Microsoft Security, Compliance, and Identity Fundamentals (SC-900) — Questions and Answers
Question 1: Which Microsoft Defender product would BEST protect against a business email compromise (BEC) attack where an attacker impersonates a CEO?
- Microsoft Defender for Cloud
- Microsoft Defender for Identity
- Microsoft Defender for Office 365 (Correct answer)
- Microsoft Defender for Endpoint
Correct answer: Microsoft Defender for Office 365
Microsoft Defender for Office 365 includes anti-phishing policies with impersonation protection specifically designed to detect and block BEC and executive impersonation attacks in email.
Question 2: In Microsoft Purview, what is the difference between a sensitivity label and a retention label?
- Sensitivity labels apply only to email; retention labels apply only to files
- Sensitivity labels control data lifecycle; retention labels control access
- Sensitivity labels protect content from unauthorized access; retention labels govern how long content is kept (Correct answer)
- They are two names for the same feature
Correct answer: Sensitivity labels protect content from unauthorized access; retention labels govern how long content is kept
Sensitivity labels classify and protect content from unauthorized access, while retention labels manage how long content must be kept or when it can be deleted.
Question 3: A user forgets their password and needs to reset it without contacting IT. Which Microsoft Entra feature enables this?
- Self-Service Password Reset (SSPR) (Correct answer)
- Identity Protection
- Conditional Access
- Privileged Identity Management
Correct answer: Self-Service Password Reset (SSPR)
Self-Service Password Reset (SSPR) allows users to reset their own passwords after verifying their identity through registered authentication methods.
Question 4: Azure AD Access Reviews are primarily used to:
- Review application permission scopes
- Periodically verify that users still need their current group memberships or role assignments (Correct answer)
- Audit sign-in logs for suspicious activity
- Monitor Conditional Access policy effectiveness
Correct answer: Periodically verify that users still need their current group memberships or role assignments
Access Reviews enable periodic recertification of user access to ensure only appropriate users retain group/role memberships.
Question 5: How does Microsoft Defender for Cloud correlate security alerts to reduce analyst fatigue?
- It uses AI to automatically group related individual alerts into security incidents representing attack campaigns (Correct answer)
- Alerts are forwarded to Azure Sentinel only, which handles all correlation
- It requires manual analyst review and grouping of all alerts into incidents
- Defender for Cloud suppresses low-priority alerts based on static threshold rules only
Correct answer: It uses AI to automatically group related individual alerts into security incidents representing attack campaigns
Defender for Cloud applies AI-driven fusion to correlate related alerts into incidents, helping analysts understand the full scope of an attack rather than investigating individual alerts.
Question 6: What is the role of threat detection in security operations?
- To configure firewalls
- To identify and monitor potential security threats (Correct answer)
- To track network usage only
- To manage network configurations
Correct answer: To identify and monitor potential security threats
Threat detection is a fundamental component of security operations, focusing on identifying malicious activities or indicators of compromise within an organization's environment. It involves using various tools and techniques, such as intrusion detection systems and security information and event management (SIEM) systems. By continuously monitoring for suspicious patterns, threat detection enables early warning and rapid response to potential security incidents.
Question 7: What is the Secure Score in Microsoft Defender for Cloud?
- A numerical representation of an organization's current security posture based on assessed controls (Correct answer)
- A certification score for meeting regulatory compliance requirements
- A password complexity strength indicator for Azure AD accounts
- A performance metric measuring the availability of Azure virtual machines
Correct answer: A numerical representation of an organization's current security posture based on assessed controls
The Secure Score aggregates all security findings into a single score that gives a snapshot of your current security situation — a higher score means lower risk.
Question 8: What is the role of access control in data governance?
