Pearson VUE
Primary third-party vendor administering Microsoft certification exams.
Getting Started: Understanding SC-900
Free knowledge base
Everything from the course in one searchable place: 234 entries. Use it to review before a practice test or look up a word you forgot.
234 results
Primary third-party vendor administering Microsoft certification exams.
Getting Started: Understanding SC-900
Exam taken remotely under live supervision via webcam and microphone.
Getting Started: Understanding SC-900
Document detailing exam performance by objective area after completion.
Getting Started: Understanding SC-900
Minimum score required to pass a Microsoft certification exam (700 for SC-900).
Getting Started: Understanding SC-900
Question type requiring selection of all correct answers from a list.
Getting Started: Understanding SC-900
Rules governing how soon and how many times an exam can be reattempted.
Getting Started: Understanding SC-900
Official Microsoft platform for learning resources and exam registration links.
Getting Started: Understanding SC-900
To remember the passing score: 'Seven Hundred Heroes' pass the exam. (700)
Getting Started: Understanding SC-900
The SC-900 exam is scored on a scale of 1-1000, and 700 is the minimum passing score. There are no performance-based labs on this fundamental exam. Remember the retake policy: 24 hours after the first fail, 14 days after subsequent fails.
Getting Started: Understanding SC-900
Not reading the entire question or all answer options before selecting an answer.
Getting Started: Understanding SC-900
Ignoring the retake policy and trying to reschedule too soon after a failed attempt.
Getting Started: Understanding SC-900
Not checking online proctoring system requirements until the last minute, leading to technical issues.
Getting Started: Understanding SC-900
Assuming partial credit for multiple-response questions; it's all or nothing.
Getting Started: Understanding SC-900
Temporary, isolated environment for safe hands-on practice.
Getting Started: Understanding SC-900
Sample questions to test knowledge and prepare for exam format.
Getting Started: Understanding SC-900
Peers collaborating to learn and discuss exam topics.
Getting Started: Understanding SC-900
Engaging with material through notes, summaries, and questions.
Getting Started: Understanding SC-900
Resource for Microsoft's security, privacy, and compliance information.
Getting Started: Understanding SC-900
To remember study tips: 'OFFICIAL HANDS-ON COMMUNITY PRACTICE' – Official resources, Hands-on, Community, Practice questions.
Getting Started: Understanding SC-900
The exam often tests your ability to identify the *best* resource for a given task. Memorize that Microsoft Learn is for self-paced training, the Azure portal is for hands-on configuration, and the Microsoft Trust Center is for compliance details.
Getting Started: Understanding SC-900
Relying solely on third-party resources without verifying against official Microsoft documentation.
Getting Started: Understanding SC-900
Only reading material without actively engaging through notes, summaries, or practice.
Getting Started: Understanding SC-900
Skipping hands-on practice, which is crucial for understanding how concepts work in reality.
Getting Started: Understanding SC-900
Protecting information from unauthorized disclosure.
Foundations of Security, Compliance, and Identity
Ensuring data accuracy, completeness, and consistency.
Foundations of Security, Compliance, and Identity
Guaranteeing authorized access to information when needed.
Foundations of Security, Compliance, and Identity
Foundational model for information security: Confidentiality, Integrity, Availability.
Foundations of Security, Compliance, and Identity
Security model: never trust, always verify, assume breach.
Foundations of Security, Compliance, and Identity
Granting only the minimum access rights necessary.
Foundations of Security, Compliance, and Identity
Dividing networks into small, isolated segments.
Foundations of Security, Compliance, and Identity
To remember CIA: 'C' for 'Confidential' (secret), 'I' for 'Intact' (unchanged), 'A' for 'Accessible' (ready when needed).
Foundations of Security, Compliance, and Identity
The SC-900 exam will test your understanding of the CIA triad as fundamental security goals. For Zero Trust, know its core principle: 'never trust, always verify' and its implications for access control and continuous monitoring.
Foundations of Security, Compliance, and Identity
Confusing integrity with confidentiality: Integrity is about data accuracy, confidentiality is about data privacy.
Foundations of Security, Compliance, and Identity
Believing Zero Trust is only for external users: Zero Trust applies to all users and devices, internal or external.
Foundations of Security, Compliance, and Identity
Assuming a firewall alone provides Zero Trust: Zero Trust requires a comprehensive approach, not just a perimeter defense.
