Microsoft Certified: Cybersecurity Architect Expert Intermediate Practice Exam: Medium Difficulty 2025
Ready to level up? Our intermediate practice exam features medium-difficulty questions with scenario-based problems that test your ability to apply concepts in real-world situations. Perfect for bridging foundational knowledge to exam-ready proficiency.
Your Learning Path
What Makes Intermediate Questions Different?
Apply your knowledge in practical scenarios
Medium Difficulty
Questions that test application of concepts in real-world scenarios
Scenario-Based
Practical situations requiring multi-concept understanding
Exam-Similar
Question style mirrors what you'll encounter on the actual exam
Bridge to Advanced
Prepare yourself for the most challenging questions
Medium Difficulty Practice Questions
10 intermediate-level questions for Microsoft Certified: Cybersecurity Architect Expert
A global company is adopting a Zero Trust strategy across Microsoft 365 and Azure. They want to reduce account takeover risk by requiring strong authentication only when risk is elevated, while minimizing user friction for low-risk sign-ins. They also want the policy decisions to consider user risk and sign-in risk signals. What should you design?
A company has on-premises apps and Azure apps. They want to enforce least privilege for administrative access, require time-bound elevation, and reduce standing privileges across both Microsoft Entra roles and Azure resource roles. What solution should you recommend?
A security architect must segment access to Azure PaaS services (Storage, Key Vault, SQL) so that they are reachable only from approved networks and do not traverse the public internet. The company also wants to reduce data exfiltration risk from compromised workloads. Which design best meets these requirements?
A company must meet internal governance requirements: all Azure resources must be deployed in approved regions, must include mandatory tags (CostCenter, DataClassification), and noncompliant deployments must be blocked. They also need evidence of compliance for audits. What should you design?
A company is designing security operations for a hybrid environment (Azure, Microsoft 365, and on-premises). They want centralized incident investigation and automated response playbooks for common alerts like suspicious sign-ins and malware detection. Which approach should you recommend?
A company hosts internet-facing applications in Azure. They need protection against large-scale volumetric attacks and want to ensure inbound traffic to the apps is inspected for common web exploits. Which design best meets these requirements with layered controls?
A company wants to enforce a secure administrative model in Azure where administrators manage resources from hardened, isolated workstations. They also want to reduce the risk of credential theft and lateral movement from typical user devices. What should you recommend?
A company uses AKS for microservices and wants to reduce supply-chain risk and runtime threats. They need to: (1) prevent deployment of images with known vulnerabilities, and (2) detect suspicious container behavior at runtime. Which design best meets these requirements?
A company stores sensitive customer data in Azure SQL Database and Azure Storage. They must ensure encryption keys are centrally managed, access to keys is tightly controlled, and key usage is audited. What should you recommend?
A company wants to reduce the blast radius of compromised credentials when accessing an internal web application. The application is hosted on Azure App Service and authenticated with Microsoft Entra ID. They want to avoid storing client secrets in the app and still call downstream Azure resources (such as Key Vault and Storage) securely. What should you design?
Mastered the intermediate level?
Challenge yourself with advanced questions when you score above 85%
Microsoft Certified: Cybersecurity Architect Expert Intermediate Practice Exam FAQs
Microsoft Certified: Cybersecurity Architect Expert is a professional certification from Microsoft Azure that validates expertise in microsoft certified: cybersecurity architect expert technologies and concepts. The official exam code is SC-100.
The Microsoft Certified: Cybersecurity Architect Expert intermediate practice exam contains medium-difficulty questions that test your working knowledge of core concepts. These questions are similar to what you'll encounter on the actual exam.
Take the Microsoft Certified: Cybersecurity Architect Expert intermediate practice exam after you've completed the beginner level and feel comfortable with basic concepts. This helps bridge the gap between foundational knowledge and exam-ready proficiency.
The Microsoft Certified: Cybersecurity Architect Expert intermediate practice exam includes scenario-based questions and multi-concept problems similar to the SC-100 exam, helping you apply knowledge in practical situations.
Continue Your Journey
More resources to help you pass the exam