SC-900 Microsoft Security, Compliance, and Identity Fundamentals Certification Exam — Questions and Answers
Question 1: A sensitivity label is configured to add a 'Confidential' watermark and encrypt the file. What two capabilities are being used?
- Data loss prevention and eDiscovery
- Auditing and retention
- Authentication and authorization
- Content marking and encryption (Correct answer)
Correct answer: Content marking and encryption
Sensitivity labels can apply both visual markings and protection policies. Content marking includes headers, footers, and watermarks, while encryption restricts access to the content to authorized users only.
Question 2: When creating a DLP policy, you must specify where it applies. Which of the following are valid locations for a DLP policy?
- Exchange Online, SharePoint Online, and Microsoft Teams (Correct answer)
- Azure Storage Accounts only
- Azure Virtual Machines only
- Azure Active Directory user profiles only
Correct answer: Exchange Online, SharePoint Online, and Microsoft Teams
DLP policies can be scoped to protect data across various Microsoft 365 services. This includes Exchange Online for emails, SharePoint Online and OneDrive for Business for files, and Microsoft Teams for chats and channel messages.
Question 3: What feature in Microsoft Defender for Endpoint provides the first line of defense against cyberthreats by reducing the attack surface?
- advanced hunting
- automated remediation
- network protection (Correct answer)
- automated investigation
Correct answer: network protection
Network protection in Microsoft Defender for Endpoint serves as a crucial first line of defense against cyberthreats by reducing the attack surface. It prevents users from accessing dangerous domains that might host phishing scams, exploits, and other malicious content. By blocking access to untrusted URLs, it significantly mitigates the risk of web-based attacks.
Question 4: Which component of Microsoft Defender for Endpoint uses cloud-based machine learning, behavior analysis, and heuristics to provide real-time malware protection?
- Endpoint Detection and Response (EDR)
- Next-generation protection (Correct answer)
- Threat & Vulnerability Management
- Attack Surface Reduction (ASR)
Correct answer: Next-generation protection
Next-generation protection is the real-time antivirus and antimalware component of Defender for Endpoint. It goes beyond traditional signature-based detection, using advanced cloud-powered techniques to block new and emerging threats.
Question 5: What term describes the use of unauthorized or unapproved cloud applications within an organization that Defender for Cloud Apps helps identify?
- Dark Web
- Shadow IT (Correct answer)
- Unsecured APIs
- Rogue Apps
Correct answer: Shadow IT
Shadow IT refers to cloud apps and services used by employees without IT department knowledge or approval, which Cloud Discovery helps uncover.
Question 6: What is the primary purpose of applying a sensitivity label to a document or email?
- To share the content with external users
- To classify and apply protection settings to the content (Correct answer)
- To archive the content automatically
- To scan the content for malware
Correct answer: To classify and apply protection settings to the content
The core function of a sensitivity label is to classify data based on its sensitivity. Once classified, the label can then apply protection settings, such as encryption or content marking, to enforce policies and protect the information.
Question 7: Which Microsoft Defender for Cloud Apps capability allows administrators to set policies that trigger alerts when unusual user behavior is detected?
- App Risk Scoring
- Anomaly Detection Policies (Correct answer)
- File Scan Policies
- Cloud Discovery Snapshots
Correct answer: Anomaly Detection Policies
Anomaly Detection Policies use behavioral analytics and machine learning to detect unusual activities that could indicate a threat.
Question 8: What is the primary goal of Attack Surface Reduction (ASR) rules in Microsoft Defender for Endpoint?
- To investigate and respond to security alerts after they occur.
- To provide security recommendations to improve device configuration.
- To scan for and remove existing malware on a device.
- To prevent malware from running by blocking common malicious behaviors. (Correct answer)
Correct answer: To prevent malware from running by blocking common malicious behaviors.
Attack Surface Reduction (ASR) rules are designed to prevent common attack techniques used by malware. They target specific software behaviors, such as Office apps creating executable content or scripts launching downloaded payloads, to stop attacks at the pre-execution stage.
Question 9: Scenario: A company is enhancing security measures to prevent unauthorized access to critical systems. Which authentication method should they employ to require multiple forms of verification?