Foundations of Security, Compliance, and Identity
Adherence to laws, regulations, and standards.
Foundations of Security, Compliance, and Identity
EU law for data privacy and protection.
Foundations of Security, Compliance, and Identity
US law protecting patient health information.
Foundations of Security, Compliance, and Identity
Management of data availability, usability, integrity, security.
Foundations of Security, Compliance, and Identity
Microsoft's suite for compliance and data governance.
Foundations of Security, Compliance, and Identity
Process of identifying and collecting electronic data.
Foundations of Security, Compliance, and Identity
Standard for credit card data security.
Foundations of Security, Compliance, and Identity
Think of COMPLIANCE as 'Can Our Machines Protect Legal Information And Never Compromise Everything?'
Foundations of Security, Compliance, and Identity
The exam often tests your knowledge of specific regulations. Memorize that GDPR is for EU data privacy and HIPAA is for US patient health information. Keywords like 'personal data' often point to GDPR, while 'patient records' points to HIPAA.
Foundations of Security, Compliance, and Identity
Confusing industry standards (like PCI DSS) with government regulations (like GDPR).
Foundations of Security, Compliance, and Identity
Believing that using a compliant cloud provider automatically makes your organization fully compliant; compliance is a shared responsibility.
Foundations of Security, Compliance, and Identity
Underestimating the ongoing effort required for compliance; it's not a one-time setup.
Foundations of Security, Compliance, and Identity
Verifying a user's identity.
Foundations of Security, Compliance, and Identity
Determining what an authenticated user can access.
Foundations of Security, Compliance, and Identity
Multi-Factor Authentication; requiring two or more factors to verify identity.
Foundations of Security, Compliance, and Identity
Authentication using unique physical characteristics (e.g., fingerprint).
Foundations of Security, Compliance, and Identity
Single Sign-On; authenticate once for multiple applications.
Foundations of Security, Compliance, and Identity
Role-Based Access Control; permissions based on assigned roles.
Foundations of Security, Compliance, and Identity
Attribute-Based Access Control; access based on user, resource, environment attributes.
Foundations of Security, Compliance, and Identity
AuthN (Authentication) is 'who you are' (N for Name). AuthZ (Authorization) is 'what you can do' (Z for Zone of access).
Foundations of Security, Compliance, and Identity
The exam frequently tests the distinction between authentication and authorization. Remember: Authentication is 'who you are', Authorization is 'what you can do'. MFA is a key security control and a common exam topic, often presented as a solution to credential theft.
Foundations of Security, Compliance, and Identity
Confusing authentication with authorization: These are distinct, sequential processes.
Foundations of Security, Compliance, and Identity
Underestimating the importance of MFA: Many breaches occur due to weak or compromised single-factor authentication.
Foundations of Security, Compliance, and Identity
Assuming all authentication methods provide the same level of security: Some methods are inherently stronger than others.
Foundations of Security, Compliance, and Identity
Framework defining security duties of CSP and customer.
Foundations of Security, Compliance, and Identity
Provider's responsibility for underlying infrastructure.
Foundations of Security, Compliance, and Identity
Customer's responsibility for data, apps, configurations.
Foundations of Security, Compliance, and Identity
Infrastructure as a Service; customer manages OS, apps, data.
Foundations of Security, Compliance, and Identity
Platform as a Service; provider manages OS, customer manages apps, data.
Foundations of Security, Compliance, and Identity
Software as a Service; provider manages most; customer manages data, access.
Foundations of Security, Compliance, and Identity
Protecting data, applications, identity, and configurations.
Foundations of Security, Compliance, and Identity
Securing physical infrastructure, network, virtualization.
Foundations of Security, Compliance, and Identity
Think of a rented apartment: The landlord (provider) secures the building (OF the cloud), but you (customer) secure your belongings and furniture inside (IN the cloud).
Foundations of Security, Compliance, and Identity
The SC-900 exam frequently tests the distinctions between 'security OF the cloud' (provider) and 'security IN the cloud' (customer) across IaaS, PaaS, and SaaS. Memorize which layers fall under whose responsibility for each service model.
Foundations of Security, Compliance, and Identity
Assuming the cloud provider handles all security, leading to neglected customer responsibilities like data encryption or access management.
