SC-900 Practice Test 20 Hard Questions

SC-900 Exam Practice Test 20 (Hard) - Conditional Access and Identity Protection Deep-Dive

SC-900 Exam Practice Tests

1 / 15

Which Conditional Access component defines the specific requirements, such as requiring MFA or a compliant device, that must be met before access is granted?

2 / 15

Which Conditional Access component defines ongoing restrictions applied during an active session, such as limiting the ability to download files in a browser session?

3 / 15

Which Conditional Access condition allows an administrator to define trusted IP address ranges, such as a corporate office network, treated differently from untrusted locations?

4 / 15

Which Conditional Access session control integrates with Microsoft Defender for Cloud Apps to enforce real-time monitoring and restrictions, such as blocking downloads, within a cloud app session?

5 / 15

Which Conditional Access session control defines how frequently a user is required to re-authenticate during an active session, rather than remaining signed in indefinitely?

6 / 15

Which Microsoft Entra ID Protection remediation action would automatically be recommended for a user flagged with high user risk due to leaked credentials?

7 / 15

Which Microsoft Entra ID Protection policy type would automatically require MFA when a sign-in attempt is deemed medium or high risk, based on real-time signals?

8 / 15

Which Microsoft Entra ID Protection risk detection type would flag a sign-in attempt occurring from a location that would be physically impossible to reach from the user's previous sign-in location within the elapsed time?

9 / 15

Which Microsoft Entra ID Protection risk detection type would flag a sign-in attempt originating from an IP address associated with a known Tor exit node or anonymizing proxy service?

10 / 15

Which Microsoft Entra Privileged Identity Management (PIM) concept requires a user to provide a business justification and can trigger an approval workflow before they can activate an eligible privileged role?

11 / 15

Which Privileged Identity Management (PIM) feature sends a notification to administrators when a privileged role is activated, supporting oversight and monitoring of privileged access usage?

12 / 15

Which Microsoft Entra Identity Governance feature allows an organization to configure automatic access expiration, ensuring temporary access, such as for a contractor, does not persist indefinitely?

13 / 15

Which access review scenario would be most appropriate for periodically confirming that members of a highly privileged security group still require that membership?

14 / 15

Which term describes the overall Microsoft Entra Identity Governance capability that encompasses entitlement management, access reviews, and Privileged Identity Management together?

15 / 15

Which term describes an Identity Protection workflow allowing a self-remediation option, where a flagged user can resolve their own risk, such as by completing MFA, without requiring administrator intervention?

Your score is

The average score is 0%

0%