Design solutions for securing privileged access

6 practice questions under this official exam objective (SC-100) — each with the community-verified answer, a full option-by-option explanation and instant feedback.

SC-100 S-grade

Using Microsoft Entra Permissions Management to find unused RBAC assignments

To identify which RBAC role assignments across 10 subscriptions were not used in the last 90 days with minimal effort, use Microsoft Entra Permissions

13 comments
SC-100 S-grade

Using the Permissions Management analytics dashboard to find privileged role assignments

To identify privileged role assignments and their security risks across multiple Azure subscriptions with minimal effort, use the Analytics dashboard

5 comments
SC-100 S-grade

Adding only the PA device-management group to the local Administrators group

For a Rapid Modernization Plan (RaMP) privileged access device, the local Administrators group should contain only the group that manages the privileg

5 comments
SC-100 A-grade

Using Defender for Identity to mark a sensitive AD group and alert in Sentinel

To mark an on-premises AD DS group (Organization Management) as sensitive and raise a Sentinel alert on changes with minimal effort, use Microsoft Def

4 comments
SC-100 A-grade

Using Entra Permissions Management to discover permissions across Azure, AWS, and GCP

To discover and review role assignments across Azure, AWS, and GCP subscriptions in a multicloud environment, use Microsoft Entra Permissions Manageme

3 comments
SC-100 A-grade

Using Azure Lighthouse to delegate the Security Operator role to customer tenants

To let Group1 perform security tasks as Security Operator in multiple customer tenants and let Group2 assign that role, with minimal guest accounts an

3 comments