Free knowledge base

Microsoft Security, Compliance, and Identity Fundamentals (SC-900) — key terms, tricks & tips

Everything from the course in one searchable place: 234 entries. Use it to review before a practice test or look up a word you forgot.

234 results

Key term

Pearson VUE

Primary third-party vendor administering Microsoft certification exams.

Getting Started: Understanding SC-900

Key term

Online Proctored Exam

Exam taken remotely under live supervision via webcam and microphone.

Getting Started: Understanding SC-900

Key term

Score Report

Document detailing exam performance by objective area after completion.

Getting Started: Understanding SC-900

Key term

Passing Score

Minimum score required to pass a Microsoft certification exam (700 for SC-900).

Getting Started: Understanding SC-900

Key term

Multiple-Response Question

Question type requiring selection of all correct answers from a list.

Getting Started: Understanding SC-900

Key term

Retake Policy

Rules governing how soon and how many times an exam can be reattempted.

Getting Started: Understanding SC-900

Key term

Microsoft Learn

Official Microsoft platform for learning resources and exam registration links.

Getting Started: Understanding SC-900

Memory trick

Exam Structure, Scoring, and Registration

To remember the passing score: 'Seven Hundred Heroes' pass the exam. (700)

Getting Started: Understanding SC-900

Exam tip

Exam Structure, Scoring, and Registration

The SC-900 exam is scored on a scale of 1-1000, and 700 is the minimum passing score. There are no performance-based labs on this fundamental exam. Remember the retake policy: 24 hours after the first fail, 14 days after subsequent fails.

Getting Started: Understanding SC-900

Common mistake

Exam Structure, Scoring, and Registration

Not reading the entire question or all answer options before selecting an answer.

Getting Started: Understanding SC-900

Common mistake

Exam Structure, Scoring, and Registration

Ignoring the retake policy and trying to reschedule too soon after a failed attempt.

Getting Started: Understanding SC-900

Common mistake

Exam Structure, Scoring, and Registration

Not checking online proctoring system requirements until the last minute, leading to technical issues.

Getting Started: Understanding SC-900

Common mistake

Exam Structure, Scoring, and Registration

Assuming partial credit for multiple-response questions; it's all or nothing.

Getting Started: Understanding SC-900

Key term

Sandbox environment

Temporary, isolated environment for safe hands-on practice.

Getting Started: Understanding SC-900

Key term

Practice questions

Sample questions to test knowledge and prepare for exam format.

Getting Started: Understanding SC-900

Key term

Study group

Peers collaborating to learn and discuss exam topics.

Getting Started: Understanding SC-900

Key term

Active learning

Engaging with material through notes, summaries, and questions.

Getting Started: Understanding SC-900

Key term

Microsoft Trust Center

Resource for Microsoft's security, privacy, and compliance information.

Getting Started: Understanding SC-900

Memory trick

Study Tips and Resources for SC-900

To remember study tips: 'OFFICIAL HANDS-ON COMMUNITY PRACTICE' – Official resources, Hands-on, Community, Practice questions.

Getting Started: Understanding SC-900

Exam tip

Study Tips and Resources for SC-900

The exam often tests your ability to identify the *best* resource for a given task. Memorize that Microsoft Learn is for self-paced training, the Azure portal is for hands-on configuration, and the Microsoft Trust Center is for compliance details.

Getting Started: Understanding SC-900

Common mistake

Study Tips and Resources for SC-900

Relying solely on third-party resources without verifying against official Microsoft documentation.

Getting Started: Understanding SC-900

Common mistake

Study Tips and Resources for SC-900

Only reading material without actively engaging through notes, summaries, or practice.

Getting Started: Understanding SC-900

Common mistake

Study Tips and Resources for SC-900

Skipping hands-on practice, which is crucial for understanding how concepts work in reality.

Getting Started: Understanding SC-900

Key term

Confidentiality

Protecting information from unauthorized disclosure.

Foundations of Security, Compliance, and Identity

Key term

Integrity

Ensuring data accuracy, completeness, and consistency.

Foundations of Security, Compliance, and Identity

Key term

Availability

Guaranteeing authorized access to information when needed.

Foundations of Security, Compliance, and Identity

Key term

CIA Triad

Foundational model for information security: Confidentiality, Integrity, Availability.

Foundations of Security, Compliance, and Identity

Key term

Zero Trust

Security model: never trust, always verify, assume breach.

Foundations of Security, Compliance, and Identity

Key term

Least Privilege

Granting only the minimum access rights necessary.

Foundations of Security, Compliance, and Identity

Key term

Micro-segmentation

Dividing networks into small, isolated segments.

Foundations of Security, Compliance, and Identity

Memory trick

Core Security Concepts: CIA Triad and Zero Trust

To remember CIA: 'C' for 'Confidential' (secret), 'I' for 'Intact' (unchanged), 'A' for 'Accessible' (ready when needed).

Foundations of Security, Compliance, and Identity

Exam tip

Core Security Concepts: CIA Triad and Zero Trust

The SC-900 exam will test your understanding of the CIA triad as fundamental security goals. For Zero Trust, know its core principle: 'never trust, always verify' and its implications for access control and continuous monitoring.

Foundations of Security, Compliance, and Identity

Common mistake

Core Security Concepts: CIA Triad and Zero Trust

Confusing integrity with confidentiality: Integrity is about data accuracy, confidentiality is about data privacy.

Foundations of Security, Compliance, and Identity

Common mistake

Core Security Concepts: CIA Triad and Zero Trust

Believing Zero Trust is only for external users: Zero Trust applies to all users and devices, internal or external.

Foundations of Security, Compliance, and Identity

Common mistake

Core Security Concepts: CIA Triad and Zero Trust

Assuming a firewall alone provides Zero Trust: Zero Trust requires a comprehensive approach, not just a perimeter defense.

Foundations of Security, Compliance, and Identity

Key term

Compliance

Adherence to laws, regulations, and standards.

Foundations of Security, Compliance, and Identity

Key term

GDPR

EU law for data privacy and protection.

Foundations of Security, Compliance, and Identity

Key term

HIPAA

US law protecting patient health information.

Foundations of Security, Compliance, and Identity

Key term

Data Governance

Management of data availability, usability, integrity, security.

Foundations of Security, Compliance, and Identity

Key term

Microsoft Purview

Microsoft's suite for compliance and data governance.

Foundations of Security, Compliance, and Identity

Key term

eDiscovery

Process of identifying and collecting electronic data.

Foundations of Security, Compliance, and Identity

Key term

PCI DSS

Standard for credit card data security.

Foundations of Security, Compliance, and Identity

Memory trick

Compliance Principles and Regulatory Frameworks

Think of COMPLIANCE as 'Can Our Machines Protect Legal Information And Never Compromise Everything?'

Foundations of Security, Compliance, and Identity

Exam tip

Compliance Principles and Regulatory Frameworks

The exam often tests your knowledge of specific regulations. Memorize that GDPR is for EU data privacy and HIPAA is for US patient health information. Keywords like 'personal data' often point to GDPR, while 'patient records' points to HIPAA.

Foundations of Security, Compliance, and Identity

Common mistake

Compliance Principles and Regulatory Frameworks

Confusing industry standards (like PCI DSS) with government regulations (like GDPR).

Foundations of Security, Compliance, and Identity

Common mistake

Compliance Principles and Regulatory Frameworks

Believing that using a compliant cloud provider automatically makes your organization fully compliant; compliance is a shared responsibility.

Foundations of Security, Compliance, and Identity

Common mistake

Compliance Principles and Regulatory Frameworks

Underestimating the ongoing effort required for compliance; it's not a one-time setup.

Foundations of Security, Compliance, and Identity

Key term

Authentication

Verifying a user's identity.

Foundations of Security, Compliance, and Identity

Key term

Authorization

Determining what an authenticated user can access.

Foundations of Security, Compliance, and Identity

Key term

MFA

Multi-Factor Authentication; requiring two or more factors to verify identity.

Foundations of Security, Compliance, and Identity

Key term

Biometrics

Authentication using unique physical characteristics (e.g., fingerprint).

Foundations of Security, Compliance, and Identity

Key term

SSO

Single Sign-On; authenticate once for multiple applications.

Foundations of Security, Compliance, and Identity

Key term

RBAC

Role-Based Access Control; permissions based on assigned roles.

Foundations of Security, Compliance, and Identity

Key term

ABAC

Attribute-Based Access Control; access based on user, resource, environment attributes.

Foundations of Security, Compliance, and Identity

Memory trick

Identity Concepts: Authentication, Authorization, MFA

AuthN (Authentication) is 'who you are' (N for Name). AuthZ (Authorization) is 'what you can do' (Z for Zone of access).

Foundations of Security, Compliance, and Identity

Exam tip

Identity Concepts: Authentication, Authorization, MFA

The exam frequently tests the distinction between authentication and authorization. Remember: Authentication is 'who you are', Authorization is 'what you can do'. MFA is a key security control and a common exam topic, often presented as a solution to credential theft.

Foundations of Security, Compliance, and Identity

Common mistake

Identity Concepts: Authentication, Authorization, MFA

Confusing authentication with authorization: These are distinct, sequential processes.

Foundations of Security, Compliance, and Identity

Common mistake

Identity Concepts: Authentication, Authorization, MFA

Underestimating the importance of MFA: Many breaches occur due to weak or compromised single-factor authentication.

Foundations of Security, Compliance, and Identity

Common mistake

Identity Concepts: Authentication, Authorization, MFA

Assuming all authentication methods provide the same level of security: Some methods are inherently stronger than others.

Foundations of Security, Compliance, and Identity

Key term

Shared Responsibility Model

Framework defining security duties of CSP and customer.

Foundations of Security, Compliance, and Identity

Key term

Security OF the Cloud

Provider's responsibility for underlying infrastructure.

Foundations of Security, Compliance, and Identity

Key term

Security IN the Cloud

Customer's responsibility for data, apps, configurations.

Foundations of Security, Compliance, and Identity

Key term

IaaS

Infrastructure as a Service; customer manages OS, apps, data.

