Microsoft Security, Compliance, and Identity Fundamentals (SC-900) — Questions and Answers
Question 1: What does Microsoft Defender for Servers provide?
- Network segmentation and micro-segmentation for VM traffic
- Server performance monitoring, auto-scaling, and capacity planning
- Backup and disaster recovery services for Azure virtual machines
- Threat detection and advanced defenses for Windows and Linux virtual machines and on-premises servers (Correct answer)
Correct answer: Threat detection and advanced defenses for Windows and Linux virtual machines and on-premises servers
Microsoft Defender for Servers provides threat detection, vulnerability assessment, and advanced defenses for Windows and Linux machines in any environment.
Question 2: Which component of the Microsoft Purview compliance portal shows administrators a historical view of all labeling, DLP, and retention activities across the organization?
- Compliance Manager
- Content Explorer
- Audit log
- Activity Explorer (Correct answer)
Correct answer: Activity Explorer
Activity Explorer provides a timeline-based view of labeling activities, DLP policy matches, and other compliance events across the Microsoft 365 environment.
Question 3: What is the primary goal of a 'penetration test'?
- To train employees on how to recognize phishing emails
- To install security patches across all systems in the network
- To simulate real-world attacks and identify exploitable vulnerabilities before malicious actors do (Correct answer)
- To monitor network traffic for signs of ongoing intrusions
Correct answer: To simulate real-world attacks and identify exploitable vulnerabilities before malicious actors do
A penetration test is an authorized simulated cyberattack on a system to evaluate its security posture and identify weaknesses before they can be exploited.
Question 4: Which Microsoft Purview feature provides a risk score for each user based on their activities, such as downloading large volumes of data before resigning?
- Compliance Manager
- Communication compliance
- Data Loss Prevention
- Insider risk management (Correct answer)
Correct answer: Insider risk management
Insider risk management assigns risk scores to users based on signals like unusual file downloads, access to sensitive data, or departure indicators like resignation emails.
Question 5: Which sensitivity label sublabel feature allows organizations to group related labels under a parent label for better organization?
- Label scoping
- Label priority
- Label taxonomy
- Sublabels (Correct answer)
Correct answer: Sublabels
Sublabels allow you to nest labels under a parent label, helping users choose the right classification level within a category like 'Confidential'.
Question 6: Which Microsoft Purview feature automatically discovers and classifies sensitive data stored across Microsoft 365 services?
- Sensitivity labels
- Information barriers
- Data Loss Prevention
- Trainable classifiers (Correct answer)
Correct answer: Trainable classifiers
Trainable classifiers use machine learning to automatically identify and classify content across Microsoft 365 based on what data looks like, not just keywords.
Question 7: What is the Secure Score in Microsoft Defender for Cloud?
- A certification score for meeting regulatory compliance requirements
- A numerical representation of an organization's current security posture based on assessed controls (Correct answer)
- A password complexity strength indicator for Azure AD accounts
- A performance metric measuring the availability of Azure virtual machines
Correct answer: A numerical representation of an organization's current security posture based on assessed controls
The Secure Score aggregates all security findings into a single score that gives a snapshot of your current security situation — a higher score means lower risk.
Question 8: When configuring a DLP policy, what does the 'user notification' option do?
- Sends an alert to the compliance administrator when a violation occurs
- Shows a policy tip to users when they try to share sensitive content (Correct answer)
- Blocks the user's account after repeated violations
- Automatically quarantines the sensitive file
Correct answer: Shows a policy tip to users when they try to share sensitive content
User notifications (policy tips) display in-app messages to users explaining why their action was flagged and providing guidance on compliant behavior.
Question 9: When Microsoft Defender for Endpoint performs an 'automated investigation,' what is the primary outcome it aims to achieve?
