Microsoft SC-900 Practice Test Questions and Exam Dumps Part 18 Q341-360

View Full Microsoft SC-900 Exam Dumps and Practice Test Dumps

 

Question 341. Which Microsoft security concept means that users should not automatically be trusted simply because they are inside the corporate network?

  1. Zero Trust
  2. Shared responsibility
  3. Defense in depth
  4. Data lifecycle management

Correct Answer: 1. Zero Trust.

Explanation:

Zero Trust is a security approach based on the idea that access should not be automatically trusted based on network location or previous authentication. Instead, organizations continuously evaluate identity, device state, application, location, risk, and other available signals before allowing access. The model is commonly summarized through three principles: verify explicitly, use least privilege access, and assume breach. Microsoft Entra Conditional Access, Intune, Defender, and Microsoft Sentinel can all contribute to implementing Zero Trust. This approach is especially important in modern environments where users, devices, applications, and data may exist across cloud, on-premises, and remote locations.

Question 342. Which security strategy uses multiple independent security controls to protect against threats?

  1. Single sign-on
  2. Defense in depth
  3. Self-service password reset
  4. Cloud Discovery

Correct Answer: 2. Defense in depth.

Explanation:

Defense in depth is a security strategy that uses multiple layers of protection so that the failure of one control does not automatically result in a successful compromise. For example, an organization may combine identity protection, multifactor authentication, endpoint security, network controls, data protection, monitoring, and incident response. Each layer addresses different risks and provides additional protection. Microsoft security products can contribute to different layers of this strategy. Defense in depth is important because no individual security control is perfect. Layered protection can reduce the likelihood of successful attacks and limit their potential impact when prevention controls fail.

Question 343. Which Microsoft Entra capability can provide administrators with information about a user’s sign-in risk?

  1. Microsoft Entra ID Protection
  2. Microsoft Purview Records Management
  3. Azure Key Vault
  4. Microsoft Intune

Correct Answer: 1. Microsoft Entra ID Protection.

Explanation:

Microsoft Entra ID Protection provides risk information associated with identities and sign-ins. Sign-in risk focuses on the likelihood that a particular authentication attempt may be suspicious or compromised based on available signals. Administrators can use this information with Conditional Access to require additional authentication or other appropriate controls. Sign-in risk should not be confused with user risk. User risk concerns the likelihood that an identity itself has been compromised, while sign-in risk evaluates the particular authentication event. Using these risk signals helps organizations make more context-aware identity decisions rather than relying only on static authentication requirements.

Question 344. Which Conditional Access capability can require stronger authentication when users access sensitive applications?

  1. Authentication strengths
  2. Dynamic groups
  3. Data Map
  4. Azure Policy

Correct Answer: 1. Authentication strengths.

Explanation:

Conditional Access authentication strengths allow organizations to specify which authentication methods are acceptable for particular access scenarios. This is useful when a sensitive application requires stronger authentication than a less sensitive resource. For example, an organization may require phishing-resistant authentication methods for privileged or highly sensitive applications. Authentication strengths work as part of Conditional Access policies and can be combined with conditions involving users, applications, devices, locations, and risk. This provides more precise control than simply requiring MFA without specifying the strength or type of authentication method that should be used.

Question 345. What is the main purpose of Microsoft Entra application registrations?

  1. To establish an identity and configuration for an application that integrates with Microsoft Entra ID
  2. To scan endpoints for vulnerabilities
  3. To create retention labels
  4. To manage Sentinel incidents

Correct Answer: 1. To establish an identity and configuration for an application that integrates with Microsoft Entra ID.

Explanation:

Microsoft Entra application registration allows developers or administrators to register an application with the identity platform so it can participate in authentication and authorization scenarios. The registration can define information such as supported account types, redirect URIs, permissions, and other application settings. A corresponding service principal can represent the application’s identity within a tenant. Application registrations are important for modern applications that need users or services to authenticate through Microsoft Entra. Proper permission configuration is essential because an application should receive only the access required for its intended functionality.

