Practice for the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) exam with 15 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: In a hybrid identity model, what can you use to synchronize identities between Active Directory Domain Services (AD DS) . Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice test →
What you will practice
- In a hybrid identity model, what can you use to synchronize identities between Active Directory Domain Servic…
- ____________________________Enables collaboration with business partners from external organizations, such as…
- In the shared responsibility model for an Azure deployment, is Microsoft exclusively responsible?
- In all Azure cloud deployment types, is managing information and data security the organization's responsibil…
- Is "Assume breach" one of the guiding principles of Zero Trust?
- In software as a service (SaaS), is applying service packs to applications the responsibility of the organiza…
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. In a hybrid identity model, what can you use to synchronize identities between Active Directory Domain Services (AD DS) and Azure Entra ID?
Answer: B. Azure Entra ID Connect
Azure Entra ID Connect is the dedicated tool for synchronizing on-premises directories to the cloud, making it essential for hybrid setups. Remember that federation handles authentication pass-through, while PIM and Sentinel serve completely different security functions.
Q2. ____________________________Enables collaboration with business partners from external organizations, such as suppliers, partners, and vendors. External users appear as guest users in the directory.
Answer: C. Azure Entra ID business-to-business (B2B)
Azure Entra ID B2B is designed specifically for collaborating with external partners by inviting them as guests into your primary directory. B2C handles consumer identity access for applications, while forest trusts are strictly for on-premises scenarios.
Q3. In the shared responsibility model for an Azure deployment, is Microsoft exclusively responsible?
Answer: A. Managing the physical hardware
The cloud provider is always exclusively responsible for managing the physical hardware, datacenters, and host network. The customer remains responsible for configuring user permissions and managing their own stored data.
Q4. In all Azure cloud deployment types, is managing information and data security the organization's responsibility?
Answer: B. Yes
The customer is always responsible for managing their own information and data security across any deployment model. A reliable exam rule is that data accountability never shifts to the provider.
Q5. Is "Assume breach" one of the guiding principles of Zero Trust?
Answer: B. Yes
Yes. Assume breach is a core Zero Trust principle, meaning you should design security as if attackers are already inside the environment. Always use least privilege and encrypt sessions to limit the blast radius.
Q6. In software as a service (SaaS), is applying service packs to applications the responsibility of the organization?
Answer: A. No
No. In SaaS, the cloud provider handles all underlying maintenance, including patching and service packs. The organization is only responsible for configuring data access and managing user identities within the application.
Q7. Does the authentication of hybrid identities require the synchronization of Active Directory Domain Services (AD DS) and Azure Entra ID?
Answer: B. Yes
Authentication requires synchronized identities because the local directory hashes or pass-through connections validate cloud access. Remember that authentication configuration options in Entra ID Connect heavily depend on whether passwords or hashes are synced locally first.
Q8. In Infrastructure as a Service (IaaS), is managing the physical network the responsibility of the cloud provider?
Answer: A. Yes
Yes, the cloud provider manages the physical infrastructure, including the network, in an IaaS model. A key exam cue is that the provider always handles the physical hardware, while the customer handles operating systems and above.
Q9. For each of the following statements, select Yes if the statement is true. Otherwise, select No. Statements:
Answer: D. Yes, No, and Yes
Azure Entra ID Connect synchronizes local Active Directory identities with Azure Entra ID, which is essential for hybrid identity. A single Microsoft 365 tenant is sufficient. Synchronization between on-premises AD DS and cloud directories is required.
Q10. Complete the sentence correctly:
Answer: D. are stored only on the local device.
Biometric data in Windows Hello for Business is never transmitted to the cloud and remains strictly on the local device's hardware. Options suggesting cloud storage or device replication are incorrect because the biometric signature unlocks a private key locally.
Q11. Is Control a fundamental Microsoft privacy principle?
Answer: B. Yes
Control is one of the six core Microsoft privacy principles. Microsoft believes people should have control over their data, including the ability to access, modify, and delete it. Remember these foundational privacy tenets for the exam.
Q12. Can Azure Entra ID Connect be used to implement hybrid identity?
Answer: A. Yes
Azure Entra ID Connect is the primary Microsoft tool designed to synchronize on-premises Active Directory identities directly with Azure Entra ID. This synchronization is the foundational mechanism required to establish a functional hybrid identity environment.
Q13. Does the Zero Trust security model assume that a firewall protects the internal network from attacks?
Answer: A. No
Zero Trust operates on the explicit assumption of breach and never trusts any implicit location like an internal network. Every access request must be continuously verified regardless of origin, moving away from traditional perimeter-only defenses.
Q14. Is Transparency a fundamental Microsoft privacy principle?
Answer: B. Yes
Transparency is a core Microsoft privacy principle. The company commits to providing clear information about data practices so users can make informed choices. Remember the other principles, like control and security, for your exam.
Q15. ____________ is a file that makes the data in the file readable and usable to viewers who have the appropriate key. Archiving
Answer: B. Encryption
Encryption uses cryptographic keys to make data readable only to authorized users who possess the correct key. For the exam, remember that archiving is simply long-term storage and does not provide data readability controls.
More Microsoft Security, Compliance, and Identity Fundamentals (SC-900) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.