Microsoft Security, Compliance, and Identity Fundamentals (SC-900) Practice Exam – Part 6/6

Practice for the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) exam with 14 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Conditional Access policies can be applied to global administrators.. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice test →

What you will practice

  • Conditional Access policies can be applied to global administrators.
  • Perform a system access audit:
  • Make configuration changes in response to a security incident.
  • Encrypt data at rest:
  • You can use ______________ in the Microsoft 365 security center to view an aggregation of alerts related to t…
  • Microsoft Secure Score measures progress in completing actions based on controls that include regulations and…

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. Conditional Access policies can be applied to global administrators.

Answer: A. Yes

Conditional Access policies actively target global administrators to enforce stricter security controls like MFA. Microsoft highly recommends configuring these policies to protect your most privileged accounts.

Q2. Perform a system access audit:

Answer: C. Detective

Auditing system access is a detective control because it actively monitors and identifies irregular behaviors or potential breaches after they happen. Preventive controls instead block an event before it occurs.

Q3. Make configuration changes in response to a security incident.

Answer: A. Corrective

Making configuration changes to fix a system after a security incident is a corrective control because it attempts to reverse damage and restore operations. Detective controls only identify issues, while corrective controls resolve them.

Q4. Encrypt data at rest:

Answer: C. Preventive

Encrypting data at rest is a preventive control because it directly blocks unauthorized users from reading sensitive data if they bypass physical or network security. Detective controls only alert you after the fact.

Q5. You can use ______________ in the Microsoft 365 security center to view an aggregation of alerts related to the same attack.

Answer: C. incidents

Incidents in the Microsoft security portal aggregate multiple related alerts into a single comprehensive view of an attack. This grouping helps defenders understand the full scope of an attack rather than reviewing isolated alerts.

Q6. Microsoft Secure Score measures progress in completing actions based on controls that include regulations and standards important for data protection and governance.

Answer: B. No

Microsoft Secure Score focuses heavily on security best practices and identity configurations rather than regulatory compliance. The phrasing is tricky, but the correct answer is yes because its controls ultimately map to data protection, unlike Microsoft Compliance Manager.

Q7. Cloud Security Posture Management (CSPM) is available for all Azure subscriptions.

Answer: A. Yes

The foundational Cloud Security Posture Management features are enabled by default on all Azure subscriptions at no extra cost. Defender CSPM is an optional paid plan adding advanced risk prioritization.

Q8. __________ is a cloud-native security information and event management (SIEM) and security orchestration automated response (SOAR) solution used to provide a single solution for alert detection, threat visibility, proactive hunting, and th…

Answer: C. Microsoft Sentinel

Microsoft Sentinel is the correct cloud-native SIEM and SOAR solution for threat detection and response across the enterprise. Azure Monitor or Advisor focus on infrastructure health and best practices rather than comprehensive security incident management.

Q9. You can use ________________________ in the Microsoft 365 security center to identify the devices affected by an alert.

Answer: A. incidents

Incidents in the Microsoft Defender portal group related alerts and affected entities, such as devices, into a single view for investigation. Policies are configuration rules, not active alert aggregators.

Q10. What requires additional verification, such as a verification code sent to a mobile phone?

Answer: C. Multi-Factor Authentication (MFA)

Multi-Factor Authentication requires an additional verification factor, like a code sent to a mobile device, on top of the primary password. Pass-through authentication simply validates passwords against your on-premises Active Directory without requiring this extra step.

Q11. Microsoft Entra ID is ___________________ used for authentication and authorization.

Answer: C. an identity provider

Microsoft Entra ID acts as a cloud-based identity provider responsible for authenticating users and authorizing their access to applications. A SIEM system is a strong distractor, but that security monitoring role belongs to Microsoft Sentinel.

Q12. Conditional Access policies are evaluated before a user is authenticated.

Answer: A. No

Conditional Access policies are evaluated after the primary authentication completes but before granting access to the target application. This ensures the system can validate identity signals like location or device compliance before finalizing the session.

Q13. Microsoft Defender for Identity can identify advanced threats from __________ signals.

Answer: A. On-premises Active Directory Domain Services (AD DS)

Defender for Identity uses your on-premises Active Directory Domain Services signals to detect advanced threats. Remember that Microsoft Entra Connect is just the synchronization tool, not the primary source for these threat detections.

Q14. Compliance Manager evaluates an organization's compliance data __________.

Answer: B. continuously

Compliance Manager continuously evaluates an organization's compliance posture to provide ongoing risk assessments. Avoid options like quarterly or on demand because the platform calculates your improvement actions and baseline assessments automatically in real time.

More Microsoft Security, Compliance, and Identity Fundamentals (SC-900) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top