- Automatically resolve or scope an incident with minimal human intervention (Correct answer)
- Generate a compliance report for auditors
- Patch all vulnerable software on the affected device
- Send phishing simulation emails to the affected user
Correct answer: Automatically resolve or scope an incident with minimal human intervention
Automated investigation in Defender for Endpoint analyzes alerts, collects evidence, and takes remediation actions automatically to resolve threats faster.
Question 10: What is the primary purpose of identity and access management (IAM)?
- To manage and secure user identities and access to resources (Correct answer)
- To assign roles to employees
- To manage hardware devices
- To track users’ actions only
Correct answer: To manage and secure user identities and access to resources
The primary purpose of Identity and Access Management (IAM) is to manage and secure digital identities and control their access to resources. IAM ensures that the right individuals have the right access to the right resources at the right time, preventing unauthorized access and maintaining security and compliance.
Question 11: Which Microsoft solution helps organizations visualize their Zero Trust posture and track improvement across all six pillars?
- Microsoft Secure Score (Correct answer)
- Azure Advisor
- Microsoft Purview Audit
- Azure Cost Management
Correct answer: Microsoft Secure Score
Microsoft Secure Score tracks an organization's security posture and provides recommended actions aligned to Zero Trust principles across all pillars.
Question 12: What does Zero Trust mean by 'never trust, always verify'?
- Distrust all vendors by default
- Require manual approval for every file download
- No user or device is trusted automatically, even on the internal network (Correct answer)
- Block all guest users
Correct answer: No user or device is trusted automatically, even on the internal network
Zero Trust's 'never trust, always verify' means that trust is never implicit—every access request must be authenticated and authorized regardless of origin.
Question 13: How does Azure AD Connect help organizations with hybrid identity?
- It creates service principals for cloud apps
- It replaces on-premises Active Directory entirely
- It synchronizes on-premises AD user accounts and groups to Azure AD (Correct answer)
- It provides MFA for on-premises applications
Correct answer: It synchronizes on-premises AD user accounts and groups to Azure AD
Azure AD Connect syncs on-premises AD objects (users, groups, passwords) to Azure AD, enabling hybrid identity scenarios.
Question 14: What is the purpose of threat intelligence in security operations?
- To configure system backups
- To provide actionable information about security threats (Correct answer)
- To reduce the cost of network devices
- To manage network traffic
Correct answer: To provide actionable information about security threats
Threat intelligence involves collecting, processing, and analyzing information about current and potential threats that could harm an organization. Its purpose is to provide security teams with actionable insights into attacker tactics, techniques, and procedures (TTPs), as well as indicators of compromise (IoCs). This knowledge allows organizations to make informed decisions, proactively strengthen their defenses, and improve their ability to detect and respond to specific threats.
Question 15: What is the role of 'threat intelligence' in a security operations workflow?
- It automatically patches vulnerabilities on endpoints
- It blocks all external email attachments by default
- It provides context about known threats, attackers, and indicators of compromise to improve detection (Correct answer)
- It enforces multi-factor authentication for all users
Correct answer: It provides context about known threats, attackers, and indicators of compromise to improve detection
Threat intelligence enriches security data with context about known malicious IPs, domains, file hashes, and attacker TTPs to help analysts detect and prioritize threats.
Question 16: A company wants to allow employees to sign in to Microsoft Entra ID using their fingerprint on a corporate laptop. Which technology enables this?
- FIDO2 USB security key
- Certificate-based authentication
- Windows Hello for Business (Correct answer)
- Smart card authentication
Correct answer: Windows Hello for Business
Windows Hello for Business uses biometrics (fingerprint, face) or PIN stored locally on the device to authenticate users to Microsoft Entra ID.
Question 17: What does the 'Kill Chain' framework help security analysts understand?
- How to assign role-based access control
- The stages an attacker follows from initial access to achieving their goal (Correct answer)
- The order in which patches should be applied
- How to configure firewall rules
Correct answer: The stages an attacker follows from initial access to achieving their goal
The Cyber Kill Chain describes the sequential stages of a cyberattack, helping analysts understand attacker progression and identify where to intervene.