- To track the amount of data stored
- To prevent users from accessing any data
- To simplify data classification
- To limit access to data based on roles and permissions (Correct answer)
Correct answer: To limit access to data based on roles and permissions
Access control is a critical component of data governance that dictates who can access specific data and what actions they can perform (e.g., read, write, delete). By implementing role-based access control (RBAC) or attribute-based access control (ABAC), organizations can ensure that individuals only have the necessary permissions aligned with their job functions. This principle of least privilege significantly reduces the risk of unauthorized data access and misuse.
Question 9: What is the main purpose of information protection in an organization?
- To improve employee productivity
- To prevent unauthorized access to sensitive data (Correct answer)
- To increase the speed of network connections
- To track employee activity
Correct answer: To prevent unauthorized access to sensitive data
The main purpose of information protection is to safeguard sensitive and critical data throughout its lifecycle, from creation to deletion. This involves implementing controls and policies to prevent unauthorized access, use, disclosure, disruption, modification, or destruction of information. By ensuring data confidentiality, integrity, and availability, information protection helps organizations comply with regulations and maintain trust.
Question 10: What does Microsoft Defender Vulnerability Management primarily help organizations identify?
- Compromised user credentials in Azure AD
- Misconfigured Azure network security groups
- Software vulnerabilities and misconfigurations on endpoints that should be remediated (Correct answer)
- Malicious email campaigns targeting employees
Correct answer: Software vulnerabilities and misconfigurations on endpoints that should be remediated
Microsoft Defender Vulnerability Management discovers, prioritizes, and helps remediate software vulnerabilities and security misconfigurations on endpoints.
Question 11: In a Zero Trust model, what is the primary assumption made about network location?
- No network location, internal or external, is implicitly trusted. (Correct answer)
- Requests from the corporate office are inherently trusted.
- Devices on the internal network are secure by default.
- External networks are untrusted, while internal networks are trusted.
Correct answer: No network location, internal or external, is implicitly trusted.
A core tenet of Zero Trust is to eliminate the concept of trust based on network location. It assumes that there is no traditional network edge and treats all requests as if they originate from an uncontrolled, external network, requiring verification for every access attempt regardless of its origin.
Question 12: In Microsoft Purview, what is Exact Data Match (EDM) classification used for?
- Matching data based on approximate spelling similarities
- Classifying documents based on their file type
- Detecting data that is encrypted incorrectly
- Identifying sensitive information based on exact values in a customer database (Correct answer)
Correct answer: Identifying sensitive information based on exact values in a customer database
EDM allows organizations to create custom sensitive information types that match exact values from a structured database, such as a list of employee IDs or patient records.
Question 13: What is the role of encryption in data protection?
- To improve data accessibility
- To protect data by making it unreadable to unauthorized users (Correct answer)
- To reduce the amount of data stored
- To track data movements within an organization
Correct answer: To protect data by making it unreadable to unauthorized users
Encryption is a fundamental data protection technique that transforms data into a coded format, making it unreadable and unusable to anyone without the correct decryption key. Its role is to ensure the confidentiality of data, both at rest and in transit. Even if unauthorized individuals gain access to encrypted data, they cannot understand its content, thereby preventing data breaches and maintaining privacy.
Question 14: What type of attack does Microsoft Defender for Identity specifically detect when an attacker uses a stolen Kerberos ticket-granting ticket to impersonate any user?
- Credential stuffing
- Golden Ticket attack (Correct answer)
- Spear phishing
- Pass-the-Hash
Correct answer: Golden Ticket attack
A Golden Ticket attack uses a forged Kerberos TGT (often created using the KRBTGT account hash) to impersonate any user, and Defender for Identity is designed to detect this lateral movement technique.
Question 15: A security administrator is configuring access policies. According to the Zero Trust principle of 'Verify explicitly', which of the following signals should be used to inform an access decision?
- The user's identity, device health, and location. (Correct answer)
- Only the user's group membership.
- Whether the user is inside the corporate firewall.
- Only the user's password.
Correct answer: The user's identity, device health, and location.
