Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice questions

310 free questions with answers and explanations.

Practice test
  1. 251.A security engineer is tasked with implementing a solution to protect an organization's Azure resources from common web-based attacks such as SQL injection and cross-site scripting. The solution must be easily deployable and scalable within Azure. Which Azure security capability should the engineer choose?Describe the capabilities of Microsoft Security solutions
  2. 252.A small business uses Azure Active Directory (Azure AD) as its primary identity provider. They are concerned about account compromise due to weak passwords, brute-force attacks, and suspicious sign-in attempts from unusual locations. They need a solution that can automatically detect these identity-based risks and enforce adaptive policies like multi-factor authentication (MFA) or password resets to protect user accounts. Which Azure security service provides these capabilities?Describe the capabilities of Microsoft Security solutions
  3. 253.A company needs to implement a solution that provides advanced threat protection for its Microsoft 365 services, including email, SharePoint, OneDrive, and Microsoft Teams. This solution should detect sophisticated phishing attacks, malware, and zero-day threats across these collaboration tools. Which Microsoft 365 Defender component offers these capabilities?Describe the capabilities of Microsoft Security solutions
  4. 254.A financial institution needs to monitor and control how sensitive data is used within sanctioned cloud applications (e.g., Microsoft 365, Salesforce) and identify unsanctioned 'shadow IT' applications. They also need to enforce data loss prevention (DLP) policies for data in these cloud apps. Which Microsoft security solution provides these capabilities?Describe the capabilities of Microsoft Security solutions
  5. 255.A security engineer is tasked with implementing a solution to protect an organization's Azure-hosted web applications from common web-based attacks, such as SQL injection, cross-site scripting, and other OWASP Top 10 vulnerabilities. The solution must integrate seamlessly with Azure Application Gateway. Which Azure security solution should be deployed?Describe the capabilities of Microsoft Security solutions
  6. 256.A small business uses Microsoft 365 and wants to ensure that all administrative actions within their tenant are recorded and auditable for compliance purposes. Which Microsoft 365 Defender capability provides this functionality?Describe the capabilities of Microsoft Security solutions
  7. 257.A company is concerned about insider threats and compromised user accounts. They need a solution that can detect suspicious user behavior, such as impossible travel, sign-ins from unfamiliar locations, and brute-force attacks, and automatically respond to these risks. Which Azure Active Directory capability should they leverage?Describe the capabilities of Microsoft Security solutions
  8. 258.A security operations center (SOC) team needs a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution to collect security data from various sources, detect threats using AI, and automate incident response workflows. Which Azure security service meets these requirements?Describe the capabilities of Microsoft Security solutions
  9. 259.A large university relies heavily on Microsoft Teams and SharePoint for collaboration among faculty and students. They need to ensure that sensitive research data shared within these platforms is protected from accidental leakage or unauthorized access. The solution must identify, classify, and protect sensitive information across these collaboration services. Which Microsoft security solution is best suited for this task?Describe the capabilities of Microsoft Security solutions
  10. 260.A global enterprise needs to manage and secure all corporate-owned and employee-owned mobile devices, including smartphones and tablets, to ensure compliance with company policies and protect sensitive data. Which Microsoft solution should they use?Describe the capabilities of Microsoft Security solutions
  11. 261.A cybersecurity analyst is responsible for monitoring security events across their organization's entire digital estate, including on-premises servers, Azure virtual machines, Microsoft 365 services, and third-party cloud applications. They need a solution that can collect security data from various sources, perform advanced threat detection using AI and machine learning, and automate responses to incidents. Which Microsoft security solution would be most effective for this scenario?Describe the capabilities of Microsoft Security solutions
  12. 262.An organization wants to implement a solution to monitor and analyze security telemetry from their Azure environment, including virtual machines, storage accounts, and network activity. They need to detect advanced threats and anomalies using machine learning and behavioral analytics. Which Azure service is specifically designed for this purpose?Describe the capabilities of Microsoft Security solutions