Question 18: What is the purpose of endpoint security in a security operations strategy?
- To ensure compliance with data storage regulations
- To protect devices from security threats and data breaches (Correct answer)
- To monitor employee activity on devices
- To improve device battery life
Correct answer: To protect devices from security threats and data breaches
Endpoint security focuses on securing individual devices, such as laptops, desktops, smartphones, and servers, that connect to an organization's network. Its purpose is to protect these endpoints from various threats, including malware, ransomware, and unauthorized access, which could lead to data breaches. By implementing robust endpoint protection, organizations can prevent malicious actors from gaining a foothold and compromising sensitive data.
Question 19: Which report in Microsoft Entra ID helps identify users who have not used their account within a specified period?
- Registered authentication methods report
- Inactive users report / Sign-in activity report (Correct answer)
- Audit log report
- Risk detections report
Correct answer: Inactive users report / Sign-in activity report
The sign-in activity report and inactive users insights in Microsoft Entra ID help identify accounts that haven't signed in recently, supporting access hygiene.
Question 20: What is the purpose of Privileged Identity Management (PIM) 'justification' when activating a role?
- It records the business reason for the temporary role activation for audit purposes (Correct answer)
- It permanently assigns the role to the user
- It automatically approves the role without manager review
- It disables MFA for the duration of the privileged session
Correct answer: It records the business reason for the temporary role activation for audit purposes
PIM requires users to provide a justification (business reason) when activating a privileged role, creating an auditable record of why elevated access was needed.
Question 21: Which Conditional Access condition helps enforce Zero Trust by requiring users to use approved applications?
- Named location policy
- Terms of use policy
- Approved client app requirement (Correct answer)
- Sign-in risk policy
Correct answer: Approved client app requirement
The approved client app requirement in Conditional Access ensures that only Microsoft-approved applications can access cloud resources.
Question 22: In Microsoft Entra ID, what is 'MFA fatigue' and how does number matching address it?
- Users forgetting their MFA method; number matching replaces it with email
- Attackers spamming push notifications hoping users accidentally approve; number matching requires entering a specific number shown at sign-in (Correct answer)
- Too many methods registered causing confusion; number matching limits to one
- MFA expiring too quickly; number matching extends token lifetime
Correct answer: Attackers spamming push notifications hoping users accidentally approve; number matching requires entering a specific number shown at sign-in
MFA fatigue involves attackers sending repeated push notifications until a tired user approves one; number matching defeats this by requiring the user to enter a code visible only during the legitimate sign-in.
Question 23: Which regulation established the right to be forgotten, requiring organizations to delete personal data upon request?
- HIPAA
- SOX
- GDPR (Correct answer)
- PCI DSS
Correct answer: GDPR
The General Data Protection Regulation (GDPR) introduced the right to erasure, commonly called the right to be forgotten, allowing EU residents to request deletion of their personal data.
Question 24: What is the purpose of Microsoft Defender for Cloud Apps' 'Shadow IT Discovery' feature?
- Encrypts data stored in sanctioned cloud apps
- Blocks all unsanctioned cloud app usage permanently
- Monitors privileged admin activity in Azure
- Identifies cloud apps being used without IT approval (Correct answer)
Correct answer: Identifies cloud apps being used without IT approval
Shadow IT Discovery analyzes network traffic logs to identify cloud applications employees are using without official IT approval or security review.
Question 25: Which SIEM capability allows Microsoft Sentinel to ingest logs from non-Microsoft sources such as firewalls and Linux servers?
- Workbooks
- Playbooks
- Hunting queries
- Data connectors (Correct answer)
Correct answer: Data connectors
Data connectors in Microsoft Sentinel enable log ingestion from hundreds of sources including non-Microsoft devices, services, and platforms.
Question 26: What is the function of Microsoft Entra ID's 'Self-Service Password Reset' (SSPR)?
