Microsoft Security, Compliance, and Identity Fundamentals (SC-900) Practice Exam – Part 2/3

Practice for the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) exam with 15 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Azure Policy supports automatic remediation.. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice test →

What you will practice

  • Azure Policy supports automatic remediation.
  • What is a use case for implementing information barrier policies in Microsoft 365?
  • What can you use to scan email attachments and forward them to recipients only if the attachments are free of…
  • In the Microsoft Cloud Adoption Framework for Azure, which two phases are addressed before the Ready phase?
  • Can Microsoft Secure Score in the Microsoft 365 security center provide recommendations for Microsoft Cloud A…
  • Does compliance evaluation in Azure Policy occur only when a target resource is created or modified?

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. Azure Policy supports automatic remediation.

Answer: A. Yes

Azure Policy supports automatic remediation by triggering deployment scripts to fix non-compliant resources. This feature enforces governance standards without requiring manual intervention for newly created or existing resources.

Q2. What is a use case for implementing information barrier policies in Microsoft 365?

Answer: B. To restrict Microsoft Teams chats between certain groups within an organization

Information barriers restrict communication between specific groups to prevent conflicts of interest. The exam focuses on Teams chats and SharePoint, though Exchange email is technically affected too, making the intent the key differentiator.

Q3. What can you use to scan email attachments and forward them to recipients only if the attachments are free of malware?

Answer: C. Microsoft Defender for Office 365

Microsoft Defender for Office 365 uses Safe Attachments to scan files in a virtual environment before delivery. Defender for Endpoint handles endpoint threats, while Defender for Identity monitors on-premises signals.

Q4. In the Microsoft Cloud Adoption Framework for Azure, which two phases are addressed before the Ready phase?

Answer: B,E. Define strategy || Plan

The Microsoft Cloud Adoption Framework starts with the Define Strategy and Plan phases before reaching the Ready phase. A practical exam tip is to remember the lifecycle order: Strategy, Plan, Ready, Adopt, and Govern.

Q5. Can Microsoft Secure Score in the Microsoft 365 security center provide recommendations for Microsoft Cloud App Security?

Answer: A. Yes

Microsoft Secure Score provides actionable recommendations across various services, including Microsoft Cloud App Security. Secure Score aggregates configuration states to measure and improve an organization's overall security posture across workloads.

Q6. Does compliance evaluation in Azure Policy occur only when a target resource is created or modified?

Answer: A. No

Azure Policy compliance evaluation also occurs during an on-demand scan or when a policy is assigned. It is not strictly limited to resource creation or modification, ensuring continuous monitoring of your environment for governance.

Q7. Can the secure score in Azure Security Center assess resources across multiple Azure subscriptions?

Answer: A. Yes

Yes, the secure score evaluates resources across multiple Azure subscriptions. For the exam, remember that this aggregation provides a comprehensive view of your overall security posture, though the service is now known as Microsoft Defender for Cloud.

Q8. Is shared responsibility a fundamental privacy principle of Microsoft?

Answer: B. No

No, shared responsibility is a security and governance model dictating cloud obligations between Microsoft and the customer. The actual six fundamental Microsoft privacy principles are control, transparency, security, no content-based targeting, legal protection, and benefits.

Q9. Does applying system updates increase an organization's secure score in Azure Security Center?

Answer: B. Yes

Yes, applying system updates directly increases your secure score by resolving vulnerability recommendations. On the exam, remember that completing recommended remediation tasks, like patch management, actively raises your security posture.

Q10. Is transparency a fundamental privacy principle of Microsoft?

Answer: B. Yes

Yes, transparency is a core Microsoft privacy principle. The company commits to being clear about data collection and usage. Expect to memorize the six privacy principles, as they are foundational for the compliance portion.

Q11. Is verify explicitly one of the guiding principles of Zero Trust?

Answer: B. Yes

Yes, verify explicitly is a core Zero Trust principle. It means authenticating and authorizing based on all available data points. Remember the three Zero Trust principles: verify explicitly, use least privilege access, and assume breach.

Q12. For which type of resource can Azure Bastion provide secure access?

Answer: B. Azure virtual machines

Azure Bastion provides secure and seamless RDP and SSH access to Azure virtual machines directly over TLS. It does not provide remote connectivity for databases or web apps, eliminating the strongest distractors.

Q13. Does the Zero Trust security model assume that a firewall protects the internal network from external threats?

Answer: B. No

No, Zero Trust assumes breach and never trusts anything by default, even behind a firewall. Traditional perimeter security relies on firewalls, but Zero Trust requires continuous verification for every request regardless of origin.

Q14. Does hybrid identity require the implementation of two Microsoft 365 tenants?

Answer: A. No

No, hybrid identity connects an on-premises Active Directory environment with Microsoft Entra ID using a single tenant. Tools like Entra Connect sync identities, allowing users to access both cloud and local resources seamlessly.

Q15. Can you manage an Azure Entra ID tenant using the Azure portal?

Answer: A. Yes

Yes, you can manage an Azure Entra ID tenant directly within the Azure portal. This portal provides a unified interface where administrators can handle directory objects, users, and groups. The Microsoft Entra admin center is another valid interface.

More Microsoft Security, Compliance, and Identity Fundamentals (SC-900) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top