SC-900 Cheat Sheet 2026

The 30 highest-yield SC-900 facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

40 questions
45 min time limit
70% to pass
  1. Which environments can Microsoft Defender for Cloud protect? → Azure, on-premises, and multicloud environments including AWS and Google Cloud
  2. Which standard provides a framework of best practices for information security management? → ISO/IEC 27001
  3. Which Microsoft Defender for Endpoint capability prevents malicious processes from running by comparing file hashes against a known-bad database? → Next-generation antivirus protection
  4. Which plan of Microsoft Defender for Office 365 adds threat hunting, attack simulation training, and campaign views? → Microsoft Defender for Office 365 Plan 2
  5. In Zero Trust, what does 'assume breach' mean for network design? → Segment networks to contain blast radius
  6. What is the role of a 'Certificate Authority (CA)' in a Public Key Infrastructure? → To issue, sign, and revoke digital certificates that bind public keys to identities
  7. What is 'business continuity planning' designed to ensure? → That an organization can continue critical operations during and after a disruption
  8. What is the role of the Microsoft Sentinel Contributor RBAC role? → Create and edit workbooks, analytics rules, playbooks, and manage incidents
  9. Which statement best describes the concept of 'least privilege' as it applies to data governance? → Users should have access only to the data necessary for their job function
  10. Which encryption type uses the same key for both encrypting and decrypting data? → Symmetric encryption
  11. Why is it important to have an effective vulnerability management program? → It helps protect systems by addressing known vulnerabilities
  12. Multi-factor authentication (MFA) is a core Zero Trust control that primarily strengthens which pillar? → Identities
  13. An Access Review is configured with 'Reviewers = Managers'. What happens when a user has no manager assigned in Azure AD? → The access review falls back to a specified fallback reviewer or the application owner
  14. Which Microsoft Sentinel feature provides a visual representation of an attack's progression across entities like users, hosts, and IPs during an investigation? → The Investigation Graph
  15. What happens to a file's sensitivity label when it is moved from a labeled SharePoint site to an unlabeled SharePoint site? → The file retains its original sensitivity label regardless of the destination
  16. Which component of Microsoft Defender for Cloud provides a regulatory compliance dashboard to track adherence to standards like PCI DSS and ISO 27001? → Regulatory Compliance
  17. Which action aligns with the Zero Trust principle of 'use least privilege access' for an HR employee? → Grant access only to the HR database required for their role
  18. In Microsoft Defender for Cloud, what is a 'security recommendation'? → Actionable guidance to harden resources and improve the secure score
  19. What type of data connectors does Microsoft Sentinel use to ingest data from Microsoft 365 services? → Built-in Microsoft connectors
  20. Which Microsoft Defender for Identity alert indicates that an attacker may be attempting to enumerate all users and groups in Active Directory? → LDAP reconnaissance
  21. Which Defender for Cloud feature assigns a numeric score to a subscription to reflect its overall security health? → Secure score
  22. Why is incident response important in threat protection? → It helps reduce downtime and operational impact after a breach
  23. Which of the following is a primary function of Microsoft Entra ID Governance? → To manage the identity and access lifecycle for users.
  24. What is the benefit of integrating identity protection with cloud services? → It enhances security by providing real-time threat detection
  25. What is the role of identity management in cloud security? → To ensure only authorized individuals access resources and data
  26. Just-in-time (JIT) access is a Zero Trust practice primarily used to manage which type of accounts? → Privileged administrator accounts
  27. What does 'Controlled Folder Access' in Microsoft Defender for Endpoint protect against? → Ransomware encrypting files in protected folders
  28. Which of the following best describes 'verify explicitly' in Zero Trust? → Always authenticate and authorize using all available data points
  29. In Microsoft Defender for Office 365, what does 'Safe Links' protection do when a user clicks a URL in an email? → Rewrites the URL and checks it against Microsoft's threat intelligence at time-of-click
  30. In Microsoft Entra ID, which authentication method uses a physical or software key that meets FIDO2 standards? → FIDO2 security key
Was this helpful?