SC-900 Exam Practice Test

SC-900 Exam Practice Test

SC-900 Exam Practice Tests

1 / 80

Your organization requires a tool to assess its compliance against various regulatory standards (like GDPR or HIPAA) and provides actionable recommendations to improve its compliance posture. Which Microsoft Purview service is designed for this?

2 / 80

Which Azure networking security service is used to create a network boundary for a set of Azure virtual machines and defines inbound and outbound rules based on IP addresses, ports, and protocols?

3 / 80

A security administrator needs to monitor and respond to security events and alerts from various sources across their Microsoft 365 and Azure environments in a centralized manner. Which Microsoft security solution provides Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) capabilities?

4 / 80

What is the primary benefit of implementing Multi-Factor Authentication (MFA) for user accounts?

5 / 80

An organization wants to ensure that specific sensitive documents, once labeled, cannot be modified or deleted for a period of seven years to meet regulatory requirements. Which Microsoft Purview capability is designed for this purpose?

6 / 80

Which type of identity in Azure AD represents a user account synchronized from an on-premises Active Directory Domain Services (AD DS) environment?

7 / 80

A company wants to identify and remediate misconfigurations across its Azure resources to improve its overall security posture. Which Microsoft security solution is primarily designed for Cloud Security Posture Management (CSPM) and provides a "Secure Score"?

8 / 80

Which Azure Active Directory (Azure AD) feature allows administrators to enforce policies that require users to meet specific conditions (e.g., specific location, compliant device) before being granted access to applications or data?

9 / 80

According to the Shared Responsibility Model in cloud computing, for an Infrastructure-as-a-Service (IaaS) offering, who is typically responsible for the security of the operating system and installed applications?

10 / 80

Which security principle emphasizes that all users, devices, and applications, whether inside or outside the organizational network, must be verified before granting access to resources?

11 / 80

Which term describes the practice of protecting data, devices, and identities from unauthorized access, attack, or damage?

12 / 80

Which term describes an organization's adherence to laws, regulations, and standards that govern how it must handle data and operate?

13 / 80

Which security model assumes that no user or device should be trusted by default, even if it is already inside the network perimeter, and instead requires continuous verification?

14 / 80

Which of the following is one of the three guiding principles of the Zero Trust model?

15 / 80

Which Zero Trust principle involves limiting user access with just-in-time and just-enough-access (JIT/JEA)?

16 / 80

Which security strategy uses multiple layers of defense, such as physical, identity, perimeter, network, compute, application, and data layers, so that if one layer fails, others still provide protection?

17 / 80

Under the shared responsibility model, as an organization moves from on-premises to IaaS to PaaS to SaaS, what generally happens to the customer's share of security responsibility?

18 / 80

Which security responsibility always remains with the customer, regardless of which cloud service model (IaaS, PaaS, or SaaS) is used?

19 / 80

Which term describes the concept of confirming a user, device, or service is who or what it claims to be?

20 / 80

Which term describes the process of determining what actions or resources an authenticated user, device, or service is permitted to access?

21 / 80

Which Microsoft Entra service is the cloud-based identity and access management service used to sign in and access resources such as Microsoft 365 and Azure?

22 / 80

Which Microsoft Entra ID object type represents a person, such as an employee, who signs in to access resources?

23 / 80

Which Microsoft Entra ID feature allows administrators to organize collections of users, and optionally devices, to simplify assigning permissions or licenses?

24 / 80

Which Microsoft Entra ID feature allows a hybrid organization to delegate administrative permissions over a specific subset of users or groups, such as those in a particular regional office?

25 / 80

Which Microsoft Entra capability synchronizes on-premises Active Directory identities with Microsoft Entra ID, enabling a consistent hybrid identity experience?

26 / 80

Which hybrid identity authentication method sends the actual password hash from on-premises Active Directory to Microsoft Entra ID, allowing users to sign in without maintaining a separate on-premises authentication infrastructure?

27 / 80

Which hybrid identity authentication method validates a user's password directly against on-premises Active Directory in real time, requiring an on-premises agent, without storing any password hash in the cloud?

28 / 80

Which hybrid identity authentication method delegates authentication to a separate, trusted identity provider, such as Active Directory Federation Services (AD FS)?

29 / 80

Which Microsoft Entra feature allows a user to sign in once and then access multiple applications without being prompted to authenticate again for each one?

30 / 80

Which Microsoft Entra External ID capability allows an organization to invite people from other organizations to collaborate using their own existing credentials, without creating a new managed account for them?

31 / 80

Which Microsoft Entra feature requires users to provide two or more verification methods, such as a password plus a code from an authenticator app, to sign in?

32 / 80

Which passwordless authentication method allows a user to sign in to a Windows device using a PIN, facial recognition, or fingerprint tied to that specific device?

33 / 80

Which passwordless authentication method uses an external hardware device that a user plugs in or taps to authenticate, based on an open industry standard?

34 / 80

Which Microsoft Entra feature evaluates signals such as user location, device compliance, and sign-in risk to enforce access decisions, such as requiring MFA only when a sign-in appears risky?

35 / 80

Which Microsoft Entra Conditional Access component defines the conditions, such as a specific user group or application, that must be met before a policy's controls are applied?

36 / 80

Which Microsoft Entra ID Protection concept refers to the calculated likelihood that a given user account has been compromised?

37 / 80

Which Microsoft Entra ID Protection concept refers to the calculated likelihood that a specific authentication attempt was not actually performed by the legitimate account owner?

38 / 80

Which Microsoft Entra feature provides just-in-time, time-bound privileged access to roles, reducing the risk of standing administrative access being misused?

39 / 80

Which Microsoft Entra Identity Governance feature allows organizations to create access packages so users can request access to a bundle of resources, requiring approval workflows?

40 / 80

Which Microsoft Entra Identity Governance feature allows an organization to periodically verify that users still require the access or group membership they currently have, removing unnecessary access?

41 / 80

Which unified security operations platform integrates signals from endpoints, identities, email, and cloud apps into a single portal for extended detection and response?

42 / 80

Which Microsoft Defender product protects endpoints such as laptops and servers from advanced threats, providing capabilities like endpoint detection and response (EDR)?

43 / 80

Which Microsoft Defender product protects against phishing, malware, and other threats delivered through email and collaboration tools like Teams and SharePoint?

44 / 80

Which Microsoft Defender product monitors on-premises Active Directory signals to detect identity-based threats, such as pass-the-hash attacks or suspicious replication requests?

45 / 80

Which Microsoft Defender product acts as a cloud access security broker (CASB), providing visibility into and control over an organization's use of cloud applications?

46 / 80

Which Microsoft Defender feature specifically helps organizations discover unsanctioned, unauthorized cloud applications being used by employees within the organization?

47 / 80

Which Microsoft Defender for Endpoint capability automatically investigates alerts and can remediate certain threats without requiring manual analyst intervention for every case?

48 / 80

Which Microsoft Defender for Endpoint capability identifies and helps prioritize remediation of software vulnerabilities and misconfigurations across an organization's devices?

49 / 80

Which term describes a set of rules within Microsoft Defender for Endpoint that reduce the surface area an attacker could exploit, such as blocking Office applications from creating child processes?

50 / 80

Which Microsoft Defender XDR feature correlates related alerts from across endpoints, identities, email, and cloud apps into a single, unified view representing a broader attack?

51 / 80

Which Microsoft service is a cloud-native security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solution?

52 / 80

Which Microsoft Sentinel capability uses pre-built or custom logic to automatically respond to detected threats, such as automatically disabling a compromised user account?

53 / 80

Which Microsoft Sentinel component ingests data from various sources, such as Microsoft 365, Azure resources, and third-party firewalls, into the Sentinel workspace?

54 / 80

Which Microsoft Sentinel feature allows security analysts to proactively search through data for signs of undetected threats, rather than only relying on automated alerts?

