Microsoft SC-900 Practice Test Questions and Exam Dumps Part 16 Q301-320

View Full Microsoft SC-900 Exam Dumps and Practice Test Dumps

 

Question 301. Which Zero Trust principle recommends limiting user and application permissions to only what is required?

  1. Verify explicitly
  2. Assume breach
  3. Use least privilege access
  4. Trust internal networks

Correct Answer: 3. Use least privilege access.

Explanation:

The Zero Trust principle of least privilege means users, applications, and services should receive only the permissions necessary to perform their required tasks. Excessive permissions increase the potential impact if an account or application is compromised. Microsoft security and identity capabilities support this principle in several ways, including role-based access control, Privileged Identity Management, and access reviews. Least privilege does not mean preventing users from completing their work; instead, it focuses on providing appropriate access for the appropriate purpose and duration. Regularly reviewing permissions also helps remove access that is no longer required.

Question 302. Which Zero Trust principle assumes that an attacker may already have access to the environment?

  1. Assume breach
  2. Verify explicitly
  3. Grant permanent access
  4. Trust the corporate network

Correct Answer: 1. Assume breach.

Explanation:

“Assume breach” is one of the core Zero Trust principles. It encourages organizations to design security controls with the expectation that an attacker could already be present somewhere in the environment. Instead of relying on a strong perimeter alone, organizations use segmentation, monitoring, identity controls, encryption, endpoint protection, and other layers to limit the impact of a compromise. Assuming breach also encourages continuous detection and investigation of suspicious activity. Microsoft Sentinel, Defender XDR, Microsoft Entra, and other security services can contribute to this approach by providing visibility and controls across identities, devices, applications, and data.

Question 303. Which Microsoft Entra feature can synchronize selected identities and groups from an on-premises directory to Microsoft Entra ID?

  1. Microsoft Purview Audit
  2. Microsoft Entra Cloud Sync
  3. Microsoft Sentinel
  4. Defender for Cloud Apps

Correct Answer: 2. Microsoft Entra Cloud Sync.

Explanation:

Microsoft Entra Cloud Sync provides a lightweight approach for synchronizing identities from supported on-premises directory environments with Microsoft Entra ID. It uses an agent-based model and can help organizations connect their existing identity infrastructure with Microsoft’s cloud identity platform. Synchronization can support scenarios where users need a consistent identity experience across on-premises and cloud resources. Cloud Sync is distinct from Microsoft Entra Connect, although both are used for hybrid identity scenarios. The appropriate synchronization approach depends on the organization’s directory architecture, synchronization requirements, and supported capabilities.

Question 304. What is the primary purpose of Microsoft Entra External ID?

  1. To provide identity capabilities for external users and customers
  2. To manage antivirus definitions
  3. To create Azure firewalls
  4. To analyze Sentinel workbooks

Correct Answer: 1. To provide identity capabilities for external users and customers.

Explanation:

Microsoft Entra External ID provides identity and access capabilities for scenarios involving people outside an organization’s workforce. Depending on the scenario, this can include business-to-business collaboration and customer-facing identity experiences. External identities allow organizations to provide appropriate access without treating every external person as a traditional internal employee. Organizations can apply authentication and authorization controls according to the type of external relationship and application requirements. External identity management is important because organizations often need to collaborate with partners, suppliers, customers, and other users while maintaining appropriate security boundaries and access controls.

Question 305. Which Microsoft Entra capability can help organizations manage access packages for external and internal users?

  1. Entitlement management
  2. Defender Antivirus
  3. Azure DDoS Protection
  4. Microsoft Sentinel notebooks

Correct Answer: 1. Entitlement management.

Explanation:

Microsoft Entra entitlement management helps organizations manage access to resources through governed access packages. An access package can group together resources that users need for a particular project, department, or collaboration scenario. Organizations can define policies controlling who can request access, who approves it, and how long access remains available. This makes access governance more structured than granting individual permissions manually. Entitlement management is particularly useful when users need temporary or changing access to multiple resources. It can support both internal workforce scenarios and external collaboration while helping organizations maintain better control over the access lifecycle.

