Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice questions
310 free questions with answers and explanations.
- 1.A company is migrating various legacy applications to Azure. These applications rely heavily on traditional LDAP and Kerberos authentication protocols and are not easily rewritable to use modern authentication methods. The company needs a managed service in Azure that provides domain controller functionality to support these applications without deploying and managing virtual machines for Active Directory. Which Microsoft Entra capability should they use?Describe the capabilities of Microsoft Entra
- 2.A small business is setting up its cloud environment and wants to implement a security policy that ensures all network traffic entering or leaving their virtual network is filtered based on predefined rules, such as source IP, destination port, and protocol. Which security concept is being applied here?Describe the concepts of security, compliance, and identity
- 3.A financial institution requires a high level of assurance for identity verification when onboarding new customers remotely. They want to enable users to present verifiable credentials issued by trusted third parties, such as government agencies, to instantly prove their identity during the onboarding process without sharing underlying sensitive data. Which Microsoft Entra capability supports this scenario?Describe the capabilities of Microsoft Entra
- 4.A manufacturing company is integrating its operational technology (OT) systems with its IT network. They need to implement security measures that assume any entity, whether inside or outside the network perimeter, could be a potential threat. All access requests must be verified explicitly, regardless of origin. Which security model is being adopted?Describe the concepts of security, compliance, and identity
- 5.A financial institution needs to implement a solution that allows its employees to prove their identity digitally using verifiable credentials issued by trusted third parties, rather than relying solely on traditional username and password combinations. Which Microsoft Entra capability supports this requirement?Describe the capabilities of Microsoft Entra
- 6.An organization is implementing a new security policy that dictates all users must have the minimum necessary permissions to perform their job functions and nothing more. This policy is designed to limit the potential damage from compromised accounts or insider threats. Which security principle is this organization enforcing?Describe the concepts of security, compliance, and identity
- 7.A global enterprise needs to manage access to thousands of applications, both cloud-based and on-premises. They want to centralize the management of these applications within Microsoft Entra ID and streamline the user experience for accessing them. Which Microsoft Entra capability allows this centralized management?Describe the capabilities of Microsoft Entra
- 8.A large organization with a complex IT environment needs to ensure that sensitive data stored across various cloud services (e.g., Office 365, Azure, third-party SaaS apps) is discovered, classified, and protected according to regulatory requirements. They need a solution that can identify sensitive information like credit card numbers or personal identifiable information (PII) wherever it resides. Which security concept is this related to?Describe the concepts of security, compliance, and identity
- 9.A small business is setting up its Microsoft Entra ID tenant. They want to allow employees to sign in to cloud applications using their existing Microsoft Entra credentials and ensure that the process is seamless and secure. Which core Microsoft Entra capability enables this functionality?Describe the capabilities of Microsoft Entra
- 10.A global enterprise is evaluating its data privacy practices. They need to ensure that personal data collected from customers is processed lawfully, fairly, and transparently, and that individuals have rights over their data. Which regulatory compliance standard is most directly concerned with these principles?Describe the concepts of security, compliance, and identity
- 11.A global organization uses Microsoft 365 and Azure services. They want to ensure that employees can only access sensitive data from managed devices located within specific geographical regions during business hours. Access from unmanaged devices or outside business hours should be blocked or require additional verification. Which identity concept would best facilitate this granular access control?Describe the concepts of security, compliance, and identity
- 12.A security auditor observes that several users have been assigned highly privileged roles in Microsoft Entra ID for an extended period, even though they only require these permissions for specific, infrequent tasks. The auditor recommends implementing a solution that provides just-in-time (JIT) access and requires multi-factor authentication (MFA) and a business justification for activating these roles. Which Microsoft Entra capability should be configured to meet these recommendations?Describe the capabilities of Microsoft Entra
- 13.A company is designing a new cloud application that will handle highly sensitive customer data. They want to ensure that every action taken by an administrator within the application is recorded, including who performed the action, what they did, and when. This is crucial for forensic investigations and compliance. Which identity concept is primarily focused on recording these actions?Describe the concepts of security, compliance, and identity
- 14.A financial institution needs to implement a solution that allows its employees to prove their identity in a secure, privacy-preserving, and verifiable manner across different organizations and services, without relying on a central authority to store all their personal data. They want to issue digital credentials that users control. Which Microsoft Entra capability supports this requirement?Describe the capabilities of Microsoft Entra
- 15.A company wants to ensure that all administrative roles in Microsoft Entra ID are assigned with just-in-time (JIT) access and require approval for activation. This helps minimize standing access for highly privileged accounts. Which Microsoft Entra capability should they implement?Describe the capabilities of Microsoft Entra
- 16.A financial institution is implementing a new security system. They need to ensure that when a user logs into their internal banking application, their identity is verified by a trusted third-party identity provider, rather than the banking application itself. This allows users to use their existing corporate credentials without creating new ones for each application. Which identity concept does this scenario describe?Describe the concepts of security, compliance, and identity
- 17.A company is integrating a legacy on-premises application with Microsoft Entra ID. The application uses Kerberos authentication and cannot be directly exposed to the internet. Users need to access this application from outside the corporate network using their Microsoft Entra credentials. Which Microsoft Entra capability should be deployed to facilitate this access?Describe the capabilities of Microsoft Entra
- 18.A consulting firm frequently collaborates with external partners on projects. They want to provide these partners with access to specific project-related resources in their Azure environment, but without creating full user accounts for them in their own corporate directory (Azure AD tenant). The partners should authenticate using their existing corporate identities from their own organizations. Which identity concept would facilitate this secure collaboration?Describe the concepts of security, compliance, and identity
- 19.A client is developing a new application that will process highly sensitive personal identifiable information (PII). They want to ensure that if the data is ever exfiltrated or accessed by unauthorized individuals, it remains unintelligible and unusable. Which security control directly addresses this requirement?Describe the concepts of security, compliance, and identity
- 20.A global enterprise needs to manage access for its 100,000 employees across various cloud services and on-premises applications. They require a centralized system to store user identities, authenticate users, and manage access rights efficiently. Which identity concept is essential for this requirement?Describe the concepts of security, compliance, and identity
- 21.A software development team needs to ensure that only specific versions of libraries and approved components are used in their applications to prevent known vulnerabilities from being introduced. They also need to track the origin and integrity of all open-source components. Which security concept is primarily concerned with managing and securing the components used in software development?Describe the concepts of security, compliance, and identity
- 22.A large enterprise is migrating its on-premises Active Directory to a cloud-based identity solution. They need a service that allows them to centrally manage user accounts, groups, and devices, and provides authentication and authorization services for applications both in the cloud and on-premises. Which type of service is best suited for this requirement?Describe the concepts of security, compliance, and identity
- 23.A company is migrating various legacy applications to Azure and needs to provide managed domain services (like domain join, group policy, and LDAP) for their Azure-hosted virtual machines without deploying and managing traditional domain controllers. Which Microsoft Entra capability provides this service?Describe the capabilities of Microsoft Entra
- 24.A global organization is implementing a new security policy that requires all users to provide two different forms of verification before accessing sensitive internal applications. Which security concept is this organization primarily implementing?Describe the concepts of security, compliance, and identity
- 25.A company is migrating several legacy applications to Azure. These applications rely heavily on traditional LDAP and Kerberos authentication for user and group management, but the company wants to avoid deploying and managing domain controllers in Azure VMs. Which Microsoft Entra capability provides managed domain services for these legacy applications in Azure?Describe the capabilities of Microsoft Entra
- 26.A global enterprise uses Microsoft Entra ID and has a complex organizational structure with many departments and projects. They need a scalable solution to delegate the management of access to specific internal applications and resources to department leads, empowering them to approve or deny access requests without involving central IT. Which Microsoft Entra capability supports this delegated access management?Describe the capabilities of Microsoft Entra
- 27.A small non-profit organization is concerned about protecting their donor list from being accidentally deleted or corrupted. Which security principle primarily addresses this concern?Describe the concepts of security, compliance, and identity
- 28.A company wants to implement a passwordless authentication strategy where users can sign in to Microsoft Entra ID using a physical security key that supports public-key cryptography. Which authentication method should they deploy?Describe the capabilities of Microsoft Entra
- 29.A small business is setting up its Microsoft Entra ID tenant. They want to ensure that users are prompted for a second verification method, such as a code from a mobile app or a phone call, when signing in. Which Microsoft Entra feature should they configure?Describe the capabilities of Microsoft Entra
- 30.A company wants to allow external contractors to access specific SharePoint Online sites and Microsoft Teams channels using their own corporate identities (e.g., from another Microsoft Entra tenant or a Google account). They need a solution that simplifies the invitation process and allows contractors to use their existing credentials without creating new accounts in the company's tenant. Which Microsoft Entra capability should be utilized?Describe the capabilities of Microsoft Entra
- 31.A company is migrating various applications to Azure and needs to provide managed domain services, such as domain join, group policy, LDAP, and Kerberos/NTLM authentication, for their Azure-based virtual machines and applications. They do not want to deploy and manage domain controllers on their own VMs. Which Microsoft Entra capability provides these managed domain services?Describe the capabilities of Microsoft Entra
- 32.A global organization uses Microsoft Entra ID and has a complex organizational structure with many departments and projects. They need a scalable solution to delegate the management of access to specific groups and applications to departmental managers, allowing them to approve or deny access requests from their team members. Which Microsoft Entra governance capability supports this delegated access management?Describe the capabilities of Microsoft Entra
- 33.A company is concerned about the security of administrative roles within Microsoft Entra ID. They want to ensure that privileged roles are assigned only when needed, for a limited time, and require approval workflows. After the assigned time, the permissions should automatically revert. Which Microsoft Entra capability addresses these requirements?Describe the capabilities of Microsoft Entra
- 34.A compliance officer requires a periodic review process for all users (including guests) who have access to highly sensitive data in specific Microsoft 365 groups and applications. The goal is to ensure that access is still appropriate and to automatically remove access for those who no longer need it. Which Microsoft Entra capability is designed for this purpose?Describe the capabilities of Microsoft Entra
- 35.A global enterprise needs to manage the identities and access rights for its employees, contractors, and partners across various cloud services (e.g., Azure, Salesforce, Workday) and on-premises applications. They require a centralized system to provision, de-provision, and manage access consistently across all these disparate systems. Which identity concept provides this overarching capability?Describe the concepts of security, compliance, and identity
- 36.A multinational corporation with a complex on-premises Active Directory infrastructure needs to consolidate its identity management. They want to synchronize users, groups, and contacts from multiple on-premises AD forests, some with non-routable UPN suffixes, into a single Microsoft Entra ID tenant while maintaining a single user identity across both environments. Which component of Microsoft Entra Connect is specifically designed to handle this complexity?Describe the capabilities of Microsoft Entra
- 37.A security architect is designing an identity solution for a company that requires users to access highly sensitive on-premises applications securely from outside the corporate network, without needing a VPN. The solution must integrate with Microsoft Entra ID for authentication and authorization. Which Microsoft Entra feature should the architect recommend?Describe the capabilities of Microsoft Entra
- 38.A large organization needs to onboard and offboard external contractors and partners quickly and securely, providing them with controlled access to specific resources without creating full user accounts in their primary Microsoft Entra ID tenant. Which Microsoft Entra capability is best suited for this scenario?Describe the capabilities of Microsoft Entra
- 39.A bank is implementing a new customer portal that will handle sensitive financial information. They want to ensure that if the underlying infrastructure is compromised, the sensitive data itself remains unreadable and unusable to unauthorized parties. Which security control would primarily achieve this goal?Describe the concepts of security, compliance, and identity
- 40.A large organization needs to onboard and offboard external contractors and partners quickly and efficiently, granting them access to specific internal applications and resources while maintaining strict security and compliance. The solution must enable these external users to use their existing identities (e.g., from their own Microsoft Entra ID tenants or social accounts) without creating new credentials in the organization's tenant. Which Microsoft Entra capability is best suited for this scenario?Describe the capabilities of Microsoft Entra
- 41.A multinational corporation uses Microsoft Entra ID and wants to ensure that all access to sensitive cloud applications is granted only to devices that are compliant with company security policies. Which Microsoft Entra capability allows them to enforce these device-based restrictions?Describe the capabilities of Microsoft Entra
- 42.A small business is setting up its Microsoft Entra ID tenant. They want to ensure that all user accounts created in Microsoft Entra ID are automatically synchronized with their on-premises Active Directory Domain Services (AD DS) for a seamless hybrid identity experience. Which Microsoft Entra capability should they use to achieve this?Describe the capabilities of Microsoft Entra
- 43.A security auditor recommends that a company implement a solution where users are prompted for an additional verification step, such as a biometric scan or a code from an authenticator app, when signing in from an unmanaged device or an unfamiliar location. Which Microsoft Entra capability directly addresses this recommendation?Describe the capabilities of Microsoft Entra
- 44.A company is redesigning its network architecture with the principle that no user, device, or application should be trusted by default, regardless of whether it is inside or outside the network perimeter. Every access request must be verified. Which security model are they adopting?Describe the concepts of security, compliance, and identity
- 45.A finance department requires a solution to ensure that all administrative roles within Microsoft Entra ID are assigned just-in-time and with approval workflows. Which Microsoft Entra governance capability addresses this requirement?Describe the capabilities of Microsoft Entra
- 46.A company is implementing Microsoft Entra ID and wants to ensure that users can only access cloud applications from devices that are marked as compliant by Microsoft Intune. Which Microsoft Entra capability should they configure?Describe the capabilities of Microsoft Entra
- 47.A security architect is designing a system that must detect and respond to unusual activities, such as an employee attempting to access sensitive data outside their typical working hours from an unfamiliar location. Which security capability is best suited for identifying and alerting on such anomalous behavior?Describe the concepts of security, compliance, and identity
- 48.A large manufacturing company is migrating several on-premises legacy applications to Azure. These applications historically relied on traditional Active Directory for authentication and authorization. The company wants to minimize application code changes during migration while leveraging cloud benefits. Which Microsoft Entra capability provides managed domain services for these legacy applications in Azure?Describe the capabilities of Microsoft Entra
- 49.A company is developing a new cloud-native application that will store sensitive customer data. To meet regulatory requirements, they need to implement continuous monitoring of all activities related to this data, including who accessed it, when, and what changes were made. This record must be immutable and legally defensible. Which compliance concept is most relevant here?Describe the concepts of security, compliance, and identity
- 50.A security administrator needs to implement a solution that allows users to sign in to Microsoft Entra ID without requiring passwords, using a hardware device that meets FIDO2 standards. Which authentication method should the administrator configure?Describe the capabilities of Microsoft Entra