Mixed Deck — All SC-900 Topics Flashcards
89 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All SC-900 Topics flashcards as text
Which log source does Cloud Discovery in Microsoft Defender for Cloud Apps use to identify cloud apps in use?
Answer: Firewall and proxy traffic logs
Cloud Discovery analyzes firewall and proxy traffic logs uploaded by the administrator or streamed automatically to discover cloud app usage across the organization.
What is a key difference between a DLP policy and a sensitivity label?
Answer: DLP policies prevent data exfiltration from locations, while sensitivity labels classify and protect the data itself.
While both are part of information protection, their focus is different. Sensitivity labels classify and apply persistent protection (like encryption) to the data itself, wherever it goes. DLP policies focus on the context of data sharing, preventing data exfiltration from specific locations like email or Teams based on rules.
When creating a DLP policy, you must specify where it applies. Which of the following are valid locations for a DLP policy?
Answer: Exchange Online, SharePoint Online, and Microsoft Teams
DLP policies can be scoped to protect data across various Microsoft 365 services. This includes Exchange Online for emails, SharePoint Online and OneDrive for Business for files, and Microsoft Teams for chats and channel messages.
You plan to implement a security strategy and place multiple layers of defense throughout a network infrastructure. Which security methodology does this represent?
Answer: defense in depth
Defense in depth is a security methodology that employs multiple, overlapping layers of security controls throughout an IT infrastructure. The principle is that if one security layer fails, another layer will still be in place to provide protection. This approach creates a robust and resilient security posture, making it significantly more difficult for attackers to breach the entire system.
Scenario: A company is enhancing security measures to prevent unauthorized access to critical systems. Which authentication method should they employ to require multiple forms of verification?
Answer: Multi-factor authentication (MFA)
Multi-factor authentication (MFA) significantly enhances security by requiring users to provide two or more distinct forms of verification to gain access. This typically combines something they know (like a password) with something they have (like a phone or token) or something they are (like a fingerprint). By adding multiple layers, MFA drastically reduces the risk of unauthorized access, even if one factor is compromised.
How does Microsoft Sentinel collect log data from various sources like Azure services, Microsoft 365, and on-premises systems?
Answer: By configuring data connectors
Data connectors are the built-in components used to ingest data from a wide range of Microsoft and third-party sources into Microsoft Sentinel. They simplify the process of connecting data sources to the Log Analytics workspace that Sentinel uses.
What integration does Microsoft Defender for Cloud Apps have with Microsoft Purview Information Protection?
Answer: It applies Microsoft Purview sensitivity labels to files stored in cloud apps
Defender for Cloud Apps can apply Microsoft Purview Information Protection sensitivity labels to files discovered in connected cloud apps, extending data protection to the cloud.
An administrator wants to create a policy to detect potential data theft by employees who have recently resigned. How can this be accomplished in Insider Risk Management?
Answer: By using a pre-configured policy template for departing users.
Insider Risk Management provides several pre-configured policy templates for common risk scenarios, including 'Data theft by departing users'. These templates simplify setup by pre-selecting relevant indicators and triggers, such as connecting to the HR system for termination dates.
In Microsoft Defender for Cloud Apps, what is the purpose of the 'App Catalog'?
Answer: A database of over 31,000 cloud apps rated for risk using more than 90 factors
The Cloud App Catalog in Defender for Cloud Apps contains over 31,000 cloud apps, each rated for risk using more than 90 risk factors to help organizations make informed decisions.
Which feature provides the extended detection and response (XDR) capability of Azure Sentinel?
Answer: integration with Microsoft 365 Defender
Azure Sentinel (now Microsoft Sentinel) provides extended detection and response (XDR) capabilities through its deep integration with Microsoft 365 Defender. This integration allows Sentinel to ingest security data from endpoints, identities, email, and applications across the Microsoft 365 ecosystem. This unified view enables comprehensive threat detection, investigation, and automated response across the entire digital estate.
Scenario: A corporation seeks centralized control over user access to applications and resources, including user lifecycle management and access reviews. Which service best suits these needs?
