Evaluate solutions for network security and Security Service Edge (SSE)
6 practice questions under this official exam objective (SC-100) — each with the community-verified answer, a full option-by-option explanation and instant feedback.
Removing the inbound firewall rule for an Entra application proxy connector
An Entra application proxy / Private Access connector uses outbound-only connectivity, so the inbound TCP 443 rule (Rule1) is unnecessary and should b
Scenarios supported by compliant network check in Global Secure Access
Compliant network check in Microsoft Entra Global Secure Access is supported for connections to Entra ID cloud apps such as a third-party SaaS app reg
Using Private Access for the on-premises app and Internet Access for the SaaS app
For Global Secure Access management of an on-premises app (App1, reached by VPN) and a SaaS app (App2), use Microsoft Entra Private Access for the on-
Using Entra Internet Access to restrict users to authenticating only to their tenant
To ensure users authenticate only to contoso.com and are prevented from authenticating to other Microsoft 365 tenants with minimal effort, use Microso
Deploying the Global Secure Access client to devices via Intune for web filtering
To control branch-office device internet traffic with Global Secure Access web filtering, first deploy the Global Secure Access client to each device
Using Virtual Network Manager security admin rules to force Bastion-only RDP
To ensure VMs are reachable only through Azure Bastion and block direct RDP that bypasses it, use Azure Virtual Network Manager security admin rules,