Microsoft Security, Compliance, and Identity Fundamentals (SC-900) Practice Exam – Part 15/15

Practice for the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) exam with 18 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Can Microsoft Defender for Cloud detect vulnerabilities and threats for Azure Storage?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice test →

What you will practice

  • Can Microsoft Defender for Cloud detect vulnerabilities and threats for Azure Storage?
  • What can you use to ensure that all users in a specific group use multi-factor authentication (MFA) to access…
  • Which security feature is available in the free tier of Microsoft Defender for Cloud?
  • What can be created in Active Directory Domain Services (AD DS)?
  • What should you use to ensure that members of a Microsoft Entra ID group use multi-factor authentication (MFA…
  • Microsoft Sentinel provides quick insights into data by using:

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. Can Microsoft Defender for Cloud detect vulnerabilities and threats for Azure Storage?

Answer: A. Yes

Defender for Cloud includes Azure Storage security features that detect vulnerabilities and threats. Microsoft Defender for Storage specifically scans for malicious file uploads and sensitive data exposure.

Q2. What can you use to ensure that all users in a specific group use multi-factor authentication (MFA) to access Microsoft Entra ID?

Answer: B. A Conditional Access policy

Conditional Access policies enforce MFA requirements based on group assignments. Azure Policy manages Azure resource configurations, while security defaults apply MFA to all users without group targeting.

Q3. Which security feature is available in the free tier of Microsoft Defender for Cloud?

Answer: D. Secure Score

The free tier provides Secure Score to evaluate your security posture. Advanced threat protection, JIT access, and vulnerability scanning require Microsoft Defender plans enabled on the subscription.

Q4. What can be created in Active Directory Domain Services (AD DS)?

Answer: B. Computer accounts

AD DS manages traditional network identities like computer accounts within an on-premises environment. Modern application authentication and SaaS integrations rely on Microsoft Entra ID rather than AD DS.

Q5. What should you use to ensure that members of a Microsoft Entra ID group use multi-factor authentication (MFA) when signing in?

Answer: D. A Conditional Access policy

A Conditional Access policy targets specific groups to enforce MFA during sign-in. PIM only manages elevated privileged roles, while Azure RBAC handles resource authorization rather than authentication.

Q6. Microsoft Sentinel provides quick insights into data by using:

Answer: C. Azure Monitor workbook templates.

Azure Monitor workbook templates provide interactive dashboards for visualizing data and gaining quick insights. Playbooks automate incident response, while Azure Logic Apps serve as their underlying automation engine.

Q7. What is a function of session controls in Conditional Access?

Answer: B. Enable limited experiences, such as blocking downloads of sensitive information

Session controls limit what users can do during an active connection, like blocking downloads on unmanaged devices. Requiring MFA is a grant control, while device compliance is evaluated as a condition.

Q8. Can Microsoft Defender for Cloud assess the security of workloads deployed in Azure or on-premises?

Answer: B. Yes

Microsoft Defender for Cloud provides hybrid security, protecting workloads across both cloud and on-premises environments. Azure Arc enables this extended visibility, letting you secure servers regardless of location.

Q9. What can you use to view the Secure Score for devices?

Answer: C. Microsoft Defender for Endpoint

Microsoft Defender for Endpoint provides the Secure Score for devices, assessing endpoint security configurations. The other Defender options focus on email, cloud apps, or identity protection rather than device configuration.

Q10. What are customers responsible for when assessing security in a SaaS (Software as a Service) cloud service model?

Answer: C. Accounts and identities

In the SaaS shared responsibility model, the provider manages operating systems, applications, and network controls. The customer remains solely responsible for data, accounts, and identity management.

Q11. Which three authentication methods can Azure AD (Entra ID) users use to reset their passwords?

Answer: A,B,D. Text message to a phone || Mobile app notification || Security questions

Self-service password reset verifies identity using methods like mobile app notifications, text messages, and security questions. Certificates and picture passwords are not valid SSPR authentication methods.

Q12. Select two cards available in the Microsoft 365 Defender portal.

Answer: C,D. Users at risk || Devices at risk

Microsoft 365 Defender displays cards for risky users and devices based on active threat analytics. Compliance score and user management are portal features for Microsoft Purview, not the Defender portal.

Q13. What can you protect when using the information protection solution in the Microsoft 365 compliance center?

Answer: B. Sensitive data against exposure to unauthorized users

Information protection classifies and protects sensitive data from unauthorized access. The other options represent threat protection features handled by Microsoft Defender services, not data compliance solutions.

Q14. Match the Microsoft Defender for Office 365 features to their corresponding descriptions:

Answer: A. Threat Trackers → Provides intelligence on top current cybersecurity issues

Threat Trackers provide security admins with intelligence on the latest cybersecurity issues. Threat Explorer is used for real-time threat analysis, while anti-phishing protection detects spoofing and impersonation attempts targeting users.

Q15. For each of the following statements, select "Yes" if it is true. Otherwise, select "No". Statements:

Answer: G. No, yes, and yes

Compliance Manager tracks both Microsoft-managed and customer-managed controls, making the first statement false. It offers regulatory templates and assesses data against privacy standards like GDPR, making the remaining statements true.

Q16. For each statement, select "Yes" if it is true. Otherwise, select "No". Statements:

Answer: G. Yes, no, and yes

Azure Entra ID B2C supports social logins and custom branding. However, it uses a separate directory from a standard Azure Entra ID tenant, meaning external consumers are not mixed with internal organizational users.

Q17. A [_______________] system is a tool that collects data from multiple systems, identifies correlations or anomalies, and generates alerts and incidents.

Answer: E. of security information and event management (SIEM)

A SIEM collects, correlates, and analyzes log data across systems to generate actionable security alerts. SOAR handles automated response, while TAXII is strictly a threat intelligence sharing protocol.

Q18. Match the Microsoft 365 insider risk management workflow stage to the corresponding task.

Answer: F. Triage → Review and filter alerts

The triage stage involves reviewing and filtering generated alerts to determine their validity. The investigate stage is where analysts create formal cases for deeper analysis and action.

More Microsoft Security, Compliance, and Identity Fundamentals (SC-900) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top