Practice for the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) exam with 14 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Global Administrator is a role in Microsoft Entra ID.. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice test →
What you will practice
- Global Administrator is a role in Microsoft Entra ID.
- With Windows Hello for Business, the biometric data of a user used for authentication is stored only on a loc…
- Microsoft Entra ID Identity Protection can detect if user credentials have been leaked to the public.
- What are two tasks you can implement using data loss prevention (DLP) policies in Microsoft 365?
- Sensitivity labels can add headers and footers to documents.
- What are three authentication methods that can be used by Azure multi-factor authentication (MFA)?
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. Global Administrator is a role in Microsoft Entra ID.
Answer: A. Yes
Global Administrator is the highest privileged role in Microsoft Entra ID, granting full access to manage all administrative features. Expect questions mapping default roles to their specific administrative boundaries.
Q2. With Windows Hello for Business, the biometric data of a user used for authentication is stored only on a local device.
Answer: B. stored only on a local device.
Windows Hello for Business stores biometric authentication data locally on the device and never transmits it to external servers or the cloud. This prevents the data from being intercepted or stolen remotely.
Q3. Microsoft Entra ID Identity Protection can detect if user credentials have been leaked to the public.
Answer: A. Yes
Microsoft Entra ID Identity Protection continuously monitors for leaked credentials by checking public and dark web databases against your tenant. This feature allows administrators to automatically remediate compromised users.
Q4. What are two tasks you can implement using data loss prevention (DLP) policies in Microsoft 365?
Answer: A,B. Display policy tips to users who are about to violate your organization's policies. || Protect documents in Microsoft OneDrive that contain sensitive information.
DLP policies protect sensitive data across Microsoft 365 locations like OneDrive and show policy tips before a user accidentally leaks information. Disk encryption and security baselines are device management tasks handled by Intune, not DLP.
Q5. Sensitivity labels can add headers and footers to documents.
Answer: A. Yes
Sensitivity labels can apply visual markings like headers, footers, and watermarks to clearly classify and protect documents. This feature helps users instantly identify the handling requirements for sensitive data.
Q6. What are three authentication methods that can be used by Azure multi-factor authentication (MFA)?
Answer: C,D,E. text message (SMS) || phone call || Microsoft Authenticator app
Azure MFA verifies identity using methods like the Microsoft Authenticator app, text messages, or voice calls. Security questions and standard email verification are not valid MFA verification methods under modern security standards.
Q7. _______________________________________ is a cloud-based solution that leverages on-premises Active Directory signals to identify, detect, and investigate advanced threats.
Answer: B. Microsoft Defender for Identity
Microsoft Defender for Identity uses on-premises Active Directory signals to detect and investigate advanced targeted attacks. Defender for Endpoint focuses on devices, while Cloud App Security monitors SaaS applications.
Q8. Conditional Access policies can use device state as a signal.
Answer: A. Yes
Conditional Access evaluates device state signals, such as Microsoft Intune compliance, to ensure only healthy devices access resources. This signal can enforce stricter controls like blocking access from unmanaged devices.
Q9. Is Microsoft Entra ID deployed in an on-premises environment?
Answer: A. No
Microsoft Entra ID is fundamentally a cloud-based identity and access management service rather than an on-premises directory. For the exam, remember that while it synchronizes with on-premises Active Directory via Entra Connect, the service itself runs entirely in the cloud.
Q10. A higher Microsoft Secure Score means a lower identified risk level in the Microsoft 365 tenant.
Answer: A. Yes
A higher Microsoft Secure Score indicates that you have implemented more recommended security controls, directly lowering your risk exposure. The score measures your security posture against best practices, so completing more actions drives the identified risk down.
Q11. Sensitivity labels can apply watermarks to emails.
Answer: A. Yes
Sensitivity labels from Microsoft Purview Information Protection can apply visual markings like watermarks, headers, and footers to emails and documents. This metadata helps users instantly recognize data classification and ensures organizational compliance rules are enforced.
Q12. With Advanced Auditing in Microsoft 365, you can identify when email items were accessed.
Answer: A. Yes
Advanced Auditing in Microsoft Purview provides MailItemsAccessed events to track when email items are accessed. This forensic capability is key for investigating potential data breaches.
Q13. Compliance Manager provides predefined templates for creating assessments.
Answer: A. Yes
Microsoft Purview Compliance Manager supplies predefined templates for various regulations and standards. These templates simplify the process of building assessments for your compliance needs.
Q14. Azure Bastion provides secure and seamless Remote Desktop connectivity to Azure virtual machines.
Answer: A. Yes
Azure Bastion provides seamless RDP and SSH access to virtual machines directly through the Azure portal over TLS. It eliminates the need to expose public IP addresses to the internet.
More Microsoft Security, Compliance, and Identity Fundamentals (SC-900) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.