- Azure Active Directory (AAD)
- Single Sign-On (SSO)
- Biometric authentication
- Multi-factor authentication (MFA) (Correct answer)
Correct answer: Multi-factor authentication (MFA)
Multi-factor authentication (MFA) significantly enhances security by requiring users to provide two or more distinct forms of verification to gain access. This typically combines something they know (like a password) with something they have (like a phone or token) or something they are (like a fingerprint). By adding multiple layers, MFA drastically reduces the risk of unauthorized access, even if one factor is compromised.
Question 10: Which of the following best describes a 'control' in the context of Microsoft Purview Compliance Manager?
- A firewall rule that blocks network traffic.
- A dashboard widget that shows real-time data.
- A user permission setting in Microsoft Entra ID.
- A requirement of a regulation or standard. (Correct answer)
Correct answer: A requirement of a regulation or standard.
A control is a requirement of a regulation, standard, or policy. Compliance Manager maps these controls to specific improvement actions, helping you understand how to meet each requirement.
Question 11: A user applies a 'General' sensitivity label to an email. Later, they add confidential project details and the system recommends changing the label to 'Confidential'. What is this an example of?
- Automatic labeling
- Default labeling
- Recommended labeling (Correct answer)
- Mandatory labeling
Correct answer: Recommended labeling
Recommended labeling is a feature where the system detects sensitive content and suggests that the user apply a more appropriate sensitivity label. This helps guide users to make the correct classification decision without forcing it on them automatically.
Question 12: An analyst observes suspicious process creation and lateral movement activities on a workstation. Which Defender for Endpoint feature provides the detailed event timeline and process tree to investigate these activities?
- Attack Surface Reduction (ASR)
- Microsoft Secure Score
- Endpoint Detection and Response (EDR) (Correct answer)
- Next-generation protection
Correct answer: Endpoint Detection and Response (EDR)
Endpoint Detection and Response (EDR) capabilities provide near real-time and actionable detections of threats. It collects and analyzes behavioral signals from endpoints, allowing security analysts to investigate the full scope of a breach through detailed timelines and process information.
Question 13: How does the 'History' tab and benchmark comparison feature in Secure Score help security administrators?
- By tracking score changes over time and comparing against similar organizations. (Correct answer)
- By automatically generating compliance reports for external auditors.
- By providing a direct integration with the company's financial budgeting software.
- By creating and assigning remediation tasks as tickets to IT staff.
Correct answer: By tracking score changes over time and comparing against similar organizations.
The history and benchmarking features are key for reporting and planning. Tracking the score over time demonstrates security improvement to leadership, while comparing the score against organizations of a similar size provides context and helps justify security investments.
Question 14: Which two types of resources can be protected by using Azure Firewall? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
- Microsoft Exchange Online inboxes
- Azure virtual machines
- Azure virtual networks (Correct answer)
- Microsoft SharePoint Online sites (Correct answer)
- Azure Active Directory (Azure AD) users
Correct answer: Azure virtual networks
Azure Firewall is a cloud-native, intelligent network firewall security service that provides threat protection for your cloud workloads. It can protect Azure virtual networks by filtering traffic to and from virtual machines and subnets. Additionally, Azure Firewall can be used to filter outbound traffic from Azure resources to internet destinations, including Microsoft SharePoint Online sites, to ensure secure access and prevent data exfiltration.
Question 15: A security operations team wants to proactively search for signs of compromise across all their onboarded devices using custom Kusto Query Language (KQL) queries. Which Defender for Endpoint feature should they use?
- Advanced hunting (Correct answer)
- Threat Analytics
- Live Response
- Automated Investigation and Remediation (AIR)
Correct answer: Advanced hunting
Advanced hunting is a query-based threat hunting tool that lets you explore up to 30 days of raw event data from your endpoints. You can use Kusto Query Language (KQL) to proactively hunt for threats, anomalies, and indicators of compromise.
Question 16: In Compliance Manager, what is the purpose of an 'improvement action'?
- A recommended task to help centralize data governance and reduce risk. (Correct answer)
- To report a security incident to Microsoft.
- A control that is managed exclusively by Microsoft.
- A policy that automatically blocks non-compliant user activity.
Correct answer: A recommended task to help centralize data governance and reduce risk.
Improvement actions are tasks recommended by Microsoft to help you align with data protection regulations and standards. Completing these actions, which are your responsibility, directly increases your compliance score.
Question 17: Microsoft Secure Score provides a holistic view by providing recommendations across which set of categories?