Foundations of Security, Compliance, and Identity

Key term

PaaS

Platform as a Service; provider manages OS, customer manages apps, data.

Foundations of Security, Compliance, and Identity

Key term

SaaS

Software as a Service; provider manages most; customer manages data, access.

Foundations of Security, Compliance, and Identity

Key term

Customer Responsibility

Protecting data, applications, identity, and configurations.

Foundations of Security, Compliance, and Identity

Key term

Cloud Provider Responsibility

Securing physical infrastructure, network, virtualization.

Foundations of Security, Compliance, and Identity

Memory trick

Shared Responsibility Model in the Cloud

Think of a rented apartment: The landlord (provider) secures the building (OF the cloud), but you (customer) secure your belongings and furniture inside (IN the cloud).

Foundations of Security, Compliance, and Identity

Exam tip

Shared Responsibility Model in the Cloud

The SC-900 exam frequently tests the distinctions between 'security OF the cloud' (provider) and 'security IN the cloud' (customer) across IaaS, PaaS, and SaaS. Memorize which layers fall under whose responsibility for each service model.

Foundations of Security, Compliance, and Identity

Common mistake

Shared Responsibility Model in the Cloud

Assuming the cloud provider handles all security, leading to neglected customer responsibilities like data encryption or access management.

Foundations of Security, Compliance, and Identity

Common mistake

Shared Responsibility Model in the Cloud

Not understanding how responsibilities shift between IaaS, PaaS, and SaaS, resulting in security gaps or duplicated efforts.

Foundations of Security, Compliance, and Identity

Common mistake

Shared Responsibility Model in the Cloud

Failing to properly configure cloud services, which is always a customer responsibility and a common source of breaches.

Foundations of Security, Compliance, and Identity

Key term

Microsoft Entra ID

Cloud-based identity and access management service.

Exploring Microsoft Entra Capabilities

Key term

Identity and Access Management (IAM)

Framework for managing digital identities and controlling resource access.

Exploring Microsoft Entra Capabilities

Key term

Single Sign-On (SSO)

Allows users to access multiple applications with one login.

Exploring Microsoft Entra Capabilities

Key term

Application Registration

Integrating an application with Entra ID for identity management.

Exploring Microsoft Entra Capabilities

Key term

Tenant

A dedicated instance of Entra ID for an organization.

Exploring Microsoft Entra Capabilities

Key term

Directory

Stores user, group, and device information in Entra ID.

Exploring Microsoft Entra Capabilities

Key term

Azure Portal

Web-based console for managing Azure and Entra ID services.

Exploring Microsoft Entra Capabilities

Memory trick

Microsoft Entra ID Core Services

Think of E.N.T.R.A. as 'Every New Tenant Requires Access' – reminding you of its core role in managing access for new organizations.

Exploring Microsoft Entra Capabilities

Exam tip

Microsoft Entra ID Core Services

Memorize that Microsoft Entra ID is the new name for Azure Active Directory (Azure AD). The exam will use Entra ID, but understanding its lineage is important. Focus on its role as a cloud-based IAM service.

Exploring Microsoft Entra Capabilities

Common mistake

Microsoft Entra ID Core Services

Confusing Microsoft Entra ID with traditional on-premises Active Directory; they are distinct services.

Exploring Microsoft Entra Capabilities

Common mistake

Microsoft Entra ID Core Services

Underestimating the importance of SSO for both security and user experience.

Exploring Microsoft Entra Capabilities

Common mistake

Microsoft Entra ID Core Services

Not realizing that Entra ID is a foundational service for many other Microsoft cloud offerings.

Exploring Microsoft Entra Capabilities

Key term

Conditional Access

Policy engine enforcing access controls based on conditions.

Exploring Microsoft Entra Capabilities

Key term

Multi-Factor Authentication (MFA)

Requires two or more verification factors for access.

Exploring Microsoft Entra Capabilities

Key term

Privileged Identity Management (PIM)

Manages and controls just-in-time access for privileged roles.

Exploring Microsoft Entra Capabilities

Key term

Just-in-Time (JIT) Access

Granting elevated permissions only when needed, for a limited time.

Exploring Microsoft Entra Capabilities

Key term

Access Policy

A set of rules defining who can access what under which conditions.

Exploring Microsoft Entra Capabilities

Key term

Risk-based Conditional Access

Policies that adapt based on real-time user and sign-in risk detections.

Exploring Microsoft Entra Capabilities

Memory trick

Identity Protection: Conditional Access, MFA, PIM

Imagine a 'CAP' on your identity. C for Conditional Access (the gatekeeper), A for Authentication (MFA, the extra lock), P for PIM (the temporary key for special access).

Exploring Microsoft Entra Capabilities

Exam tip

Identity Protection: Conditional Access, MFA, PIM

The exam often presents scenarios asking which Microsoft Entra feature best addresses a specific security need. Look for keywords like 'require MFA based on location,' 'just-in-time access,' or 'block access from risky sign-ins' to identify Conditional Access, PIM, or risk policies.