Question 306. What is the purpose of Microsoft Entra lifecycle workflows?

  1. To automate identity lifecycle tasks for users
  2. To scan email attachments
  3. To create Azure network routes
  4. To classify documents

Correct Answer: 1. To automate identity lifecycle tasks for users.

Explanation:

Microsoft Entra lifecycle workflows help organizations automate common identity lifecycle processes for users. Examples include actions associated with onboarding, employee transitions, and offboarding. Automating these processes can reduce manual administrative work and help ensure that access-related tasks occur consistently. Lifecycle management is important because users’ access requirements change over time. When someone joins an organization, changes roles, or leaves, their identity and access state may need to be updated. Automated workflows can help organizations apply predefined processes and reduce the chance that important lifecycle tasks are overlooked.

Question 307. Which authentication method uses a physical security key based on the FIDO2 standard?

  1. Password hash synchronization
  2. FIDO2 security key
  3. Conditional Access
  4. Security Defaults

Correct Answer: 2. FIDO2 security key.

Explanation:

FIDO2 security keys are authentication devices that use public-key cryptography to provide strong authentication without requiring users to enter traditional passwords. The authentication process is designed to resist common phishing techniques because credentials are cryptographically associated with the legitimate service. A user typically interacts with the security key through a supported method such as touching the key or entering a PIN, depending on the device. Microsoft Entra supports FIDO2 authentication as one of its passwordless authentication options. Security keys can be particularly useful for protecting privileged accounts and users who require strong, phishing-resistant authentication.

Question 308. Which Microsoft Entra capability can require users to use a stronger authentication method for sensitive resources?

  1. Authentication strengths
  2. Data Lifecycle Management
  3. Secure Score
  4. Microsoft Purview Audit

Correct Answer: 1. Authentication strengths.

Explanation:

Microsoft Entra Conditional Access authentication strengths allow organizations to define requirements for the types of authentication methods that users must use when accessing protected resources. This can be useful when a basic authentication method is not sufficient for a sensitive application or administrative operation. An organization can require stronger methods, including phishing-resistant authentication, depending on its security requirements and supported configuration. Authentication strengths work with Conditional Access policies to make authentication requirements more context-aware. This provides more granular control than simply requiring MFA without specifying which authentication methods are acceptable for a particular access scenario.

Question 309. Which Microsoft Intune capability is specifically designed to protect organizational data within supported mobile applications?

  1. App protection policies
  2. Azure Policy
  3. Microsoft Sentinel analytics rules
  4. Microsoft Entra Access Reviews

Correct Answer: 1. App protection policies.

Explanation:

Microsoft Intune app protection policies help protect organizational data within supported applications, particularly in mobile and bring-your-own-device scenarios. These policies can apply controls to help prevent organizational information from being copied, transferred, or accessed inappropriately. An important advantage is that application-level protection can help secure business data even when a device is not fully enrolled in mobile device management, depending on the supported scenario. App protection policies are therefore different from device configuration profiles and compliance policies. They focus primarily on protecting organizational information within applications rather than configuring the entire device.

Question 310. What is the primary purpose of Microsoft Intune endpoint security policies?

  1. To configure and manage security-related settings on managed endpoints
  2. To perform legal discovery
  3. To manage cloud application subscriptions
  4. To investigate identity risks

Correct Answer: 1. To configure and manage security-related settings on managed endpoints.

Explanation:

Microsoft Intune endpoint security policies provide a structured way to configure security settings on managed devices. Depending on the platform and policy type, administrators can manage settings related to antivirus, firewall, attack surface reduction, account protection, and other endpoint security areas. These policies help organizations apply consistent security configurations across groups of devices rather than relying on manual configuration. Endpoint security policies work alongside compliance policies and configuration profiles. While compliance policies evaluate whether devices satisfy defined requirements, endpoint security policies focus more directly on configuring security-related controls that help protect the endpoint.

Question 311. Which Microsoft Defender for Endpoint capability helps security teams investigate suspicious activity by querying security data?

  1. Advanced hunting
  2. Access Reviews
  3. Retention labels
  4. Security Defaults

Correct Answer: 1. Advanced hunting.

Explanation:

Advanced hunting in Microsoft Defender XDR and Defender for Endpoint allows security teams to use queries to investigate available security data and search for potentially suspicious activity. Analysts can use this capability to explore events, identify patterns, investigate indicators, and support threat-hunting activities. Advanced hunting is particularly useful when analysts need to investigate beyond automatically generated alerts. It complements automated detections by giving security professionals a way to ask targeted questions of available security data. Organizations can use these investigations to understand possible attack activity and identify behaviors that may require additional security response.

Question 312. What is the primary purpose of Microsoft Defender Vulnerability Management?

  1. To identify and help prioritize vulnerabilities and security weaknesses on supported devices
  2. To manage employee onboarding
  3. To create retention policies
  4. To configure cloud identities

Correct Answer: 1. To identify and help prioritize vulnerabilities and security weaknesses on supported devices.

Explanation:

Microsoft Defender Vulnerability Management helps organizations identify vulnerabilities and security weaknesses affecting supported devices and software. It provides information that can help security teams understand exposure and prioritize remediation activities. Vulnerability management is different from antivirus protection because its focus is on identifying weaknesses that attackers could potentially exploit rather than simply detecting malicious files. It can help organizations understand device exposure, software-related vulnerabilities, and recommended remediation actions. By combining vulnerability visibility with endpoint security capabilities, organizations can take a more proactive approach to reducing attack opportunities across their device environment.

Question 313. Which Microsoft Defender XDR capability correlates related security alerts into incidents?

  1. Incident correlation
  2. Data Lifecycle Management
  3. Access package management
  4. Azure Resource Locks

Correct Answer: 1. Incident correlation.

Explanation:

Microsoft Defender XDR can correlate related security alerts into incidents to provide security teams with a more complete picture of an attack. Instead of requiring analysts to investigate every alert independently, related signals can be grouped so investigators can understand how different events may belong to the same security activity. This can improve investigation efficiency and help analysts identify attack relationships across supported security products. Defender XDR can correlate signals from areas such as endpoints, identities, email, and other Microsoft security services. Incident-based investigation is especially useful when an attack produces multiple related alerts across different parts of an organization.

Question 314. What is the primary purpose of Microsoft Sentinel analytics rules?

  1. To identify conditions or patterns that may indicate security threats
  2. To configure mobile device applications
  3. To manage sensitivity labels
  4. To assign Microsoft Entra roles

Correct Answer: 1. To identify conditions or patterns that may indicate security threats.

Explanation:

Microsoft Sentinel analytics rules are used to detect potentially suspicious or malicious activity in collected security data. Rules can evaluate events and identify patterns that may represent security threats, helping generate alerts and support incident creation. Analytics rules are a key part of Sentinel’s SIEM capabilities because they turn collected data into actionable security detections. They differ from workbooks, which primarily visualize data, and playbooks, which can automate response actions. Organizations can create or use supported detection rules according to their security requirements and use the resulting alerts as starting points for investigation.

Question 315. Which Microsoft Sentinel capability can automate actions in response to security events?

  1. Playbooks
  2. Workbooks
  3. Access Reviews
  4. Sensitivity labels

Correct Answer: 1. Playbooks.

Explanation:

Microsoft Sentinel playbooks support automated response workflows that can perform actions when security events or alerts meet defined conditions. They can integrate with other services and help automate repetitive response tasks, reducing the amount of manual effort required from security teams. For example, an organization may use automation to notify personnel, create a ticket, or perform another supported response action. Playbooks are commonly associated with security orchestration and automation. They differ from analytics rules, which detect suspicious conditions, and workbooks, which visualize security information. Together, these capabilities help support detection, investigation, visualization, and response processes.

Question 316. What is the primary purpose of Microsoft Sentinel data connectors?

  1. To bring security-related data from supported sources into Sentinel
  2. To assign Microsoft Entra administrator roles
  3. To encrypt documents
  4. To manage endpoint compliance

Correct Answer: 1. To bring security-related data from supported sources into Sentinel.

Explanation:

Microsoft Sentinel data connectors help connect supported data sources to the Sentinel workspace so security information can be collected and analyzed. Sources can include Microsoft services, security products, cloud platforms, applications, and other supported systems. Centralizing relevant data is important because security teams need visibility across different parts of an environment when investigating incidents. Once data is available in Sentinel, analytics rules can help detect suspicious patterns, workbooks can visualize information, and playbooks can support automated responses. Data connectors therefore contribute to the data-collection foundation of Sentinel’s SIEM capabilities.

Question 317. Which Azure service helps protect sensitive secrets, keys, and certificates used by applications?

  1. Azure Key Vault
  2. Microsoft Sentinel
  3. Microsoft Intune
  4. Microsoft Purview Audit

Correct Answer: 1. Azure Key Vault.

Explanation:

Azure Key Vault is designed to securely store and manage secrets, cryptographic keys, and certificates used by applications and services. Instead of embedding sensitive credentials directly into application code or configuration files, organizations can use Key Vault to provide controlled access to protected secrets. This helps reduce the risk associated with exposing credentials in source code or application settings. Key Vault can be integrated with Azure services and applications according to supported authentication and authorization configurations. Protecting secrets is an important part of cloud security because compromised credentials can potentially provide attackers with access to applications or resources.

Question 318. Which Azure service can help enforce organizational standards by evaluating resource configurations?

  1. Azure Policy
  2. Azure Key Vault
  3. Microsoft Defender Antivirus
  4. Microsoft Purview eDiscovery

Correct Answer: 1. Azure Policy.

Explanation:

Azure Policy helps organizations enforce and assess standards for Azure resources by evaluating their configurations against defined policy rules. Organizations can use policies to help ensure that resources comply with requirements such as permitted resource types, locations, configurations, or other governance conditions. Azure Policy supports governance at scale because administrators can apply policies across relevant scopes instead of manually checking every resource. It is important to distinguish Azure Policy from role-based access control. RBAC primarily controls who can perform actions on resources, while Azure Policy evaluates whether resource configurations or deployments comply with defined organizational requirements.

Question 319. Which Azure feature can help prevent accidental deletion or modification of important resources?

  1. Azure Resource Locks
  2. Microsoft Entra ID Protection
  3. Microsoft Sentinel notebooks
  4. Purview Communication Compliance

Correct Answer: 1. Azure Resource Locks.

Explanation:

Azure Resource Locks help protect important Azure resources from accidental deletion or modification. Depending on the lock type and configuration, administrators can prevent deletion or prevent changes to protected resources. Resource locks are useful as an additional governance safeguard, especially for critical infrastructure or resources that should not be changed casually. They do not replace authorization controls such as RBAC, and they should be considered as one layer within a broader management strategy. Proper permissions, change management, monitoring, and backup practices remain important because resource locks address specific types of resource-level actions.

Question 320. Which Azure service provides protection against certain distributed denial-of-service attacks targeting Azure resources?

  1. Azure DDoS Protection
  2. Microsoft Purview
  3. Microsoft Entra PIM
  4. Microsoft Intune

Correct Answer: 1. Azure DDoS Protection.

Explanation:

Azure DDoS Protection is designed to help protect supported Azure resources against distributed denial-of-service attacks. DDoS attacks attempt to overwhelm a service or network resource with large amounts of traffic, potentially affecting availability. Azure provides baseline infrastructure-level protection, while Azure DDoS Protection offers additional capabilities for supported scenarios and resources. DDoS protection is different from a web application firewall or identity security service because its primary focus is mitigating distributed denial-of-service threats. Organizations should consider DDoS protection as one component of a broader defense-in-depth strategy that includes network security, application security, monitoring, and access controls.