- Only Microsoft Office desktop application settings.
- Only Azure virtual machines and storage accounts.
- Identity, Devices, and Apps. (Correct answer)
- Only on-premises Active Directory and file servers.
Correct answer: Identity, Devices, and Apps.
Secure Score is comprehensive and provides a view of security posture across multiple domains. It includes scores and recommendations for Identity (Azure AD), Devices (Microsoft Defender for Endpoint), and Apps (such as Microsoft Defender for Cloud Apps).
Question 18: Which of the following can be accomplished with the use of the Azure Privileged Identity Management Service?
- Filter traffic to Azure virtual machines
- Enable MFA for the users based on detected sign-in-risks
- Measure Security posture of resources defined in Azure environment
- Provide just-in-time access to resources roles in Azure (Correct answer)
Correct answer: Provide just-in-time access to resources roles in Azure
Azure Privileged Identity Management (PIM) is a service in Azure AD that enables you to manage, control, and monitor access to important resources. A key feature is providing just-in-time (JIT) access, which grants elevated privileges only when needed and for a limited time. This minimizes the exposure time of privileged access, significantly reducing the risk of unauthorized use.
Question 19: What is the primary function of Cloud Security Posture Management (CSPM) within Microsoft Defender for Cloud?
- To identify and remediate security misconfigurations across cloud resources. (Correct answer)
- To manage user access and permissions to cloud services.
- To automatically encrypt all data stored in the cloud.
- To provide real-time threat protection for virtual machines and containers.
Correct answer: To identify and remediate security misconfigurations across cloud resources.
CSPM is designed to identify and remediate security misconfigurations and vulnerabilities in cloud environments. It provides visibility into the security state of resources and offers recommendations to improve the overall security posture, which is reflected in the secure score.
Question 20: In the context of Microsoft Defender for Cloud Apps, what does 'sanctioning' a cloud application mean?
- Requiring legal review before any cloud app can be accessed
- Officially approving an app for use within the organization (Correct answer)
- Encrypting all data exchanged with the cloud app
- Penalizing employees who use unauthorized apps
Correct answer: Officially approving an app for use within the organization
Sanctioning a cloud app marks it as approved for organizational use in the Cloud App Catalog, which can also be used to configure firewall and proxy rules to allow its traffic.
Question 21: What is the primary function of Microsoft Secure Score?
- To assign a compliance score based on regulations like GDPR or ISO 27001.
- To provide a numerical representation of security posture and offer improvement recommendations. (Correct answer)
- To automatically remediate all identified security vulnerabilities without admin intervention.
- To calculate the real-time financial risk of a potential data breach.
Correct answer: To provide a numerical representation of security posture and offer improvement recommendations.
Microsoft Secure Score serves as a centralized dashboard and measurement of an organization's security posture. It provides visibility into security gaps and offers guided recommendations, known as improvement actions, to help organizations prioritize and reduce their attack surface.
Question 22: Scenario: A multinational corporation collects customer data across various countries and needs to ensure compliance with different data protection laws. Which Microsoft service should they use to facilitate compliance with these regulations?
- Azure Policy
- Microsoft Intune
- Azure Information Protection (AIP) (Correct answer)
- Azure Active Directory (AAD)
Correct answer: Azure Information Protection (AIP)
Azure Information Protection (AIP) is designed to classify, label, and protect sensitive data across various platforms and locations. It helps organizations comply with different data protection laws by applying encryption, access restrictions, and persistent protection to information. This ensures data remains secure and compliant, regardless of where it's stored or shared globally.
Question 23: You plan to implement a security strategy and place multiple layers of defense throughout a network infrastructure. Which security methodology does this represent?
- defense in depth (Correct answer)
- identity as the security perimeter
- the shared responsibility model
- threat modeling
Correct answer: defense in depth
Defense in depth is a security methodology that employs multiple, overlapping layers of security controls throughout an IT infrastructure. The principle is that if one security layer fails, another layer will still be in place to provide protection. This approach creates a robust and resilient security posture, making it significantly more difficult for attackers to breach the entire system.
Question 24: Which of the following is a key prerequisite for enabling and using Microsoft Purview Insider Risk Management?
- A standalone Microsoft Defender for Endpoint P1 license.
- An Azure Active Directory Premium P1 license.
