Practice for the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) exam with 16 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which of the following is available for the Azure Application Gateway service to help protect web applications from comm. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice test →
What you will practice
- Which of the following is available for the Azure Application Gateway service to help protect web application…
- What type of identity is created when you register an application with Microsoft Entra ID?
- Can the secure score in Microsoft Defender for Cloud assess resources across multiple Azure subscriptions?
- Can network security groups (NSGs) deny outbound traffic to the Internet?
- Does Azure Bastion provide secure user connections using RDP?
- You are considering using sensitivity labels in Microsoft 365. Do sensitivity labels add a header and footer…
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. Which of the following is available for the Azure Application Gateway service to help protect web applications from common exploits and vulnerabilities?
Answer: D. Azure Web Application Firewall
Azure Web Application Firewall provides centralized protection for web applications from common vulnerabilities like SQL injection. Azure Firewall protects network layers instead of application-specific web threats.
Q2. What type of identity is created when you register an application with Microsoft Entra ID?
Answer: B. a service principal
Registering an application in Entra ID creates an application object and a corresponding service principal. The service principal is what actually gets assigned permissions to access resources.
Q3. Can the secure score in Microsoft Defender for Cloud assess resources across multiple Azure subscriptions?
Answer: B. Yes
Microsoft Defender for Cloud evaluates resources across multiple subscriptions simultaneously, providing a unified view of your security posture. This aggregation allows administrators to monitor security health across the entire organization.
Q4. Can network security groups (NSGs) deny outbound traffic to the Internet?
Answer: A. Yes
Network security groups can evaluate and block outbound traffic to the Internet using customizable security rules. This basic filtering mechanism secures virtual machines by restricting unauthorized network communication.
Q5. Does Azure Bastion provide secure user connections using RDP?
Answer: A. Yes
Azure Bastion provides secure RDP and SSH access directly through the Azure portal without exposing public IP addresses. This service simplifies remote administration while protecting virtual machines from external threats.
Q6. You are considering using sensitivity labels in Microsoft 365. Do sensitivity labels add a header and footer to the underlying Office 365 document to which the label is applied?
Answer: B. Yes
Sensitivity labels can apply visual markings like headers and footers to Office documents to indicate their protection level. This feature helps users instantly recognize data classification and handling requirements.
Q7. Which of the following encryption techniques is used to "Encrypt information residing in persistent storage on physical media"?
Answer: C. Encryption at rest
Encryption at rest protects data stored on physical media like hard drives and SSDs from unauthorized access. This differs from encryption in transit, which safeguards data actively moving across networks.
Q8. When using multi-factor authentication (MFA), a password is considered something you:
Answer: C. know
A password represents something you know, which is one of the core authentication factors. For the exam, remember the triad: something you know, something you have, and something you are.
Q9. Your company is planning to use Azure cloud services. Which of the following options can be used to ensure that data can only be read by authorized users?
Answer: C. Encryption
Encryption encodes data so only users with the correct decryption keys can read it. Deduplication and compression manage storage efficiency, but they offer no security against unauthorized reading.
Q10. A company is planning to use Azure Active Directory. Which of the following options is used to describe the exact term for Azure Entra ID?
Answer: C. Identity Provider
Microsoft Entra ID acts as an Identity Provider, managing identities and controlling access to resources. A firewall filters network traffic, while a federation server handles trust relationships but does not serve as the core identity management service.
Q11. You have an Azure subscription. You need to implement time-bound and approval-based role activation. What should you use?
Answer: C. Microsoft Entra ID Privileged Identity Management (PIM)
Privileged Identity Management provides time-bound and approval-based activation for administrative roles. Access reviews periodically validate permissions, while Identity Protection focuses on risk detection rather than managing privileged role assignments.
Q12. Your company is planning to use Azure Blueprints. Can Azure Blueprints be used to create role assignments for an Azure subscription?
Answer: B. Yes
Yes, Azure Blueprints can package role assignments, policy assignments, and resource templates together for repeatable deployments. This orchestration ensures your environment consistently complies with organizational standards every time the blueprint is applied to a new subscription.
Q13. Do you need to deploy Azure virtual machines to host a Microsoft Entra ID tenant?
Answer: A. No
No, Microsoft Entra ID is a fully managed cloud-based identity service that does not require you to deploy or maintain any virtual machines. You simply create the tenant and manage identities directly through the web-based admin center.
Q14. Which three authentication methods are supported by Windows Hello for Business?
Answer: A,C,D. Fingerprint || PIN || Facial recognition
Windows Hello for Business replaces passwords with biometric and PIN credentials. Fingerprint, facial recognition, and PINs are valid because they are tied cryptographically to the local device, unlike standard email or security question recovery methods.
Q15. Your company is planning to use Network Security Groups. Can you use network security groups to filter traffic based on IP address, protocol, and port number?
Answer: B. Yes
Yes, network security groups use rules to allow or deny inbound and outbound traffic based on source and destination IP addresses, ports, and protocols. This basic layer of filtering protects resources connected to your Azure virtual networks effectively.
Q16. Can network security groups (NSGs) deny inbound traffic from the Internet?
Answer: B. Yes
Yes, NSGs can block inbound internet traffic by creating deny rules for specific source IP ranges or service tags like Internet. This prevents unauthorized external connections from reaching your protected subnets and associated virtual machines.
More Microsoft Security, Compliance, and Identity Fundamentals (SC-900) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.