Question 346. Which Microsoft Entra capability helps organizations govern permissions granted to applications?

  1. Enterprise applications and permissions management
  2. Microsoft Sentinel workbooks
  3. Azure DDoS Protection
  4. Microsoft Purview Audit

Correct Answer: 1. Enterprise applications and permissions management.

Explanation:

Microsoft Entra provides capabilities for managing enterprise applications and controlling the permissions that applications receive when accessing organizational resources. Application permissions can be sensitive because an application with excessive privileges could potentially access more information than necessary if compromised or misconfigured. Administrators can review and manage application access and permissions according to organizational requirements. This supports least privilege for non-human identities as well as users. Application governance is an important part of cloud security because organizations increasingly depend on applications and automated services that interact with identity platforms and business resources.

Question 347. Which Microsoft Entra feature can require periodic review of guest users’ access to resources?

  1. Access Reviews
  2. Microsoft Defender Antivirus
  3. Azure Firewall
  4. Sentinel notebooks

Correct Answer: 1. Access Reviews.

Explanation:

Access Reviews allow organizations to periodically review whether users, including supported guest users, should retain access to resources. Guest accounts can be especially important to review because external collaborators may need access for a limited period or project. Without regular reviews, permissions can remain active after the business relationship or original requirement has ended. Reviewers can examine access and determine whether it should continue. Access Reviews therefore support identity governance and least privilege by introducing a recurring process for validating access rather than assuming that previously granted permissions remain appropriate indefinitely.

Question 348. Which Microsoft Entra feature is designed to manage temporary privileged role activation?

  1. Privileged Identity Management
  2. Microsoft Purview Data Map
  3. Defender for Cloud Apps
  4. Azure Resource Locks

Correct Answer: 1. Privileged Identity Management.

Explanation:

Microsoft Entra Privileged Identity Management helps organizations manage privileged roles by allowing users to be eligible for roles and activate them only when required. Depending on configuration, activation can be limited by time and may require additional authentication, approval, or justification. This reduces the need for permanent administrative privileges and supports the principle of least privilege. PIM can also provide visibility into privileged role assignments and activation activity. Temporary activation is valuable because administrative accounts are attractive targets for attackers, and limiting the period of elevated access can reduce unnecessary exposure.

Question 349. Which Microsoft Entra capability can automatically update user access based on predefined identity lifecycle events?

  1. Lifecycle Workflows
  2. Microsoft Sentinel Analytics
  3. Azure Key Vault
  4. Microsoft Purview DLP

Correct Answer: 1. Lifecycle Workflows.

Explanation:

Microsoft Entra Lifecycle Workflows help automate identity lifecycle tasks associated with events such as onboarding, role changes, and offboarding. Organizations can define workflows that perform supported actions according to predefined conditions and schedules. Automation can improve consistency and reduce the possibility that administrators forget important access-management tasks when users join, move within, or leave an organization. Lifecycle Workflows are particularly useful in larger environments where manually processing every identity lifecycle event can be time-consuming. They complement other identity governance capabilities such as entitlement management, Access Reviews, and Privileged Identity Management.

Question 350. Which Microsoft Entra capability can help organizations provide users with a consistent sign-in experience across multiple applications?

  1. Single sign-on
  2. Azure Policy
  3. Defender Vulnerability Management
  4. Purview Audit

Correct Answer: 1. Single sign-on.

Explanation:

Single sign-on allows users to authenticate through a centralized identity provider and then access multiple supported applications without repeatedly entering credentials. Microsoft Entra provides SSO capabilities for supported applications and authentication scenarios. This can improve usability while also allowing organizations to centralize identity-related controls such as multifactor authentication and Conditional Access. SSO does not eliminate the need for authorization or security policies. Applications still need appropriate permissions and access controls. When implemented correctly, SSO can reduce password-related friction while allowing organizations to apply consistent identity security requirements across many applications.