- A Microsoft 365 E3 license.
- A Microsoft 365 E5 license or an equivalent add-on. (Correct answer)
Correct answer: A Microsoft 365 E5 license or an equivalent add-on.
Microsoft Purview Insider Risk Management is a premium feature included in specific high-tier licenses. The Microsoft 365 E5 license (or the E5 Compliance / E5 Insider Risk Management add-ons) is required to access the advanced signals and capabilities needed for the service to function.
Question 25: Which query language is used to create analytics rules, perform threat hunting, and visualize data in Microsoft Sentinel workbooks?
- SQL
- Python
- Kusto Query Language (KQL) (Correct answer)
- PowerShell
Correct answer: Kusto Query Language (KQL)
Kusto Query Language (KQL) is the language used to query the Log Analytics workspace where all Microsoft Sentinel data is stored. Analysts use KQL to write detection rules, hunt for threats, and build custom visualizations in workbooks.
Question 26: What is a key difference between a DLP policy and a sensitivity label?
- There is no difference; they are two names for the same feature.
- Sensitivity labels are for containers only, while DLP is for files.
- DLP policies prevent data exfiltration from locations, while sensitivity labels classify and protect the data itself. (Correct answer)
- DLP policies apply encryption, while sensitivity labels do not.
Correct answer: DLP policies prevent data exfiltration from locations, while sensitivity labels classify and protect the data itself.
While both are part of information protection, their focus is different. Sensitivity labels classify and apply persistent protection (like encryption) to the data itself, wherever it goes. DLP policies focus on the context of data sharing, preventing data exfiltration from specific locations like email or Teams based on rules.
Question 27: Scenario: A financial institution must regularly provide reports to regulators regarding data access and security. What Azure service can assist in generating compliance reports?
- Azure Information Protection (AIP)
- Azure Policy
- Azure Monitor
- Azure Security Center (Correct answer)
Correct answer: Azure Security Center
Azure Security Center (now Microsoft Defender for Cloud) offers robust capabilities for monitoring security posture and compliance. It includes a regulatory compliance dashboard that maps an organization's compliance against various standards and regulations. This service can generate reports on data access, security events, and compliance status, which are essential for regulatory reporting requirements.
Question 28: Match Microsoft 365 insider risk management workflow step to the appropriate task. "Create cases in the Case dashboard"
- Triage
- Action
- Investigate (Correct answer)
Correct answer: Investigate
In the Microsoft 365 insider risk management workflow, 'Create cases in the Case dashboard' falls under the Investigate step. After potential insider risks are identified and triaged, the investigation phase involves creating cases to gather more evidence, analyze activities, and determine the appropriate response. This structured approach helps manage and resolve insider risk incidents effectively.
Question 29: Which of the following measures might an organization implement as part of the defense in-depth security methodology?
- Ensuring there's no segmentation of your corporate network.
- Multi-factor authentication for all users. (Correct answer)
- Locating all its servers in a single physical location.
Correct answer: Multi-factor authentication for all users.
Multi-factor authentication (MFA) is a prime example of a control implemented as part of a defense-in-depth security methodology. By requiring multiple forms of verification, MFA adds an additional, robust layer of security beyond just a password. This makes it significantly harder for unauthorized users to gain access, even if one credential layer is compromised.
Question 30: Which feature provides the extended detection and response (XDR) capability of Azure Sentinel?
- support for threat hunting
- support for Azure Monitor Workbooks
- integration with the Microsoft 365 compliance center
- integration with Microsoft 365 Defender (Correct answer)
Correct answer: integration with Microsoft 365 Defender
Azure Sentinel (now Microsoft Sentinel) provides extended detection and response (XDR) capabilities through its deep integration with Microsoft 365 Defender. This integration allows Sentinel to ingest security data from endpoints, identities, email, and applications across the Microsoft 365 ecosystem. This unified view enables comprehensive threat detection, investigation, and automated response across the entire digital estate.
Question 31: Which Microsoft Defender for Cloud Apps feature provides a risk score to help evaluate how safe a discovered cloud app is?
- Threat Intelligence Feed
- Compliance Dashboard
- Cloud App Risk Score (Correct answer)
- Security Benchmark
Correct answer: Cloud App Risk Score
Each app in the Cloud App Catalog receives a risk score based on over 90 factors including security, compliance, and legal attributes to help organizations assess app safety.