The 'Verify explicitly' principle requires authentication and authorization to be based on all available data points. This includes not just the user's identity, but also contextual signals like the location, the health and compliance of the device, the service or workload being accessed, and data classification.
Question 16: Which of the following best describes a 'Distributed Denial of Service (DDoS)' attack?
- Encrypting a victim's files and demanding a ransom payment
- Stealing user credentials through fake login pages
- Flooding a target system with traffic from multiple sources to make it unavailable (Correct answer)
- Injecting malicious code into a web application's database
Correct answer: Flooding a target system with traffic from multiple sources to make it unavailable
A DDoS attack overwhelms a target (website, server, or network) with massive traffic from many compromised systems, rendering it unavailable to legitimate users.
Question 17: What type of signal does Microsoft Defender for Identity primarily analyze to detect suspicious activity?
- Endpoint process trees
- Network packet captures
- Active Directory Domain Services logs and traffic (Correct answer)
- Cloud app access logs
Correct answer: Active Directory Domain Services logs and traffic
Microsoft Defender for Identity monitors Active Directory Domain Services traffic and logs to detect identity-based attacks such as pass-the-hash and lateral movement.
Question 18: What is the role of a Security Information and Event Management (SIEM) system?
- To analyze and respond to security incidents in real time (Correct answer)
- To ensure software applications are bug-free
- To monitor server hardware only
- To configure network firewalls
Correct answer: To analyze and respond to security incidents in real time
A Security Information and Event Management (SIEM) system centralizes and correlates security event data from various sources across an organization's IT infrastructure. Its main role is to provide real-time analysis of security alerts generated by network hardware and applications. This enables security teams to detect, investigate, and respond to potential security incidents promptly, enhancing overall threat visibility and response capabilities.
Question 19: Which type of sensitive information type uses document fingerprinting to detect sensitive forms?
- Named entities
- Document fingerprint (Correct answer)
- Exact Data Match (EDM)
- Keyword dictionary
Correct answer: Document fingerprint
Document fingerprinting converts a standard form (like a W-2 or patent form) into a fingerprint used to detect when similar forms are shared.
Question 20: Why is identity protection important for cloud-based applications?
- It speeds up application performance
- It prevents unauthorized access to cloud-based applications and resources (Correct answer)
- It allows anyone to access cloud applications
- It only protects local data storage
Correct answer: It prevents unauthorized access to cloud-based applications and resources
Identity protection is crucial for cloud-based applications because these applications are often accessible from anywhere, increasing the attack surface. It prevents unauthorized access by detecting and remediating identity-based risks, such as compromised credentials or suspicious sign-in attempts, safeguarding sensitive data and services in the cloud.
Question 21: Why is it important to have data retention policies?
- To comply with legal, regulatory, and business requirements (Correct answer)
- To reduce data storage costs
- To improve data retrieval speed
- To allow for unlimited data storage
Correct answer: To comply with legal, regulatory, and business requirements
Data retention policies define how long specific types of data must be kept and when they should be securely disposed of. These policies are crucial for ensuring an organization complies with various legal statutes, industry regulations (like GDPR, HIPAA), and internal business operational needs. Proper data retention helps mitigate legal risks, manage storage costs, and ensure data is available when required for audits or investigations.
Question 22: What capabilities does the free tier of Microsoft Defender for Cloud provide?
- Foundational Cloud Security Posture Management (CSPM) including Secure Score and security recommendations (Correct answer)
- Full workload protection for all Azure services at no cost
- Complete regulatory compliance dashboards for all major standards
- Advanced threat detection and automated incident response
Correct answer: Foundational Cloud Security Posture Management (CSPM) including Secure Score and security recommendations
The free foundational CSPM tier provides Secure Score, security recommendations, and basic posture assessment without paid workload protection plans.
Question 23: Which standard provides a framework of best practices for information security management?
