Microsoft Security, Compliance, and Identity Fundamentals Identity Protection and Governance Flashcards
7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Identity Protection and Governance flashcards as text
A company wants to allow external customers to create their own accounts and sign in to a consumer-facing application. Which Azure AD capability supports this scenario?
Answer: Azure AD B2C (Business to Consumer)
Azure AD B2C is designed for customer-facing apps, allowing millions of external consumers to self-register and authenticate using social identities or local accounts.
Which of the following best describes the Zero Trust principle of 'assume breach'?
Answer: Design systems assuming attackers may already be inside the network and minimize blast radius through segmentation and encryption
Assume breach means architecting as if attackers are already inside: segment networks, encrypt traffic, enforce least privilege, and monitor everything to limit what a successful attacker can access.
What is the role of a 'connected organization' in Azure AD Entitlement Management?
Answer: It represents an external organization whose users can be allowed to request access packages
Connected organizations in Entitlement Management define trusted external Azure AD tenants or domains from which users can be permitted to request access packages through the self-service portal.
Which Azure AD Identity Protection risk remediation action requires the user to complete MFA to prove they are the legitimate account owner?
Answer: Require MFA self-remediation
Configuring Identity Protection to 'Require MFA' allows a risky sign-in to proceed if the user successfully completes multi-factor authentication, proving they possess the second factor.
An Access Review is configured with 'Reviewers = Managers'. What happens when a user has no manager assigned in Azure AD?
Answer: The access review falls back to a specified fallback reviewer or the application owner
When manager-based reviews encounter users without a manager attribute, Azure AD falls back to an administrator-designated fallback reviewer to ensure no accounts are skipped.
What is the maximum activation duration that can be configured for a PIM eligible role assignment?
Answer: 24 hours
PIM allows role activation durations to be configured up to a maximum of 24 hours per activation, after which the user must re-activate if continued access is needed.
Which Azure AD feature provides a self-service portal where users can view their own risk status and trigger remediation like a password reset?
Answer: My Sign-Ins (mysignins.microsoft.com)
The My Sign-Ins portal lets end users review their own recent sign-ins, report suspicious activity, and trigger self-service password reset to remediate risk without admin involvement.