Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice questions

310 free questions with answers and explanations.

Practice test
  1. 151.A global manufacturing company uses Microsoft Entra ID. They need a way to automatically manage the lifecycle of user accounts and attributes across various cloud-based human resources (HR) applications and on-premises directories. Which Microsoft Entra capability should they implement?Describe the capabilities of Microsoft Entra
  2. 152.A multinational corporation needs to manage access to thousands of applications, both cloud-based and on-premises, using a centralized identity store. They want to integrate these applications with Microsoft Entra ID to provide a consistent sign-in experience and streamline user provisioning. Which core Microsoft Entra capability is essential for achieving this widespread application integration and management?Describe the capabilities of Microsoft Entra
  3. 153.A company is migrating various legacy applications to Azure and needs to provide managed domain services, such as domain join, group policy, and LDAP authentication, without deploying and maintaining domain controllers in Azure VMs. Which Microsoft Entra capability should they use?Describe the capabilities of Microsoft Entra
  4. 154.A software development team needs to ensure that only specific versions of libraries and approved components are used in their applications to prevent known vulnerabilities from being introduced. Which compliance concept is this primarily related to?Describe the concepts of security, compliance, and identity
  5. 155.An organization wants to implement a passwordless authentication strategy for its mobile workforce. They require a method that allows users to sign in to Microsoft Entra ID and connected applications using a cryptographic key stored on their device, without ever typing a password. Which Microsoft Entra authentication method supports this requirement?Describe the capabilities of Microsoft Entra
  6. 156.A compliance officer is reviewing the organization's data handling policies to ensure adherence to regulations like GDPR and HIPAA. They need to define how long certain types of data must be kept and when they must be securely disposed of. Which compliance concept is the officer primarily focusing on?Describe the concepts of security, compliance, and identity
  7. 157.A large enterprise is migrating its applications to Azure. They need a service that allows Azure resources (like Virtual Machines or Azure Functions) to authenticate to other Azure services (like Key Vault or Storage Accounts) without managing credentials in their code. Which identity concept best addresses this requirement?Describe the concepts of security, compliance, and identity
  8. 158.A healthcare provider needs to ensure that patient records are protected from unauthorized access, modification, or deletion, while also remaining accessible to medical staff when needed. They are particularly concerned about maintaining the accuracy and trustworthiness of this highly sensitive data. Which core security principle are they primarily focusing on?Describe the concepts of security, compliance, and identity
  9. 159.An organization wants to implement a solution where users can verify their identity using a decentralized, verifiable credential issued by a trusted third party, rather than relying solely on a centralized identity provider. This credential would then be used to access certain applications. Which Microsoft Entra capability supports this approach?Describe the capabilities of Microsoft Entra
  10. 160.A security team is implementing a new framework where every access request, regardless of whether it originates from inside or outside the network, is explicitly verified. They assume that no user or device can be inherently trusted, and access is granted only after strict validation of identity, device health, and other contextual factors. Which security model are they adopting?Describe the concepts of security, compliance, and identity
  11. 161.A compliance officer is setting up a new system to monitor user activities within cloud applications to detect potential insider threats or compromised accounts. The system needs to analyze behavioral patterns, such as unusual login times, access to sensitive data outside normal working hours, or excessive downloads. Which security technology is best suited for this task?Describe the concepts of security, compliance, and identity
  12. 162.An organization wants to simplify the sign-in experience for its users by allowing them to authenticate to Microsoft Entra ID without typing a password, using a strong, phishing-resistant method. This method should leverage hardware-backed security keys or biometric authentication built into devices. Which passwordless authentication method in Microsoft Entra ID directly supports this requirement?Describe the capabilities of Microsoft Entra
  13. 163.A software company is developing a new cloud-native application that will frequently interact with other microservices and databases within Azure. They want to simplify the management of secrets and credentials for these interactions, ensuring secure communication without hardcoding authentication details. Which identity solution provides a centralized, secure way to manage and access these secrets?Describe the concepts of security, compliance, and identity
  14. 164.A financial institution requires employees to use a smart card in addition to their password to access sensitive customer data. This practice significantly strengthens the security posture by requiring two distinct types of evidence to verify identity. What term best describes this security measure?Describe the concepts of security, compliance, and identity
  15. 165.A security architect is designing an identity solution for a company that requires users to access on-premises web applications from outside the corporate network without using a VPN. The solution must provide secure, single sign-on (SSO) access to these internal applications through Microsoft Entra ID. Which Microsoft Entra capability is essential for this requirement?Describe the capabilities of Microsoft Entra
  16. 166.A company wants to manage the lifecycle of user access to groups, applications, and SharePoint sites, including automated assignments, approvals, and expiration. They also want to delegate access management decisions to resource owners. Which Microsoft Entra capability should they use?Describe the capabilities of Microsoft Entra
  17. 167.A healthcare organization uses Microsoft Entra ID and is subject to strict regulatory compliance requiring a periodic review of all user access, including guest accounts, to sensitive patient data applications. The reviews must be auditable and allow resource owners to certify or revoke access. Which Microsoft Entra capability best facilitates this requirement?Describe the capabilities of Microsoft Entra
  18. 168.A security architect is designing a system that must detect and respond to unusual activities, such as an employee attempting to access a sensitive database outside of their normal working hours from an unfamiliar location. Which security technology is designed for this type of behavioral analysis?Describe the concepts of security, compliance, and identity
  19. 169.An organization is preparing for a potential data breach. They want to ensure that even if an attacker gains access to their systems, the sensitive data remains unreadable and unusable. Which security control directly addresses this objective?Describe the concepts of security, compliance, and identity
  20. 170.A company is integrating a new cloud-based SaaS application with Microsoft Entra ID. They need to ensure that users are automatically provisioned to the application when their account is created in Microsoft Entra ID and de-provisioned when their account is disabled. Which Microsoft Entra capability should be configured?Describe the capabilities of Microsoft Entra
  21. 171.A global software company maintains sensitive intellectual property. They need a security strategy that ensures only specific employees, based on their job function, can access certain code repositories. For example, only developers can access active development branches, while testers can only access staging environments. Which access control model is best suited for implementing this requirement?Describe the concepts of security, compliance, and identity
  22. 172.A security team is implementing a new framework where every access request, regardless of whether it originates from inside or outside the network, must be explicitly verified. This verification includes evaluating user identity, device compliance, and the sensitivity of the resource being accessed before granting least-privilege access. Which security model is being adopted?Describe the concepts of security, compliance, and identity
  23. 173.A multinational corporation needs to provide secure access to its on-premises web applications for external partners without exposing the internal network directly to the internet. Which Microsoft Entra capability allows this secure remote access?Describe the capabilities of Microsoft Entra
  24. 174.A security administrator needs to ensure that only devices that meet specific compliance standards (e.g., up-to-date antivirus, OS version) can access sensitive corporate resources in Microsoft Entra ID. Which Microsoft Entra capability allows the administrator to define these device-specific requirements and enforce them?Describe the capabilities of Microsoft Entra
  25. 175.A security team is implementing a new framework where every access request, regardless of whether it originates from inside or outside the network, is explicitly verified. This includes verifying user identity, device health, and the context of the access attempt before granting least-privilege access. Which security framework are they adopting?Describe the concepts of security, compliance, and identity
  26. 176.A security architect is designing an identity solution for a company that requires users to access an on-premises web application securely from outside the corporate network without using a VPN. Which Microsoft Entra capability should be implemented?Describe the capabilities of Microsoft Entra
  27. 177.A large organization needs to ensure that its employees can access critical business applications and data at all times, even during unexpected outages or cyberattacks. They are investing in redundant systems, backup strategies, and disaster recovery plans. Which core security principle are they primarily focusing on?Describe the concepts of security, compliance, and identity
  28. 178.A small business is setting up its Microsoft Entra ID tenant. They want to ensure that all user accounts are synchronized from their on-premises Active Directory to Microsoft Entra ID. Which Microsoft Entra capability should they implement?Describe the capabilities of Microsoft Entra
  29. 179.A compliance officer is reviewing the organization's data handling policies to ensure adherence to privacy regulations like GDPR. They need to establish clear rules for how long different types of data should be kept and how they should be securely disposed of once their purpose is served. Which compliance concept is the officer primarily focused on?Describe the concepts of security, compliance, and identity
  30. 180.A software development company uses Microsoft Entra ID and wants to ensure that all newly created users have strong, unique passwords that are not easily guessed or part of known compromised password lists. They also want to prevent users from reusing old passwords. Which Microsoft Entra capability helps enforce these password policies?Describe the capabilities of Microsoft Entra
  31. 181.A financial institution needs to implement a solution that allows its employees to prove their identity using digital credentials issued by trusted organizations, reducing reliance on traditional usernames and passwords for certain high-assurance scenarios. This system should enable users to securely present verifiable claims about themselves. Which Microsoft Entra capability aligns with this requirement?Describe the capabilities of Microsoft Entra
  32. 182.A growing startup uses Microsoft Entra ID and has many external contractors and temporary staff who require access to specific project-related resources for a limited duration. They need a solution to streamline the onboarding and offboarding of these external users and manage their access to groups, applications, and SharePoint Online sites through self-service and approval workflows. Which Microsoft Entra governance capability is ideal for this scenario?Describe the capabilities of Microsoft Entra
  33. 183.A multinational corporation has a hybrid identity environment with users provisioned from on-premises Active Directory to Microsoft Entra ID. They need to ensure that when a user's account is disabled in the on-premises Active Directory, their access to Microsoft 365 services is automatically revoked. Which Microsoft Entra capability facilitates this synchronization?Describe the capabilities of Microsoft Entra
  34. 184.A large organization with a complex IT environment needs to ensure that sensitive data stored in various cloud services and on-premises systems is classified, labeled, and protected according to its sensitivity level. This includes applying encryption, access restrictions, and visual markings based on content. Which security concept specifically addresses these requirements?Describe the concepts of security, compliance, and identity