Answer: Microsoft Entra ID
Microsoft Entra ID (formerly Azure Active Directory) is a cloud-based identity and access management service that provides centralized control over user access to applications and resources. It includes robust features for user lifecycle management, access reviews, and single sign-on capabilities. This service is ideal for managing user identities and their access permissions across an organization's entire IT environment.
In the context of Microsoft Defender for Cloud Apps, what does 'sanctioning' a cloud application mean?
Answer: Officially approving an app for use within the organization
Sanctioning a cloud app marks it as approved for organizational use in the Cloud App Catalog, which can also be used to configure firewall and proxy rules to allow its traffic.
Match Microsoft 365 insider risk management workflow step to the appropriate task. "Create cases in the Case dashboard"
Answer: Investigate
In the Microsoft 365 insider risk management workflow, 'Create cases in the Case dashboard' falls under the Investigate step. After potential insider risks are identified and triaged, the investigation phase involves creating cases to gather more evidence, analyze activities, and determine the appropriate response. This structured approach helps manage and resolve insider risk incidents effectively.
An analyst observes suspicious process creation and lateral movement activities on a workstation. Which Defender for Endpoint feature provides the detailed event timeline and process tree to investigate these activities?
Answer: Endpoint Detection and Response (EDR)
Endpoint Detection and Response (EDR) capabilities provide near real-time and actionable detections of threats. It collects and analyzes behavioral signals from endpoints, allowing security analysts to investigate the full scope of a breach through detailed timelines and process information.
Employees are allowed to bring and use their cell phones at work. The employees don't want their phone to be under full corporate control, but admins want to allow users to read emails and use Teams while protecting corporate data. Which of the following will allow admins to accomplish these goals?
Answer: Mobile Application Management (MAM).
Mobile Application Management (MAM) allows organizations to manage and protect corporate data within specific applications, without requiring full device enrollment or control. This is ideal for Bring Your Own Device (BYOD) scenarios where users want personal privacy but corporate data needs protection. MAM policies can enforce data encryption, prevent copy/paste of corporate data, and selectively wipe corporate data from apps.
A security analyst wants to proactively search for new and unknown threats in their organization's data. Which Microsoft Sentinel feature should they use?
Answer: Hunting
Threat hunting is the proactive process of searching for cyber threats that are lurking undetected in a network. Microsoft Sentinel provides powerful search and query tools, including built-in hunting queries, to guide security analysts in this process.
What Microsoft 365 Defender capability does Microsoft Defender for Cloud Apps contribute to when integrated into the unified security operations platform?
Answer: Cross-domain threat signals for extended detection and response (XDR)
As part of the Microsoft Defender XDR suite, Defender for Cloud Apps contributes cloud app threat signals that correlate with endpoint, identity, and email signals for comprehensive cross-domain threat detection.
Which of the following is NOT one of the four pillars of the Cloud Access Security Broker (CASB) framework that Defender for Cloud Apps provides?
Answer: Network Segmentation
The four CASB pillars are Visibility, Compliance, Data Security, and Threat Protection — Network Segmentation is not a CASB pillar.
Which component of Microsoft Defender for Endpoint uses cloud-based machine learning, behavior analysis, and heuristics to provide real-time malware protection?
Answer: Next-generation protection
Next-generation protection is the real-time antivirus and antimalware component of Defender for Endpoint. It goes beyond traditional signature-based detection, using advanced cloud-powered techniques to block new and emerging threats.
An administrator needs to grant a developer temporary access to a specific port on an Azure virtual machine. Which Microsoft Defender for Cloud feature should be used to achieve this securely?
Answer: Just-in-time (JIT) VM access
Just-in-time (JIT) VM access locks down inbound traffic to your Azure VMs, reducing exposure to attacks while providing easy access to connect to VMs when needed. When a user requests access, Defender for Cloud checks permissions and, if approved, configures the Network Security Groups (NSGs) to allow inbound traffic to the requested ports for a limited time.