- It integrates with third-party password managers
- It enforces password complexity requirements automatically
- It enables users to reset their own passwords without contacting the helpdesk (Correct answer)
- It allows IT admins to reset all user passwords in bulk
Correct answer: It enables users to reset their own passwords without contacting the helpdesk
SSPR lets users securely reset their passwords themselves using registered authentication methods, reducing helpdesk burden.
Question 27: What is 'federation' in the context of Azure AD identity management?
- Replicating Azure AD to multiple regions
- Establishing trust between Azure AD and another identity provider so users authenticate at their home directory (Correct answer)
- Assigning multiple roles to a single user
- Combining multiple Azure subscriptions into one
Correct answer: Establishing trust between Azure AD and another identity provider so users authenticate at their home directory
Federation creates a trust relationship so users can authenticate with their own identity provider and access federated resources.
Question 28: What is the role of Microsoft Compliance Manager in managing data governance?
- It only tracks employee performance
- It improves network performance
- It helps organizations manage regulatory compliance and data protection (Correct answer)
- It manages hardware components
Correct answer: It helps organizations manage regulatory compliance and data protection
Microsoft Compliance Manager is a feature in Microsoft 365 designed to help organizations manage their compliance posture against various regulations and standards. It provides a dashboard that assesses compliance risks, offers actionable recommendations, and helps track progress in implementing controls for data protection and privacy. This tool simplifies the complex task of meeting regulatory requirements and demonstrating compliance to auditors.
Question 29: Which type of sensitive information type uses document fingerprinting to detect sensitive forms?
- Exact Data Match (EDM)
- Keyword dictionary
- Named entities
- Document fingerprint (Correct answer)
Correct answer: Document fingerprint
Document fingerprinting converts a standard form (like a W-2 or patent form) into a fingerprint used to detect when similar forms are shared.
Question 30: What capabilities does the free tier of Microsoft Defender for Cloud provide?
- Foundational Cloud Security Posture Management (CSPM) including Secure Score and security recommendations (Correct answer)
- Advanced threat detection and automated incident response
- Complete regulatory compliance dashboards for all major standards
- Full workload protection for all Azure services at no cost
Correct answer: Foundational Cloud Security Posture Management (CSPM) including Secure Score and security recommendations
The free foundational CSPM tier provides Secure Score, security recommendations, and basic posture assessment without paid workload protection plans.
Question 31: Which Microsoft Defender for Endpoint feature restricts the actions that Office applications can take, such as preventing them from spawning child processes?
- Web Content Filtering
- Network Protection
- Attack Surface Reduction (ASR) rules (Correct answer)
- Controlled Folder Access
Correct answer: Attack Surface Reduction (ASR) rules
Attack Surface Reduction rules block specific behaviors that are commonly exploited, such as Office apps launching child processes or injecting into other processes.
Question 32: What is the role of a 'Certificate Authority (CA)' in a Public Key Infrastructure?
- To store users' passwords in a secure vault
- To generate private keys for end users
- To encrypt all communications on the network
- To issue, sign, and revoke digital certificates that bind public keys to identities (Correct answer)
Correct answer: To issue, sign, and revoke digital certificates that bind public keys to identities
A CA is a trusted entity that issues digital certificates, verifying that a public key belongs to the stated entity and enabling trust in encrypted communications.
Question 33: Why is it important to have an effective vulnerability management program?
- It ensures compliance with legal regulations only
- It focuses on increasing network bandwidth
- It helps manage user data
- It helps protect systems by addressing known vulnerabilities (Correct answer)
Correct answer: It helps protect systems by addressing known vulnerabilities
An effective vulnerability management program systematically identifies, assesses, and remediates security weaknesses (vulnerabilities) in an organization's systems, applications, and networks. By proactively addressing these known flaws, it significantly reduces the attack surface that adversaries could exploit. This continuous process is vital for preventing breaches and maintaining a strong security posture against evolving threats.
