Microsoft Security, Compliance, and Identity Fundamentals (SC-900) Practice Exam – Part 4/6

Practice for the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) exam with 15 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which Microsoft Entra ID feature can you use to provide Just-in-Time (JIT) access to manage Azure resources?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice test →

What you will practice

  • Which Microsoft Entra ID feature can you use to provide Just-in-Time (JIT) access to manage Azure resources?
  • In a hybrid identity model, what can you use to synchronize identities between Active Directory Domain Servic…
  • Which Azure Entra ID feature can you use to evaluate group membership and automatically remove users who no l…
  • Which Microsoft 365 compliance feature can you use to automatically encrypt content based on specific conditi…
  • Which feature of the Microsoft 365 compliance center can you use to identify all documents on a Microsoft Sha…
  • What can you use to provide a user with a two-hour window to complete an administrative task in Azure?

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. Which Microsoft Entra ID feature can you use to provide Just-in-Time (JIT) access to manage Azure resources?

Answer: A. Microsoft Entra ID Privileged Identity Management (PIM)

Privileged Identity Management provides Just-in-Time access by allowing eligible users to temporarily activate elevated privileges. This minimizes risk compared to standing access, which is a key exam objective.

Q2. In a hybrid identity model, what can you use to synchronize identities between Active Directory Domain Services (AD DS) and Microsoft Entra ID?

Answer: B. Microsoft Entra ID Connect

Microsoft Entra Connect is the tool used to synchronize identities from on-premises Active Directory Domain Services to the cloud. It handles password hash synchronization and seamless single sign-on.

Q3. Which Azure Entra ID feature can you use to evaluate group membership and automatically remove users who no longer require membership in a group?

Answer: A. access reviews

Access reviews allow administrators to periodically verify group memberships and automatically remove users who no longer need access. Identity Protection is used for risk-based sign-in detection, not routine group membership validation.

Q4. Which Microsoft 365 compliance feature can you use to automatically encrypt content based on specific conditions?

Answer: C. sensitivity labels

Sensitivity labels can apply encryption automatically when specific content conditions or sensitive data types are detected. Retention policies handle data deletion and lifecycle management rather than encryption.

Q5. Which feature of the Microsoft 365 compliance center can you use to identify all documents on a Microsoft SharePoint Online site that contain a specific keyword?

Answer: C. Content Search

The Content Search tool locates specific documents across Microsoft 365 locations like SharePoint Online using targeted keyword queries. Auditing tracks logged user actions rather than searching for specific file contents.

Q6. What can you use to provide a user with a two-hour window to complete an administrative task in Azure?

Answer: C. Microsoft Entra ID Privileged Identity Management (PIM)

Microsoft Entra ID Privileged Identity Management provides just-in-time access by letting eligible users activate administrative roles for a specific, time-bound window. Conditional Access is a strong distractor, but it enforces session rules rather than temporarily assigning the role itself.

Q7. Which two are features of Microsoft Defender for Endpoint?

Answer: B,D. Automated investigation and remediation || Attack surface reduction

Automated investigation and remediation, along with attack surface reduction, are core endpoint protection capabilities of Microsoft Defender for Endpoint. Shadow IT discovery is a distractor because it belongs to Microsoft Defender for Cloud Apps, not the endpoint solution.

Q8. Conditional Access policies can be used to block access to an application based on the user's location.

Answer: A. Yes

Conditional Access uses signals like network location to allow, block, or require multi-factor authentication for specific applications. Administrators frequently create location-based policies to block access entirely from unauthorized or high-risk countries.

Q9. Conditional Access policies can trigger Multi-Factor Authentication (MFA) if a user attempts to access a specific application.

Answer: A. Yes

Conditional Access can enforce Multi-Factor Authentication when users target specific cloud applications, adding dynamic verification upon access. This ensures sensitive applications require stronger identity assurance during the sign-in event.

Q10. Can a Microsoft Entra ID user be assigned only one role?

Answer: A. No

A Microsoft Entra ID user can be assigned multiple roles to grant different levels of access. For the exam, remember that role assignments are additive and not mutually exclusive.

Q11. Compliance Manager can be accessed directly from the:

Answer: C. Microsoft 365 compliance center.

Compliance Manager is accessed directly through the Microsoft Purview compliance portal, formerly the Microsoft 365 compliance center. The Defender portal is used for security operations instead of compliance tasks.

Q12. What is the purpose of Microsoft Entra ID Password Protection?

Answer: D. to prevent users from using specific words in their passwords

Microsoft Entra ID Password Protection prevents users from creating passwords containing easily guessed or banned terms. It expands native password policies beyond complexity rules by blocking weak custom words.

Q13. Which Microsoft 365 feature can you use to restrict communication and information sharing between members of two departments in your organization?

Answer: D. Information barriers

Information barriers restrict communication and collaboration between specific groups to prevent conflicts of interest. Sensitivity labels classify and protect data but do not block users from interacting.

Q14. What can you use to provision Azure resources across multiple subscriptions consistently?

Answer: B. Azure Blueprints

Azure Blueprints orchestrates deploying resources and policies consistently across multiple subscriptions. While Azure Policy enforces rules on existing resources, Blueprints packages those artifacts for repeatable deployments.

Q15. Microsoft Entra ID Identity Protection can be used to invoke multi-factor authentication based on a user's risk level.

Answer: A. Yes

Microsoft Entra ID Identity Protection uses risk policies to automatically challenge users with multi-factor authentication when their session appears risky. Remember that Identity Protection is the primary engine for risk-based MFA.

More Microsoft Security, Compliance, and Identity Fundamentals (SC-900) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top