Exploring Microsoft Entra Capabilities

Common mistake

Identity Protection: Conditional Access, MFA, PIM

Confusing PIM with general role-based access control (RBAC); PIM specifically manages temporary elevation of privileged roles.

Exploring Microsoft Entra Capabilities

Common mistake

Identity Protection: Conditional Access, MFA, PIM

Not understanding that Conditional Access is the 'how' for enforcing MFA in specific scenarios, not just MFA itself.

Exploring Microsoft Entra Capabilities

Common mistake

Identity Protection: Conditional Access, MFA, PIM

Overlooking that Conditional Access policies are processed AFTER user authentication, but BEFORE access to the resource.

Exploring Microsoft Entra Capabilities

Key term

Access Sprawl

Accumulation of unneeded access rights over time.

Exploring Microsoft Entra Capabilities

Key term

Access Review

Periodic verification of user access to resources.

Exploring Microsoft Entra Capabilities

Key term

Entitlement Management

Manages identity and access lifecycle at scale.

Exploring Microsoft Entra Capabilities

Key term

Access Package

Bundles resources for users to request access to.

Exploring Microsoft Entra Capabilities

Key term

Approval Workflow

Process for granting access requests with approvers.

Exploring Microsoft Entra Capabilities

Key term

Identity Governance

Managing identity and access lifecycle across an organization.

Exploring Microsoft Entra Capabilities

Memory trick

Microsoft Entra Governance: Access Reviews & Entitlements

Remember 'ARE' for Access Reviews: 'A' for Audit, 'R' for Review, 'E' for Existing Access. And 'EAT' for Entitlement Management: 'E' for Entitlements, 'A' for Access Packages, 'T' for Time-limited.

Exploring Microsoft Entra Capabilities

Exam tip

Microsoft Entra Governance: Access Reviews & Entitlements

The exam often tests the difference between access reviews (periodic verification of existing access) and entitlement management (streamlining access provisioning and deprovisioning, often time-limited). Keywords to spot include 'periodic review,' 'confirm access,' 'revoke access' for access reviews, and 'access package,' 'self-service,' 'time-limited access,' 'approval workflow' for entitlement management.

Exploring Microsoft Entra Capabilities

Common mistake

Microsoft Entra Governance: Access Reviews & Entitlements

Confusing access reviews (auditing existing access) with entitlement management (streamlining new and temporary access).

Exploring Microsoft Entra Capabilities

Common mistake

Microsoft Entra Governance: Access Reviews & Entitlements

Believing these features are only for large enterprises; they benefit organizations of all sizes.

Exploring Microsoft Entra Capabilities

Common mistake

Microsoft Entra Governance: Access Reviews & Entitlements

Forgetting that both features contribute to the principle of least privilege and compliance.

Exploring Microsoft Entra Capabilities

Key term

Microsoft Entra External ID

Comprehensive solution for managing all external identity types.

Exploring Microsoft Entra Capabilities

Key term

B2B Collaboration

Inviting external users (guests) to access internal resources.

Exploring Microsoft Entra Capabilities

Key term

Guest User

An external user invited to an organization's Microsoft Entra tenant.

Exploring Microsoft Entra Capabilities

Key term

B2C Identities

Managing customer identities for consumer-facing applications.

Exploring Microsoft Entra Capabilities

Key term

Device Registration

Linking a personal device to Microsoft Entra for conditional access.

Exploring Microsoft Entra Capabilities

Key term

Microsoft Entra Joined

Organization-owned devices fully managed by Microsoft Entra.

Exploring Microsoft Entra Capabilities

Key term

Hybrid Microsoft Entra Joined

Devices joined to on-premises AD and registered with Microsoft Entra.

Exploring Microsoft Entra Capabilities

Memory trick

External Identities and Device Management in Entra

B2B is for Business-to-Business (partners), B2C is for Business-to-Customer (consumers). Think 'C' for 'Customers'!

Exploring Microsoft Entra Capabilities

Exam tip

External Identities and Device Management in Entra

For the exam, distinguish between B2B (partners/guests) and B2C (customers). Remember that device registration is for personal devices (BYOD), while Microsoft Entra joined is for organization-owned devices.

Exploring Microsoft Entra Capabilities

Common mistake

External Identities and Device Management in Entra

Confusing B2B collaboration with B2C identities; they serve different external user types.

Exploring Microsoft Entra Capabilities

Common mistake

External Identities and Device Management in Entra

Assuming all devices accessing resources are fully managed; some are only registered.

Exploring Microsoft Entra Capabilities

Common mistake

External Identities and Device Management in Entra

Not understanding that guest users are distinct user objects in the directory.

Exploring Microsoft Entra Capabilities

Key term

Hybrid Identity

Combines on-premises AD DS with Microsoft Entra ID for unified access.

Exploring Microsoft Entra Capabilities

Key term

Microsoft Entra Connect

Tool to synchronize identities between on-premises AD and Entra ID.

Exploring Microsoft Entra Capabilities

Key term

Directory Synchronization

Process of copying user/group objects and attributes to Entra ID.

Exploring Microsoft Entra Capabilities

Key term

Password Hash Synchronization (PHS)

Synchronizes a hash of the on-premises password hash to Entra ID.