Foundations of Security, Compliance, and Identity
Not understanding how responsibilities shift between IaaS, PaaS, and SaaS, resulting in security gaps or duplicated efforts.
Foundations of Security, Compliance, and Identity
Failing to properly configure cloud services, which is always a customer responsibility and a common source of breaches.
Foundations of Security, Compliance, and Identity
Cloud-based identity and access management service.
Exploring Microsoft Entra Capabilities
Framework for managing digital identities and controlling resource access.
Exploring Microsoft Entra Capabilities
Allows users to access multiple applications with one login.
Exploring Microsoft Entra Capabilities
Integrating an application with Entra ID for identity management.
Exploring Microsoft Entra Capabilities
A dedicated instance of Entra ID for an organization.
Exploring Microsoft Entra Capabilities
Stores user, group, and device information in Entra ID.
Exploring Microsoft Entra Capabilities
Web-based console for managing Azure and Entra ID services.
Exploring Microsoft Entra Capabilities
Think of E.N.T.R.A. as 'Every New Tenant Requires Access' – reminding you of its core role in managing access for new organizations.
Exploring Microsoft Entra Capabilities
Memorize that Microsoft Entra ID is the new name for Azure Active Directory (Azure AD). The exam will use Entra ID, but understanding its lineage is important. Focus on its role as a cloud-based IAM service.
Exploring Microsoft Entra Capabilities
Confusing Microsoft Entra ID with traditional on-premises Active Directory; they are distinct services.
Exploring Microsoft Entra Capabilities
Underestimating the importance of SSO for both security and user experience.
Exploring Microsoft Entra Capabilities
Not realizing that Entra ID is a foundational service for many other Microsoft cloud offerings.
Exploring Microsoft Entra Capabilities
Policy engine enforcing access controls based on conditions.
Exploring Microsoft Entra Capabilities
Requires two or more verification factors for access.
Exploring Microsoft Entra Capabilities
Manages and controls just-in-time access for privileged roles.
Exploring Microsoft Entra Capabilities
Granting elevated permissions only when needed, for a limited time.
Exploring Microsoft Entra Capabilities
A set of rules defining who can access what under which conditions.
Exploring Microsoft Entra Capabilities
Policies that adapt based on real-time user and sign-in risk detections.
Exploring Microsoft Entra Capabilities
Imagine a 'CAP' on your identity. C for Conditional Access (the gatekeeper), A for Authentication (MFA, the extra lock), P for PIM (the temporary key for special access).
Exploring Microsoft Entra Capabilities
The exam often presents scenarios asking which Microsoft Entra feature best addresses a specific security need. Look for keywords like 'require MFA based on location,' 'just-in-time access,' or 'block access from risky sign-ins' to identify Conditional Access, PIM, or risk policies.
Exploring Microsoft Entra Capabilities
Confusing PIM with general role-based access control (RBAC); PIM specifically manages temporary elevation of privileged roles.
Exploring Microsoft Entra Capabilities
Not understanding that Conditional Access is the 'how' for enforcing MFA in specific scenarios, not just MFA itself.
Exploring Microsoft Entra Capabilities
Overlooking that Conditional Access policies are processed AFTER user authentication, but BEFORE access to the resource.
Exploring Microsoft Entra Capabilities
Accumulation of unneeded access rights over time.
Exploring Microsoft Entra Capabilities
Periodic verification of user access to resources.
Exploring Microsoft Entra Capabilities
Manages identity and access lifecycle at scale.
Exploring Microsoft Entra Capabilities
Bundles resources for users to request access to.
Exploring Microsoft Entra Capabilities
Process for granting access requests with approvers.
Exploring Microsoft Entra Capabilities
Managing identity and access lifecycle across an organization.
Exploring Microsoft Entra Capabilities
Remember 'ARE' for Access Reviews: 'A' for Audit, 'R' for Review, 'E' for Existing Access. And 'EAT' for Entitlement Management: 'E' for Entitlements, 'A' for Access Packages, 'T' for Time-limited.
Exploring Microsoft Entra Capabilities
The exam often tests the difference between access reviews (periodic verification of existing access) and entitlement management (streamlining access provisioning and deprovisioning, often time-limited). Keywords to spot include 'periodic review,' 'confirm access,' 'revoke access' for access reviews, and 'access package,' 'self-service,' 'time-limited access,' 'approval workflow' for entitlement management.
