SC-900 Cheat Sheet 2026

The 30 highest-yield SC-900 facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

40 questions
45 min time limit
70% to pass
  1. Which environments can Microsoft Defender for Cloud protect? Azure, on-premises, and multicloud environments including AWS and Google Cloud
  2. Which standard provides a framework of best practices for information security management? ISO/IEC 27001
  3. Which Microsoft Defender for Endpoint capability prevents malicious processes from running by comparing file hashes against a known-bad database? Next-generation antivirus protection
  4. Which plan of Microsoft Defender for Office 365 adds threat hunting, attack simulation training, and campaign views? Microsoft Defender for Office 365 Plan 2
  5. In Zero Trust, what does 'assume breach' mean for network design? Segment networks to contain blast radius
  6. What is the role of a 'Certificate Authority (CA)' in a Public Key Infrastructure? To issue, sign, and revoke digital certificates that bind public keys to identities
  7. What is 'business continuity planning' designed to ensure? That an organization can continue critical operations during and after a disruption
  8. What is the role of the Microsoft Sentinel Contributor RBAC role? Create and edit workbooks, analytics rules, playbooks, and manage incidents
  9. Which statement best describes the concept of 'least privilege' as it applies to data governance? Users should have access only to the data necessary for their job function
  10. Which encryption type uses the same key for both encrypting and decrypting data? Symmetric encryption
  11. Why is it important to have an effective vulnerability management program? It helps protect systems by addressing known vulnerabilities
  12. Multi-factor authentication (MFA) is a core Zero Trust control that primarily strengthens which pillar? Identities
  13. An Access Review is configured with 'Reviewers = Managers'. What happens when a user has no manager assigned in Azure AD? The access review falls back to a specified fallback reviewer or the application owner
  14. Which Microsoft Sentinel feature provides a visual representation of an attack's progression across entities like users, hosts, and IPs during an investigation? The Investigation Graph
  15. What happens to a file's sensitivity label when it is moved from a labeled SharePoint site to an unlabeled SharePoint site? The file retains its original sensitivity label regardless of the destination
  16. Which component of Microsoft Defender for Cloud provides a regulatory compliance dashboard to track adherence to standards like PCI DSS and ISO 27001? Regulatory Compliance
  17. Which action aligns with the Zero Trust principle of 'use least privilege access' for an HR employee? Grant access only to the HR database required for their role
  18. In Microsoft Defender for Cloud, what is a 'security recommendation'? Actionable guidance to harden resources and improve the secure score
  19. What type of data connectors does Microsoft Sentinel use to ingest data from Microsoft 365 services? Built-in Microsoft connectors
  20. Which Microsoft Defender for Identity alert indicates that an attacker may be attempting to enumerate all users and groups in Active Directory? LDAP reconnaissance
  21. Which Defender for Cloud feature assigns a numeric score to a subscription to reflect its overall security health? Secure score
  22. Why is incident response important in threat protection? It helps reduce downtime and operational impact after a breach
  23. Which of the following is a primary function of Microsoft Entra ID Governance? To manage the identity and access lifecycle for users.
  24. What is the benefit of integrating identity protection with cloud services? It enhances security by providing real-time threat detection
  25. What is the role of identity management in cloud security? To ensure only authorized individuals access resources and data
  26. Just-in-time (JIT) access is a Zero Trust practice primarily used to manage which type of accounts? Privileged administrator accounts
  27. What does 'Controlled Folder Access' in Microsoft Defender for Endpoint protect against? Ransomware encrypting files in protected folders
  28. Which of the following best describes 'verify explicitly' in Zero Trust? Always authenticate and authorize using all available data points
  29. In Microsoft Defender for Office 365, what does 'Safe Links' protection do when a user clicks a URL in an email? Rewrites the URL and checks it against Microsoft's threat intelligence at time-of-click
  30. In Microsoft Entra ID, which authentication method uses a physical or software key that meets FIDO2 standards? FIDO2 security key
Was this helpful?