Free SC-900 Capabilities of Microsoft Identity Questions and Answers — Questions and Answers
Question 1: What feature in Microsoft Defender for Endpoint provides the first line of defense against cyberthreats by reducing the attack surface?
- automated remediation
- automated investigation
- advanced hunting
- network protection (Correct answer)
Correct answer: network protection
Network protection in Microsoft Defender for Endpoint serves as a crucial first line of defense against cyberthreats by reducing the attack surface. It prevents users from accessing dangerous domains that might host phishing scams, exploits, and other malicious content. By blocking access to untrusted URLs, it significantly mitigates the risk of web-based attacks.
Question 2: Which two types of resources can be protected by using Azure Firewall? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
- Azure virtual machines
- Azure Active Directory (Azure AD) users
- Microsoft Exchange Online inboxes
- Azure virtual networks (Correct answer)
- Microsoft SharePoint Online sites (Correct answer)
Correct answer: Azure virtual networks
Azure Firewall is a cloud-native, intelligent network firewall security service that provides threat protection for your cloud workloads. It can protect Azure virtual networks by filtering traffic to and from virtual machines and subnets. Additionally, Azure Firewall can be used to filter outbound traffic from Azure resources to internet destinations, including Microsoft SharePoint Online sites, to ensure secure access and prevent data exfiltration.
Question 3: You plan to implement a security strategy and place multiple layers of defense throughout a network infrastructure. Which security methodology does this represent?
- threat modeling
- identity as the security perimeter
- defense in depth (Correct answer)
- the shared responsibility model
Correct answer: defense in depth
Defense in depth is a security methodology that employs multiple, overlapping layers of security controls throughout an IT infrastructure. The principle is that if one security layer fails, another layer will still be in place to provide protection. This approach creates a robust and resilient security posture, making it significantly more difficult for attackers to breach the entire system.
Question 4: What can you use to scan email attachments and forward the attachments to recipients only if the attachments are free from malware?
- Microsoft Defender for Office 365 (Correct answer)
- Microsoft Defender Antivirus
- Microsoft Defender for Identity
- Microsoft Defender for Endpoint
Correct answer: Microsoft Defender for Office 365
Microsoft Defender for Office 365 provides advanced protection against sophisticated threats like phishing, business email compromise, and malware in email attachments. Its Safe Attachments feature scans email attachments in a sandbox environment before they reach the recipient's inbox. This ensures that only malware-free attachments are delivered, effectively protecting users from malicious content.
Question 5: Which feature provides the extended detection and response (XDR) capability of Azure Sentinel?
- integration with the Microsoft 365 compliance center
- support for threat hunting
- integration with Microsoft 365 Defender (Correct answer)
- support for Azure Monitor Workbooks
Correct answer: integration with Microsoft 365 Defender
Azure Sentinel (now Microsoft Sentinel) provides extended detection and response (XDR) capabilities through its deep integration with Microsoft 365 Defender. This integration allows Sentinel to ingest security data from endpoints, identities, email, and applications across the Microsoft 365 ecosystem. This unified view enables comprehensive threat detection, investigation, and automated response across the entire digital estate.
What feature in Microsoft Defender for Endpoint provides the first line of defense against cyberthreats by reducing the attack surface?