SC-100 Practice Question 4021

Exam: SC-100
Domain: Design security solutions for applications and data
Difficulty: medium
An architect is designing an automated code security scanning strategy for Azure DevOps. You need to scan source code for static application vulnerabilities (SAST) and open-source license risks (SCA). Which solution integrates natively?

Answer Options

A
Microsoft Defender for DevOps integrated with Azure DevOps and GitHub
B
Windows Memory Diagnostic utility
C
Microsoft Word grammar and spell-checker
D
Exchange message tracking logs

Correct Answer

A: Microsoft Defender for DevOps integrated with Azure DevOps and GitHub

Explanation

Microsoft Defender for DevOps integrates with Azure DevOps and GitHub, analyzing source repositories for vulnerabilities, IaC misconfigurations, and software supply chain risks.