Question 32: Which of the following provides: "an end to end workflow to preserve, collect, analyze, review and export content in MS365"?
- Advanced eDiscovery (Correct answer)
- Sensitivity Labels
- Core eDiscovery
- Content Search
Correct answer: Advanced eDiscovery
Advanced eDiscovery in Microsoft 365 provides an end-to-end workflow for preserving, collecting, analyzing, reviewing, and exporting content in Microsoft 365. It helps organizations efficiently respond to legal matters and internal investigations. This comprehensive solution includes features like custodian management, legal hold, and advanced analytics to streamline the entire eDiscovery process.
Question 33: Scenario: An organization migrates its infrastructure to Azure cloud services and needs to maintain compliance with industry standards. What tool should they utilize to continuously monitor and assess compliance?
- Azure Sentinel
- Azure Policy
- Azure Security Center (Correct answer)
- Azure AD Identity Protection
Correct answer: Azure Security Center
Azure Security Center (now part of Microsoft Defender for Cloud) provides unified security management and advanced threat protection across hybrid cloud workloads. It continuously monitors and assesses compliance against industry standards and regulatory requirements. This includes providing recommendations, security scores, and regulatory compliance dashboards to help organizations maintain their security posture and report on it.
Question 34: What can you use to scan email attachments and forward the attachments to recipients only if the attachments are free from malware?
- Microsoft Defender for Endpoint
- Microsoft Defender for Identity
- Microsoft Defender for Office 365 (Correct answer)
- Microsoft Defender Antivirus
Correct answer: Microsoft Defender for Office 365
Microsoft Defender for Office 365 provides advanced protection against sophisticated threats like phishing, business email compromise, and malware in email attachments. Its Safe Attachments feature scans email attachments in a sandbox environment before they reach the recipient's inbox. This ensures that only malware-free attachments are delivered, effectively protecting users from malicious content.
Question 35: A new admin has joined the team and needs to be able to access the Microsoft 365 Compliance Center. Which of the following roles could the admin use to access the Compliance Center?
- User Administrator role
- Help desk Administrator role
- Compliance Administrator role (Correct answer)
Correct answer: Compliance Administrator role
The Compliance Administrator role in Microsoft 365 is specifically designed to manage compliance features within the Microsoft 365 Compliance Center. Assigning this role grants the necessary permissions to access and manage compliance-related settings, policies, and reports. This ensures the new admin can effectively perform their duties related to organizational compliance.
Question 36: In Microsoft Sentinel, what component, powered by Azure Logic Apps, is used to automate responses to security alerts?
- Workbooks
- Playbooks (Correct answer)
- Data connectors
- Hunting queries
Correct answer: Playbooks
Playbooks in Microsoft Sentinel are collections of procedures that can be run automatically in response to an alert. They are built on Azure Logic Apps, allowing for complex, automated workflows that can interact with various services to contain and remediate threats.
Question 37: What are the two primary functions that define Microsoft Sentinel's role in a security operations center?
- Identity and Access Management
- Firewall and Antivirus
- SIEM and SOAR (Correct answer)
- Data Loss Prevention and Information Protection
Correct answer: SIEM and SOAR
Microsoft Sentinel combines Security Information and Event Management (SIEM) for collecting and analyzing security data, and Security Orchestration, Automation, and Response (SOAR) for automating responses to threats. This dual capability allows organizations to both detect and react to security incidents from a single platform.
Question 38: What does Conditional Access App Control in Microsoft Defender for Cloud Apps enable?
- Blocking all third-party cloud applications
- Real-time session monitoring and control of user activity in cloud apps (Correct answer)
- Automatic patching of cloud application vulnerabilities
- Encrypting all data stored in cloud applications
Correct answer: Real-time session monitoring and control of user activity in cloud apps
Conditional Access App Control uses reverse proxy architecture to monitor and control user sessions and access to cloud apps in real time.
Question 39: Which of the following is NOT one of the benefits of Microsoft Compliance Manager?
- Contains compliance information about Microsoft Cloud services organized by industry and region. (Correct answer)
- Step-by-step improvement actions that admins can take to help meet regulations and standards
- Pre-built assessments based on common regional and industry regulations and standards.
- Translating complicated regulations, standards, company policies, or other control frameworks into a simple language.
