Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice questions
310 free questions with answers and explanations.
- 51.A regulatory body requires that a company must implement measures to prevent the unauthorized disclosure of sensitive customer data. This includes encrypting data at rest and in transit, and restricting access to only those who explicitly need it for their job functions. Which core security principle is this requirement most aligned with?Describe the concepts of security, compliance, and identity
- 52.An organization uses Microsoft Entra ID and wants to empower its department managers to approve or deny access requests for specific applications and groups without involving IT administrators. This delegation should also include automated expiration of access. Which Microsoft Entra capability supports this self-service access governance model?Describe the capabilities of Microsoft Entra
- 53.A government agency needs to ensure that all access to highly sensitive applications is reviewed and re-certified by resource owners on a quarterly basis. This process must cover both internal employees and guest accounts. Which Microsoft Entra governance capability automates and tracks these periodic access reviews?Describe the capabilities of Microsoft Entra
- 54.A company wants to enable its employees to use a single set of credentials to access multiple applications, both cloud-based and on-premises, without re-entering their username and password for each application. Which core Microsoft Entra capability provides this functionality?Describe the capabilities of Microsoft Entra
- 55.A software development team is building a new application that will store sensitive customer data. They want to ensure that even if a malicious actor gains access to the application's underlying database, they cannot deny having accessed or modified specific records. Which security concept is the team trying to implement?Describe the concepts of security, compliance, and identity
- 56.A security architect is designing a system that must detect and respond to unusual activities, such as an employee attempting to access sensitive files outside of their usual working hours or from an unfamiliar location. The goal is to identify potential insider threats or compromised accounts. Which security capability is primarily focused on this type of detection?Describe the concepts of security, compliance, and identity
- 57.A global corporation is implementing a Zero Trust security model. They need to ensure that every access request, regardless of its origin, is explicitly verified before granting access to resources. Which core Microsoft Entra capability directly supports this principle?Describe the capabilities of Microsoft Entra
- 58.A global organization uses Microsoft 365 and Azure services. They want to ensure that employees based in different geographical regions receive varied levels of access to sensitive internal applications, based on their location and the device they are using. For example, access might be denied if an employee tries to access from an unmanaged device outside of the corporate network. Which identity and access concept is best suited to enforce these dynamic access policies?Describe the concepts of security, compliance, and identity
- 59.A software development company uses Microsoft Entra ID and wants to ensure that all newly created user accounts comply with a strict password policy that includes custom banned passwords specific to their organization (e.g., common project names, company slogans). Which Microsoft Entra capability allows defining and enforcing such a custom banned password list?Describe the capabilities of Microsoft Entra
- 60.A security team observes unusual sign-in patterns, such as sign-ins from unfamiliar locations or multiple failed sign-in attempts from the same account. They need a Microsoft Entra capability to automatically detect these suspicious activities and, optionally, trigger actions like requiring multifactor authentication or blocking the sign-in. Which Microsoft Entra capability provides this automated risk detection and response?Describe the capabilities of Microsoft Entra
- 61.A compliance officer is reviewing the organization's adherence to regulatory requirements for data processing. They need to ensure that the organization can demonstrate that all data handling activities, from collection to deletion, are performed according to policy and legal mandates. Which security and compliance concept is most relevant here?Describe the concepts of security, compliance, and identity
- 62.A software development team needs to ensure that only specific versions of libraries and approved software components are used in their applications to reduce security risks. They also want to enforce coding standards and security best practices during the development pipeline. Which compliance concept are they focusing on?Describe the concepts of security, compliance, and identity
- 63.A security auditor is reviewing an organization's compliance with data privacy regulations. They need to ensure that the organization can demonstrate exactly who accessed sensitive customer data, when they accessed it, and what actions they performed. Which security and compliance concept is the auditor primarily focused on?Describe the concepts of security, compliance, and identity
- 64.A company is implementing a new security framework that assumes every user, device, and application is potentially hostile, regardless of its location (inside or outside the network perimeter). Access decisions are made based on verifying identity, device health, and least privilege for every request. Which security model are they adopting?Describe the concepts of security, compliance, and identity
- 65.A healthcare organization needs to ensure that all users, including guest accounts, who have access to sensitive patient data applications, periodically confirm their continued need for that access. This is to comply with regulatory requirements and maintain a strong security posture. Which Microsoft Entra governance capability allows administrators to schedule and manage these recurring access reviews?Describe the capabilities of Microsoft Entra
- 66.A security architect is designing an identity solution for a company that wants to eliminate passwords entirely for its workforce while maintaining a high level of security. They need a method that uses biometric or hardware-based authentication. Which technology in Microsoft Entra ID supports this requirement?Describe the capabilities of Microsoft Entra
- 67.A large multinational corporation with a complex on-premises Active Directory infrastructure needs to synchronize user identities, groups, and contacts from their on-premises environment to Microsoft Entra ID. They also require password hash synchronization. Which Microsoft Entra tool should they deploy?Describe the capabilities of Microsoft Entra