Exploring Microsoft Entra Capabilities
Confusing access reviews (auditing existing access) with entitlement management (streamlining new and temporary access).
Exploring Microsoft Entra Capabilities
Believing these features are only for large enterprises; they benefit organizations of all sizes.
Exploring Microsoft Entra Capabilities
Forgetting that both features contribute to the principle of least privilege and compliance.
Exploring Microsoft Entra Capabilities
Comprehensive solution for managing all external identity types.
Exploring Microsoft Entra Capabilities
Inviting external users (guests) to access internal resources.
Exploring Microsoft Entra Capabilities
An external user invited to an organization's Microsoft Entra tenant.
Exploring Microsoft Entra Capabilities
Managing customer identities for consumer-facing applications.
Exploring Microsoft Entra Capabilities
Linking a personal device to Microsoft Entra for conditional access.
Exploring Microsoft Entra Capabilities
Organization-owned devices fully managed by Microsoft Entra.
Exploring Microsoft Entra Capabilities
Devices joined to on-premises AD and registered with Microsoft Entra.
Exploring Microsoft Entra Capabilities
B2B is for Business-to-Business (partners), B2C is for Business-to-Customer (consumers). Think 'C' for 'Customers'!
Exploring Microsoft Entra Capabilities
For the exam, distinguish between B2B (partners/guests) and B2C (customers). Remember that device registration is for personal devices (BYOD), while Microsoft Entra joined is for organization-owned devices.
Exploring Microsoft Entra Capabilities
Confusing B2B collaboration with B2C identities; they serve different external user types.
Exploring Microsoft Entra Capabilities
Assuming all devices accessing resources are fully managed; some are only registered.
Exploring Microsoft Entra Capabilities
Not understanding that guest users are distinct user objects in the directory.
Exploring Microsoft Entra Capabilities
Combines on-premises AD DS with Microsoft Entra ID for unified access.
Exploring Microsoft Entra Capabilities
Tool to synchronize identities between on-premises AD and Entra ID.
Exploring Microsoft Entra Capabilities
Process of copying user/group objects and attributes to Entra ID.
Exploring Microsoft Entra Capabilities
Synchronizes a hash of the on-premises password hash to Entra ID.
Exploring Microsoft Entra Capabilities
Validates cloud sign-ins directly against on-premises Active Directory.
Exploring Microsoft Entra Capabilities
Advanced authentication method using Active Directory Federation Services.
Exploring Microsoft Entra Capabilities
Directory service running on servers within an organization's network.
Exploring Microsoft Entra Capabilities
To remember the authentication methods: 'PHS' is 'Password Hashes Syncing,' 'PTA' is 'Pass-Through Authenticating,' and 'AD FS' is 'Advanced Federation Services.'
Exploring Microsoft Entra Capabilities
The exam often tests your understanding of the different authentication methods for hybrid identity. Pay close attention to the characteristics and use cases for Password Hash Synchronization (PHS), Pass-through Authentication (PTA), and Federation (AD FS). Keywords to spot include 'simplest method,' 'on-premises validation,' and 'advanced scenarios.'
Exploring Microsoft Entra Capabilities
Confusing the role of Microsoft Entra Connect with Microsoft Entra ID itself; Connect is the synchronization tool, Entra ID is the cloud directory.
Exploring Microsoft Entra Capabilities
Not understanding the differences between PHS, PTA, and AD FS authentication methods, especially their infrastructure requirements and where authentication actually occurs.
Exploring Microsoft Entra Capabilities
Assuming hybrid identity means users have separate identities; the goal is a single, unified identity.
Exploring Microsoft Entra Capabilities
CSPM and CWPP for hybrid and multi-cloud environments.
Microsoft Security Solutions in Focus
Virtual firewall controlling traffic to Azure resources.
Microsoft Security Solutions in Focus
Managed, stateful network security service for VNETs.
Microsoft Security Solutions in Focus
Mitigates distributed denial of service attacks.
Microsoft Security Solutions in Focus
Measurement of an organization's security posture in Defender for Cloud.
Microsoft Security Solutions in Focus
Cloud Security Posture Management.
Microsoft Security Solutions in Focus
Cloud Workload Protection Platform.
Microsoft Security Solutions in Focus
To remember the shared responsibility model, think 'Cloud is OF Microsoft, You are IN control.' Microsoft handles the 'OF' the cloud infrastructure, you handle security 'IN' your cloud resources.