55 / 80

Which Microsoft service provides cloud security posture management (CSPM) and cloud workload protection (CWP) for resources across Azure, AWS, and Google Cloud?

56 / 80

Which Microsoft Defender for Cloud feature calculates a score reflecting an organization's current security posture, along with specific, actionable recommendations to improve it?

57 / 80

Which Azure network security feature filters inbound and outbound traffic to and from Azure resources within a virtual network, based on defined rules for IP address, port, and protocol?

58 / 80

Which Azure service is a managed, cloud-based network security service that protects Azure virtual network resources with centralized policy and threat intelligence-based filtering?

59 / 80

Which Azure service provides secure and seamless RDP or SSH connectivity to Azure virtual machines directly through the Azure portal, without exposing the VM's public IP address?

60 / 80

Which Azure service helps protect Azure resources from distributed denial-of-service attacks, which attempt to overwhelm a resource with excessive traffic to make it unavailable?

61 / 80

Which Microsoft service provides a unified set of solutions to help organizations govern, protect, and manage their data across its entire lifecycle?

62 / 80

Which Microsoft Purview feature scans and classifies content across an organization's data estate, applying labels such as 'Confidential' based on defined criteria?

63 / 80

Which type of sensitivity label action would automatically apply encryption and restrict who can open a document, regardless of where that document is subsequently shared?

64 / 80

Which Microsoft Purview feature helps prevent sensitive information, such as credit card numbers, from being shared inappropriately outside the organization via email or Teams?

65 / 80

Which Microsoft Purview capability helps organizations classify and label sensitive information types, such as passport numbers or credit card numbers, using built-in or custom pattern-matching definitions?

66 / 80

Which Microsoft Purview capability manages the entire lifecycle of content, including how long it must be retained and when it should be automatically deleted?

67 / 80

Which term describes a Microsoft Purview retention setting that prevents content from being permanently deleted or modified before its designated retention period has expired?

68 / 80

Which Microsoft Purview feature helps organizations understand and manage the risk of sensitive data being oversharable or exposed to too many users, particularly within SharePoint and OneDrive?

69 / 80

Which Microsoft Purview feature allows an organization to discover, classify, and map data across on-premises, multicloud, and SaaS data sources into a unified data catalog?

70 / 80

Which Microsoft Purview capability monitors internal communications, such as email and chat, for policy violations like inappropriate language or potential regulatory non-compliance?

71 / 80

Which Microsoft Purview solution helps organizations identify, hold, and export content relevant to a legal case or internal investigation, such as emails and documents related to a lawsuit?

72 / 80

Which Microsoft Purview eDiscovery tier provides advanced capabilities, such as custodian management and analytics like near-duplicate detection, beyond basic content search and hold?

73 / 80

Which Microsoft Purview solution uses machine learning to identify potentially risky user activities, such as a departing employee downloading unusually large amounts of data before their exit?

74 / 80

Which Microsoft Purview Insider Risk Management concept groups related signals together, such as data exfiltration combined with an upcoming resignation, to calculate an overall risk score for a user?

75 / 80

Which Microsoft Purview solution provides organizations a set of controls and recommended actions, along with a compliance score, to help improve their compliance posture against regulations like GDPR?

76 / 80

Which Compliance Manager concept represents a specific regulation, standard, or policy, such as GDPR, against which an organization's compliance posture is being assessed?

77 / 80

Which Compliance Manager concept differentiates between controls Microsoft is responsible for implementing versus controls the customer organization must implement themselves?

78 / 80

Which Microsoft Purview solution provides a searchable log of user and administrator activities across Microsoft 365 services, useful for investigations and compliance requirements?

79 / 80

Which Microsoft Purview Audit tier provides a longer default retention period for audit log data and higher bandwidth access to audit log data via API, compared to the basic tier?

80 / 80

Which Azure governance feature allows organizations to create, assign, and manage policies that enforce rules over resources, such as requiring all storage accounts to use encryption?

Your score is

The average score is 68%

0%