- 68.A company is considering migrating its on-premises applications to Azure. They want to ensure that these applications can securely access other Azure resources (like Azure Key Vault or Azure Storage) without needing to manage credentials in their code. Which Azure identity feature should they implement?Describe the concepts of security, compliance, and identity
- 69.A financial institution is implementing a new compliance framework. They need to ensure that all financial transactions are processed according to strict regulatory guidelines and that any deviations are immediately detected and flagged for review. Which aspect of compliance is being addressed here?Describe the concepts of security, compliance, and identity
- 70.A compliance officer is setting up a new system to monitor user activities within cloud applications. The goal is to detect unusual login patterns, such as multiple failed login attempts from different geographic locations in a short period, or access to sensitive resources by a user who rarely interacts with them. Which security capability is best suited for this type of monitoring and anomaly detection?Describe the concepts of security, compliance, and identity
- 71.A software development company uses Microsoft Entra ID and wants to ensure that all newly created user accounts have strong, unique passwords that meet specific complexity requirements and are not easily guessable. Which Microsoft Entra capability helps enforce these password policies?Describe the capabilities of Microsoft Entra
- 72.A security architect is designing an identity solution for a company that wants to eliminate passwords for better security and user experience. They plan to use hardware devices that provide strong, phishing-resistant authentication. Which Microsoft Entra authentication method should the architect recommend?Describe the capabilities of Microsoft Entra
- 73.A company is implementing Microsoft Entra ID. They want to ensure that users are prompted for an additional verification method when signing in from an unfamiliar location or a non-compliant device. Which Microsoft Entra capability should they configure?Describe the capabilities of Microsoft Entra
- 74.A software development company uses Microsoft Entra ID and wants to ensure that all newly created user accounts and password changes adhere to strong password policies, including custom banned password lists. Which Microsoft Entra capability should they configure?Describe the capabilities of Microsoft Entra
- 75.A security administrator needs to ensure that all users accessing Microsoft Entra ID-integrated applications from unmanaged devices (personal laptops or phones) are automatically required to perform multifactor authentication, regardless of their location. Which Microsoft Entra capability provides this granular control?Describe the capabilities of Microsoft Entra
- 76.A software development company uses Microsoft Entra ID and wants to ensure that all newly created user accounts and existing users cannot use passwords that are commonly known, easily guessed, or have been previously compromised in data breaches. Which Microsoft Entra capability helps enforce this policy?Describe the capabilities of Microsoft Entra
- 77.A healthcare organization is subject to strict regulations regarding patient data. They need a system to ensure that when a patient requests their medical records, the system can verify the patient's identity and provide access, while also preventing unauthorized individuals from accessing the data. Which identity concept is primarily described by the ability to confirm the user's identity?Describe the concepts of security, compliance, and identity
- 78.A security architect is designing an identity solution for a company that wants to eliminate passwords for enhanced security and a streamlined user experience. They specifically want to leverage biometric authentication (e.g., fingerprint, facial recognition) directly from users' devices. Which passwordless authentication method aligns best with this requirement?Describe the capabilities of Microsoft Entra
- 79.A company is implementing a Zero Trust security model. They need to ensure that every access request to a resource is explicitly verified, regardless of whether the request originates from inside or outside the network. This verification must consider user identity, device health, location, application sensitivity, and data classification before granting access. Which core Microsoft Entra capability underpins this 'Verify Explicitly' principle?Describe the capabilities of Microsoft Entra
- 80.A small business is implementing a cybersecurity strategy. They want to prevent unauthorized disclosure of sensitive customer data. Which security principle are they primarily focusing on?Describe the concepts of security, compliance, and identity
- 81.A company is migrating its entire infrastructure to Azure and wants to ensure that all virtual machines (VMs) and Azure resources are automatically joined to a domain and managed using Group Policy Objects (GPOs), similar to their on-premises environment. They need a managed service that replicates Active Directory domain controller functionality within Azure without the overhead of deploying and maintaining IaaS domain controllers. Which Microsoft Entra capability fulfills this requirement?Describe the capabilities of Microsoft Entra
- 82.A company is implementing a new compliance framework. They need to ensure that all changes to critical system configurations are recorded, including who made the change, when it was made, and what exactly was changed. This is crucial for accountability and forensic analysis. Which compliance-related concept is being addressed?Describe the concepts of security, compliance, and identity
- 83.A company is implementing a new security framework that assumes every user, device, and application attempting to access resources, whether internal or external, is untrusted until proven otherwise. This framework mandates strict verification regardless of location or previous authentication. Which security concept is this company adopting?Describe the concepts of security, compliance, and identity
- 84.A large enterprise uses various cloud services and on-premises applications. They want to ensure that access permissions for employees are automatically provisioned and de-provisioned based on their employment status and role changes within the company. This automation should also extend to integrating with their Human Resources (HR) system. Which identity management capability is most relevant here?Describe the concepts of security, compliance, and identity