Question 351. Which Microsoft Defender for Endpoint capability helps organizations reduce exploitable weaknesses in applications and operating systems?

  1. Vulnerability Management
  2. Safe Links
  3. Communication Compliance
  4. Access Reviews

Correct Answer: 1. Vulnerability Management.

Explanation:

Microsoft Defender Vulnerability Management helps organizations discover and assess vulnerabilities affecting supported devices, applications, and software. It provides visibility into weaknesses that could potentially be exploited by attackers and helps security teams prioritize remediation activities. Addressing vulnerabilities is an important part of reducing the attack surface because attackers frequently exploit outdated or insecure software. Vulnerability Management differs from endpoint detection and response, which focuses more on detecting and investigating suspicious activity. Organizations can use both capabilities together: vulnerability management helps reduce weaknesses proactively, while endpoint detection and response helps identify and respond to threats that occur.

Question 352. Which Microsoft Defender for Endpoint feature can help prevent common attack techniques from executing on endpoints?

  1. Attack Surface Reduction rules
  2. Microsoft Entra Access Reviews
  3. Purview Data Map
  4. Azure Resource Locks

Correct Answer: 1. Attack Surface Reduction rules.

Explanation:

Attack Surface Reduction rules in Microsoft Defender for Endpoint are designed to reduce the ability of common attack techniques to succeed on supported endpoints. They can restrict behaviors that attackers frequently abuse, helping prevent or limit malicious activity before it develops into a larger compromise. Organizations can configure these rules according to their security requirements and testing processes. Because restrictive security controls can affect legitimate applications in some environments, organizations should evaluate configurations carefully before broad deployment. Attack Surface Reduction is one part of endpoint security and can complement antivirus, vulnerability management, endpoint detection, and other controls.

Question 353. Which Microsoft Defender for Office 365 feature is specifically designed to protect users from malicious links?

  1. Safe Links
  2. Safe Attachments
  3. Attack Surface Reduction
  4. Cloud Discovery

Correct Answer: 1. Safe Links.

Explanation:

Safe Links helps protect users from malicious or suspicious URLs found in supported email and collaboration content. The capability can evaluate links and help prevent users from reaching known or identified malicious destinations according to the organization’s configuration. This is particularly useful for phishing protection because attackers frequently attempt to persuade users to click links that lead to credential-harvesting pages or malware. Safe Links complements Safe Attachments, which focuses on potentially malicious files. Together, these Defender for Office 365 capabilities address two common methods attackers use to deliver threats through email and collaboration platforms.

Question 354. Which Microsoft Defender for Office 365 capability helps analyze potentially dangerous email attachments?

  1. Safe Attachments
  2. Safe Links
  3. Dynamic Groups
  4. Security Defaults

Correct Answer: 1. Safe Attachments.

Explanation:

Safe Attachments helps protect users from malicious or suspicious files delivered through supported email and collaboration services. Attachments can be an effective delivery mechanism for malware, ransomware, and other threats because users may open files believing they are legitimate. Safe Attachments provides security analysis designed to identify potentially harmful content and apply the configured protection behavior. It works alongside Safe Links, which focuses on URLs. These capabilities contribute to a layered email security strategy and can reduce the likelihood that users will interact with common malicious content used in phishing and other social-engineering attacks.

Question 355. Which Microsoft Defender for Cloud Apps capability can help control user sessions for supported cloud applications?

  1. Session controls
  2. Azure Resource Locks
  3. Microsoft Entra PIM
  4. Purview Records Management

Correct Answer: 1. Session controls.

Explanation:

Microsoft Defender for Cloud Apps session controls can help organizations apply security controls to user sessions involving supported cloud applications. These controls can provide additional governance over how users interact with cloud services and can be useful when organizations need visibility or restrictions without relying solely on traditional network boundaries. Session controls are part of a broader cloud access security strategy that can help organizations manage cloud application usage. They complement Cloud Discovery and application risk assessment capabilities by providing controls over supported activities. The exact available controls depend on the application, integration, and organizational configuration.

