Microsoft Security, Compliance, and Identity Fundamentals (SC-900) Practice Exam – Part 14/15

Practice for the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) exam with 18 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which compliance feature should you use to identify documents that are employee resumes?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice test →

What you will practice

  • Which compliance feature should you use to identify documents that are employee resumes?
  • Select the answer that correctly completes the statement. [________________] can be used to provide Microsoft…
  • Select the answer that correctly completes the statement: [___________] is a cloud service for storing applic…
  • What is an assessment in Compliance Manager?
  • Select the answer that correctly completes the statement:
  • Which two tasks can you implement with data loss prevention (DLP) policies in Microsoft 365?

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. Which compliance feature should you use to identify documents that are employee resumes?

Answer: A. Trainable classifiers

Trainable classifiers use machine learning to identify specific types of content, such as resumes or source code. Content and Activity explorers only show where labels exist or how users interacted with data.

Q2. Select the answer that correctly completes the statement. [________________] can be used to provide Microsoft support engineers with access to an organization's data stored in Microsoft Exchange Online, SharePoint Online, and OneDrive for…

Answer: D. Customer Lockbox

Customer Lockbox provides an explicit approval workflow so organizations control when Microsoft engineers access their data for support. Privileged Access Management is for internal task approvals, not external vendor access.

Q3. Select the answer that correctly completes the statement: [___________] is a cloud service for storing application secrets.

Answer: C. Azure Key Vault

Azure Key Vault securely stores application secrets like API tokens and cryptographic keys. While Microsoft Entra ID Password Protection blocks weak passwords, it does not store application credentials.

Q4. What is an assessment in Compliance Manager?

Answer: A. A grouping of controls from a specific regulation, standard, or policy

An assessment groups controls from a specific regulation to help measure compliance. It provides a structured baseline, whereas policies enforce rules and data classification prevents sensitive sharing.

Q5. Select the answer that correctly completes the statement:

Answer: E. continuously

Compliance Manager continuously evaluates your Microsoft 365 environment against selected controls. This real-time scanning means your compliance score updates automatically rather than on a fixed monthly schedule.

Q6. Which two tasks can you implement with data loss prevention (DLP) policies in Microsoft 365?

Answer: A,C. Protect documents in Microsoft OneDrive that contain sensitive information. || Display policy tips to users who are about to violate organizational policies.

DLP policies protect sensitive items across Microsoft 365 locations and display policy tips to users before they violate rules. Device encryption and baselines are Intune features, not DLP functions.

Q7. Which identity pillar relates to tracking the resources accessed by a user?

Answer: B. Auditing

Auditing tracks user activities and records who accessed what resources within the environment. Authorization defines what permissions users have, while authentication simply verifies their identity during sign-in.

Q8. You need to keep a copy of all files from a Microsoft SharePoint site for one year, even if users delete the files from the site. What should you apply to the site?

Answer: B. A retention policy

A retention policy preserves data for a specified period, preventing permanent deletion by users. Sensitivity labels classify and encrypt data, whereas DLP focuses on preventing external data sharing.

Q9. Which Microsoft portal provides information on how Microsoft manages privacy, compliance, and security?

Answer: B. Microsoft Service Trust Portal

The Microsoft Service Trust Portal provides transparency by publishing audits, compliance reports, and security practices. The Microsoft Purview compliance portal is where you actively manage your organization's policies.

Q10. What can you specify in Microsoft 365 sensitivity labels?

Answer: B. What watermark to add to files

Sensitivity labels apply visual markings like watermarks, headers, and footers, alongside encryption. Retention policies handle data preservation timing, not sensitivity labels.

Q11. Which Microsoft 365 feature can you use to restrict users from sending email messages that contain lists of customers and their respective credit card numbers?

Answer: C. Data loss prevention (DLP) policies

Data loss prevention policies detect and block sensitive information, like credit card numbers, from being shared via email. Conditional Access controls access based on user signals rather than email content.

Q12. What does Conditional Access evaluate when using Microsoft Entra ID Identity Protection?

Answer: A. User risk

Conditional Access evaluates Identity Protection risk levels to require MFA or block access. Device compliance is a separate condition usually checked through Intune, while group membership simply targets the policy scope.

Q13. Are FIDO2 security keys an example of passwordless authentication?

Answer: B. Yes

FIDO2 security keys enable passwordless authentication using hardware-backed cryptographic credentials. Remember that passwordless methods, including Windows Hello and the Microsoft Authenticator app, never rely on a password at any step.

Q14. Which of the following statements represents a Microsoft privacy principle?

Answer: B. Microsoft respects local privacy laws applicable to its customers.

Microsoft respects local privacy laws like GDPR and LGPD as a core privacy principle. A strong exam cue is knowing Microsoft never uses enterprise customer data for targeted advertising.

Q15. You need to create a data loss prevention (DLP) policy. What should you use?

Answer: D. The Microsoft 365 compliance center

The Microsoft Purview compliance portal is the central hub for configuring DLP policies to protect sensitive data. Defender handles threats, while the admin center manages basic setup and billing.

Q16. Is Cloud Security Posture Management (CSPM) available for all Azure subscriptions?

Answer: A. Yes

The foundational Cloud Security Posture Management features are free and enabled automatically on all Azure subscriptions. Enhanced security capabilities require Microsoft Defender for Cloud plans.

Q17. Is Windows Hello an example of passwordless authentication?

Answer: B. Yes

Windows Hello uses biometrics or a local PIN tied to the device, removing the need for a traditional password. True passwordless authentication methods never rely on passwords during the sign-in process.

Q18. Are software tokens an example of passwordless authentication?

Answer: A. No

Software tokens act as a second factor but still rely on a primary password, so they do not qualify as passwordless. True passwordless authentication replaces passwords entirely with biometrics or security keys.

More Microsoft Security, Compliance, and Identity Fundamentals (SC-900) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top