Microsoft Security, Compliance, and Identity Fundamentals Microsoft Entra Access Management Flashcards
7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Entra Access Management flashcards as text
What is the primary purpose of Microsoft Entra Verified ID?
Answer: To issue and verify decentralized digital identity credentials
Microsoft Entra Verified ID is a decentralized identity solution that allows organizations to issue and verify tamper-proof digital credentials.
Which Conditional Access condition can restrict access based on whether a device meets organizational compliance requirements?
Answer: Device compliance/state condition
Conditional Access can require that a device be marked as compliant by Microsoft Intune before granting access to resources.
In Microsoft Entra ID, what is a 'Managed Identity'?
Answer: An automatically managed identity for Azure resources to authenticate to services without storing credentials
Managed identities provide Azure resources with an automatically managed identity in Microsoft Entra ID, eliminating the need to store credentials in code.
What distinguishes a 'System-assigned' managed identity from a 'User-assigned' managed identity?
Answer: System-assigned identities are tied to a single resource and deleted with it; user-assigned are standalone and reusable
System-assigned managed identities have a 1:1 lifecycle with their resource, while user-assigned managed identities are independent resources that can be associated with multiple Azure services.
Which Microsoft Entra feature provides visibility into permissions granted to identities across multi-cloud environments (Azure, AWS, GCP)?
Answer: Microsoft Entra Permissions Management
Microsoft Entra Permissions Management is a CIEM (Cloud Infrastructure Entitlement Management) solution that provides visibility and control over permissions across Azure, AWS, and GCP.
What is 'Entitlement Management' in Microsoft Entra ID Governance?
Answer: A feature that automates access request, approval, and assignment workflows for resources
Entitlement Management automates identity governance by creating access packages that bundle resources and define who can request them, how they're approved, and when access expires.
In Microsoft Entra ID, which authentication method uses a physical or software key that meets FIDO2 standards?
Answer: FIDO2 security key
FIDO2 security keys (such as YubiKeys) are phishing-resistant hardware or software authenticators that meet the FIDO2 open standard supported by Microsoft Entra ID.