Practice for the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) exam with 15 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Correctly complete the sentence: "Microsoft Defender for Identity can identify advanced threats from [__________] signal. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice test →
What you will practice
- Correctly complete the sentence: "Microsoft Defender for Identity can identify advanced threats from [_______…
- Which Microsoft Entra ID feature can you use to restrict Microsoft Intune-managed devices from accessing corp…
- Which two Azure resources can be associated with a network security group (NSG)?
- What should you use in the Microsoft Defender portal to view security trends and track the protection status…
- Which Microsoft Defender for Endpoint feature provides the first line of defense against cyber threats by red…
- Which feature provides the extended detection and response (XDR) capability of Microsoft Sentinel?
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. Correctly complete the sentence: "Microsoft Defender for Identity can identify advanced threats from [__________] signals."
Answer: C. On-premises Active Directory Domain Services (AD DS)
Microsoft Defender for Identity analyzes on-premises Active Directory Domain Services signals to detect advanced threats. It does not monitor cloud identities directly, which is handled by Microsoft Entra ID Protection.
Q2. Which Microsoft Entra ID feature can you use to restrict Microsoft Intune-managed devices from accessing corporate resources?
Answer: B. Conditional Access policies
Conditional Access policies evaluate device compliance and other signals to allow or block access. For the exam, remember that PIM only governs privileged role activation, while NSGs filter network traffic rather than authentication.
Q3. Which two Azure resources can be associated with a network security group (NSG)?
Answer: A,C. a virtual network subnet || a network interface
Network security groups attach to subnets or network interfaces to filter network traffic. They are not associated with entire virtual networks or resource groups, which is a common exam trap.
Q4. What should you use in the Microsoft Defender portal to view security trends and track the protection status of identities?
Answer: A. Reports
The Reports section in the Microsoft Defender portal provides dashboards for tracking security trends and protection statuses. Incidents are used for managing active alerts and investigating attacks, not for viewing long-term trends.
Q5. Which Microsoft Defender for Endpoint feature provides the first line of defense against cyber threats by reducing the attack surface?
Answer: A. Network protection
Network protection acts proactively to block access to dangerous domains, shrinking the attack surface before threats execute. The other options handle post-detection activities like investigation and remediation.
Q6. Which feature provides the extended detection and response (XDR) capability of Microsoft Sentinel?
Answer: D. Integration with Microsoft 365 Defender
Integrating with Microsoft 365 Defender brings XDR capabilities by correlating signals across endpoints and email. While threat hunting is supported, the specific XDR feature comes from this integration.
Q7. By enabling security defaults in Entra ID, [ ________ ] will be enabled for all Microsoft Entra ID users.
Answer: B. Multifactor authentication (MFA)
Enabling security defaults automatically requires all users to register for and use multifactor authentication. It does not enable premium features like Identity Protection or PIM.
Q8. Which type of alert can you manage from the Microsoft 365 Defender portal?
Answer: C. Microsoft Defender for Endpoint
The Microsoft 365 Defender portal centralizes endpoint alerts for investigation and remediation. Cloud workload alerts like SQL or Storage are managed in Microsoft Defender for Cloud.
Q9. Which two Azure resources can a network security group (NSG) be associated with? Each correct answer presents a complete solution.
Answer: A,E. a virtual network subnet || a network interface
Network security groups attach directly to virtual network subnets or individual network interfaces to filter traffic. They cannot be assigned to resource groups or entire virtual networks, which is a common exam trap.
Q10. With a Microsoft 365 E3 subscription, how long are audit logs retained in the unified audit log and Standard Audit?
Answer: C. 180 days
Microsoft 365 E3 includes Standard Audit, which currently retains unified audit logs for 180 days. Remember this updated retention limit, as older documentation might incorrectly point to the previous 90-day default.
Q11. When using multi-factor authentication (MFA), a password is considered something you [ ___________________ ].
Answer: C. know
A password represents something you know in multi-factor authentication. For the exam, recall the other two factors: something you have, like a token, and something you are, like biometrics.
Q12. You need to connect to an Azure virtual machine using Azure Bastion. What should you use?
Answer: D. The Azure portal
Azure Bastion provides secure RDP and SSH access directly through the Azure portal over TLS. Because the connection happens in the browser, you do not need standalone remote desktop or SSH clients.
Q13. Complete the sentence:
Answer: C. Microsoft 365 compliance center
The Microsoft Purview compliance portal provides the central hub for information protection, governance, and data loss prevention. Although the Microsoft 365 compliance center name is legacy, it remains the intended answer over device management portals.
Q14. Select the answer that correctly completes the sentence: "[__________________] is a native cloud solution for SIEM (security information and event management) and SOAR (security orchestration automated response), used to provide a single s…
Answer: B. Azure Sentinel
Azure Sentinel, now officially named Microsoft Sentinel, is the cloud-native SIEM and SOAR solution. While the product name changed, the concept remains identical for the exam.
Q15. Regarding Advanced Audit in Microsoft 365, select Yes or No for each statement:
Answer: G. Yes, yes, and no
Advanced Audit provides longer log retention and dedicated bandwidth, and allows tracking email access. Standard auditing lacks these premium capabilities, making the retention period different between the tiers.
More Microsoft Security, Compliance, and Identity Fundamentals (SC-900) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.