Microsoft Security Solutions in Focus
The exam emphasizes understanding the core function of Microsoft Defender for Cloud (CSPM + CWPP) and how Network Security Groups (NSGs) control traffic. Be prepared for questions distinguishing between Azure Firewall and NSGs, and always remember the shared responsibility model's implications.
Microsoft Security Solutions in Focus
Confusing Azure Firewall with NSGs: Azure Firewall is a centralized, stateful firewall for entire virtual networks, while NSGs are decentralized and control traffic at the subnet or NIC level.
Microsoft Security Solutions in Focus
Forgetting the customer's responsibility in the shared model: Even with PaaS/SaaS, customers are always responsible for their data and identity management.
Microsoft Security Solutions in Focus
Not understanding that NSG rules are processed in priority order (lowest number first) and that implicit deny rules exist at the end of every NSG.
Microsoft Security Solutions in Focus
Extended Detection and Response; unified security across domains.
Microsoft Security Solutions in Focus
Unified pre- and post-breach enterprise defense suite.
Microsoft Security Solutions in Focus
Protects devices like workstations and servers.
Microsoft Security Solutions in Focus
Secures email and collaboration tools.
Microsoft Security Solutions in Focus
Monitors Active Directory for identity-based threats.
Microsoft Security Solutions in Focus
Provides visibility and control for cloud applications.
Microsoft Security Solutions in Focus
Security Information and Event Management; centralizes logs.
Microsoft Security Solutions in Focus
Security Orchestration, Automation, and Response.
Microsoft Security Solutions in Focus
To remember the core components of Microsoft 365 Defender: **E**very **I**nvestigator **C**ares **O**utside. (Endpoint, Identity, Cloud Apps, Office 365).
Microsoft Security Solutions in Focus
The exam often tests your understanding of the *integrated nature* of Microsoft 365 Defender. Remember it's a *suite* that *natively coordinates* across multiple *domains* (endpoints, identity, email, cloud apps). Key keywords: 'unified,' 'XDR,' 'correlation,' 'automated response.'
Microsoft Security Solutions in Focus
Confusing Microsoft 365 Defender (XDR) with Microsoft Sentinel (SIEM/SOAR). Defender is deep within Microsoft 365; Sentinel is broad across everything.
Microsoft Security Solutions in Focus
Thinking Microsoft 365 Defender only protects endpoints. It covers identities, email, and cloud apps too.
Microsoft Security Solutions in Focus
Underestimating the 'automated response' capabilities; it's not just about detection, but also active mitigation.
Microsoft Security Solutions in Focus
Cloud-native SIEM and SOAR solution from Microsoft.
Microsoft Security Solutions in Focus
Automated workflow for security incident response.
Microsoft Security Solutions in Focus
Mechanism for ingesting data into Sentinel.
Microsoft Security Solutions in Focus
Proactive search for undiscovered threats.
Microsoft Security Solutions in Focus
A collection of related alerts and evidence.
Microsoft Security Solutions in Focus
Remember 'Sentinel' as a 'Sentry' guarding your digital gates, not just watching (SIEM) but also actively fighting back (SOAR)!
Microsoft Security Solutions in Focus
The exam often tests your understanding of Sentinel's role as a cloud-native SIEM and SOAR solution. Look for keywords like 'centralized logging,' 'threat detection,' 'automated response,' and 'proactive hunting' when identifying Sentinel's capabilities.
Microsoft Security Solutions in Focus
Confusing SIEM (monitoring/detection) with SOAR (automation/response). They are distinct but complementary.
Microsoft Security Solutions in Focus
Underestimating Sentinel's cloud-native advantage, assuming it's just an on-premises SIEM moved to the cloud.
Microsoft Security Solutions in Focus
Forgetting that Sentinel integrates with non-Microsoft security products, not just Microsoft's own.
Microsoft Security Solutions in Focus
Cloud-based service for mobile device management (MDM) and mobile application management (MAM).
Microsoft Security Solutions in Focus
Any device (laptop, phone, tablet) that connects to a network and accesses resources.
Microsoft Security Solutions in Focus
Managing and securing entire devices, typically corporate-owned, through policies.
Microsoft Security Solutions in Focus
Managing and securing data within specific applications, often for BYOD scenarios.