Exploring Microsoft Entra Capabilities

Key term

Pass-through Authentication (PTA)

Validates cloud sign-ins directly against on-premises Active Directory.

Exploring Microsoft Entra Capabilities

Key term

Federation (AD FS)

Advanced authentication method using Active Directory Federation Services.

Exploring Microsoft Entra Capabilities

Key term

On-premises Active Directory

Directory service running on servers within an organization's network.

Exploring Microsoft Entra Capabilities

Memory trick

Hybrid Identity with Microsoft Entra Connect

To remember the authentication methods: 'PHS' is 'Password Hashes Syncing,' 'PTA' is 'Pass-Through Authenticating,' and 'AD FS' is 'Advanced Federation Services.'

Exploring Microsoft Entra Capabilities

Exam tip

Hybrid Identity with Microsoft Entra Connect

The exam often tests your understanding of the different authentication methods for hybrid identity. Pay close attention to the characteristics and use cases for Password Hash Synchronization (PHS), Pass-through Authentication (PTA), and Federation (AD FS). Keywords to spot include 'simplest method,' 'on-premises validation,' and 'advanced scenarios.'

Exploring Microsoft Entra Capabilities

Common mistake

Hybrid Identity with Microsoft Entra Connect

Confusing the role of Microsoft Entra Connect with Microsoft Entra ID itself; Connect is the synchronization tool, Entra ID is the cloud directory.

Exploring Microsoft Entra Capabilities

Common mistake

Hybrid Identity with Microsoft Entra Connect

Not understanding the differences between PHS, PTA, and AD FS authentication methods, especially their infrastructure requirements and where authentication actually occurs.

Exploring Microsoft Entra Capabilities

Common mistake

Hybrid Identity with Microsoft Entra Connect

Assuming hybrid identity means users have separate identities; the goal is a single, unified identity.

Exploring Microsoft Entra Capabilities

Key term

Microsoft Defender for Cloud

CSPM and CWPP for hybrid and multi-cloud environments.

Microsoft Security Solutions in Focus

Key term

Network Security Group (NSG)

Virtual firewall controlling traffic to Azure resources.

Microsoft Security Solutions in Focus

Key term

Azure Firewall

Managed, stateful network security service for VNETs.

Microsoft Security Solutions in Focus

Key term

Azure DDoS Protection

Mitigates distributed denial of service attacks.

Microsoft Security Solutions in Focus

Key term

Secure Score

Measurement of an organization's security posture in Defender for Cloud.

Microsoft Security Solutions in Focus

Key term

CSPM

Cloud Security Posture Management.

Microsoft Security Solutions in Focus

Key term

CWPP

Cloud Workload Protection Platform.

Microsoft Security Solutions in Focus

Memory trick

Azure Security Basics: Defender for Cloud, Network

To remember the shared responsibility model, think 'Cloud is OF Microsoft, You are IN control.' Microsoft handles the 'OF' the cloud infrastructure, you handle security 'IN' your cloud resources.

Microsoft Security Solutions in Focus

Exam tip

Azure Security Basics: Defender for Cloud, Network

The exam emphasizes understanding the core function of Microsoft Defender for Cloud (CSPM + CWPP) and how Network Security Groups (NSGs) control traffic. Be prepared for questions distinguishing between Azure Firewall and NSGs, and always remember the shared responsibility model's implications.

Microsoft Security Solutions in Focus

Common mistake

Azure Security Basics: Defender for Cloud, Network

Confusing Azure Firewall with NSGs: Azure Firewall is a centralized, stateful firewall for entire virtual networks, while NSGs are decentralized and control traffic at the subnet or NIC level.

Microsoft Security Solutions in Focus

Common mistake

Azure Security Basics: Defender for Cloud, Network

Forgetting the customer's responsibility in the shared model: Even with PaaS/SaaS, customers are always responsible for their data and identity management.

Microsoft Security Solutions in Focus

Common mistake

Azure Security Basics: Defender for Cloud, Network

Not understanding that NSG rules are processed in priority order (lowest number first) and that implicit deny rules exist at the end of every NSG.

Microsoft Security Solutions in Focus

Key term

XDR

Extended Detection and Response; unified security across domains.

Microsoft Security Solutions in Focus

Key term

Microsoft 365 Defender

Unified pre- and post-breach enterprise defense suite.

Microsoft Security Solutions in Focus

Key term

Defender for Endpoint

Protects devices like workstations and servers.

Microsoft Security Solutions in Focus

Key term

Defender for Office 365

Secures email and collaboration tools.

Microsoft Security Solutions in Focus

Key term

Defender for Identity

Monitors Active Directory for identity-based threats.

Microsoft Security Solutions in Focus

Key term

Defender for Cloud Apps

Provides visibility and control for cloud applications.

Microsoft Security Solutions in Focus

Key term

SIEM

Security Information and Event Management; centralizes logs.

Microsoft Security Solutions in Focus

Key term

SOAR

Security Orchestration, Automation, and Response.

