Practice for the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) exam with 16 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: When users sign in to the Azure portal, they first are:. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice test →
What you will practice
- When users sign in to the Azure portal, they first are:
- Which of the following provides best practices from Microsoft employees, partners, and customers, including t…
- Which Microsoft portal provides information on how Microsoft cloud services comply with regulatory standards…
- Do you need to deploy Azure virtual machines to host an Azure Entra ID tenant?
- Which score measures an organization's progress in completing actions that help reduce risks associated with…
- Which two types of resources can be protected using Azure Firewall?
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. When users sign in to the Azure portal, they first are:
Answer: C. authenticated
Users must be authenticated first, which verifies their identity before anything else happens. Authorization comes later to determine what permissions they have, so always associate authentication with identity verification and authorization with access control.
Q2. Which of the following provides best practices from Microsoft employees, partners, and customers, including tools and guidance to assist with Azure deployment?
Answer: D. Microsoft Cloud Adoption Framework for Azure
The Microsoft Cloud Adoption Framework for Azure provides proven guidance and best practices to accelerate your cloud adoption journey. Resource locks and Azure Policy are governance tools used to enforce rules rather than frameworks.
Q3. Which Microsoft portal provides information on how Microsoft cloud services comply with regulatory standards, such as the International Organization for Standardization (ISO)?
Answer: C. Microsoft Service Trust Portal
The Microsoft Service Trust Portal provides detailed compliance documentation and audit reports for Microsoft cloud services. The other portals handle billing or administration, while the Service Trust Portal is specifically dedicated to compliance.
Q4. Do you need to deploy Azure virtual machines to host an Azure Entra ID tenant?
Answer: B. No
No, Azure Entra ID is a fully managed cloud-based directory service. You never need to deploy or maintain underlying virtual machines. Remember that Entra ID operates natively as a multi-tenant SaaS solution managed entirely by Microsoft.
Q5. Which score measures an organization's progress in completing actions that help reduce risks associated with data protection and regulatory standards?
Answer: A. Compliance score
Compliance score tracks your progress in completing improvement actions aligned with data protection and regulatory standards. Do not confuse this with Secure Score, which specifically measures the implementation of security configurations across your environment.
Q6. Which two types of resources can be protected using Azure Firewall?
Answer: C,E. Azure virtual machines || Azure virtual networks
Azure Firewall is a managed network security service designed to protect Azure virtual networks and the virtual machines connected to them. SaaS applications like SharePoint Online are protected at the application layer, not by Azure infrastructure firewalls.
Q7. Azure DDoS Protection Standard can be used to protect:
Answer: D. Virtual networks
Azure DDoS Protection Standard is explicitly designed to safeguard virtual networks against distributed denial-of-service attacks. Remember that this service operates at the network layer, making resource groups and identity objects invalid targets.
Q8. In the shared responsibility model for an Azure deployment, what is Microsoft solely responsible for managing?
Answer: A. Physical hardware management
Microsoft is solely responsible for managing physical hardware, including datacenters and host infrastructure. Customers always remain responsible for configuring data permissions and managing their own user accounts and devices in the cloud.
Q9. What should you use in the Microsoft 365 Defender portal to view security trends and track identity protection status?
Answer: B. Reports
The Reports section in the Microsoft 365 Defender portal provides the visibility needed to track security trends and monitor identity protection status. Incidents are for active investigations, while reports aggregate historical data and metrics.
Q10. You plan to implement a security strategy and place multiple layers of defense in a network infrastructure. What security methodology does this represent?
Answer: B. Defense in depth
Defense in depth uses multiple layers of security controls to protect data and infrastructure. If one layer fails, others remain to stop threats. Identity as a perimeter focuses only on authentication, not layered defenses.
Q11. What do you use to provide real-time integration between Azure Sentinel and another security source?
Answer: A. a connector
Data connectors ingest logs from various sources into Azure Sentinel for real-time analysis. While a Log Analytics workspace stores the data, the connector itself establishes the actual integration pipeline for security alerts and events.
Q12. What is an example of encryption at rest?
Answer: A. encrypting a virtual machine disk
Encrypting a virtual machine disk protects data stored on the physical storage media, which defines encryption at rest. HTTPS, encrypted emails, and VPNs represent encryption in transit, safeguarding data moving across networks.
Q13. Applications registered in Azure Entra ID are automatically associated with a _____________
Answer: A. service principal
Registering an application in Azure Entra ID automatically creates an application object and a service principal in the tenant. The service principal is the local instance used to define permissions and access policies.
Q14. In software as a service (SaaS), applying service packs to applications is the responsibility of the organization.
Answer: A. No
No, in SaaS the cloud provider handles all underlying maintenance including service packs and patching. The customer organization only manages their data, user access, and devices connecting to the SaaS application.
Q15. Which three statements accurately describe the guiding principles of Zero Trust?
Answer: A,B,D. Always explicitly verify user permissions. || Always assume the user system can be breached. || Use identity as the primary security perimeter.
Zero Trust requires explicit permission verification, assumes compromise, and uses identity as the primary security perimeter. Options citing the network or physical locations reflect legacy castle-and-moat models rather than modern Zero Trust concepts.
Q16. Which Azure Entra ID feature can you use to prevent devices not managed by Microsoft Intune from accessing corporate resources?
Answer: C. Conditional Access policies
Conditional Access policies evaluate device compliance and grants access only to Intune-managed devices. Network security groups filter network traffic but do not evaluate user identity or device compliance state.
More Microsoft Security, Compliance, and Identity Fundamentals (SC-900) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.