Microsoft Security Solutions in Focus
Rules defined in Intune that devices must meet to access corporate resources.
Microsoft Security Solutions in Focus
Remotely removing only corporate data from an application or device, leaving personal data intact.
Microsoft Security Solutions in Focus
Policy allowing employees to use personal devices for work, managed by MAM.
Microsoft Security Solutions in Focus
Intune: I N T U N E. 'I Need To Understand New Endpoints' – reminding you it manages new devices and their security.
Microsoft Security Solutions in Focus
The exam often tests the core difference between MDM (device-level control) and MAM (app-level control). Look for keywords like 'corporate-owned device' for MDM and 'personal device' or 'application data' for MAM.
Microsoft Security Solutions in Focus
Confusing MDM with MAM: MDM manages the whole device, MAM manages only the apps and data within them.
Microsoft Security Solutions in Focus
Believing Intune only works for mobile devices: It manages Windows, macOS, iOS, iPadOS, and Android.
Microsoft Security Solutions in Focus
Underestimating Intune's role in compliance: It's central to enforcing security standards and conditional access.
Microsoft Security Solutions in Focus
Actionable insights about existing or emerging threats to assets.
Microsoft Security Solutions in Focus
The overall cybersecurity readiness and defensive capabilities of an organization.
Microsoft Security Solutions in Focus
Microsoft's real-time threat intelligence platform for proactive defense.
Microsoft Security Solutions in Focus
Forensic data that identifies potential intrusion on a system or network.
Microsoft Security Solutions in Focus
The sum of all points where an unauthorized user can try to enter or extract data from an environment.
Microsoft Security Solutions in Focus
Measures taken to prevent attacks before they occur.
Microsoft Security Solutions in Focus
TIP: Threat Intelligence Prevents. POSTURE: Prioritize, Observe, Secure, Track, Understand, React, Evolve.
Microsoft Security Solutions in Focus
Memorize that Microsoft Defender Threat Intelligence (MDTI) provides global threat intelligence, while Microsoft Defender for Cloud focuses on security posture management and protection across cloud and hybrid environments. Look for keywords like 'proactive defense' and 'continuous assessment.'
Microsoft Security Solutions in Focus
Confusing threat intelligence with simple threat data; intelligence provides context and actionable insights.
Microsoft Security Solutions in Focus
Treating security posture management as a one-time audit instead of a continuous process.
Microsoft Security Solutions in Focus
Ignoring recommendations from security posture tools, assuming they are not critical.
Microsoft Security Solutions in Focus
Microsoft's central hub for compliance reports, audit documents, and data protection information.
Understanding Microsoft Compliance Solutions
A personal portal for Microsoft account users to view, manage, and delete their activity data.
Understanding Microsoft Compliance Solutions
Documents detailing adherence to specific industry standards or regulations (e.g., SOC, ISO).
Understanding Microsoft Compliance Solutions
Formal declaration or certification that a system or process meets certain standards.
Understanding Microsoft Compliance Solutions
Legal rights of individuals regarding their personal data (e.g., access, deletion, correction).
Understanding Microsoft Compliance Solutions
California Consumer Privacy Act; US state law on consumer privacy rights.
Understanding Microsoft Compliance Solutions
STP is for 'See The Proof' (organizational compliance). PD is for 'Personal Data' (individual control).
Understanding Microsoft Compliance Solutions
Memorize that the Service Trust Portal is for organizational compliance documentation, while the Privacy Dashboard is for individual user data management. Keywords to spot: 'audit reports', 'compliance documentation' for STP; 'personal data', 'activity history' for Privacy Dashboard.
Understanding Microsoft Compliance Solutions
Confusing the Service Trust Portal with the Microsoft Learn documentation portal; STP is specifically for compliance and trust documents.
Understanding Microsoft Compliance Solutions
Assuming the Privacy Dashboard is for managing organizational data; it's strictly for individual user account data.
Understanding Microsoft Compliance Solutions
Believing all documents in the Service Trust Portal are publicly accessible without a Microsoft account; some sensitive reports require authentication.
Understanding Microsoft Compliance Solutions
A tool in Microsoft Purview for managing compliance.
Understanding Microsoft Compliance Solutions
A numerical measure of an organization's compliance posture.
Understanding Microsoft Compliance Solutions
Controls Microsoft implements for platform security.
Understanding Microsoft Compliance Solutions
Controls organizations implement within their environment.
