SC-900 Cheat Sheet 2026
The 30 highest-yield SC-900 facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
40 questions
45 min time limit
70% to pass
- Which environments can Microsoft Defender for Cloud protect? → Azure, on-premises, and multicloud environments including AWS and Google Cloud
- Which standard provides a framework of best practices for information security management? → ISO/IEC 27001
- Which Microsoft Defender for Endpoint capability prevents malicious processes from running by comparing file hashes against a known-bad database? → Next-generation antivirus protection
- Which plan of Microsoft Defender for Office 365 adds threat hunting, attack simulation training, and campaign views? → Microsoft Defender for Office 365 Plan 2
- In Zero Trust, what does 'assume breach' mean for network design? → Segment networks to contain blast radius
- What is the role of a 'Certificate Authority (CA)' in a Public Key Infrastructure? → To issue, sign, and revoke digital certificates that bind public keys to identities
- What is 'business continuity planning' designed to ensure? → That an organization can continue critical operations during and after a disruption
- What is the role of the Microsoft Sentinel Contributor RBAC role? → Create and edit workbooks, analytics rules, playbooks, and manage incidents
- Which statement best describes the concept of 'least privilege' as it applies to data governance? → Users should have access only to the data necessary for their job function
- Which encryption type uses the same key for both encrypting and decrypting data? → Symmetric encryption
- Why is it important to have an effective vulnerability management program? → It helps protect systems by addressing known vulnerabilities
- Multi-factor authentication (MFA) is a core Zero Trust control that primarily strengthens which pillar? → Identities
- An Access Review is configured with 'Reviewers = Managers'. What happens when a user has no manager assigned in Azure AD? → The access review falls back to a specified fallback reviewer or the application owner
- Which Microsoft Sentinel feature provides a visual representation of an attack's progression across entities like users, hosts, and IPs during an investigation? → The Investigation Graph
- What happens to a file's sensitivity label when it is moved from a labeled SharePoint site to an unlabeled SharePoint site? → The file retains its original sensitivity label regardless of the destination
- Which component of Microsoft Defender for Cloud provides a regulatory compliance dashboard to track adherence to standards like PCI DSS and ISO 27001? → Regulatory Compliance
- Which action aligns with the Zero Trust principle of 'use least privilege access' for an HR employee? → Grant access only to the HR database required for their role
- In Microsoft Defender for Cloud, what is a 'security recommendation'? → Actionable guidance to harden resources and improve the secure score
- What type of data connectors does Microsoft Sentinel use to ingest data from Microsoft 365 services? → Built-in Microsoft connectors
- Which Microsoft Defender for Identity alert indicates that an attacker may be attempting to enumerate all users and groups in Active Directory? → LDAP reconnaissance
- Which Defender for Cloud feature assigns a numeric score to a subscription to reflect its overall security health? → Secure score
- Why is incident response important in threat protection? → It helps reduce downtime and operational impact after a breach
- Which of the following is a primary function of Microsoft Entra ID Governance? → To manage the identity and access lifecycle for users.
- What is the benefit of integrating identity protection with cloud services? → It enhances security by providing real-time threat detection
- What is the role of identity management in cloud security? → To ensure only authorized individuals access resources and data
- Just-in-time (JIT) access is a Zero Trust practice primarily used to manage which type of accounts? → Privileged administrator accounts
- What does 'Controlled Folder Access' in Microsoft Defender for Endpoint protect against? → Ransomware encrypting files in protected folders
- Which of the following best describes 'verify explicitly' in Zero Trust? → Always authenticate and authorize using all available data points
- In Microsoft Defender for Office 365, what does 'Safe Links' protection do when a user clicks a URL in an email? → Rewrites the URL and checks it against Microsoft's threat intelligence at time-of-click
- In Microsoft Entra ID, which authentication method uses a physical or software key that meets FIDO2 standards? → FIDO2 security key
Turn these facts into recall:
Was this helpful?