Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityEasy

A large enterprise is migrating its on-premises Active Directory to a cloud-based identity solution. They need a service that allows them to centrally manage user accounts, groups, and devices, and provides authentication and authorization services for applications both in the cloud and on-premises. Which type of service is best suited for this requirement?

  1. AData Loss Prevention (DLP)
  2. BCloud Access Security Broker (CASB)
  3. CSecurity Information and Event Management (SIEM)
  4. DIdentity and Access Management (IAM)
Show answer & explanation

Correct answer: D. Identity and Access Management (IAM)

Identity and Access Management (IAM) systems are designed to manage digital identities and control access to resources. This includes user provisioning, authentication, authorization, and directory services, perfectly matching the scenario's requirements for central management of users, groups, devices, and access services.

Why the other options are wrong

  • A. DLP prevents sensitive data from leaving the organization, unrelated to identity management.
  • B. CASB focuses on monitoring and securing access to cloud applications, not core identity management.
  • C. SIEM focuses on collecting and analyzing security logs, not identity management.

Identity and Access Management (IAM)

A framework of policies and technologies for ensuring that the right individuals and things have the right access to the right resources at the right time and for the right reasons.

  • Manages user identities and their access privileges.
  • Includes authentication, authorization, and user lifecycle management.
  • Central to modern security strategies.

Memory trick: IAM is the bouncer and guest list for all digital parties.

More Describe the concepts of security, compliance, and identity questions