Understanding Microsoft Compliance Solutions
An evaluation of an organization's compliance against standards.
Understanding Microsoft Compliance Solutions
Pre-built frameworks for specific regulations or standards.
Understanding Microsoft Compliance Solutions
A safeguard or countermeasure to protect assets.
Understanding Microsoft Compliance Solutions
To remember 'Compliance Manager', think of a 'CM' as a 'Compliance Maestro' conducting an orchestra of regulations and actions to achieve a perfect 'Compliance Score'.
Understanding Microsoft Compliance Solutions
The exam often tests your understanding of the Compliance Score calculation and the distinction between Microsoft-managed and customer-managed actions. Remember that a higher score indicates better compliance.
Understanding Microsoft Compliance Solutions
Confusing Microsoft-managed actions with customer-managed actions. Remember, Microsoft manages its infrastructure, you manage your tenant's configuration.
Understanding Microsoft Compliance Solutions
Believing a perfect Compliance Score means an organization is 100% compliant and immune to all risks. It's a continuous journey, not a destination.
Understanding Microsoft Compliance Solutions
Not understanding that Compliance Manager is a tool to *help* manage compliance, not a magic button that makes an organization compliant automatically.
Understanding Microsoft Compliance Solutions
Classify data and apply protection settings like encryption.
Understanding Microsoft Compliance Solutions
Policies to prevent sensitive data from leaving the organization.
Understanding Microsoft Compliance Solutions
Scrambling data to protect it from unauthorized access.
Understanding Microsoft Compliance Solutions
Analyzing data to identify specific types of sensitive information.
Understanding Microsoft Compliance Solutions
Notifications to users about DLP policy violations.
Understanding Microsoft Compliance Solutions
System applies labels based on content or conditions.
Understanding Microsoft Compliance Solutions
Think of 'Labels' as sticky notes with rules that attach to your files, and 'DLP' as a watchful bouncer at the door, stopping anything labeled 'Forbidden' from leaving.
Understanding Microsoft Compliance Solutions
Memorize that sensitivity labels provide persistent protection that travels with the data, while DLP policies prevent unauthorized sharing by monitoring data in motion and at rest. The exam often tests the distinction and how they complement each other.
Understanding Microsoft Compliance Solutions
Confusing sensitivity labels with DLP policies: Labels classify and protect the data itself; DLP monitors and enforces rules on data movement.
Understanding Microsoft Compliance Solutions
Assuming labels automatically prevent all sharing: Labels apply protection, but DLP is often needed for real-time enforcement of sharing policies.
Understanding Microsoft Compliance Solutions
Forgetting that both manual and automatic labeling exist: Users can apply labels, or policies can apply them based on content.
Understanding Microsoft Compliance Solutions
Managing data from creation to deletion, optimizing value and minimizing risk.
Understanding Microsoft Compliance Solutions
Any data stored electronically that can be used as evidence in legal proceedings.
Understanding Microsoft Compliance Solutions
A process to preserve all forms of ESI when litigation is anticipated or pending.
Understanding Microsoft Compliance Solutions
Rules defining how long data is kept and what happens after that period.
Understanding Microsoft Compliance Solutions
An individual who has administrative control or possession of ESI relevant to a case.
Understanding Microsoft Compliance Solutions
A collection of ESI in Advanced eDiscovery for legal review, tagging, and redaction.
Understanding Microsoft Compliance Solutions
Sophisticated eDiscovery solution with custodian management, advanced indexing, and analytics.
Understanding Microsoft Compliance Solutions
To remember the eDiscovery stages: 'I Ponder Carefully, Preparing Really Perfectly'. (Identify, Preserve, Collect, Process, Review, Produce)
Understanding Microsoft Compliance Solutions
The exam often tests the stages of the eDiscovery workflow and the distinction between Standard and Advanced eDiscovery capabilities. Remember the core sequence: Identify, Preserve, Collect, Process, Review, Produce.
Understanding Microsoft Compliance Solutions
Confusing DLM with data archiving; DLM is broader, covering the entire lifecycle.
Understanding Microsoft Compliance Solutions
Underestimating the importance of legal holds; failure to preserve data can lead to severe penalties.
Understanding Microsoft Compliance Solutions
Not understanding that eDiscovery applies to all ESI, not just emails.
Understanding Microsoft Compliance Solutions