SC-900 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Entra Access Management 2 — Questions and Answers
Question 1: Which Microsoft Entra feature allows organizations to grant temporary, time-bound access to privileged roles?
- Privileged Identity Management (PIM) (Correct answer)
- Conditional Access
- Identity Protection
- Access Reviews
Correct answer: Privileged Identity Management (PIM)
Privileged Identity Management (PIM) enables just-in-time, time-bound access to privileged roles, reducing exposure of sensitive permissions.
Question 2: In Microsoft Entra ID, what is the purpose of an Access Review?
- To monitor sign-in activity for suspicious behavior
- To periodically verify that users still need their current access rights (Correct answer)
- To enforce multi-factor authentication policies
- To block legacy authentication protocols
Correct answer: To periodically verify that users still need their current access rights
Access Reviews allow administrators and resource owners to periodically verify that users still need their assigned access, helping maintain least-privilege.
Question 3: What does the 'Never Expire' password policy setting in Microsoft Entra ID mean?
- Passwords are reset every 90 days automatically
- User passwords do not have a forced expiration date (Correct answer)
- Passwords must meet complexity requirements forever
- Users cannot change their own passwords
Correct answer: User passwords do not have a forced expiration date
When 'Never Expire' is configured, Microsoft Entra ID does not enforce periodic password expiration for those users.
Question 4: Which Microsoft Entra ID role grants full control over the directory, including managing other administrators?
- Security Administrator
- User Administrator
- Global Administrator (Correct answer)
- Privileged Role Administrator
Correct answer: Global Administrator
The Global Administrator role has complete control over Microsoft Entra ID, including the ability to manage all other administrator roles.
Question 5: What is the function of Microsoft Entra ID's 'Self-Service Password Reset' (SSPR)?
- It allows IT admins to reset all user passwords in bulk
- It enables users to reset their own passwords without contacting the helpdesk (Correct answer)
- It enforces password complexity requirements automatically
- It integrates with third-party password managers
Correct answer: It enables users to reset their own passwords without contacting the helpdesk
SSPR lets users securely reset their passwords themselves using registered authentication methods, reducing helpdesk burden.
Question 6: In Microsoft Entra External ID, what scenario does 'B2B collaboration' address?
- Allowing customers to sign up for an app using social identities
- Enabling partner or guest users from external organizations to access your resources (Correct answer)
- Providing single sign-on for internal employees across cloud apps
- Syncing on-premises AD users to the cloud
Correct answer: Enabling partner or guest users from external organizations to access your resources
B2B collaboration allows external partner or guest users to securely access your organization's apps and resources using their own credentials.
Question 7: Which Microsoft Entra feature uses machine learning to detect risky sign-ins and compromised user accounts?
- Microsoft Entra Permissions Management
- Microsoft Entra Identity Protection (Correct answer)
- Privileged Identity Management
- Microsoft Entra Verified ID
Correct answer: Microsoft Entra Identity Protection
Microsoft Entra Identity Protection leverages machine learning to detect risk events such as anonymous IP usage, leaked credentials, and atypical travel.
Which Microsoft Entra feature allows organizations to grant temporary, time-bound access to privileged roles?