Practice for the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) exam with 16 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: You need to decide on the right service to use based on the requirement. Which of the following would you use for the re. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice test →
What you will practice
- You need to decide on the right service to use based on the requirement. Which of the following would you use…
- Federation is used to establish __________ between organizations.
- Which of the following is a scalable, cloud-native, automated response, security information event management…
- Your company is planning to use Azure Entra ID for identity storage. They want to use the self-service passwo…
- You have a resource group in Azure. Can you add a delete lock to a resource that already has a read-only lock?
- In Microsoft Sentinel, you can automate common tasks using ______________
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. You need to decide on the right service to use based on the requirement. Which of the following would you use for the requirement below? Provide a secure way to RDP/SSH into Azure virtual machines
Answer: B. Azure Bastion
Azure Bastion provides secure and seamless RDP and SSH access to virtual machines directly from the Azure portal. It eliminates the need to expose public IP addresses on your virtual machines, reducing attack surfaces.
Q2. Federation is used to establish __________ between organizations.
Answer: A. a trust relationship
Federation establishes a trust relationship between organizations, allowing users in one domain to authenticate and access resources in another. This avoids creating duplicate accounts in separate directories.
Q3. Which of the following is a scalable, cloud-native, automated response, security information event management, and security orchestration solution?
Answer: B. Azure Sentinel
Microsoft Sentinel is the cloud-native SIEM and SOAR solution providing intelligent security analytics and automated incident response. Entra ID handles authentication, not broad event orchestration.
Q4. Your company is planning to use Azure Entra ID for identity storage. They want to use the self-service password reset feature. Which of the following authentication methods are available for self-service password reset?
Answer: C,D,F. Email || Mobile app notification || Mobile app code
Self-service password reset supports email, mobile app notifications, and mobile app codes for verification. Options like image messages or passport numbers are not valid authentication methods within the Microsoft Entra ID self-service password reset configuration.
Q5. You have a resource group in Azure. Can you add a delete lock to a resource that already has a read-only lock?
Answer: A. Yes
Yes, you can apply multiple locks to a single Azure resource to prevent both modifications and deletions. When multiple locks are assigned, the strictest permission level always applies, ensuring the resource remains fully protected from unwanted changes.
Q6. In Microsoft Sentinel, you can automate common tasks using ______________
Answer: B. playbooks
Playbooks automate responses to threats in Microsoft Sentinel by running predefined sequences of actions. Workbooks visualize data, while hunting tools actively search for threats, distinguishing them from automated remediation workflows.
Q7. You are looking to use Microsoft Entra ID Access Reviews. Can you use Microsoft Entra ID Access Reviews to review group memberships for users defined in Microsoft Entra ID?
Answer: B. Yes
Yes, Access Reviews allow you to periodically validate user access to groups, applications, and roles. This feature is essential for maintaining security and compliance by ensuring only the right people retain their permissions over time.
Q8. Your company wants to start using Azure. They are looking at different security aspects when it comes to using Azure. Which of the following options can be used for the following requirement?
Answer: E. Azure Entra ID Connect
Microsoft Entra Connect synchronizes on-premises directory identities to Entra ID, acting as the bridge for hybrid environments. Other options handle access control but lack the specific synchronization capability.
Q9. Your company is planning to use Azure Entra ID. Do all versions of Azure Entra ID provide the same set of features?
Answer: A. No
No, Azure Entra ID editions do not all offer the same features. The Free tier provides basic identity management, while Premium tiers add advanced features like conditional access. Knowing the specific differences between these editions is essential.
Q10. Can Microsoft Intune be used to manage organization-owned devices and personal devices?
Answer: B. Yes
Yes, Microsoft Intune manages both corporate and personal devices. It supports bring your own device scenarios by separating personal and corporate data. Remember that Intune is the core component for mobile device management.
Q11. Are global administrators exempt from conditional access policies?
Answer: B. No
No, global administrators are not automatically exempt from conditional access policies. These policies apply to all users, including admins. Microsoft actually recommends securing your global administrators with conditional access.
Q12. Can network security groups (NSGs) filter traffic based on IP address, protocol, and port?
Answer: A. Yes
Yes, network security groups filter network traffic using rules based on source IP, destination IP, port, and protocol. This basic network filtering is a fundamental Azure networking concept. Expect questions mapping features to security tools.
Q13. Does Azure Bastion provide a secure connection to an Azure virtual machine using the Azure portal?
Answer: A. Yes
Yes, Azure Bastion provides secure RDP and SSH access directly through the Azure portal. It connects you to virtual machines without exposing public IP addresses. Remember that Bastion secures remote connectivity.
Q14. Can Windows Hello for Business use the Microsoft Authenticator app as an authentication method?
Answer: B. No
Windows Hello for Business primarily relies on biometrics or PINs to authenticate users locally. The Microsoft Authenticator app is used separately for verifying identity during sign-ins.
Q15. Your company is reviewing the different options available when it comes to security solutions for Microsoft 365. Below are the main requirements:
Answer: H. Customer Lockbox
Customer Lockbox ensures any Microsoft support engineer access to Exchange Online data requires explicit approval from your organization. This approval workflow prevents unauthorized access during support tickets.
Q16. An Azure resource can use a system-assigned _____________ to access Azure services.
Answer: B. managed identity
A managed identity allows an Azure resource to authenticate to other services without storing credentials in code. This eliminates the need to manage secrets. Be prepared to identify managed identities as the secure authentication method.
More Microsoft Security, Compliance, and Identity Fundamentals (SC-900) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.