Microsoft Security Solutions in Focus

Memory trick

Microsoft 365 Defender: XDR capabilities

To remember the core components of Microsoft 365 Defender: **E**very **I**nvestigator **C**ares **O**utside. (Endpoint, Identity, Cloud Apps, Office 365).

Microsoft Security Solutions in Focus

Exam tip

Microsoft 365 Defender: XDR capabilities

The exam often tests your understanding of the *integrated nature* of Microsoft 365 Defender. Remember it's a *suite* that *natively coordinates* across multiple *domains* (endpoints, identity, email, cloud apps). Key keywords: 'unified,' 'XDR,' 'correlation,' 'automated response.'

Microsoft Security Solutions in Focus

Common mistake

Microsoft 365 Defender: XDR capabilities

Confusing Microsoft 365 Defender (XDR) with Microsoft Sentinel (SIEM/SOAR). Defender is deep within Microsoft 365; Sentinel is broad across everything.

Microsoft Security Solutions in Focus

Common mistake

Microsoft 365 Defender: XDR capabilities

Thinking Microsoft 365 Defender only protects endpoints. It covers identities, email, and cloud apps too.

Microsoft Security Solutions in Focus

Common mistake

Microsoft 365 Defender: XDR capabilities

Underestimating the 'automated response' capabilities; it's not just about detection, but also active mitigation.

Microsoft Security Solutions in Focus

Key term

Microsoft Sentinel

Cloud-native SIEM and SOAR solution from Microsoft.

Microsoft Security Solutions in Focus

Key term

Playbook

Automated workflow for security incident response.

Microsoft Security Solutions in Focus

Key term

Data Connector

Mechanism for ingesting data into Sentinel.

Microsoft Security Solutions in Focus

Key term

Threat Hunting

Proactive search for undiscovered threats.

Microsoft Security Solutions in Focus

Key term

Incident

A collection of related alerts and evidence.

Microsoft Security Solutions in Focus

Memory trick

Microsoft Sentinel: SIEM and SOAR Overview

Remember 'Sentinel' as a 'Sentry' guarding your digital gates, not just watching (SIEM) but also actively fighting back (SOAR)!

Microsoft Security Solutions in Focus

Exam tip

Microsoft Sentinel: SIEM and SOAR Overview

The exam often tests your understanding of Sentinel's role as a cloud-native SIEM and SOAR solution. Look for keywords like 'centralized logging,' 'threat detection,' 'automated response,' and 'proactive hunting' when identifying Sentinel's capabilities.

Microsoft Security Solutions in Focus

Common mistake

Microsoft Sentinel: SIEM and SOAR Overview

Confusing SIEM (monitoring/detection) with SOAR (automation/response). They are distinct but complementary.

Microsoft Security Solutions in Focus

Common mistake

Microsoft Sentinel: SIEM and SOAR Overview

Underestimating Sentinel's cloud-native advantage, assuming it's just an on-premises SIEM moved to the cloud.

Microsoft Security Solutions in Focus

Common mistake

Microsoft Sentinel: SIEM and SOAR Overview

Forgetting that Sentinel integrates with non-Microsoft security products, not just Microsoft's own.

Microsoft Security Solutions in Focus

Key term

Microsoft Intune

Cloud-based service for mobile device management (MDM) and mobile application management (MAM).

Microsoft Security Solutions in Focus

Key term

Endpoint

Any device (laptop, phone, tablet) that connects to a network and accesses resources.

Microsoft Security Solutions in Focus

Key term

MDM (Mobile Device Management)

Managing and securing entire devices, typically corporate-owned, through policies.

Microsoft Security Solutions in Focus

Key term

MAM (Mobile Application Management)

Managing and securing data within specific applications, often for BYOD scenarios.

Microsoft Security Solutions in Focus

Key term

Compliance Policies

Rules defined in Intune that devices must meet to access corporate resources.

Microsoft Security Solutions in Focus

Key term

Selective Wipe

Remotely removing only corporate data from an application or device, leaving personal data intact.

Microsoft Security Solutions in Focus

Key term

BYOD (Bring Your Own Device)

Policy allowing employees to use personal devices for work, managed by MAM.

Microsoft Security Solutions in Focus

Memory trick

Endpoint security with Microsoft Intune

Intune: I N T U N E. 'I Need To Understand New Endpoints' – reminding you it manages new devices and their security.

Microsoft Security Solutions in Focus

Exam tip

Endpoint security with Microsoft Intune

The exam often tests the core difference between MDM (device-level control) and MAM (app-level control). Look for keywords like 'corporate-owned device' for MDM and 'personal device' or 'application data' for MAM.

Microsoft Security Solutions in Focus

Common mistake

Endpoint security with Microsoft Intune

Confusing MDM with MAM: MDM manages the whole device, MAM manages only the apps and data within them.

Microsoft Security Solutions in Focus

Common mistake

Endpoint security with Microsoft Intune

Believing Intune only works for mobile devices: It manages Windows, macOS, iOS, iPadOS, and Android.

Microsoft Security Solutions in Focus

Common mistake

Endpoint security with Microsoft Intune

Underestimating Intune's role in compliance: It's central to enforcing security standards and conditional access.

Microsoft Security Solutions in Focus

Key term

Threat Intelligence

Actionable insights about existing or emerging threats to assets.

Microsoft Security Solutions in Focus

Key term

Security Posture

The overall cybersecurity readiness and defensive capabilities of an organization.

Microsoft Security Solutions in Focus

Key term

Microsoft Defender Threat Intelligence (MDTI)

Microsoft's real-time threat intelligence platform for proactive defense.

Microsoft Security Solutions in Focus

Key term

Indicator of Compromise (IOC)

Forensic data that identifies potential intrusion on a system or network.

Microsoft Security Solutions in Focus

Key term

Attack Surface

The sum of all points where an unauthorized user can try to enter or extract data from an environment.

Microsoft Security Solutions in Focus

Key term

Proactive Security

Measures taken to prevent attacks before they occur.

Microsoft Security Solutions in Focus

Memory trick

Threat Intelligence & Security Posture Management

TIP: Threat Intelligence Prevents. POSTURE: Prioritize, Observe, Secure, Track, Understand, React, Evolve.

Microsoft Security Solutions in Focus

Exam tip

Threat Intelligence & Security Posture Management

Memorize that Microsoft Defender Threat Intelligence (MDTI) provides global threat intelligence, while Microsoft Defender for Cloud focuses on security posture management and protection across cloud and hybrid environments. Look for keywords like 'proactive defense' and 'continuous assessment.'

Microsoft Security Solutions in Focus

Common mistake

Threat Intelligence & Security Posture Management

Confusing threat intelligence with simple threat data; intelligence provides context and actionable insights.

Microsoft Security Solutions in Focus

Common mistake

Threat Intelligence & Security Posture Management

Treating security posture management as a one-time audit instead of a continuous process.

Microsoft Security Solutions in Focus

Common mistake

Threat Intelligence & Security Posture Management

Ignoring recommendations from security posture tools, assuming they are not critical.

Microsoft Security Solutions in Focus

Key term

Service Trust Portal

Microsoft's central hub for compliance reports, audit documents, and data protection information.

Understanding Microsoft Compliance Solutions

Key term

Privacy Dashboard

A personal portal for Microsoft account users to view, manage, and delete their activity data.

Understanding Microsoft Compliance Solutions

Key term

Compliance Reports

Documents detailing adherence to specific industry standards or regulations (e.g., SOC, ISO).

Understanding Microsoft Compliance Solutions

Key term

Attestation

Formal declaration or certification that a system or process meets certain standards.

Understanding Microsoft Compliance Solutions

Key term

Data Subject Rights

Legal rights of individuals regarding their personal data (e.g., access, deletion, correction).

Understanding Microsoft Compliance Solutions

Key term

CCPA

California Consumer Privacy Act; US state law on consumer privacy rights.

Understanding Microsoft Compliance Solutions

Memory trick

Service Trust Portal and Privacy Dashboard

STP is for 'See The Proof' (organizational compliance). PD is for 'Personal Data' (individual control).

Understanding Microsoft Compliance Solutions

Exam tip

Service Trust Portal and Privacy Dashboard

Memorize that the Service Trust Portal is for organizational compliance documentation, while the Privacy Dashboard is for individual user data management. Keywords to spot: 'audit reports', 'compliance documentation' for STP; 'personal data', 'activity history' for Privacy Dashboard.

Understanding Microsoft Compliance Solutions

Common mistake

Service Trust Portal and Privacy Dashboard

Confusing the Service Trust Portal with the Microsoft Learn documentation portal; STP is specifically for compliance and trust documents.

Understanding Microsoft Compliance Solutions

Common mistake

Service Trust Portal and Privacy Dashboard

Assuming the Privacy Dashboard is for managing organizational data; it's strictly for individual user account data.

Understanding Microsoft Compliance Solutions

Common mistake

Service Trust Portal and Privacy Dashboard

Believing all documents in the Service Trust Portal are publicly accessible without a Microsoft account; some sensitive reports require authentication.

Understanding Microsoft Compliance Solutions

Key term

Compliance Manager

A tool in Microsoft Purview for managing compliance.

Understanding Microsoft Compliance Solutions

Key term

Compliance Score

A numerical measure of an organization's compliance posture.

Understanding Microsoft Compliance Solutions

Key term

Microsoft-managed actions

Controls Microsoft implements for platform security.

Understanding Microsoft Compliance Solutions

Key term

Customer-managed actions

Controls organizations implement within their environment.

Understanding Microsoft Compliance Solutions

Key term

Assessment

An evaluation of an organization's compliance against standards.

Understanding Microsoft Compliance Solutions

Key term

Template

Pre-built frameworks for specific regulations or standards.

Understanding Microsoft Compliance Solutions

Key term

Control

A safeguard or countermeasure to protect assets.

Understanding Microsoft Compliance Solutions

Memory trick

Compliance Manager and Compliance Score

To remember 'Compliance Manager', think of a 'CM' as a 'Compliance Maestro' conducting an orchestra of regulations and actions to achieve a perfect 'Compliance Score'.

Understanding Microsoft Compliance Solutions

Exam tip

Compliance Manager and Compliance Score

The exam often tests your understanding of the Compliance Score calculation and the distinction between Microsoft-managed and customer-managed actions. Remember that a higher score indicates better compliance.

Understanding Microsoft Compliance Solutions

Common mistake

Compliance Manager and Compliance Score

Confusing Microsoft-managed actions with customer-managed actions. Remember, Microsoft manages its infrastructure, you manage your tenant's configuration.

Understanding Microsoft Compliance Solutions

Common mistake

Compliance Manager and Compliance Score

Believing a perfect Compliance Score means an organization is 100% compliant and immune to all risks. It's a continuous journey, not a destination.

Understanding Microsoft Compliance Solutions

Common mistake

Compliance Manager and Compliance Score

Not understanding that Compliance Manager is a tool to *help* manage compliance, not a magic button that makes an organization compliant automatically.

Understanding Microsoft Compliance Solutions

Key term

Sensitivity Labels

Classify data and apply protection settings like encryption.

Understanding Microsoft Compliance Solutions

Key term

Data Loss Prevention (DLP)

Policies to prevent sensitive data from leaving the organization.

Understanding Microsoft Compliance Solutions

Key term

Encryption

Scrambling data to protect it from unauthorized access.

Understanding Microsoft Compliance Solutions

Key term

Content Inspection

Analyzing data to identify specific types of sensitive information.

Understanding Microsoft Compliance Solutions

Key term

Policy Tips

Notifications to users about DLP policy violations.

Understanding Microsoft Compliance Solutions

Key term

Automatic Labeling

System applies labels based on content or conditions.

Understanding Microsoft Compliance Solutions

Memory trick

Information Protection: Sensitivity Labels, DLP

Think of 'Labels' as sticky notes with rules that attach to your files, and 'DLP' as a watchful bouncer at the door, stopping anything labeled 'Forbidden' from leaving.

Understanding Microsoft Compliance Solutions

Exam tip

Information Protection: Sensitivity Labels, DLP

Memorize that sensitivity labels provide persistent protection that travels with the data, while DLP policies prevent unauthorized sharing by monitoring data in motion and at rest. The exam often tests the distinction and how they complement each other.

Understanding Microsoft Compliance Solutions

Common mistake

Information Protection: Sensitivity Labels, DLP

Confusing sensitivity labels with DLP policies: Labels classify and protect the data itself; DLP monitors and enforces rules on data movement.

Understanding Microsoft Compliance Solutions

Common mistake

Information Protection: Sensitivity Labels, DLP

Assuming labels automatically prevent all sharing: Labels apply protection, but DLP is often needed for real-time enforcement of sharing policies.

Understanding Microsoft Compliance Solutions

Common mistake

Information Protection: Sensitivity Labels, DLP

Forgetting that both manual and automatic labeling exist: Users can apply labels, or policies can apply them based on content.

Understanding Microsoft Compliance Solutions

Key term

Data Lifecycle Management (DLM)

Managing data from creation to deletion, optimizing value and minimizing risk.

Understanding Microsoft Compliance Solutions

Key term

Electronically Stored Information (ESI)

Any data stored electronically that can be used as evidence in legal proceedings.

Understanding Microsoft Compliance Solutions

Key term

Legal Hold

A process to preserve all forms of ESI when litigation is anticipated or pending.

Understanding Microsoft Compliance Solutions

Key term

Retention Policy

Rules defining how long data is kept and what happens after that period.

Understanding Microsoft Compliance Solutions

Key term

Custodian

An individual who has administrative control or possession of ESI relevant to a case.

Understanding Microsoft Compliance Solutions

Key term

Review Set

A collection of ESI in Advanced eDiscovery for legal review, tagging, and redaction.

Understanding Microsoft Compliance Solutions

Key term

Advanced eDiscovery

Sophisticated eDiscovery solution with custodian management, advanced indexing, and analytics.

Understanding Microsoft Compliance Solutions

Memory trick

Data Lifecycle Management and eDiscovery

To remember the eDiscovery stages: 'I Ponder Carefully, Preparing Really Perfectly'. (Identify, Preserve, Collect, Process, Review, Produce)

Understanding Microsoft Compliance Solutions

Exam tip

Data Lifecycle Management and eDiscovery

The exam often tests the stages of the eDiscovery workflow and the distinction between Standard and Advanced eDiscovery capabilities. Remember the core sequence: Identify, Preserve, Collect, Process, Review, Produce.

Understanding Microsoft Compliance Solutions

Common mistake

Data Lifecycle Management and eDiscovery

Confusing DLM with data archiving; DLM is broader, covering the entire lifecycle.

Understanding Microsoft Compliance Solutions

Common mistake

Data Lifecycle Management and eDiscovery

Underestimating the importance of legal holds; failure to preserve data can lead to severe penalties.

Understanding Microsoft Compliance Solutions

Common mistake

Data Lifecycle Management and eDiscovery

Not understanding that eDiscovery applies to all ESI, not just emails.

Understanding Microsoft Compliance Solutions