Evaluate solutions for network security and Security Service Edge (SSE)

6 practice questions under this official exam objective (SC-100) — each with the community-verified answer, a full option-by-option explanation and instant feedback.

SC-100 S-grade

Removing the inbound firewall rule for an Entra application proxy connector

An Entra application proxy / Private Access connector uses outbound-only connectivity, so the inbound TCP 443 rule (Rule1) is unnecessary and should b

5 comments
SC-100 S-grade

Scenarios supported by compliant network check in Global Secure Access

Compliant network check in Microsoft Entra Global Secure Access is supported for connections to Entra ID cloud apps such as a third-party SaaS app reg

5 comments
SC-100 A-grade

Using Private Access for the on-premises app and Internet Access for the SaaS app

For Global Secure Access management of an on-premises app (App1, reached by VPN) and a SaaS app (App2), use Microsoft Entra Private Access for the on-

4 comments
SC-100 A-grade

Using Entra Internet Access to restrict users to authenticating only to their tenant

To ensure users authenticate only to contoso.com and are prevented from authenticating to other Microsoft 365 tenants with minimal effort, use Microso

4 comments
SC-100 A-grade

Deploying the Global Secure Access client to devices via Intune for web filtering

To control branch-office device internet traffic with Global Secure Access web filtering, first deploy the Global Secure Access client to each device

3 comments
SC-100 A-grade

Using Virtual Network Manager security admin rules to force Bastion-only RDP

To ensure VMs are reachable only through Azure Bastion and block direct RDP that bypasses it, use Azure Virtual Network Manager security admin rules,

3 comments