Mixed Deck — All SC-900 Topics Flashcards
100 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All SC-900 Topics flashcards as text
What capability does Microsoft Purview's 'Content Search' provide to compliance administrators?
Answer: Searching for content across Exchange, SharePoint, Teams, and OneDrive for compliance purposes
Content Search in Microsoft Purview allows administrators to search for emails, documents, Teams messages, and other content across Microsoft 365 services to support compliance investigations.
A company is implementing a Zero Trust strategy. They want to ensure that users are only granted the absolute minimum permissions required to perform their job functions. Which Zero Trust principle does this directly support?
Answer: Use least privileged access
The principle of 'Use least privileged access' is fundamental to Zero Trust. It involves limiting user access with Just-In-Time (JIT) and Just-Enough-Access (JEA), risk-based adaptive policies, and data protection to minimize the potential damage if an account is compromised.
Just-in-time (JIT) access is a Zero Trust practice primarily used to manage which type of accounts?
Answer: Privileged administrator accounts
JIT access grants privileged administrator accounts elevated permissions only when needed and for a limited time, reducing standing access risk.
What does Azure AD External Identities B2C primarily enable?
Answer: Allowing customers to sign in to consumer-facing apps using social or local accounts
Azure AD B2C is a customer identity solution that lets end users authenticate with social providers or custom accounts.
Why is data classification important in information protection?
Answer: To ensure data is protected according to its sensitivity
Data classification is the process of categorizing data based on its sensitivity, value, and regulatory requirements. This is crucial for information protection because it allows organizations to apply appropriate security controls and protection mechanisms tailored to each data type. By understanding the sensitivity of data, resources can be allocated effectively to protect the most critical information, preventing over- or under-protection.
In a zero trust model, which of the following is a core guiding principle?
Answer: Assume breach and verify every request explicitly, regardless of origin
Zero trust operates on the principle of 'assume breach,' requiring explicit verification of every access request and granting least-privilege access continuously.
What does the Microsoft Purview Data Map provide in the context of data governance?
Answer: A unified inventory of an organization's data assets and their classification
The Microsoft Purview Data Map creates a unified, automated inventory of data assets across cloud and on-premises sources, with classification metadata to support governance.
A new employee is starting, and an administrator needs to provide them with a method to sign in and register for passwordless authentication for the first time. The employee does not yet have a corporate device or any registered authentication methods. Which Microsoft Entra authentication method is specifically designed for this onboarding scenario?
Answer: Temporary Access Pass (TAP)
A Temporary Access Pass (TAP) is a time-limited passcode that can be used to onboard other authentication methods, including passwordless ones like the Microsoft Authenticator app or a FIDO2 key. It is ideal for new users who need to register their permanent authentication methods without first needing a password.
Which of the following is a core guiding principle of the Zero Trust security model?
Answer: Assume breach
The Zero Trust model operates on three core principles: Verify explicitly, Use least privileged access, and Assume breach. The 'Assume breach' principle means that you operate as if an attacker is already inside your network, minimizing the potential 'blast radius' through segmentation and continuous monitoring.
What does 'Continuous Access Evaluation' (CAE) enable in Microsoft Entra ID?
Answer: It allows services to revoke access tokens in near real-time when user conditions change
CAE enables Microsoft Entra ID to signal participating services to revoke access tokens immediately when critical events occur, such as account disablement or IP address change.
Which Microsoft Sentinel component uses Azure Logic Apps to automate responses to security threats?
Answer: Playbooks
Playbooks in Microsoft Sentinel are built on Azure Logic Apps and automate response actions when specific security events or alerts occur.
What does 'Hybrid Azure AD Join' (Microsoft Entra Hybrid Join) accomplish?
Answer: It registers on-premises Active Directory-joined devices with Microsoft Entra ID
Hybrid Entra Join allows domain-joined on-premises devices to also register with Microsoft Entra ID, enabling both on-premises and cloud SSO scenarios.
When a user sets up Microsoft Authenticator for push notifications, what information does the app display to prevent MFA fatigue attacks?
Answer: Number matching and geographic context
Number matching requires users to enter a number shown on the sign-in screen into the app, while geographic context shows the location — both combat MFA fatigue attacks.
What is 'federation' in the context of Azure AD identity management?
Answer: Establishing trust between Azure AD and another identity provider so users authenticate at their home directory
Federation creates a trust relationship so users can authenticate with their own identity provider and access federated resources.
In Azure AD, what is a 'guest user' account primarily used for?
Answer: Providing external partners or vendors with limited access to organizational resources via Azure AD B2B
Guest user accounts (Azure AD B2B) allow external users to authenticate with their own identity provider and access specific resources in your organization without being full members of your directory.
What is the purpose of microsegmentation in a Zero Trust network architecture?
Answer: Isolate workloads to prevent lateral movement
Microsegmentation divides the network into small zones so that even if an attacker gains access, they cannot move laterally to other segments.
Which of the following capabilities is a core function of Microsoft Defender for Endpoint?
Answer: Providing endpoint detection and response (EDR) and attack surface reduction.
Microsoft Defender for Endpoint is an enterprise endpoint security platform that provides capabilities such as attack surface reduction, next-generation protection, and endpoint detection and response (EDR) to prevent, detect, investigate, and respond to advanced threats on devices.
Which encryption type uses the same key for both encrypting and decrypting data?
Answer: Symmetric encryption
Symmetric encryption uses a single shared key for both encryption and decryption, making it faster but requiring secure key distribution.
In Zero Trust architecture, what is the primary purpose of session controls?
Answer: Monitor and limit what users can do during an active session
Session controls in Zero Trust limit what authenticated users can do during a session, such as blocking downloads or requiring re-authentication for sensitive actions.
Which Microsoft Sentinel analytics rule type runs on a fixed schedule and queries historical log data?
Answer: Scheduled analytics rules
Scheduled analytics rules in Microsoft Sentinel run KQL queries against log data at configurable intervals (e.g., every 5 minutes or every hour) to detect threats in historical data.