Question 34: A company wants to simulate phishing attacks against its employees to improve security awareness. Which Microsoft tool should they use?
- Microsoft Sentinel
- Attack Simulation Training (Correct answer)
- Defender for Endpoint
- Microsoft Defender for Identity
Correct answer: Attack Simulation Training
Attack Simulation Training in Microsoft 365 Defender lets organizations run simulated phishing and other attack scenarios to train employees.
Question 35: Why is compliance important in security?
- It focuses on the financial side of operations
- It is optional if a company chooses to follow regulations
- It reduces the need for security measures
- It helps avoid penalties and fosters trust with customers (Correct answer)
Correct answer: It helps avoid penalties and fosters trust with customers
Compliance is crucial in security because it ensures an organization adheres to relevant laws, regulations, and industry standards. Meeting compliance requirements helps avoid significant legal penalties and fines, while also building trust and credibility with customers and stakeholders by demonstrating a commitment to data protection.
Question 36: What is 'Pass-through Authentication' (PTA) in Azure AD Connect, and how does it differ from PHS?
- PTA caches credentials in Azure; PHS validates them on-premises
- PTA and PHS are identical in function
- PTA is used for guest users; PHS is for employees
- PTA validates passwords against on-premises AD in real time; PHS syncs password hashes to the cloud (Correct answer)
Correct answer: PTA validates passwords against on-premises AD in real time; PHS syncs password hashes to the cloud
PTA agents on-premises validate each user's password directly against on-premises AD at sign-in time, without storing any password data in Azure AD.
Question 37: Which eDiscovery feature allows legal teams to identify duplicate emails and near-duplicate documents to reduce review volume?
- Custodian management
- Legal hold
- Content search
- Analytics in eDiscovery (Premium) (Correct answer)
Correct answer: Analytics in eDiscovery (Premium)
eDiscovery (Premium) analytics capabilities identify duplicate and near-duplicate items, email threads, and themes, significantly reducing the volume of content requiring manual review.
Question 38: Which Microsoft Purview feature helps organizations assess their compliance posture against regulations like GDPR, HIPAA, and ISO 27001?
- Compliance Manager (Correct answer)
- Microsoft Secure Score
- Microsoft Defender for Cloud
- Service Trust Portal
Correct answer: Compliance Manager
Compliance Manager provides a compliance score and step-by-step guidance to help organizations meet regulatory requirements and manage compliance activities.
Question 39: When configuring the FIDO2 security key authentication method policy in the Microsoft Entra admin center, an administrator chooses to set "Enforce attestation" to "Yes". What is the primary purpose of this setting?
- To ensure that the security key model is genuine and from a legitimate vendor. (Correct answer)
- To log all sign-in attempts using FIDO2 keys for auditing purposes.
- To require users to provide a fingerprint every time they use the key.
- To force users to register their key from a trusted network location.
Correct answer: To ensure that the security key model is genuine and from a legitimate vendor.
The "Enforce attestation" setting for FIDO2 security keys verifies the Authenticator Attestation GUID (AAGUID) of the key during registration. This process ensures that the key is from a specific, trusted manufacturer and model, preventing the use of unapproved or potentially compromised hardware.
Question 40: In Azure AD, what is a 'guest user' account primarily used for?
- Providing external partners or vendors with limited access to organizational resources via Azure AD B2B (Correct answer)
- Creating temporary accounts for new employees during onboarding
- Allowing anonymous access to public-facing applications
- Granting full administrative access to external consultants
Correct answer: Providing external partners or vendors with limited access to organizational resources via Azure AD B2B
Guest user accounts (Azure AD B2B) allow external users to authenticate with their own identity provider and access specific resources in your organization without being full members of your directory.
Microsoft Security, Compliance, and Identity Fundamentals (SC-900)
The SC-900 exam validates foundational knowledge of Microsoft security, compliance, and identity (SCI) solutions.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds