
- Cloud platform: Operate and mature the platform.
- Cloud automation: Accelerate adoption and innovation.
- Cloud data: Manage data and enable analytics solutions.
Cloud security: Manage information security risk.
List the technical benefits of shifting to the cloud - ANSWER✔✔-- Scalability
- Availability
- Security and Compliance
- Capacity Optimization
List the cycle of Business Resilience - ANSWER✔✔-- Before an incident
- During an incident
Copyright © Stuvia International BV 2010-2024 Page 3/20