  13. 263.A global enterprise uses Microsoft 365 for its productivity suite and has a hybrid cloud environment with resources in Azure and on-premises. The security team needs a unified solution to manage device compliance, deploy applications, and enforce security policies across all corporate-owned and personal devices, regardless of their location. Which Microsoft security solution best meets these requirements?Describe the capabilities of Microsoft Security solutions
  14. 264.A security administrator needs to protect all user identities within Azure Active Directory from advanced attacks such as password spray, impossible travel, and malware-linked IP addresses. The solution must also provide automated remediation actions like forcing password resets or blocking sign-ins for risky users. Which Azure AD capability provides this protection?Describe the capabilities of Microsoft Security solutions
  15. 265.A software development company uses Azure DevOps for its continuous integration/continuous deployment (CI/CD) pipelines. They want to ensure that their cloud-native applications are secure throughout their lifecycle, from code to production. They need a solution that can scan container images for vulnerabilities, protect Kubernetes clusters, and monitor serverless functions. Which Microsoft security solution provides these 'DevSecOps' capabilities for cloud-native applications?Describe the capabilities of Microsoft Security solutions
  16. 266.A global enterprise needs to manage and secure all corporate-owned and employee-owned mobile devices (smartphones, tablets) and applications. They require capabilities to enforce device compliance, deploy applications, and remotely wipe devices if lost or stolen. Which Microsoft security solution is designed for this comprehensive endpoint management?Describe the capabilities of Microsoft Security solutions
  17. 267.A company is implementing a new security strategy and needs a solution to provide centralized security information and event management (SIEM) across all their Azure resources and on-premises infrastructure. This solution must offer advanced threat detection, intelligent analytics, and automated responses. Which Microsoft security solution should they choose?Describe the capabilities of Microsoft Security solutions
  18. 268.A global enterprise requires a solution to centrally manage security policies and applications on all their corporate-owned and personal mobile devices (BYOD), including Windows laptops, macOS, iOS, and Android devices. The solution must ensure compliance and data protection across these diverse platforms. Which Microsoft security solution should they implement?Describe the capabilities of Microsoft Security solutions
  19. 269.A software development company uses Azure DevOps for its continuous integration/continuous deployment (CI/CD) pipelines and deploys applications as containers to Azure Kubernetes Service (AKS). They need a solution to scan container images for vulnerabilities, monitor runtime threats in AKS, and enforce security best practices across their containerized workloads. Which Microsoft security solution should they leverage?Describe the capabilities of Microsoft Security solutions
  20. 270.A small non-profit organization is moving its website and donor database to Azure. They have a limited budget but need to ensure their web applications are protected against common web-based attacks like SQL injection and cross-site scripting. Which Azure security service should they prioritize for this purpose?Describe the capabilities of Microsoft Security solutions
  21. 271.A company is migrating its on-premises SQL databases to Azure SQL Database. They need a solution that provides advanced threat detection capabilities for these databases, such as identifying unusual database access patterns, SQL injection attacks, and potential data exfiltration attempts. Which Azure security solution should they enable?Describe the capabilities of Microsoft Security solutions
  22. 272.A company needs to protect its web applications hosted on Azure App Service from common web-based attacks such as SQL injection, cross-site scripting, and other OWASP Top 10 vulnerabilities. They require a solution that filters traffic before it reaches the application, without modifying the application code. Which Azure security solution should they implement?Describe the capabilities of Microsoft Security solutions
  23. 273.A company is migrating various production workloads to Azure, including virtual machines, containers, and serverless functions. They need a unified security management system that provides continuous security posture management, vulnerability assessment, and threat protection across these diverse Azure workloads. The solution should also offer security recommendations based on industry benchmarks. Which Microsoft security service is designed for this comprehensive cloud security management?Describe the capabilities of Microsoft Security solutions
  24. 274.A company is implementing a new security strategy and needs a solution to continuously assess the security posture of its Azure and on-premises resources, provide security recommendations, and identify potential vulnerabilities. Which Microsoft security solution should they use?Describe the capabilities of Microsoft Security solutions