Question 356. Which Microsoft Defender for Cloud capability provides recommendations for improving the security posture of Azure resources?

  1. Security recommendations
  2. Safe Attachments
  3. Access Packages
  4. Microsoft Authenticator

Correct Answer: 1. Security recommendations.

Explanation:

Microsoft Defender for Cloud provides security recommendations that can help organizations identify configuration weaknesses and improve the security posture of supported cloud resources. Recommendations may identify areas where resources do not meet desired security practices and suggest actions that can reduce exposure. These recommendations are part of the cloud security posture management side of Defender for Cloud. They are different from workload threat protection, which focuses more directly on detecting and protecting supported workloads from threats. Organizations can use posture recommendations to prioritize configuration improvements and strengthen cloud environments as part of an ongoing security program.

Question 357. Which Microsoft Sentinel feature provides a visual representation of security information and trends?

  1. Workbooks
  2. Analytics rules
  3. Playbooks
  4. Access packages

Correct Answer: 1. Workbooks.

Explanation:

Microsoft Sentinel workbooks provide interactive dashboards and visualizations that can help security teams understand security data and trends. They can display information using charts, tables, metrics, and other visual components. Workbooks are useful for monitoring, reporting, investigation, and communicating security information to analysts or other stakeholders. They are distinct from analytics rules, which identify potentially suspicious activity, and playbooks, which can automate response actions. A typical Sentinel workflow may therefore involve data connectors bringing information into Sentinel, analytics rules detecting relevant activity, workbooks visualizing information, and playbooks automating appropriate responses.

Question 358. Which Microsoft Sentinel capability can use automation to send notifications or initiate response actions after an alert occurs?

  1. Playbooks
  2. Workbooks
  3. Data Map
  4. Sensitivity labels

Correct Answer: 1. Playbooks.

Explanation:

Microsoft Sentinel playbooks support automated response and orchestration workflows. They can perform supported actions when triggered by alerts, incidents, or other configured events. Examples can include sending notifications, creating tickets, enriching security information, or performing other response actions through integrated services. Automation can reduce repetitive manual work and help security teams respond consistently to common situations. Playbooks do not replace detection logic; analytics rules are generally responsible for identifying suspicious patterns and generating alerts. Instead, playbooks help determine what automated actions should occur after a relevant security event has been identified.

Question 359. Which Microsoft Purview capability helps identify sensitive information based on predefined patterns or classifiers?

  1. Sensitive Information Types
  2. Microsoft Entra PIM
  3. Azure DDoS Protection
  4. Defender for Endpoint

Correct Answer: 1. Sensitive Information Types.

Explanation:

Microsoft Purview Sensitive Information Types help identify categories of sensitive information using predefined or customized detection patterns. Examples can include financial information, identification numbers, or other types of data that organizations consider sensitive. These detections can support broader Purview capabilities such as Data Loss Prevention and information protection. Sensitive Information Types are not themselves a complete security policy; rather, they provide detection mechanisms that can help other controls recognize sensitive content. Organizations can use them to build more targeted data protection policies based on the types of information they need to protect.

Question 360. Which Microsoft Purview feature can help preserve content so that it is not deleted while an investigation or legal matter is ongoing?

  1. Legal hold
  2. Microsoft Entra Cloud Sync
  3. Defender Antivirus
  4. Azure Policy

Correct Answer: 1. Legal hold.

Explanation:

Microsoft Purview legal hold capabilities can help organizations preserve relevant content when information may be required for an investigation, legal proceeding, or other matter. Preservation is important because ordinary retention or deletion processes could otherwise remove information that needs to remain available. Legal hold should be used according to the organization’s legal and compliance procedures, including appropriate authorization and scope. It is closely related to eDiscovery, which helps organizations identify and manage potentially relevant information. The key distinction is that legal hold focuses on preserving information, while eDiscovery provides capabilities for finding, collecting, and reviewing relevant content.