Microsoft Security, Compliance, and Identity Fundamentals (SC-900) Practice Exam – Part 12/13

Practice for the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) exam with 15 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: For each of the following statements, select "Yes" if the statement is true. Otherwise, select "No". Statements:. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice test →

What you will practice

  • For each of the following statements, select "Yes" if the statement is true. Otherwise, select "No". Statemen…
  • Complete the sentence: "[__________] is a cloud-based solution that leverages signals from on-premises Active…
  • What type of identity is created when you register an application in Microsoft Entra ID?
  • An Azure resource can use a system-assigned [______________________] to access Azure services.
  • When security defaults are enabled in a Microsoft Entra ID tenant, which two requirements are applied?
  • Which feature of Microsoft Entra ID can you use to provide just-in-time (JIT) access to manage Azure resource…

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. For each of the following statements, select "Yes" if the statement is true. Otherwise, select "No". Statements:

Answer: G. Yes, no, and yes

Conditional Access policies apply to all users including global admins and evaluate device platform signals, but they are enforced only after primary authentication succeeds. Remember that the policy enforcement happens post-authentication.

Q2. Complete the sentence: "[__________] is a cloud-based solution that leverages signals from on-premises Active Directory to identify, detect, and investigate advanced threats."

Answer: D. Microsoft Defender for Identity

Microsoft Defender for Identity uses on-premises Active Directory signals to detect advanced threats like lateral movement. The other Defender solutions focus on endpoints, email, or cloud apps rather than on-premises AD integration.

Q3. What type of identity is created when you register an application in Microsoft Entra ID?

Answer: D. Service principal

Registering an application creates a service principal, which lets the app authenticate and access resources. Managed identities are special service principals automatically managed by Azure for specific resources.

Q4. An Azure resource can use a system-assigned [______________________] to access Azure services.

Answer: A. Managed identity

A system-assigned managed identity lets an Azure resource authenticate to Entra ID without storing credentials. Service principals require manual secrets, so they fail the automatic access requirement.

Q5. When security defaults are enabled in a Microsoft Entra ID tenant, which two requirements are applied?

Answer: B,E. Registration for MFA is required for all users. || Administrators must always use multifactor authentication (MFA).

Security defaults enforce MFA registration for everyone and require administrators to perform MFA on every sign-in. Passwordless or specific device logins are not globally forced by this baseline protection.

Q6. Which feature of Microsoft Entra ID can you use to provide just-in-time (JIT) access to manage Azure resources? Correct answer

Answer: A. Microsoft Entra ID Privileged Identity Management (PIM)

Privileged Identity Management provides time-based and approval-based activation to grant temporary access. Conditional Access controls sign-in requirements but does not manage role activation.

Q7. With which two Azure resources can a network security group (NSG) be associated?

Answer: C,D. A virtual network subnet || A network interface

Network security groups attach directly to subnets and network interfaces to filter traffic. You cannot assign an NSG to an entire virtual network or a resource group.

Q8. Select the answer that correctly completes the sentence: "[__________] requires additional verification, such as a verification code sent to a mobile phone."

Answer: C. Multifactor authentication (MFA)

Multifactor authentication requires a second verification method, like a code sent to a phone. Single sign-on simplifies access but does not inherently provide a second verification step.

Q9. Which feature of the Microsoft 365 compliance center can you use to identify all documents in a SharePoint Online site that contain a specific keyword?

Answer: D. Content search

Content search locates specific keywords across SharePoint, Exchange, and OneDrive. Compliance Manager assesses regulatory posture rather than scanning file contents.

Q10. You can use [_________________] in the Microsoft 365 Defender portal to identify devices affected by an alert. Classifications

Answer: C. Incidents

The Incidents view in the Microsoft Defender portal correlates related alerts into a single investigative scenario, exposing affected devices and users. Secure score evaluates your security posture rather than mapping active alerts to specific compromised assets.

Q11. Correctly complete the sentence: Applications registered in Microsoft Entra ID are automatically associated with a [__________].

Answer: C. Service Principal

When you register an application in Microsoft Entra ID, a service principal is automatically created in your tenant to represent that application for permissions. Managed identities are a specialized service principal type automatically managed by Azure for supported resources.

Q12. Which service includes the attack simulation training feature?

Answer: C. Microsoft Defender for Office 365

Attack simulation training is included with Microsoft Defender for Office 365 to help train users against phishing. The other Defender plans focus on SQL, identity, or cloud apps, but email threats belong to Defender for Office 365.

Q13. For which resource type can Azure Bastion provide secure access?

Answer: A. Azure virtual machines

Azure Bastion provides secure and seamless RDP and SSH access to Azure virtual machines directly from the Azure portal. It does not secure access to PaaS services like App Service or Azure SQL.

Q14. In Microsoft Sentinel, you can automate common tasks using:

Answer: B. Playbooks

Playbooks, powered by Azure Logic Apps, are used in Microsoft Sentinel to automate responses to security incidents. Workbooks are just for visualization, and hunting tools are strictly for manual threat probing.

Q15. Which three tasks can be performed with Microsoft Entra ID Identity Protection?

Answer: A,B,C. Investigate risks related to user authentication. || Automate the detection and remediation of identity-based risks. || Export risk detections to third-party tools.

Identity Protection investigates user risk, automates remediation through policies, and exports risk data to third-party SIEMs. Configuring external partner access is handled by Entra B2B, not Identity Protection.

More Microsoft Security, Compliance, and Identity Fundamentals (SC-900) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top