SC-900 Microsoft Security, Compliance, and Identity Fundamentals Certification Exam — Questions and Answers
Question 1: What term describes the use of unauthorized or unapproved cloud applications within an organization that Defender for Cloud Apps helps identify?
- Dark Web
- Shadow IT (Correct answer)
- Rogue Apps
- Unsecured APIs
Correct answer: Shadow IT
Shadow IT refers to cloud apps and services used by employees without IT department knowledge or approval, which Cloud Discovery helps uncover.
Question 2: Employees are allowed to bring and use their cell phones at work. The employees don't want their phone to be under full corporate control, but admins want to allow users to read emails and use Teams while protecting corporate data. Which of the following will allow admins to accomplish these goals?
- Mobile Device Management (MDM).
- Mobile Application Management (MAM). (Correct answer)
- Role-based access control (RBAC).
Correct answer: Mobile Application Management (MAM).
Mobile Application Management (MAM) allows organizations to manage and protect corporate data within specific applications, without requiring full device enrollment or control. This is ideal for Bring Your Own Device (BYOD) scenarios where users want personal privacy but corporate data needs protection. MAM policies can enforce data encryption, prevent copy/paste of corporate data, and selectively wipe corporate data from apps.
Question 3: Which of the following tools helps you to strengthen your cloud security posture?
- Azure Security Centre (Correct answer)
- Azure Defender
- Azure Sentinel
- Microsoft 365 Defender
Correct answer: Azure Security Centre
Azure Security Center (now Microsoft Defender for Cloud) is a unified infrastructure security management system that strengthens the security posture of your cloud workloads. It provides tools to assess vulnerabilities, monitor security configurations, and receive actionable recommendations to improve your security score. This helps organizations proactively identify and remediate security weaknesses across their cloud environment.
Question 4: Which edition of the Azure active directory gives you Privileged Identity Management to help discover, restrict, and monitor administrators?
- Office 365
- Premium P1
- Free
- Premium P2 (Correct answer)
Correct answer: Premium P2
Azure Active Directory Premium P2 is the edition that includes advanced identity protection capabilities, such as Azure AD Privileged Identity Management (PIM). PIM allows organizations to discover, restrict, and monitor administrators, and provide just-in-time access to resources. This robust feature set is essential for managing and securing privileged access effectively within an organization.
Question 5: A user applies a 'General' sensitivity label to an email. Later, they add confidential project details and the system recommends changing the label to 'Confidential'. What is this an example of?
- Automatic labeling
- Recommended labeling (Correct answer)
- Default labeling
- Mandatory labeling
Correct answer: Recommended labeling
Recommended labeling is a feature where the system detects sensitive content and suggests that the user apply a more appropriate sensitivity label. This helps guide users to make the correct classification decision without forcing it on them automatically.
Question 6: Scenario: An organization migrates its infrastructure to Azure cloud services and needs to maintain compliance with industry standards. What tool should they utilize to continuously monitor and assess compliance?
- Azure AD Identity Protection
- Azure Sentinel
- Azure Security Center (Correct answer)
- Azure Policy
Correct answer: Azure Security Center
Azure Security Center (now part of Microsoft Defender for Cloud) provides unified security management and advanced threat protection across hybrid cloud workloads. It continuously monitors and assesses compliance against industry standards and regulatory requirements. This includes providing recommendations, security scores, and regulatory compliance dashboards to help organizations maintain their security posture and report on it.
Question 7: Which Microsoft Defender for Endpoint capability is designed to discover, prioritize, and remediate software vulnerabilities and misconfigurations on devices?
- Threat & Vulnerability Management (Correct answer)
- Automated Investigation and Remediation (AIR)
- Endpoint Detection and Response (EDR)
- Attack Surface Reduction (ASR)
Correct answer: Threat & Vulnerability Management
Threat & Vulnerability Management provides a risk-based approach to the discovery, prioritization, and remediation of endpoint vulnerabilities and misconfigurations. It helps organizations reduce their overall exposure to threats.
Question 8: Scenario: A company is enhancing security measures to prevent unauthorized access to critical systems. Which authentication method should they employ to require multiple forms of verification?
- Azure Active Directory (AAD)
- Single Sign-On (SSO)
- Multi-factor authentication (MFA) (Correct answer)
- Biometric authentication
Correct answer: Multi-factor authentication (MFA)
Multi-factor authentication (MFA) significantly enhances security by requiring users to provide two or more distinct forms of verification to gain access. This typically combines something they know (like a password) with something they have (like a phone or token) or something they are (like a fingerprint). By adding multiple layers, MFA drastically reduces the risk of unauthorized access, even if one factor is compromised.
Question 9: What is the purpose of the secure score in Microsoft Defender for Cloud?
- To calculate the monthly cost of your Azure security services.
- To count the number of active threats detected in the last 24 hours.
- To assign a risk level to individual users based on their sign-in activity.
- To measure and track the security posture of your cloud environment. (Correct answer)
Correct answer: To measure and track the security posture of your cloud environment.
The secure score is a numerical representation of your security posture. It is calculated based on security recommendations, and implementing these recommendations improves the score, helping you to track and prioritize security hardening efforts.
Question 10: Which Defender for Cloud Apps capability helps detect when a user account may have been compromised by analyzing impossible travel scenarios?
- App Risk Scoring
- Conditional Access App Control
- Anomaly Detection — Impossible Travel (Correct answer)
- Cloud Discovery
Correct answer: Anomaly Detection — Impossible Travel
The Impossible Travel anomaly detection policy identifies when a user logs in from two geographically distant locations within a timeframe that makes physical travel impossible, suggesting account compromise.
Question 11: What type of security solution is Microsoft Defender for Cloud Apps primarily classified as?
- Cloud Access Security Broker (CASB) (Correct answer)
- Security Orchestration Automated Response (SOAR)
- Security Information and Event Management (SIEM)
- Extended Detection and Response (XDR)
Correct answer: Cloud Access Security Broker (CASB)
Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides visibility, data control, and threat protection for cloud apps.
Question 12: Scenario: A financial institution must regularly provide reports to regulators regarding data access and security. What Azure service can assist in generating compliance reports?
- Azure Policy
- Azure Security Center (Correct answer)
- Azure Information Protection (AIP)
- Azure Monitor
Correct answer: Azure Security Center
Azure Security Center (now Microsoft Defender for Cloud) offers robust capabilities for monitoring security posture and compliance. It includes a regulatory compliance dashboard that maps an organization's compliance against various standards and regulations. This service can generate reports on data access, security events, and compliance status, which are essential for regulatory reporting requirements.
Question 13: In Microsoft Sentinel, what component, powered by Azure Logic Apps, is used to automate responses to security alerts?
- Workbooks
- Playbooks (Correct answer)
- Data connectors
- Hunting queries
Correct answer: Playbooks
Playbooks in Microsoft Sentinel are collections of procedures that can be run automatically in response to an alert. They are built on Azure Logic Apps, allowing for complex, automated workflows that can interact with various services to contain and remediate threats.
Question 14: An organization wants to ensure that all documents containing a passport number are automatically labeled as 'Highly Confidential'. What feature enables this?
- Automatic sensitivity labeling policies (Correct answer)
- Data Loss Prevention (DLP) policy actions
- Manual labeling by users
- Conditional Access policies
Correct answer: Automatic sensitivity labeling policies
Microsoft Purview Information Protection allows for automatic application of sensitivity labels. Policies can be configured to detect specific sensitive information types, like passport numbers, and then automatically apply the appropriate label without user intervention.
Question 15: You plan to implement a security strategy and place multiple layers of defense throughout a network infrastructure. Which security methodology does this represent?
- the shared responsibility model
- threat modeling
- defense in depth (Correct answer)
- identity as the security perimeter
Correct answer: defense in depth
Defense in depth is a security methodology that employs multiple, overlapping layers of security controls throughout an IT infrastructure. The principle is that if one security layer fails, another layer will still be in place to provide protection. This approach creates a robust and resilient security posture, making it significantly more difficult for attackers to breach the entire system.
Question 16: Which action can an administrator take in Microsoft Defender for Cloud Apps to prevent users from accessing a specific cloud application deemed risky?
- Mark the app as 'Unsanctioned' (Correct answer)
- Set the app status to 'Pending Review'
- Archive the app in the catalog
- Mark the app as 'Monitored'
Correct answer: Mark the app as 'Unsanctioned'
Marking an app as 'Unsanctioned' in Defender for Cloud Apps can block access to it, especially when integrated with firewall or proxy solutions.
Question 17: What is the primary purpose of applying a sensitivity label to a document or email?
- To scan the content for malware
- To classify and apply protection settings to the content (Correct answer)
- To archive the content automatically
- To share the content with external users
Correct answer: To classify and apply protection settings to the content
The core function of a sensitivity label is to classify data based on its sensitivity. Once classified, the label can then apply protection settings, such as encryption or content marking, to enforce policies and protect the information.
Question 18: What does a 'File Policy' in Microsoft Defender for Cloud Apps allow an organization to do?
- Scan files stored in connected cloud apps and apply governance actions based on content (Correct answer)
- Encrypt files before they are uploaded to any cloud service
- Automatically delete files older than 90 days
- Block all file sharing within Microsoft Teams
Correct answer: Scan files stored in connected cloud apps and apply governance actions based on content
File Policies scan files stored in connected cloud apps for sensitive content (such as PII or credit card numbers) and can trigger actions like quarantine, remove sharing, or apply labels.
Question 19: What is the term for a group of related alerts in Microsoft Sentinel that are aggregated to represent a potential security attack?
- A Workbook
- An Event
- A Playbook
- An Incident (Correct answer)
Correct answer: An Incident
Microsoft Sentinel uses fusion technology and analytics rules to correlate millions of low-fidelity alerts into a manageable number of high-fidelity incidents. An incident is a collection of related alerts that, together, form an actionable attack story.
Question 20: Which component of Microsoft Defender for Endpoint uses cloud-based machine learning, behavior analysis, and heuristics to provide real-time malware protection?
- Next-generation protection (Correct answer)
- Endpoint Detection and Response (EDR)
- Attack Surface Reduction (ASR)
- Threat & Vulnerability Management
Correct answer: Next-generation protection
Next-generation protection is the real-time antivirus and antimalware component of Defender for Endpoint. It goes beyond traditional signature-based detection, using advanced cloud-powered techniques to block new and emerging threats.
Question 21: Which two types of resources can be protected by using Azure Firewall? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
- Microsoft Exchange Online inboxes
- Azure Active Directory (Azure AD) users
- Microsoft SharePoint Online sites (Correct answer)
- Azure virtual machines
- Azure virtual networks (Correct answer)
Correct answer: Microsoft SharePoint Online sites
Azure Firewall is a cloud-native, intelligent network firewall security service that provides threat protection for your cloud workloads. It can protect Azure virtual networks by filtering traffic to and from virtual machines and subnets. Additionally, Azure Firewall can be used to filter outbound traffic from Azure resources to internet destinations, including Microsoft SharePoint Online sites, to ensure secure access and prevent data exfiltration.
Question 22: Insider Risk Management relies on signals from various sources to detect risky behavior. Which service is the primary source for user activity signals like 'File downloaded' or 'File shared externally'?
- Azure Active Directory sign-in logs
- Microsoft Defender for Identity security alerts
- Microsoft Intune device compliance reports
- Microsoft 365 unified audit log (Correct answer)
Correct answer: Microsoft 365 unified audit log
Insider Risk Management is built upon the signals captured in the Microsoft 365 unified audit log. This log records a wide range of user and admin activities across services like SharePoint Online, OneDrive for Business, and Exchange Online, which are then analyzed to detect risky patterns.
Question 23: What is the primary benefit of using Microsoft Defender for Cloud Apps 'Governance Actions'?
- Creating backup copies of sensitive files
- Automatically reporting compliance issues to regulators
- Automatically remediating policy violations in connected cloud apps without manual intervention (Correct answer)
- Generating invoices for cloud app usage
Correct answer: Automatically remediating policy violations in connected cloud apps without manual intervention
Governance Actions allow Defender for Cloud Apps to automatically remediate issues — such as revoking sharing permissions, quarantining files, or suspending users — when policies are triggered.
Question 24: When an Insider Risk Management policy generates a high-severity alert, what is the typical next step in the built-in workflow?
- The policy that generated the alert is automatically disabled.
- An email notification is sent directly to the user who triggered the alert.
- The alert is triaged, and an investigator can create a case for deeper analysis. (Correct answer)
- The user's account is automatically suspended.
Correct answer: The alert is triaged, and an investigator can create a case for deeper analysis.
The standard workflow is designed for systematic investigation. An analyst or investigator first reviews (triages) the generated alert. If the alert is deemed credible and requires further action, it is promoted to a case, which allows for in-depth analysis, evidence gathering, and collaboration.
Question 25: Which of the following can be accomplished with the use of the Azure Privileged Identity Management Service?
- Provide just-in-time access to resources roles in Azure (Correct answer)
- Measure Security posture of resources defined in Azure environment
- Enable MFA for the users based on detected sign-in-risks
- Filter traffic to Azure virtual machines
Correct answer: Provide just-in-time access to resources roles in Azure
Azure Privileged Identity Management (PIM) is a service in Azure AD that enables you to manage, control, and monitor access to important resources. A key feature is providing just-in-time (JIT) access, which grants elevated privileges only when needed and for a limited time. This minimizes the exposure time of privileged access, significantly reducing the risk of unauthorized use.
Question 26: What feature in Microsoft Defender for Endpoint provides the first line of defense against cyberthreats by reducing the attack surface?
- automated investigation
- automated remediation
- network protection (Correct answer)
- advanced hunting
Correct answer: network protection
Network protection in Microsoft Defender for Endpoint serves as a crucial first line of defense against cyberthreats by reducing the attack surface. It prevents users from accessing dangerous domains that might host phishing scams, exploits, and other malicious content. By blocking access to untrusted URLs, it significantly mitigates the risk of web-based attacks.
Question 27: What integration does Microsoft Defender for Cloud Apps have with Microsoft Purview Information Protection?
- It replaces Microsoft Purview labels with its own classification system
- It converts cloud app files into encrypted PDFs automatically
- It applies Microsoft Purview sensitivity labels to files stored in cloud apps (Correct answer)
- It blocks all file uploads to cloud apps regardless of sensitivity
Correct answer: It applies Microsoft Purview sensitivity labels to files stored in cloud apps
Defender for Cloud Apps can apply Microsoft Purview Information Protection sensitivity labels to files discovered in connected cloud apps, extending data protection to the cloud.
Question 28: Scenario: A corporation seeks centralized control over user access to applications and resources, including user lifecycle management and access reviews. Which service best suits these needs?
- Microsoft Entra ID (Correct answer)
- Azure Key Vault
- Azure Information Protection (AIP)
- Azure Sentinel
Correct answer: Microsoft Entra ID
Microsoft Entra ID (formerly Azure Active Directory) is a cloud-based identity and access management service that provides centralized control over user access to applications and resources. It includes robust features for user lifecycle management, access reviews, and single sign-on capabilities. This service is ideal for managing user identities and their access permissions across an organization's entire IT environment.
Question 29: Which query language is used to create analytics rules, perform threat hunting, and visualize data in Microsoft Sentinel workbooks?
- Python
- PowerShell
- Kusto Query Language (KQL) (Correct answer)
- SQL
Correct answer: Kusto Query Language (KQL)
Kusto Query Language (KQL) is the language used to query the Log Analytics workspace where all Microsoft Sentinel data is stored. Analysts use KQL to write detection rules, hunt for threats, and build custom visualizations in workbooks.
Question 30: What is the primary goal of Attack Surface Reduction (ASR) rules in Microsoft Defender for Endpoint?
- To investigate and respond to security alerts after they occur.
- To prevent malware from running by blocking common malicious behaviors. (Correct answer)
- To scan for and remove existing malware on a device.
- To provide security recommendations to improve device configuration.
Correct answer: To prevent malware from running by blocking common malicious behaviors.
Attack Surface Reduction (ASR) rules are designed to prevent common attack techniques used by malware. They target specific software behaviors, such as Office apps creating executable content or scripts launching downloaded payloads, to stop attacks at the pre-execution stage.
Question 31: If your organization improves its compliance score from 60% to 75%, what does this change signify?
- The organization has completed more recommended improvement actions. (Correct answer)
- The number of active security alerts has decreased.
- The organization has purchased more Microsoft 365 licenses.
- Microsoft has updated its own internal controls.
Correct answer: The organization has completed more recommended improvement actions.
An increase in the compliance score directly reflects that the organization has successfully implemented more of the recommended improvement actions. This indicates a stronger compliance posture and a reduction in risks associated with data protection and regulatory standards.
Question 32: What are the two primary functions that define Microsoft Sentinel's role in a security operations center?
- Identity and Access Management
- Firewall and Antivirus
- Data Loss Prevention and Information Protection
- SIEM and SOAR (Correct answer)
Correct answer: SIEM and SOAR
Microsoft Sentinel combines Security Information and Event Management (SIEM) for collecting and analyzing security data, and Security Orchestration, Automation, and Response (SOAR) for automating responses to threats. This dual capability allows organizations to both detect and react to security incidents from a single platform.
Question 33: Which of the following measures might an organization implement as part of the defense in-depth security methodology?
- Locating all its servers in a single physical location.
- Multi-factor authentication for all users. (Correct answer)
- Ensuring there's no segmentation of your corporate network.
Correct answer: Multi-factor authentication for all users.
Multi-factor authentication (MFA) is a prime example of a control implemented as part of a defense-in-depth security methodology. By requiring multiple forms of verification, MFA adds an additional, robust layer of security beyond just a password. This makes it significantly harder for unauthorized users to gain access, even if one credential layer is compromised.
Question 34: Match Microsoft 365 insider risk management workflow step to the appropriate task. "Create cases in the Case dashboard"
- Triage
- Action
- Investigate (Correct answer)
Correct answer: Investigate
In the Microsoft 365 insider risk management workflow, 'Create cases in the Case dashboard' falls under the Investigate step. After potential insider risks are identified and triaged, the investigation phase involves creating cases to gather more evidence, analyze activities, and determine the appropriate response. This structured approach helps manage and resolve insider risk incidents effectively.
Question 35: A new admin has joined the team and needs to be able to access the Microsoft 365 Compliance Center. Which of the following roles could the admin use to access the Compliance Center?
- Help desk Administrator role
- User Administrator role
- Compliance Administrator role (Correct answer)
Correct answer: Compliance Administrator role
The Compliance Administrator role in Microsoft 365 is specifically designed to manage compliance features within the Microsoft 365 Compliance Center. Assigning this role grants the necessary permissions to access and manage compliance-related settings, policies, and reports. This ensures the new admin can effectively perform their duties related to organizational compliance.
Question 36: Which log source does Cloud Discovery in Microsoft Defender for Cloud Apps use to identify cloud apps in use?
- Windows event logs
- Active Directory audit logs
- Azure Monitor logs
- Firewall and proxy traffic logs (Correct answer)
Correct answer: Firewall and proxy traffic logs
Cloud Discovery analyzes firewall and proxy traffic logs uploaded by the administrator or streamed automatically to discover cloud app usage across the organization.
Question 37: Scenario: A multinational corporation collects customer data across various countries and needs to ensure compliance with different data protection laws. Which Microsoft service should they use to facilitate compliance with these regulations?
- Microsoft Intune
- Azure Active Directory (AAD)
- Azure Information Protection (AIP) (Correct answer)
- Azure Policy
Correct answer: Azure Information Protection (AIP)
Azure Information Protection (AIP) is designed to classify, label, and protect sensitive data across various platforms and locations. It helps organizations comply with different data protection laws by applying encryption, access restrictions, and persistent protection to information. This ensures data remains secure and compliant, regardless of where it's stored or shared globally.
Question 38: How does Microsoft Purview Compliance Manager help organizations understand their shared compliance responsibilities?
- By automatically implementing all required controls.
- By detailing which controls are managed by Microsoft versus the customer. (Correct answer)
- By providing a list of third-party auditors.
- By assigning all responsibility to the customer.
Correct answer: By detailing which controls are managed by Microsoft versus the customer.
Compliance Manager clearly delineates between actions managed by Microsoft and actions managed by the customer. This helps organizations understand which controls they are responsible for implementing to meet the requirements of a specific regulation or standard.
Question 39: Which feature provides the extended detection and response (XDR) capability of Azure Sentinel?
- integration with the Microsoft 365 compliance center
- support for threat hunting
- integration with Microsoft 365 Defender (Correct answer)
- support for Azure Monitor Workbooks
Correct answer: integration with Microsoft 365 Defender
Azure Sentinel (now Microsoft Sentinel) provides extended detection and response (XDR) capabilities through its deep integration with Microsoft 365 Defender. This integration allows Sentinel to ingest security data from endpoints, identities, email, and applications across the Microsoft 365 ecosystem. This unified view enables comprehensive threat detection, investigation, and automated response across the entire digital estate.
Question 40: Which of the following provides: "an end to end workflow to preserve, collect, analyze, review and export content in MS365"?
- Sensitivity Labels
- Core eDiscovery
- Content Search
- Advanced eDiscovery (Correct answer)
Correct answer: Advanced eDiscovery
Advanced eDiscovery in Microsoft 365 provides an end-to-end workflow for preserving, collecting, analyzing, reviewing, and exporting content in Microsoft 365. It helps organizations efficiently respond to legal matters and internal investigations. This comprehensive solution includes features like custodian management, legal hold, and advanced analytics to streamline the entire eDiscovery process.
Question 41: An administrator enables multi-factor authentication (MFA) for all admin roles as recommended by an improvement action. When should they expect to see the Secure Score increase?
- The score only updates at the beginning of each month.
- Immediately after the change is saved.
- The administrator must manually report the change to update the score.
- The score will update automatically, typically within 24-48 hours. (Correct answer)
Correct answer: The score will update automatically, typically within 24-48 hours.
After an improvement action is implemented, Microsoft's services need time to detect and verify the configuration change. The Secure Score is not updated in real-time; it typically reflects the new, improved security posture within 24 to 48 hours.
Question 42: A security analyst wants to proactively search for new and unknown threats in their organization's data. Which Microsoft Sentinel feature should they use?
- Data Connectors
- Hunting (Correct answer)
- Incidents
- Workbooks
Correct answer: Hunting
Threat hunting is the proactive process of searching for cyber threats that are lurking undetected in a network. Microsoft Sentinel provides powerful search and query tools, including built-in hunting queries, to guide security analysts in this process.
Question 43: What is a key difference between a DLP policy and a sensitivity label?
- DLP policies prevent data exfiltration from locations, while sensitivity labels classify and protect the data itself. (Correct answer)
- DLP policies apply encryption, while sensitivity labels do not.
- There is no difference; they are two names for the same feature.
- Sensitivity labels are for containers only, while DLP is for files.
Correct answer: DLP policies prevent data exfiltration from locations, while sensitivity labels classify and protect the data itself.
While both are part of information protection, their focus is different. Sensitivity labels classify and apply persistent protection (like encryption) to the data itself, wherever it goes. DLP policies focus on the context of data sharing, preventing data exfiltration from specific locations like email or Teams based on rules.
Question 44: Microsoft Defender for Cloud can protect resources in which of the following environments?
- Only Azure and on-premises servers
- Only Microsoft 365 services
- Azure, AWS, Google Cloud, and on-premises (Correct answer)
- Only Azure
Correct answer: Azure, AWS, Google Cloud, and on-premises
Microsoft Defender for Cloud is a multi-cloud and hybrid-cloud solution. It can protect not only Azure resources but also resources running in other cloud providers like AWS and Google Cloud, as well as on-premises servers, by using Azure Arc.
Question 45: What can you use to scan email attachments and forward the attachments to recipients only if the attachments are free from malware?
- Microsoft Defender for Office 365 (Correct answer)
- Microsoft Defender for Identity
- Microsoft Defender Antivirus
- Microsoft Defender for Endpoint
Correct answer: Microsoft Defender for Office 365
Microsoft Defender for Office 365 provides advanced protection against sophisticated threats like phishing, business email compromise, and malware in email attachments. Its Safe Attachments feature scans email attachments in a sandbox environment before they reach the recipient's inbox. This ensures that only malware-free attachments are delivered, effectively protecting users from malicious content.
Question 46: What is the primary purpose of Microsoft Purview Insider Risk Management?
- To discover, classify, and apply sensitivity labels to data at rest.
- To detect, investigate, and act on risky activities by users within the organization. (Correct answer)
- To manage device compliance and enforce configuration policies on endpoints.
- To block external phishing attacks targeting the organization.
Correct answer: To detect, investigate, and act on risky activities by users within the organization.
Insider Risk Management is designed to help organizations minimize internal risks by detecting, investigating, and acting on malicious and inadvertent activities by users. It leverages signals from various Microsoft 365 services to identify potential risks like data theft or security policy violations.
SC-900 Microsoft Security, Compliance, and Identity Fundamentals Certification Exam
The SC-900 exam certifies foundational knowledge of Microsoft security, compliance, and identity concepts including Microsoft identity solutions, security solutions, Microsoft Sentinel, and Microsoft Purview information protection.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds