Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Microsoft Security, Compliance, and Identity Fundamentals SC-900 Exam Questions

Page: 1 / 15 Total 215 questions

Want more questions? Get Premium Access.

Question 1

What can you use to view the Microsoft Secure Score for Devices?

Correct Answer: B. Microsoft Defender for Endpoint
Explanation:

Microsoft Secure Score for Devices

Artikel

12.05.2022

3Minuten Lesedauer

Applies to:

Microsoft Defender for Endpoint Plan 2

Microsoft Defender Vulnerability Management

Microsoft 365 Defender

Some information relates to pre-released product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.

To sign up for the Defender Vulnerability Management public preview or if you have any questions, contact us (mdvmtrial@microsoft.com).

Already have Microsoft Defender for Endpoint P2? Sign up for a free trial of the Defender Vulnerability Management Add-on.

Configuration score is now part of vulnerability management as Microsoft Secure Score for Devices.

Your score for devices is visible in the Defender Vulnerability Management dashboard of the Microsoft 365 Defender portal. A higher Microsoft Secure Score for Devices means your endpoints are more resilient from cybersecurity threat attacks. It reflects the collective security configuration state of your devices across the following categories:

Application

Operating system

Network

Accounts

Security controls

Select a category to go to the Security recommendations page and view the relevant recommendations.

Turn on the Microsoft Secure Score connector

Forward Microsoft Defender for Endpoint signals, giving Microsoft Secure Score visibility into the device security posture. Forwarded data is stored and processed in the same location as your Microsoft Secure Score data.

Changes might take up to a few hours to reflect in the dashboard.

In the navigation pane, go to Settings > Endpoints > General > Advanced features

Scroll down to Microsoft Secure Score and toggle the setting to On.

Select Save preferences.

How it works

Microsoft Secure Score for Devices currently supports configurations set via Group Policy. Due to the current partial Intune support, configurations which might have been set through Intune might show up as misconfigured. Contact your IT Administrator to verify the actual configuration status in case your organization is using Intune for secure configuration management.

The data in the Microsoft Secure Score for Devices card is the product of meticulous and ongoing vulnerability discovery process. It is aggregated with configuration discovery assessments that continuously:

Compare collected configurations to the collected benchmarks to discover misconfigured assets

Map configurations to vulnerabilities that can be remediated or partially remediated (risk reduction)

Collect and maintain best practice configuration benchmarks (vendors, security feeds, internal research teams)

Collect and monitor changes of security control configuration state from all assets


Question 2

Which compliance feature should you use to identify documents that are employee resumes?

Correct Answer: A. pre-trained classifiers
Explanation:

In Microsoft Purview Information Protection, pre-trained (Microsoft-provided) trainable classifiers are designed to automatically recognize specific categories of content by learning from examples rather than relying only on patterns or keywords. Microsoft's guidance explains that trainable classifiers ''look for data by learning from examples,'' and that Microsoft supplies a catalog of ''pre-trained classifiers that you can use immediately in your tenant.'' The documentation explicitly lists content types these classifiers can recognize, including ''Resumes,'' along with other categories such as Source code, Threat and harassment, and more. Because they're already trained by Microsoft, you can use them ''to identify and classify items across SharePoint, OneDrive, and Exchange,'' and then take actions such as auto-labeling or enforcing DLP policies based on the classifier match.

By contrast, Content explorer is a reporting tool that lets you view where sensitive info types/labels were found; it doesn't identify resumes on its own. Activity explorer shows events like DLP policy matches over time. eDiscovery is used for legal hold, search, and review, not for semantic content identification. Therefore, to identify documents that are employee resumes, the correct Microsoft compliance feature is the pre-trained (Microsoft-provided) trainable classifier for Resumes.


Question 3

You have a Microsoft 365 E3 subscription.

You plan to audit user activity by using the unified audit log and Basic Audit.

For how long will the audit records be retained?

Correct Answer: D. 180 days
Explanation:

In Microsoft 365, the unified audit log retention depends on the audit tier included with the subscription. Current SCI/Compliance documentation states that Audit (Standard)---which is available with Microsoft 365 E3---retains audit records for 180 days. The docs describe that organizations with E3 receive ''up to 180 days of audit log retention'' for user and admin activities captured in the unified audit pipeline. Longer retention (for example 365 days and beyond with customizable policies) is part of Audit (Premium) features generally associated with E5/E5 Compliance. Because the scenario specifies a Microsoft 365 E3 subscription using the unified audit log and Basic/Standard Audit, the retention period for audit records is 180 days.


Question 4

Which service includes Microsoft Secure Score for Devices?

Correct Answer: A. Microsoft Defender for Endpoint
Explanation:

Microsoft Secure Score for Devices is a feature included in Microsoft Defender for Endpoint. This service provides:

  • Security recommendations specific to devices and endpoints
  • Visibility into the security posture of Windows, Linux, and Mac devices
  • Assessment of device vulnerabilities and misconfigurations
  • Scoring and tracking of security improvements over time
  • Integration with threat intelligence and attack surface analysis

Microsoft Defender for Endpoint is Microsoft's endpoint protection and detection and response (EDR) solution that helps organizations detect, investigate, and respond to advanced threats on their devices.

Question 5

What feature supports email as a method of authenticating users?

Correct Answer: C. self-service password reset (SSPR)
Explanation:

In Microsoft Entra ID (formerly Azure AD), self-service password reset (SSPR) is the feature that explicitly supports email as an authentication method when users need to verify their identity to reset or unlock their password.

According to Microsoft's identity and access documentation and the SCI learning content, SSPR lets administrators choose which verification methods are available to users, such as mobile phone, office phone, mobile app, security questions, and email. When email is enabled, a verification code can be sent to a registered alternate email address. The user proves their identity by entering this code, which is treated as an authentication step in the SSPR process.

By contrast:

Microsoft Entra Multi-Factor Authentication (MFA) does not support email as an MFA method; it focuses on methods like authenticator apps, phone calls, and text messages.

Microsoft Entra ID Protection detects and responds to risky sign-ins and users but does not provide email-based authentication.

Microsoft Entra Password Protection deals with banned and compromised passwords, not with email verification.

Therefore, the only option in the list that uses email as a supported authentication method is self-service password reset (SSPR).


Question 6

To which type of resource can Azure Bastion provide secure access?

Correct Answer: C. Azure virtual machines
Explanation:

Azure Bastion is a managed PaaS service that provides secure and seamless RDP/SSH connectivity to your Azure virtual machines directly from the Azure portal over TLS/HTTPS. SCI and Azure security documentation summarize it as eliminating public IP exposure on VMs by using a fully managed bastion host deployed inside your virtual network. Users connect through their browser and the service brokers the RDP or SSH session, which ''protects your VMs from exposing RDP/SSH to the Internet.'' Bastion does not provide access to Azure Files, SQL Managed Instance, or App Service; it is specifically built to secure management access to VMs without requiring a VPN or public endpoints. Therefore, the resource type Azure Bastion securely connects to is Azure virtual machines.


Question 7

What should you use in the Microsoft 365 security center to view security trends and track the protection status of identities?

Correct Answer: B. Reports
Explanation:

In the Microsoft 365 security center/Microsoft 365 Defender portal, the Reports area is designed to provide organization-wide visibility into security posture and activity over time. Microsoft describes the Reports experience as enabling you to ''view security trends and track the protection status across identities, endpoints, email & collaboration, and cloud apps.'' Within Reports, the Identity section aggregates signals from Microsoft Entra ID protection and related identity defenses so security teams can monitor trends such as risky sign-ins, user risk, MFA adoption/registration, and other identity protection metrics. These curated, read-only dashboards are aimed at measuring protection status and changes over time, helping you validate the impact of controls and prioritize remediation.

By contrast, Attack simulator is used to run user training simulations (e.g., phishing) and is not intended for posture trend reporting. Hunting (Advanced hunting) lets analysts query raw telemetry for investigations, not to provide summarized trend dashboards. Incidents correlates alerts into incident records for triage and response, rather than showing long-term trends and protection status views. Therefore, to view security trends and track the protection status of identities, the correct place is Reports in the Microsoft 365 security center/Microsoft 365 Defender portal.


Question 8

What can you use to provide a user with a two-hour window to complete an administrative task in Azure?

Correct Answer: D. conditional access policies
Explanation:

https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure

Privileged Identity Management provides time-based and approval-based role activation to mitigate the risks of excessive, unnecessary, or misused access permissions on resources that you care about. Here are some of the key features of Privileged Identity Management: Provide just-in-time privileged access to Azure AD and Azure resources Assign time-bound access to resources using start and end dates Require approval to activate privileged roles Enforce multi-factor authentication to activate any role Use justification to understand why users activate Get notifications when privileged roles are activated Conduct access reviews to ensure users still need roles Download audit history for internal or external audit Prevents removal of the last active Global Administrator role assignment


Question 9

You have an Azure subscription that contains a Log Analytics workspace.

You need to onboard Microsoft Sentinel.

What should you do first?

Correct Answer: C. Connect to your security sources.
Explanation:

Onboarding Microsoft Sentinel starts by enabling Sentinel on an existing Log Analytics workspace and then connecting data sources so analytics can operate on ingested security data. Microsoft's Sentinel onboarding guidance emphasizes that after you add Sentinel to a workspace, you must ''connect Microsoft services, non-Microsoft solutions, and custom sources'' using built-in data connectors. Microsoft also states that ''you need data in your workspace before you can use Microsoft Sentinel's analytics, hunting, and investigation capabilities.'' Features such as custom analytics rules, hunting queries, and incident correlation depend on ingested telemetry from sources like Microsoft Entra ID sign-in logs, Microsoft 365, Defender products, firewalls, and other appliances. Because the question already gives you a Log Analytics workspace (the prerequisite for enabling Sentinel), the first action in the onboarding workflow that unlocks Sentinel's value is to connect your security sources. Only after data is flowing should you proceed to create analytics rules, hunting queries, and incident processes. Therefore, the correct first step to onboard Microsoft Sentinel is connect to your security sources.


Question 10

Which two types of devices can be managed by using Endpoint data loss prevention (Endpoint DLP)? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

Correct Answer: A. Windows 11; D. macOS
Explanation:

Endpoint data loss prevention (Endpoint DLP), a feature in Microsoft Purview, supports Windows 10 and 11 and now also supports macOS for core DLP capabilities. It allows organizations to monitor and restrict actions like copying sensitive files to USBs, printing, or uploading to unapproved cloud services.

SCI Extract: 'Endpoint DLP extends Microsoft Purview Data Loss Prevention to Windows 10, Windows 11, and macOS devices, allowing for monitoring and control of sensitive data usage at the endpoint.'

Other platforms like Linux, iOS, and Android are not currently supported for Endpoint DLP


Question 11

What is the purpose of Azure Active Directory (Azure AD) Password Protection?

Correct Answer: D. to prevent users from using specific words in their passwords
Explanation:

Explanation

Azure AD Password Protection detects and blocks known weak passwords and their variants, and can also block additional weak terms that are specific to your organization.

With Azure AD Password Protection, default global banned password lists are automatically applied to all users in an Azure AD tenant. To support your own business and security needs, you can define entries in a custom banned password list.


https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-password-ban-bad-on-premises

Question 12

What can you use to provision Azure resources across multiple subscriptions in a consistent manner?

Correct Answer: B. Azure Blueprints
Explanation:

Azure Blueprints allow cloud architects and central IT to define a repeatable set of Azure resources and governance artifacts---including Azure Policy assignments, role assignments (RBAC), resource groups, and ARM/Bicep templates---and then deploy them consistently across subscriptions. Microsoft's guidance describes Blueprints as a way to ''orchestrate the deployment of various resource templates and other artifacts'' to establish standards, patterns, and compliance for environments at scale. This is distinct from Azure Policy, which evaluates and enforces configuration but does not package multi-artifact environments; Microsoft Sentinel and Defender are security analytics/protection services rather than provisioning frameworks. Thus, for consistent provisioning across multiple subscriptions, the prescribed solution is Azure Blueprints.


Question 13

What can you use to protect against malicious links sent in email messages, chat messages, and channels?

Correct Answer: D. Microsoft Defender for Office 365
Explanation:

Microsoft Defender for Office 365 is the Microsoft 365 solution designed to protect users from threats delivered through email and collaboration workloads. SCI training material explains that Defender for Office 365 protects Exchange Online, Microsoft Teams, SharePoint Online, and OneDrive for Business by detecting and blocking malware, phishing, and other advanced attacks that use messages and shared content as the delivery channel.

A key capability is Safe Links, which specifically protects against malicious URLs. When a user receives an email, Teams chat message, or channel post that contains a hyperlink, Safe Links scans and rewrites that URL. At the moment the user clicks, the link is checked again; if it is identified as malicious or leads to a known phishing or malware-hosting site, access is blocked and a warning page is shown. This time-of-click protection is emphasized in Microsoft's security documentation as a primary defense against weaponized links in email and collaborative communications.


Question 14

Which feature is included in Microsoft Entra ID Governance?

Correct Answer: D. Privileged Identity Management
Explanation:

Microsoft defines Microsoft Entra ID Governance as the capability to manage ''the identity lifecycle, access lifecycle, and privileged access'' so organizations can ensure ''the right people have the right access to the right resources at the right time.'' The product family explicitly lists the following core features: ''Lifecycle workflows, Entitlement management, Access reviews, and Privileged Identity Management (PIM).'' Microsoft further explains that PIM helps you ''manage, control, and monitor access within your organization,'' enabling just-in-time elevation, approval workflows, MFA/justification on activation, and detailed auditing for privileged roles. By contrast, the other options are separate Microsoft Entra offerings outside ID Governance: Verifiable credentials (Microsoft Entra Verified ID) issues and validates digital credentials; Permissions Management (Microsoft Entra Permissions Management) provides CIEM for multi-cloud permissions; and Identity Protection offers risk-based detection and policies for sign-ins and users. Therefore, among the choices, the feature that is included in Microsoft Entra ID Governance is Privileged Identity Management (PIM), which is specifically called out by Microsoft as a pillar of ID Governance and is used to govern privileged access with policy-based controls, time-bound assignments, approvals, and comprehensive auditability.


Question 15

What can you protect by using the information protection solution in the Microsoft 365 compliance center?

Correct Answer: D. sensitive data from being exposed to unauthorized users
Explanation:

Microsoft Purview Information Protection (in the Microsoft 365 compliance center) enables you to discover, classify, label, and protect sensitive information across emails, documents, and other data stores. Labels and policies can enforce encryption, access restrictions, and visual markings, helping prevent unauthorized disclosure of sensitive data---inside or outside your organization.