Microsoft Certification Microsoft Security Fundamentals (SC-900) 2 — Questions and Answers
Question 1: What does Microsoft Defender for Endpoint protect?
- Azure databases
- Windows and other OS devices against advanced threats using behavioral analysis and threat intelligence (Correct answer)
- Email inboxes from phishing
- Network perimeter firewalls
Correct answer: Windows and other OS devices against advanced threats using behavioral analysis and threat intelligence
Microsoft Defender for Endpoint is an enterprise endpoint detection and response (EDR) platform that protects devices against malware, ransomware, and advanced persistent threats.
Question 2: What is phishing in the context of cybersecurity?
- A network scanning technique
- A social engineering attack where attackers impersonate trusted entities to steal credentials or data (Correct answer)
- A type of encryption algorithm
- A method for testing firewall rules
Correct answer: A social engineering attack where attackers impersonate trusted entities to steal credentials or data
Phishing involves deceptive emails, messages, or websites that impersonate legitimate organizations to trick users into revealing credentials or downloading malware.
Question 3: What is the purpose of Azure Defender for Cloud (formerly Security Center)?
- Storing security log archives
- Providing unified security management and advanced threat protection across hybrid cloud workloads (Correct answer)
- Managing SSL certificates
- Encrypting Azure Blob Storage
Correct answer: Providing unified security management and advanced threat protection across hybrid cloud workloads
Microsoft Defender for Cloud continuously assesses the security posture of Azure and hybrid resources, providing threat protection and actionable security recommendations.
Question 4: What does DDoS (Distributed Denial of Service) attack attempt to do?
- Steal user credentials by brute force
- Overwhelm a service with traffic from many sources to make it unavailable to legitimate users (Correct answer)
- Encrypt files and demand ransom
- Intercept network communications
Correct answer: Overwhelm a service with traffic from many sources to make it unavailable to legitimate users
DDoS attacks flood a target service with massive amounts of traffic from many compromised systems simultaneously, exhausting resources and causing outages.
Question 5: Which Microsoft solution provides Privileged Identity Management (PIM) for just-in-time admin access?
- Microsoft Sentinel
- Microsoft Entra Privileged Identity Management (Correct answer)
- Azure Key Vault
- Microsoft Defender for Cloud Apps
Correct answer: Microsoft Entra Privileged Identity Management
Microsoft Entra PIM provides just-in-time privileged access to Azure AD roles, requiring approval and time-limiting elevated access to reduce standing admin exposure.
Question 6: What is ransomware?
- Software that optimizes CPU performance
- Malware that encrypts victim files and demands payment for the decryption key (Correct answer)
- A type of network protocol
- A vulnerability scanner tool
Correct answer: Malware that encrypts victim files and demands payment for the decryption key
Ransomware is malicious software that encrypts a victim's files or systems and demands a ransom payment in exchange for the decryption key.
What does Microsoft Defender for Endpoint protect?