Correct answer: Contains compliance information about Microsoft Cloud services organized by industry and region.
Microsoft Compliance Manager is a workflow-based solution designed to help organizations manage their compliance activities efficiently. Its benefits include translating complex regulations into actionable steps, providing pre-built assessments, and offering improvement actions. While it helps manage compliance against standards, it does not primarily *contain* compliance information about Microsoft Cloud services organized by industry and region; that information is typically found in the Service Trust Portal.
Question 40: What is the function of assessment templates in Compliance Manager?
- To create templates for user-facing compliance reports.
- To store evidence and documentation for legal holds.
- To provide frameworks for assessing compliance against specific regulations. (Correct answer)
- To design email templates for compliance notifications.
Correct answer: To provide frameworks for assessing compliance against specific regulations.
Assessment templates are pre-built frameworks for specific regulations and standards, like GDPR or ISO 27001. They provide the necessary controls and improvement actions required to assess your compliance against that particular standard.
Question 41: What is the term for a group of related alerts in Microsoft Sentinel that are aggregated to represent a potential security attack?
- An Incident (Correct answer)
- A Playbook
- A Workbook
- An Event
Correct answer: An Incident
Microsoft Sentinel uses fusion technology and analytics rules to correlate millions of low-fidelity alerts into a manageable number of high-fidelity incidents. An incident is a collection of related alerts that, together, form an actionable attack story.
Question 42: Scenario: A corporation seeks centralized control over user access to applications and resources, including user lifecycle management and access reviews. Which service best suits these needs?
- Azure Sentinel
- Azure Information Protection (AIP)
- Azure Key Vault
- Microsoft Entra ID (Correct answer)
Correct answer: Microsoft Entra ID
Microsoft Entra ID (formerly Azure Active Directory) is a cloud-based identity and access management service that provides centralized control over user access to applications and resources. It includes robust features for user lifecycle management, access reviews, and single sign-on capabilities. This service is ideal for managing user identities and their access permissions across an organization's entire IT environment.
Question 43: How does Microsoft Defender for Cloud Apps connect to supported third-party cloud applications to gain deeper visibility?
- By installing agents on user devices
- Via App Connectors using provider APIs (Correct answer)
- Through DNS sinkholing
- Through network packet inspection
Correct answer: Via App Connectors using provider APIs
App Connectors use APIs provided by cloud service providers to connect Defender for Cloud Apps and give visibility into activities and data within those platforms.
Question 44: What does a 'File Policy' in Microsoft Defender for Cloud Apps allow an organization to do?
- Block all file sharing within Microsoft Teams
- Encrypt files before they are uploaded to any cloud service
- Scan files stored in connected cloud apps and apply governance actions based on content (Correct answer)
- Automatically delete files older than 90 days
Correct answer: Scan files stored in connected cloud apps and apply governance actions based on content
File Policies scan files stored in connected cloud apps for sensitive content (such as PII or credit card numbers) and can trigger actions like quarantine, remove sharing, or apply labels.
Question 45: How does Microsoft Sentinel collect log data from various sources like Azure services, Microsoft 365, and on-premises systems?
- Using analytics rules
- By configuring data connectors (Correct answer)
- Through Azure Policy assignments
- Via Sentinel playbooks
Correct answer: By configuring data connectors
Data connectors are the built-in components used to ingest data from a wide range of Microsoft and third-party sources into Microsoft Sentinel. They simplify the process of connecting data sources to the Log Analytics workspace that Sentinel uses.
Question 46: Which edition of the Azure active directory gives you Privileged Identity Management to help discover, restrict, and monitor administrators?
- Premium P2 (Correct answer)
- Free
- Office 365
- Premium P1
Correct answer: Premium P2
Azure Active Directory Premium P2 is the edition that includes advanced identity protection capabilities, such as Azure AD Privileged Identity Management (PIM). PIM allows organizations to discover, restrict, and monitor administrators, and provide just-in-time access to resources. This robust feature set is essential for managing and securing privileged access effectively within an organization.
SC-900 Microsoft Security, Compliance, and Identity Fundamentals Certification Exam
The SC-900 exam certifies foundational knowledge of Microsoft security, compliance, and identity concepts including Microsoft identity solutions, security solutions, Microsoft Sentinel, and Microsoft Purview information protection.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds