Microsoft Security, Compliance, and Identity Fundamentals Identity Protection and Governance Flashcards
7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Identity Protection and Governance flashcards as text
What is the primary purpose of the 'Identity Secure Score' in Azure AD?
Answer: It measures how well an organization's identity configuration follows Microsoft's recommended security practices and provides actionable improvement steps
Identity Secure Score evaluates your Azure AD tenant configuration against Microsoft's identity security best practices and gives a percentage score with prioritized recommendations to improve your posture.
Which Azure AD Conditional Access grant control can require a device to be marked as compliant in Microsoft Intune before allowing access?
Answer: Require device to be marked as compliant
The 'Require device to be marked as compliant' grant control checks that the device meets Intune compliance policies (e.g., encryption, OS version) before granting access to the resource.
In Azure AD Identity Protection, what action should an administrator take when they confirm a risky user alert is a false positive?
Answer: Dismiss the user risk
Dismissing user risk in Identity Protection clears the risk state for a confirmed false positive, preventing unnecessary remediation actions while providing feedback to Microsoft's ML models.
What does 'separation of duties' in identity governance help prevent?
Answer: A single user having conflicting access rights that could enable fraud or errors, such as creating and approving their own purchase orders
Separation of duties ensures no individual holds combinations of permissions that could be abused without detection, a core internal control principle enforced through access review and entitlement management.
Which Microsoft service can detect when on-premises Active Directory accounts are behaving suspiciously, such as performing reconnaissance or lateral movement?
Answer: Microsoft Defender for Identity
Microsoft Defender for Identity (formerly Azure ATP) monitors on-premises Active Directory signals and network traffic to detect advanced attacks like pass-the-hash, golden ticket, and lateral movement.
An organization enables the Azure AD Identity Protection policy to require password change when user risk is 'High'. What must users do to regain normal access?
Answer: Complete a self-service password reset to prove identity and clear the risk
When user risk policy enforces password change, affected users can self-remediate by completing SSPR (Self-Service Password Reset), which clears the risk flag and restores normal access.
What is a 'lifecycle workflow' in Azure AD Identity Governance, introduced to automate joiner-mover-leaver processes?
Answer: Automated task sequences that run when employees join, change roles, or leave the organization to provision or deprovision access
Lifecycle Workflows automate identity tasks triggered by HR events (new hire start date, department change, termination) such as sending welcome emails, adding to groups, or disabling accounts.