  25. 275.A company wants to assess its overall security posture across its Azure subscriptions, identify misconfigurations, and get actionable recommendations to improve its security score. They need a centralized view of security recommendations for virtual machines, databases, storage accounts, and network resources. Which Microsoft security solution provides this capability?Describe the capabilities of Microsoft Security solutions
  26. 276.A security administrator needs to protect Microsoft 365 services, including email, documents, and identities, from sophisticated cyberattacks. The solution must offer extended detection and response (XDR) capabilities across these services. Which Microsoft solution is best suited for this requirement?Describe the capabilities of Microsoft Security solutions
  27. 277.A development team uses Azure DevOps for its continuous integration/continuous deployment (CI/CD) pipelines. They need to ensure that container images are scanned for vulnerabilities before deployment to Azure Kubernetes Service (AKS). Which capability of Microsoft Defender for Cloud can provide this specific protection?Describe the capabilities of Microsoft Security solutions
  28. 278.A security operations center (SOC) team needs to automate their incident response playbooks for common security alerts detected by Microsoft Sentinel. They want to integrate Sentinel with other security tools and services to streamline remediation actions. Which Microsoft Sentinel capability enables this automation and orchestration?Describe the capabilities of Microsoft Security solutions
  29. 279.A security analyst is investigating a suspicious activity report involving a user's workstation. They need to quickly identify if the workstation has been compromised, isolate it from the network, and remediate any detected threats. Which component of Microsoft 365 Defender provides these advanced endpoint detection and response (EDR) capabilities?Describe the capabilities of Microsoft Security solutions
  30. 280.A compliance officer needs to ensure that all email communications within their Microsoft 365 environment are protected from advanced threats like phishing, spoofing, and business email compromise (BEC). They also require capabilities for safe attachments and safe links. Which Microsoft 365 Defender component provides these specific protections?Describe the capabilities of Microsoft Security solutions
  31. 281.A manufacturing company operates a large fleet of IoT devices on its factory floor, including sensors, robotic arms, and automated vehicles. They need to secure these devices from cyber threats, monitor their behavior for anomalies, and ensure their operational integrity. Which Microsoft security solution is specifically designed to provide comprehensive security for IoT devices?Describe the capabilities of Microsoft Security solutions
  32. 282.A compliance officer needs to ensure that all email communications within their Microsoft 365 environment are protected against sophisticated phishing attacks, business email compromise (BEC), and zero-day malware. They require advanced capabilities like impersonation detection, URL sandboxing, and attachment scanning before delivery. Which Microsoft 365 Defender service should be configured?Describe the capabilities of Microsoft Security solutions
  33. 283.A software development team uses Azure DevOps to manage their containerized applications, which are deployed to Azure Kubernetes Service (AKS). They need a security solution that can scan container images for vulnerabilities, monitor running containers for suspicious activity, and provide runtime protection. Which Microsoft security solution is best suited for this?Describe the capabilities of Microsoft Security solutions
  34. 284.A security operations center (SOC) team needs to automate their response to common security incidents, such as blocking IP addresses or isolating compromised devices, based on alerts generated by their security information and event management (SIEM) system. Which Microsoft security solution provides this automation capability?Describe the capabilities of Microsoft Security solutions
  35. 285.A financial institution is implementing a new data governance strategy. They need to categorize sensitive data (e.g., credit card numbers, personal identifiable information), encrypt it, and apply retention labels across various Microsoft 365 services, including SharePoint Online, OneDrive, and Exchange Online. Which Microsoft security solution provides these capabilities?Describe the capabilities of Microsoft Security solutions
  36. 286.A security operations center (SOC) team needs to streamline their threat response by automating repetitive tasks, such as blocking malicious IPs, isolating infected devices, and enriching incident data, directly from alerts generated by Microsoft 365 Defender and Microsoft Sentinel. Which capability within Microsoft Sentinel is designed for this automation?Describe the capabilities of Microsoft Security solutions
  37. 287.A security administrator needs to protect all user identities within Azure Active Directory from compromise, including detecting suspicious sign-ins, risky user behavior, and providing automated remediation actions like blocking access or requiring multi-factor authentication (MFA). Which Azure security solution should be configured?Describe the capabilities of Microsoft Security solutions
  38. 288.A large enterprise needs to ensure that all email communications are protected from phishing, spam, and malware, and that sensitive information is not accidentally leaked. They require a solution that can filter email, identify advanced threats, and help enforce data loss prevention (DLP) policies for email content. Which Microsoft 365 Defender component should be configured?Describe the capabilities of Microsoft Security solutions
  39. 289.A security administrator needs to protect all user identities within Azure Active Directory (Azure AD) from compromised credentials, brute-force attacks, and suspicious sign-in activities. They want to set up policies that automatically block or challenge users based on risk levels. Which Microsoft security solution provides these capabilities?Describe the capabilities of Microsoft Security solutions
  40. 290.A global conglomerate uses a hybrid cloud environment, including Azure, AWS, and on-premises servers. They need a unified security information and event management (SIEM) solution that can ingest security logs from all these sources, perform threat detection, and automate incident response. Which Microsoft security solution is best suited for this requirement?Describe the capabilities of Microsoft Security solutions
  41. 291.A security auditor needs to gain a comprehensive overview of the security posture of an organization's Azure subscriptions, identify misconfigurations, and receive actionable recommendations to improve security. The auditor also requires a 'secure score' to track progress over time. Which basic security capability in Azure provides this centralized view and guidance?Describe the capabilities of Microsoft Security solutions
  42. 292.A company is migrating its on-premises virtual machines to Azure. They need a solution that can automatically discover vulnerabilities, recommend security configurations, and provide a secure score for their Azure and hybrid cloud workloads. Which Microsoft security solution provides these capabilities?Describe the capabilities of Microsoft Security solutions
  43. 293.A financial institution is concerned about sensitive data exfiltration from cloud applications, unauthorized access to corporate resources by third-party apps, and shadow IT. They need a solution that provides deep visibility into cloud app usage, real-time threat detection, and granular control over data. Which Microsoft security solution is best suited to address these concerns?Describe the capabilities of Microsoft Security solutions
  44. 294.A security auditor needs to gain a comprehensive overview of the security posture of an organization's Azure subscriptions, identify misconfigurations, and receive actionable recommendations without incurring additional costs for advanced threat protection features. Which tier of Microsoft Defender for Cloud should be utilized?Describe the capabilities of Microsoft Security solutions
  45. 295.A global corporation requires a solution to centrally manage security policies and applications on all corporate-owned mobile devices (smartphones, tablets) and employee-owned devices (BYOD) accessing corporate resources. The solution must ensure data protection on these devices. Which Microsoft security solution is best suited for this requirement?Describe the capabilities of Microsoft Security solutions
  46. 296.A company is migrating its on-premises virtual machines to Azure. They need a basic level of security for these VMs, including vulnerability assessments, just-in-time VM access, and adaptive network hardening. Which foundational Azure security service provides these capabilities for their virtual machines?Describe the capabilities of Microsoft Security solutions
  47. 297.A small non-profit organization wants to implement a basic, cost-effective security solution to protect its Azure virtual machines (VMs) from common threats, such as malware and suspicious activities. They need file integrity monitoring and just-in-time VM access but have a limited budget. Which capability of Microsoft Defender for Cloud should they enable?Describe the capabilities of Microsoft Security solutions
  48. 298.A financial institution needs to monitor and control how sensitive data is used within sanctioned and unsanctioned cloud applications (SaaS, PaaS, IaaS) to prevent data loss and ensure compliance. They require visibility into user activities, data governance, and threat protection across these cloud services. Which Microsoft security solution is designed for this Cloud Access Security Broker (CASB) functionality?Describe the capabilities of Microsoft Security solutions
  49. 299.An organization needs to monitor and protect its Internet of Things (IoT) devices from cyber threats. These devices range from sensors in a smart factory to connected medical equipment. Which Microsoft security solution is designed for this specific purpose?Describe the capabilities of Microsoft Security solutions
  50. 300.A manufacturing company uses a large number of operational technology (OT) devices and industrial control systems (ICS) on its factory floor. They need to monitor these devices for vulnerabilities, detect anomalies, and protect them from cyber threats without impacting their critical operations. Which Microsoft security solution is designed for this specialized environment?Describe the capabilities of Microsoft Security solutions