  35. 185.A software development company uses Microsoft Entra ID and wants to ensure that all newly created user accounts and existing accounts are prevented from using weak, easily guessable, or previously compromised passwords. They also want to provide specific custom banned password lists. Which Microsoft Entra capability should they implement?Describe the capabilities of Microsoft Entra
  36. 186.A financial institution requires strict control over administrative roles in Microsoft Entra ID. They want to ensure that privileged roles are assigned only when needed, for a limited time, and with proper approval workflows. Additionally, all activations of these roles must be logged for auditing purposes. Which Microsoft Entra capability is designed to meet these governance requirements?Describe the capabilities of Microsoft Entra
  37. 187.A company is implementing a new security strategy. They want to ensure that all data, whether in transit or at rest, is protected from unauthorized access. Which core security principle is primarily addressed by this objective?Describe the concepts of security, compliance, and identity
  38. 188.A company is implementing Microsoft Entra ID and wants to ensure that all newly created user accounts adhere to a strong password policy, including custom banned passwords specific to their organization. Which Microsoft Entra capability should they use?Describe the capabilities of Microsoft Entra
  39. 189.A manufacturing company needs to manage access to its operational technology (OT) systems from its corporate IT network. They want to ensure that only specific, authorized users can access these sensitive systems and that their access is limited to a defined time window. Additionally, they need to log all access attempts to the OT systems. Which Microsoft Entra capability, when integrated with a jump server or secure access workstation, helps enforce time-bound access and auditing for these highly sensitive resources?Describe the capabilities of Microsoft Entra
  40. 190.A healthcare organization uses Microsoft Entra ID and is subject to strict regulatory compliance. They need to demonstrate that access to sensitive patient data applications is regularly reviewed and that users who no longer require access have their permissions revoked. The reviews should be recurring and generate audit trails. Which Microsoft Entra governance capability is best suited for this task?Describe the capabilities of Microsoft Entra
  41. 191.A financial institution is implementing a new system for managing customer accounts. They want to ensure that only authorized personnel can view sensitive financial data, even if the data is stolen or accidentally exposed. Which security concept is this scenario primarily addressing?Describe the concepts of security, compliance, and identity
  42. 192.A finance department uses a critical application that processes daily transactions. It is imperative that these transactions are not altered or corrupted during processing or storage. Which core security principle is most directly concerned with preventing such unauthorized modification?Describe the concepts of security, compliance, and identity
  43. 193.An organization is migrating its applications to a cloud environment. They need a mechanism for these cloud applications to securely access other cloud resources (e.g., storage accounts, databases) without embedding credentials directly in the application code. This mechanism should manage identity automatically for the application. Which type of identity should they use?Describe the concepts of security, compliance, and identity
  44. 194.A company is migrating its on-premises applications to Azure. They want to ensure that these applications can securely access other Azure resources (like storage accounts or databases) without needing to store credentials directly in their code or configuration files. Which Azure identity concept should they use?Describe the concepts of security, compliance, and identity
  45. 195.A company is implementing a Zero Trust security model. They want to ensure that all access requests are evaluated against user identity, location, device health, and application sensitivity in real-time, and then enforce appropriate access controls like MFA or blocking access. Which Microsoft Entra capability is best suited for this dynamic policy enforcement?Describe the capabilities of Microsoft Entra
  46. 196.A company is implementing a new security policy. They want to ensure that all actions performed by users and systems are recorded and can be traced back to the responsible entity. Which security concept are they primarily focusing on?Describe the concepts of security, compliance, and identity
  47. 197.A multinational corporation uses several cloud-based applications, some hosted in Azure, others by third-party providers. They need a system where employees can use their corporate credentials to access all these applications without re-entering their username and password for each. Which identity concept is best suited for this scenario?Describe the concepts of security, compliance, and identity
  48. 198.A software development team is building an application that needs to securely access resources in Azure, such as Azure Key Vault and Azure Storage. The team wants to avoid hardcoding credentials in their application code or configuration files. They are looking for a solution that allows their application to authenticate to Azure AD and access resources without managing secrets directly. Which identity concept should they use?Describe the concepts of security, compliance, and identity
  49. 199.A startup is rapidly expanding and needs to manage user identities and access for its customer-facing web and mobile applications. They require a scalable solution that allows customers to register, sign in using social identities (e.g., Google, Facebook), and manage their own profiles. Which Microsoft Entra capability is designed for this type of customer identity and access management (CIAM)?Describe the capabilities of Microsoft Entra
  50. 200.A multinational corporation uses Microsoft Entra ID and wants to ensure that all access to sensitive applications is conditional based on factors such as user location, device compliance, and sign-in risk. If a user attempts to access a sensitive application from an untrusted location or an uncompliant device, access should be blocked or require multifactor authentication. Which Microsoft Entra capability allows for this granular access control?Describe the capabilities of Microsoft Entra