Practice for the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) exam with 15 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which Microsoft portal provides information about how Microsoft cloud services comply with regulatory standards, such as. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice test →
What you will practice
- Which Microsoft portal provides information about how Microsoft cloud services comply with regulatory standar…
- Select the answer that correctly completes the sentence. [__________] provides benchmark recommendations and…
- What is the purpose of the Azure Entra ID password protection feature?
- Which service should you use to view your secure score in Azure?
- When users sign in to the Azure portal, they are first:
- ____________________ provides benchmark recommendations and guidance to secure Azure services.
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. Which Microsoft portal provides information about how Microsoft cloud services comply with regulatory standards, such as those of the International Organization for Standardization (ISO)?
Answer: A. Microsoft Service Trust Portal
The Microsoft Service Trust Portal provides compliance documentation and audit reports for Microsoft cloud services. For the exam, associate the Service Trust Portal directly with regulatory standards like ISO and GDPR.
Q2. Select the answer that correctly completes the sentence. [__________] provides benchmark recommendations and guidance to secure Azure services.
Answer: D. Security baselines for Azure
Security baselines for Azure deliver predefined security recommendations based on best practices to protect Azure resources. The other options are monitoring tools rather than security configuration guides.
Q3. What is the purpose of the Azure Entra ID password protection feature?
Answer: B. Preventing users from using specific words in their passwords
Azure Entra ID Password Protection prevents users from creating passwords that include specific weak or banned words. This feature blocks predictable passwords to reduce the risk of password spray attacks. It does not control expiration periods.
Q4. Which service should you use to view your secure score in Azure?
Answer: C. Microsoft Defender for Cloud
Microsoft Defender for Cloud contains the secure score dashboard to evaluate and improve your Azure security posture. While Azure Advisor offers general best practice recommendations, Defender for Cloud specifically handles security threats and scoring.
Q5. When users sign in to the Azure portal, they are first:
Answer: C. Authenticated
Users are always authenticated first to verify their identity when signing into the Azure portal. Authorization happens afterward to determine what resources they can access.
Q6. ____________________ provides benchmark recommendations and guidance to secure Azure services.
Answer: A. Security baselines for Azure
Security baselines for Azure provide benchmark recommendations and guidance to secure Azure services. The other options handle monitoring and analytics rather than security configuration guidance.
Q7. For each of the following statements, select Yes if the statement is true. Otherwise, select No. All Azure Entra ID licensing editions include the same features.
Answer: E. No, Yes, and No
Azure Entra ID editions have varying features, so statement one is No. You can manage tenants in the Azure portal, but it is a managed service requiring no virtual machines. Match the sequence correctly.
Q8. Which three statements correctly describe the guiding principles of the Zero Trust model?
Answer: C,D,E. Use identity as the primary security boundary || Always explicitly verify a user's permissions || Always assume the user's system can be breached
Zero Trust relies on identity as the new perimeter, continuous explicit verification, and assuming breach to minimize impact. Traditional network perimeters are obsolete here, so eliminate any option relying on physical locations or legacy trust boundaries.
Q9. In the Microsoft Cloud Adoption Framework for Azure, which two phases are handled before the Ready phase?
Answer: A,E. Strategy definition || Plan
The Cloud Adoption Framework dictates that defining strategy and planning occur before preparing infrastructure. Governance and management are ongoing phases that happen after readiness, so remember the flow: strategy, plan, ready, adopt, govern, manage.
Q10. What can you use to provide a user a two-hour window to complete an administrative task in Azure?
Answer: D. Azure Entra ID Privileged Identity Management (PIM)
Privileged Identity Management provides time-based privileged access for specific administrative tasks. Conditional Access controls access based on conditions but does not grant temporary, time-bound role activations like PIM does.
Q11. Select the answer that correctly completes the sentence. [__________] is the process of identifying whether an authenticated user can access a specific resource.
Answer: B. Authorization
Authorization determines what level of access an authenticated user has to specific resources. A common distractor is authentication, but that only validates user identity without granting permissions to resources.
Q12. Which Azure Entra ID feature can you use to evaluate group membership and automatically remove users who no longer need to belong to a group?
Answer: D. Access reviews
Access reviews let administrators periodically validate group memberships and automatically remove access when users no longer need it. Conditional Access and Identity Protection focus on real-time sign-in security rather than recurring access certification.
Q13. Select the answer that correctly completes the sentence. When users sign in to the Azure portal, they are first [_________________].
Answer: B. Authenticated
Authentication happens first because the system must validate user identities before checking permissions. Authorization follows authentication, determining which resources and actions the verified user is permitted to access.
Q14. Select the answer that correctly completes the sentence:
Answer: C. Encryption
Applying encryption ensures data remains inaccessible without the correct cryptographic key. Archiving, compression, and deduplication simply organize or reduce file sizes. For the exam, associate cryptographic keys directly with the encryption process.
Q15. ______________ is the process of determining whether a signed-in user can access a specific resource.
Answer: A. Authorization
Authorization determines whether an authenticated user has permission to access a specific resource. Authentication is the separate step of validating the user identity, while Single Sign-On manages the session.
More Microsoft Security, Compliance, and Identity Fundamentals (SC-900) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.