- 85.A manufacturing company needs to manage identity-related risks within Microsoft Entra ID. They want to automatically detect suspicious actions, such as impossible travel, sign-ins from unfamiliar locations, or leaked credentials, and configure automated responses like blocking access or requiring multifactor authentication (MFA). Which Microsoft Entra capability provides these automated detection and response features?Describe the capabilities of Microsoft Entra
- 86.A company is implementing a new security policy. They want to ensure that all actions performed on critical systems and sensitive data are traceable to the individual who performed them, and that there is an undeniable record of these actions. This is essential for compliance and forensic investigations. Which security principle is being emphasized?Describe the concepts of security, compliance, and identity
- 87.A large enterprise uses various cloud services and on-premises applications. They want to ensure that all employees have appropriate access rights to resources based on their job roles, and that these rights are regularly reviewed and certified. Additionally, they need to manage the lifecycle of identities from onboarding to offboarding. Which identity concept best describes this comprehensive approach?Describe the concepts of security, compliance, and identity
- 88.A global enterprise needs to manage the identities of its 200,000 employees, ensuring they can securely access various applications and resources, both on-premises and in the cloud, from any device. Which type of service is best suited to fulfill this broad requirement?Describe the concepts of security, compliance, and identity
- 89.A hospital needs to ensure that patient medical records are accessible only by authorized healthcare professionals, and that those professionals can only view or modify the data relevant to their specific role (e.g., a nurse can update vitals, but only a doctor can diagnose). Additionally, the system must prevent unauthorized disclosure to external parties. Which security concept is being primarily addressed by ensuring access is limited to specific roles and preventing unauthorized disclosure?Describe the concepts of security, compliance, and identity
- 90.A multinational corporation uses several cloud-based applications, some hosted in Azure, others by third-party vendors. They want to enable their employees to use their existing corporate credentials to access all these applications without needing to create separate accounts for each. Which identity concept facilitates this seamless access across different service providers?Describe the concepts of security, compliance, and identity
- 91.A regulatory body has mandated that a healthcare organization must be able to demonstrate that only authorized medical professionals have accessed specific patient records. This requires logging every access attempt, indicating who accessed what, when, and from where. Which aspect of compliance is this requirement primarily addressing?Describe the concepts of security, compliance, and identity
- 92.A company is implementing a Zero Trust security model and wants to ensure that all user access requests are continuously evaluated and validated in real-time, even after initial authentication. This includes verifying device health, user location, and application security posture for every access attempt. Which core Microsoft Entra principle aligns with this continuous validation approach?Describe the capabilities of Microsoft Entra
- 93.A company is integrating a new cloud-based SaaS application with Microsoft Entra ID. They want to automate the creation of user accounts in the SaaS application when new employees join the company, and automatically deactivate those accounts when employees leave. This process should eliminate manual administrative effort. Which Microsoft Entra capability enables this automated user lifecycle management?Describe the capabilities of Microsoft Entra
- 94.A company is migrating various legacy applications to Azure. These applications rely on traditional Lightweight Directory Access Protocol (LDAP) and Kerberos authentication. The company wants to avoid deploying and managing domain controllers in Azure Virtual Machines. Which Microsoft Entra capability can provide managed domain services for these applications?Describe the capabilities of Microsoft Entra
- 95.A company is implementing a security policy that states: 'Users should only have access to the resources absolutely necessary to perform their job functions, and for the shortest possible duration.' Which security principle is being directly applied here?Describe the concepts of security, compliance, and identity
- 96.A large enterprise with a complex on-premises Active Directory environment needs to synchronize user accounts, groups, and password hashes to Microsoft Entra ID. They also require support for advanced filtering rules and the ability to write back certain attributes from Microsoft Entra ID to on-premises AD. Which Microsoft Entra capability is essential for fulfilling these specific synchronization requirements?Describe the capabilities of Microsoft Entra
- 97.A security team observes unusual sign-in patterns, such as sign-ins from unfamiliar locations or impossible travel scenarios, for several user accounts. They want to automatically detect and respond to these identity-based risks. Which Microsoft Entra capability provides this functionality?Describe the capabilities of Microsoft Entra
- 98.A multinational corporation uses several cloud-based applications, some hosted in Azure, others by third-party providers. They want to provide a seamless login experience for their employees, where users can log in once with their corporate credentials and access all approved applications without re-entering their password. This also helps centralize user management. Which identity concept is being implemented?Describe the concepts of security, compliance, and identity
- 99.A security administrator needs to configure Microsoft Entra ID to automatically revoke access for users who have not accessed a specific application in the last 90 days. Additionally, they want to ensure that managers regularly review their team's access to sensitive resources. Which Microsoft Entra governance capability should be used?Describe the capabilities of Microsoft Entra
- 100.A small non-profit organization uses Microsoft 365 and Microsoft Entra ID. They want to ensure that all their employees can easily access their cloud applications using a single set of credentials. Which core Microsoft Entra capability directly addresses this requirement?Describe the capabilities of Microsoft Entra