Microsoft Security, Compliance, and Identity Fundamentals (SC-900) Practice Exam – Part 3/3

Practice for the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) exam with 15 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: All editions of Microsoft Entra ID licenses include the same features.. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice test →

What you will practice

  • All editions of Microsoft Entra ID licenses include the same features.
  • Is assuming breach one of the guiding principles of Zero Trust?
  • It is used to identify, hold, and export electronic information that can be used in an investigation:
  • It is the process of identifying whether a signed-in user can access a specific resource:
  • Does the digital signature of a document require a private key?
  • Federation is used to establish __________________ between organizations.

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. All editions of Microsoft Entra ID licenses include the same features.

Answer: A. No

The correct answer is No because Microsoft Entra ID editions like Free, P1, and P2 offer different capabilities. For the exam, remember that advanced features such as Conditional Access and Identity Protection require the premium P1 or P2 tiers.

Q2. Is assuming breach one of the guiding principles of Zero Trust?

Answer: A. Yes

The correct answer is Yes because assuming breach is a core guiding principle of Zero Trust. For the exam, pair this with the verify explicitly principle, which ensures users and devices are continuously authenticated rather than trusted by default.

Q3. It is used to identify, hold, and export electronic information that can be used in an investigation:

Answer: A. Electronic Discovery (eDiscovery)

eDiscovery is used to identify, hold, and export electronic information for legal or internal investigations. Data Loss Prevention prevents sensitive data sharing, while Customer Lockbox controls Microsoft engineer access.

Q4. It is the process of identifying whether a signed-in user can access a specific resource:

Answer: C. Authorization

Authorization determines whether an authenticated user has the necessary permissions to access a specific resource. Authentication merely verifies user identity, while single sign-on simplifies the login prompt process.

Q5. Does the digital signature of a document require a private key?

Answer: A. Yes

A digital signature requires a private key to ensure authenticity and integrity. The corresponding public key is then used by recipients to validate the signature and confirm the document origin.

Q6. Federation is used to establish __________________ between organizations.

Answer: A. a trust relationship

Federation establishes a trust relationship between organizations, allowing secure sharing of identity information. Account synchronization is handled by directory sync tools, not by establishing a federation trust.

Q7. Hybrid identity refers to synchronizing Active Directory Domain Services (AD DS) and Azure Entra ID.

Answer: A. Yes

Hybrid identity synchronizes Active Directory Domain Services with Azure Entra ID to provide a common identity. This synchronization allows users to access both cloud and on-premises resources seamlessly.

Q8. Azure Entra ID Connect can be used to implement hybrid identity.

Answer: A. Yes

Azure Entra Connect synchronizes identities between on-premises Active Directory and Azure Entra ID. This tool is the primary Microsoft solution for configuring and maintaining a hybrid identity environment.

Q9. Does verifying the authenticity of a digitally signed document require the signer's public key?

Answer: A. Yes

Verifying a digital signature requires the signer's public key to mathematically confirm the signature was created with the matching private key. Public key cryptography ensures secure validation without exposing the private key.

Q10. You have a Microsoft 365 E3 subscription. You plan to audit user activity using the unified audit log and Basic Auditing. How long will the audit records be retained?

Answer: C. 180 days

With Basic Auditing in a standard Microsoft 365 E3 subscription, audit records are retained for 180 days. Advanced Audit, typically licensed via E5, extends this retention period to a full year for long-term compliance needs.

Q11. What can you use to provide threat detection for Azure SQL Managed Instance?

Answer: C. Azure Defender

Microsoft Defender for Cloud provides advanced threat detection for Azure SQL Managed Instances. Although the older name Azure Defender appears, it correctly identifies the service. Secure Score only evaluates configurations, not live threats.

Q12. Which of the following admin centers can you use to manage Microsoft Intune?

Answer: A. Microsoft Endpoint Manager admin center

The Microsoft Endpoint Manager admin center is the dedicated interface for managing Intune policies and devices. Note that Microsoft has renamed this to the Intune admin center, so a modern exam might use that updated terminology.

Q13. Is control a fundamental privacy principle of Microsoft?

Answer: B. Yes

Control is indeed one of the six foundational Microsoft privacy principles, meaning users should have control over their data. The other principles are security, transparency, compliance, no content-based targeting, and legal protections.

Q14. Fill in the blank: Provides reference recommendations and guidance for securing Azure services. Azure Network Watcher

Answer: B. Security baselines for Azure

Security baselines for Azure provide reference recommendations and guidance to help secure your Azure services. The distractors are monitoring tools, whereas security baselines specifically focus on applying cloud security best practices and hardening configurations.

Q15. Which of the following enables collaboration with business partners from external organizations like suppliers, partners, and vendors, where external users appear as guest users in the directory?

Answer: B. Azure Entra ID business-to-business (B2B)

Microsoft Entra ID business-to-business allows external users to collaborate as guests in your directory. Use Entra ID B2C for consumer applications, not business partner collaboration. Formatting here is messy, but the concept holds.

More Microsoft Security, Compliance, and Identity Fundamentals (SC-900) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top