- ISO/IEC 27001 (Correct answer)
- SOC 2
- PCI DSS
- NIST SP 800-53
Correct answer: ISO/IEC 27001
ISO/IEC 27001 is an internationally recognized standard that specifies requirements for establishing, implementing, and maintaining an Information Security Management System (ISMS).
Question 24: Multi-factor authentication (MFA) is a core Zero Trust control that primarily strengthens which pillar?
- Endpoints
- Infrastructure
- Identities (Correct answer)
- Networks
Correct answer: Identities
MFA strengthens the Identities pillar by adding additional verification factors beyond passwords, reducing the risk of compromised credentials.
Question 25: What is Microsoft Entra Domain Services (formerly Azure AD Domain Services) primarily used for?
- Syncing on-premises AD groups to Microsoft 365
- Providing cloud-based LDAP, Kerberos, and NTLM services for legacy apps without on-premises DCs (Correct answer)
- Enabling passwordless authentication for mobile devices
- Replacing Microsoft Entra ID as the primary identity store
Correct answer: Providing cloud-based LDAP, Kerberos, and NTLM services for legacy apps without on-premises DCs
Microsoft Entra Domain Services provides managed domain services such as LDAP, Kerberos, and NTLM, allowing legacy applications to use domain features without on-premises domain controllers.
Question 26: Which Microsoft Sentinel component uses Azure Logic Apps to automate responses to security threats?
- Data connectors
- Workbooks
- Analytics rules
- Playbooks (Correct answer)
Correct answer: Playbooks
Playbooks in Microsoft Sentinel are built on Azure Logic Apps and automate response actions when specific security events or alerts occur.
Question 27: Which Microsoft Purview feature automatically discovers and classifies sensitive data stored across Microsoft 365 services?
- Trainable classifiers (Correct answer)
- Data Loss Prevention
- Information barriers
- Sensitivity labels
Correct answer: Trainable classifiers
Trainable classifiers use machine learning to automatically identify and classify content across Microsoft 365 based on what data looks like, not just keywords.
Question 28: An organization enables the Azure AD Identity Protection policy to require password change when user risk is 'High'. What must users do to regain normal access?
- Re-enroll in MFA from a new device
- Wait 24 hours for the risk to automatically expire
- Contact the help desk to have an admin reset the password
- Complete a self-service password reset to prove identity and clear the risk (Correct answer)
Correct answer: Complete a self-service password reset to prove identity and clear the risk
When user risk policy enforces password change, affected users can self-remediate by completing SSPR (Self-Service Password Reset), which clears the risk flag and restores normal access.
Question 29: Which Microsoft service is specifically designed to protect identities by detecting risks like leaked credentials and atypical sign-in behavior for Azure AD accounts?
- Microsoft Defender for Cloud Apps
- Microsoft Entra ID Protection (Correct answer)
- Microsoft Sentinel
- Microsoft Defender for Identity
Correct answer: Microsoft Entra ID Protection
Microsoft Entra ID Protection monitors cloud identity signals and detects risks such as anonymous IP usage, leaked credentials, and password spray attacks.
Question 30: Which Microsoft 365 Defender portal feature provides a unified view of incidents across endpoints, email, identities, and apps?
- Secure Score
- Device inventory
- Threat analytics
- Incidents queue (Correct answer)
Correct answer: Incidents queue
The Incidents queue in the Microsoft 365 Defender portal aggregates correlated alerts from across all Microsoft 365 Defender products into unified incidents.
Question 31: Which role is required to create and manage sensitivity labels in the Microsoft Purview compliance portal?
- Compliance Administrator or higher (Correct answer)
- SharePoint Administrator
- Global Reader
- Security Reader
Correct answer: Compliance Administrator or higher
Creating and managing sensitivity labels requires the Compliance Administrator role or equivalent permissions in the Microsoft Purview compliance portal.
Question 32: Which feature in Microsoft Sentinel maps detected threats to the MITRE ATT&CK framework?
