Microsoft Security, Compliance, and Identity Fundamentals (SC-900) Practice Exam – Part 8/9

Practice for the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) exam with 16 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Can Microsoft Intune be used to manage Android devices?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice test →

What you will practice

  • Can Microsoft Intune be used to manage Android devices?
  • Your company is planning to use Microsoft Entra ID Privileged Identity Management. Can Privileged Identity Ma…
  • Your company is planning to use Azure cloud services. They are looking at the concept of the Zero Trust princ…
  • Which option provides best practices from Microsoft employees, partners, and customers, including tools and g…
  • Does applying system updates increase an organization's secure score in Microsoft Defender for Cloud?
  • Can Microsoft Intune be used to provision Azure subscriptions?

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. Can Microsoft Intune be used to manage Android devices?

Answer: A. Yes

Yes, Microsoft Intune fully supports managing Android devices through native enrollment and Android Enterprise profiles. This allows administrators to enforce security compliance and separate personal data from corporate data effectively.

Q2. Your company is planning to use Microsoft Entra ID Privileged Identity Management. Can Privileged Identity Management be used to provide time-bound assignments for Azure resources?

Answer: A. Yes

Privileged Identity Management provides time-based access to Azure resources by enabling just-in-time role assignments. For the exam, remember that PIM limits standing privileges rather than permanently granting administrative access.

Q3. Your company is planning to use Azure cloud services. They are looking at the concept of the Zero Trust principle. Is verify explicitly a principle of Zero Trust?

Answer: A. Yes

Verify explicitly is a core principle of Zero Trust, requiring authentication and authorization for every access request. This approach evaluates all data points to ensure strict security before granting access.

Q4. Which option provides best practices from Microsoft employees, partners, and customers, including tools and guidance to assist with Azure deployment?

Answer: A. The Microsoft Cloud Adoption Framework for Azure

The Microsoft Cloud Adoption Framework for Azure provides proven best practices, tools, and guidance for planning and deploying Azure solutions. For the exam, remember that Azure Policy is for governance, while this framework handles the broader cloud adoption journey.

Q5. Does applying system updates increase an organization's secure score in Microsoft Defender for Cloud?

Answer: B. Yes

Applying system updates directly increases your secure score because it remediates an active vulnerability recommendation. A strong exam cue is associating remediation steps with positive score impacts in Defender for Cloud.

Q6. Can Microsoft Intune be used to provision Azure subscriptions?

Answer: A. No

Microsoft Intune is used for mobile device and application management, not for provisioning Azure subscriptions. Subscriptions are billing and administrative boundaries managed through the Azure portal.

Q7. Your company is planning to use Azure cloud services. They are looking at the different security aspects regarding Microsoft privacy. Is Transparency one of the main Microsoft privacy principles?

Answer: A. Yes

Transparency is indeed one of the foundational Microsoft privacy principles. The others are control, strong legal protections, security, and no content-based targeting.

Q8. You are planning to use the Azure Firewall service. Can you use the Azure Firewall service to encrypt inbound network traffic to Azure virtual machines?

Answer: A. No

Azure Firewall filters network traffic but does not encrypt it; encryption requires services like VPN Gateways or Azure Virtual Network Encryption. Firewalls focus on threat prevention and routing.

Q9. Your company is currently looking to use the Azure Policy service. Can the Azure Policy service be used to remediate issues detected through its compliance checks?

Answer: A. Yes

Azure Policy can automatically remediate non-compliant resources using built-in effects like deployIfNotExists or modify. This ensures environments continuously meet your corporate standards.

Q10. Your company is planning to use Microsoft Defender for Endpoint. Can you use Microsoft Defender for Endpoint to protect Windows 10 computers?

Answer: B. Yes

Yes, Microsoft Defender for Endpoint protects Windows 10 computers by providing advanced threat protection, including endpoint detection and response. For the exam, associate Defender for Endpoint with securing client operating systems like Windows.

Q11. Does enabling multi-factor authentication (MFA) increase an organization's secure score in Microsoft Defender for Cloud?

Answer: B. Yes

Yes, enabling MFA increases your secure score because it is a critical security control that protects user accounts. The secure score evaluates your configuration against best practices, and enabling MFA directly aligns with those recommended baseline security configurations.

Q12. Can Windows Hello for Business use a PIN code as an authentication method?

Answer: B. Yes

Yes, Windows Hello for Business uses a PIN as user-provided entropy to unlock a cryptographic key stored in the Trusted Platform Module. Unlike a password, the PIN is local to the specific device and never travels across networks.

Q13. Do all editions of Azure Entra ID licenses include the same features?

Answer: B. No

No, Microsoft Entra ID has multiple tiers like Free, Premium P1, and Premium P2, each offering progressively advanced features. Higher tiers include capabilities like conditional access and identity protection, which are unavailable in the free version.

Q14. Can you create one Azure Bastion per virtual network?

Answer: A. Yes

Yes, Azure Bastion is deployed directly into a virtual network to provide secure RDP and SSH access without public IP addresses. You provision one Bastion host per virtual network to enable seamless and secure browser-based connectivity to your virtual machines.

Q15. Are Windows Hello for Business authentication credentials synchronized across all devices registered by a user?

Answer: B. No

No, the biometric and PIN credentials are stored locally and independently on each specific device. This design ensures that a compromise of one laptop or phone does not expose the user's authentication keys on their other registered hardware.

Q16. Your company is planning to use Microsoft Entra ID Identity Protection. Can you use Microsoft Entra ID Identity Protection to provide access to resources in Azure?

Answer: B. Yes

Identity Protection evaluates user and sign-in risk to enforce Conditional Access policies, securing access to Azure resources. It does not grant access directly, but works through Conditional Access to block risky authentications.

More Microsoft Security, Compliance, and Identity Fundamentals (SC-900) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top