- Workbooks
- MITRE ATT&CK coverage view in Analytics and Threat Intelligence (Correct answer)
- Fusion rules
- Data connectors dashboard
Correct answer: MITRE ATT&CK coverage view in Analytics and Threat Intelligence
Microsoft Sentinel includes a MITRE ATT&CK framework view in the Analytics section that maps your enabled detection rules to specific tactics and techniques to show coverage.
Question 33: Which Microsoft Sentinel feature automatically groups related alerts into a single actionable item to reduce alert fatigue?
- Hunting queries
- Incidents (Correct answer)
- Playbooks
- Workbooks
Correct answer: Incidents
Microsoft Sentinel groups related alerts into incidents, giving analysts a single consolidated item to investigate instead of many separate alerts.
Question 34: A company wants to simulate phishing attacks against its employees to improve security awareness. Which Microsoft tool should they use?
- Attack Simulation Training (Correct answer)
- Defender for Endpoint
- Microsoft Sentinel
- Microsoft Defender for Identity
Correct answer: Attack Simulation Training
Attack Simulation Training in Microsoft 365 Defender lets organizations run simulated phishing and other attack scenarios to train employees.
Question 35: What is a Microsoft Sentinel Watchlist?
- A list of blocked IP addresses in the firewall
- A list of approved software applications
- A curated set of data imported from external sources used to correlate against event data (Correct answer)
- A queue of pending incidents for analysts
Correct answer: A curated set of data imported from external sources used to correlate against event data
Watchlists are imported datasets (such as lists of critical assets or known bad IPs) that can be referenced in analytics rules and hunting queries to enrich detection logic.
Question 36: Which feature in Microsoft Entra ID provides risk-based Zero Trust enforcement by detecting suspicious sign-in behaviors?
- Identity Protection (Correct answer)
- Enterprise Application Registration
- Administrative Units
- B2B Collaboration
Correct answer: Identity Protection
Microsoft Entra ID Protection uses machine learning to detect risky sign-ins and users, triggering step-up authentication or access blocks.
Question 37: Which Microsoft Defender for Endpoint capability prevents malicious processes from running by comparing file hashes against a known-bad database?
- Attack Surface Reduction rules
- Threat & Vulnerability Management
- Endpoint Detection and Response
- Next-generation antivirus protection (Correct answer)
Correct answer: Next-generation antivirus protection
Next-generation antivirus (Microsoft Defender Antivirus) uses cloud-delivered protection and hash-based detection to block known malware before execution.
Question 38: Which Microsoft Purview Information Protection capability allows organizations to apply labels and protection to on-premises files stored in file shares and SharePoint Server?
- Microsoft Purview Information Protection scanner (Correct answer)
- Microsoft Defender for Cloud Apps
- Azure AD Conditional Access
- Microsoft Purview Data Map
Correct answer: Microsoft Purview Information Protection scanner
The Microsoft Purview Information Protection scanner discovers, classifies, and protects files stored on-premises in file shares and SharePoint Server.
Question 39: What does Microsoft Defender for Cloud use to provide a prioritized list of security recommendations?
- Secure Score (Correct answer)
- Threat Intelligence feeds
- Compliance dashboard
- Sentinel incidents
Correct answer: Secure Score
Secure Score in Microsoft Defender for Cloud quantifies your security posture and provides prioritized recommendations to improve it.
Question 40: What is the purpose of encryption in security?
- To prevent data from being lost
- To make data accessible to all users
- To ensure only authorized parties can access and read data (Correct answer)
- To increase internet speed
Correct answer: To ensure only authorized parties can access and read data
The primary purpose of encryption in security is to protect data confidentiality. By transforming data into an unreadable format, encryption ensures that even if unauthorized parties gain access, they cannot understand or use the information, making it accessible only to those with the correct decryption key.
Microsoft Security, Compliance, and Identity Fundamentals (SC-900)
The SC-900 exam validates foundational knowledge of Microsoft security, compliance, and identity (SCI) solutions.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds