View Full Microsoft SC-900 Exam Dumps and Practice Test Dumps
Question 361. Which cloud security concept defines which security responsibilities remain with the cloud provider and which remain with the customer?
- Shared responsibility model
- Zero Trust model
- Defense in depth
- Principle of least privilege
Correct Answer: 1. Shared responsibility model
Explanation:
The shared responsibility model explains how security and operational responsibilities are divided between a cloud service provider and its customers. Microsoft is responsible for securing the underlying cloud infrastructure, including physical facilities, hosts, and core platform components. The customer remains responsible for areas that depend on the services and configuration they use, such as identities, access permissions, data, and certain application or operating-system controls. The exact division varies according to whether the organization uses infrastructure, platform, or software services. Understanding this model helps organizations avoid assuming that moving workloads to the cloud automatically transfers every security responsibility to Microsoft.
Question 362. Which Azure service provides network-level filtering by allowing or denying inbound and outbound traffic based on rules associated with virtual network resources?
- Azure Key Vault
- Network Security Group
- Microsoft Purview
- Microsoft Sentinel
Correct Answer: 2. Network Security Group
Explanation:
An Azure Network Security Group, commonly called an NSG, provides network traffic filtering for Azure resources. It contains security rules that can allow or deny inbound and outbound network traffic based on characteristics such as source, destination, port, and protocol. NSGs are commonly associated with subnets or network interfaces and are useful for controlling communication within Azure virtual networks. They provide an important network security layer, but they are not a replacement for every network security service. For example, organizations requiring centralized, stateful firewall capabilities and advanced traffic inspection may use Azure Firewall in addition to NSGs.
Question 363. Which Azure service is designed to provide centralized, stateful network traffic filtering and firewall capabilities across Azure environments?
- Azure Firewall
- Azure Policy
- Microsoft Entra ID
- Microsoft Priva
Correct Answer: 1. Azure Firewall
Explanation:
Azure Firewall is a managed, stateful network security service designed to protect Azure virtual network resources and control network traffic. It can provide centralized traffic filtering and supports features that are more extensive than basic network security rules. Azure Firewall can be used to create and enforce network access policies across workloads while providing centralized management and logging capabilities. In comparison, Network Security Groups provide more granular traffic filtering at the subnet or network-interface level. Organizations can use both technologies together as part of a layered security architecture, with each addressing different network protection requirements.
Question 364. Which Microsoft Sentinel capability helps identify unusual behavior by analyzing patterns associated with users and entities?
- Data connectors
- Workbooks
- User and Entity Behavior Analytics
- Content Hub
Correct Answer: 3. User and Entity Behavior Analytics
Explanation:
User and Entity Behavior Analytics, or UEBA, in Microsoft Sentinel helps security teams identify unusual or suspicious behavior involving users, devices, hosts, applications, and other entities. Instead of relying only on predefined indicators, UEBA can establish behavioral patterns and help identify activities that deviate from expected behavior. This can be valuable when an account behaves differently from its historical or contextual baseline. Sentinel can use UEBA-related insights to enrich investigations and incidents. Security analysts can therefore gain additional context when determining whether activity represents a potential compromise, insider threat, or other security concern.
Question 365. What is the primary purpose of threat intelligence in Microsoft Sentinel?
- Create employee payroll reports
- Enforce device encryption
- Replace all authentication methods
- Provide information about known threats and indicators
Correct Answer: 4. Provide information about known threats and indicators
Explanation:
Threat intelligence provides information that helps security teams understand known or suspected threats. In Microsoft Sentinel, threat intelligence can include indicators and contextual information associated with malicious infrastructure, such as suspicious IP addresses, domains, URLs, or file-related indicators. Security teams can use this information alongside organizational security data to improve detection and investigation. Threat intelligence does not automatically mean that every matching indicator represents a confirmed attack; analysts should evaluate context and supporting evidence. When integrated appropriately, threat intelligence can help organizations identify potentially malicious activity more efficiently and strengthen their overall security monitoring capabilities.
Question 366. Which Microsoft Sentinel feature provides interactive visualizations that help analysts monitor trends and investigate security data?
- Workbooks
- Access Reviews
- Sensitivity labels
- Security Defaults
Correct Answer: 1. Workbooks
Explanation:
Microsoft Sentinel workbooks provide interactive dashboards and visualizations that help security teams analyze and understand collected security information. Workbooks can present data through charts, graphs, tables, and other visual elements, allowing analysts to examine trends, investigate activity, and monitor important security metrics. They can be based on queries and can be customized for different monitoring or investigation requirements. For example, an organization might use a workbook to visualize authentication activity, security incidents, or network-related events. Workbooks are primarily an analysis and visualization capability rather than a mechanism for directly enforcing security controls.
Question 367. Which Microsoft Sentinel capability allows automated actions to be triggered when specific conditions are met for incidents?
- Data Map
- Automation rules
- Sensitivity labels
- Secure Score
Correct Answer: 2. Automation rules
Explanation:
Automation rules in Microsoft Sentinel help organizations automate actions associated with security incidents and alerts. They can be configured to perform actions when defined conditions are met, reducing the amount of repetitive manual work required from security analysts. Depending on the scenario, automation can help update incidents, assign ownership, modify classifications, or trigger other response processes. Automation rules can work alongside playbooks, which can provide more extensive workflow automation through integrations and actions. This capability is particularly useful for security operations teams that need consistent and timely handling of common incident-management tasks.
Question 368. Which Microsoft Defender XDR capability allows security analysts to query large amounts of security data to investigate potential threats?
- Advanced hunting
- Security Defaults
- Access Reviews
- Compliance Manager
Correct Answer: 1. Advanced hunting
Explanation:
Advanced hunting in Microsoft Defender XDR provides security analysts with a powerful query-based method for investigating security data across supported Microsoft security services. Analysts can use queries to search for suspicious activity, identify relationships between events, investigate potential attacks, and develop custom detections. This is particularly useful when analysts need to investigate beyond predefined alerts and incidents. Advanced hunting can help connect information from different security sources and provide greater visibility into potentially related activities. It is an investigation capability rather than a simple dashboard, authentication control, or compliance-management feature.
Question 369. What is a primary purpose of Microsoft Defender for Identity?
- Manage Azure billing
- Protect physical data centers
- Detect identity-based threats in an organization’s environment
- Create data retention labels
Correct Answer: 3. Detect identity-based threats in an organization’s environment
Explanation:
Microsoft Defender for Identity is designed to help organizations detect and investigate identity-based threats, particularly activities involving on-premises identities and Active Directory environments. It can identify suspicious behaviors such as credential-related attacks, reconnaissance, and other activities that may indicate compromise of identity infrastructure. Defender for Identity contributes identity-related signals to the broader Microsoft Defender ecosystem, helping security teams correlate activity with other security information. This differs from Defender for Endpoint, which focuses primarily on endpoint and device threats, and Defender for Office 365, which focuses on threats delivered through email and collaboration services.
Question 370. Which Microsoft Defender for Office 365 capability helps protect users from malicious links contained in email and collaboration messages?
- Safe Links
- Safe Attachments
- Cloud Discovery
- Attack Surface Reduction
Correct Answer: 1. Safe Links
Explanation:
Safe Links is a Microsoft Defender for Office 365 capability designed to help protect users from malicious or suspicious URLs. It can analyze links and apply protection when users interact with URLs in supported email and collaboration scenarios. This helps reduce the risk associated with phishing websites, credential theft pages, and other malicious destinations. Safe Links should be distinguished from Safe Attachments, which focuses on analyzing potentially dangerous file attachments. Together, these capabilities provide different layers of protection against common email-based threats. Organizations can configure Defender for Office 365 policies according to their security requirements and risk tolerance.
Question 371. Which Microsoft Defender for Cloud capability focuses primarily on assessing and improving the security posture of cloud resources?
- Cloud Discovery
- Cloud Security Posture Management
- Safe Attachments
- Communication Compliance
Correct Answer: 2. Cloud Security Posture Management
Explanation:
Cloud Security Posture Management, or CSPM, in Microsoft Defender for Cloud helps organizations identify security weaknesses and improve the security configuration of cloud resources. It can provide recommendations related to security configuration, regulatory requirements, and other posture-related concerns. The goal is to help organizations understand where their cloud environment may not meet desired security practices and provide guidance for improvement. This differs from workload protection capabilities, which focus more directly on protecting specific workloads such as servers, databases, containers, or other resources from active threats. CSPM is therefore primarily associated with security posture visibility and improvement.
Question 372. What does Microsoft Defender for Cloud Apps help organizations discover and manage?
- Physical server hardware
- Cloud application usage
- Employee salaries
- Azure subscription invoices
Correct Answer: 2. Cloud application usage
Explanation:
Microsoft Defender for Cloud Apps provides visibility and control over cloud application usage within an organization. Through capabilities such as Cloud Discovery, organizations can identify cloud applications being used by employees and evaluate them according to security and organizational requirements. This can help security teams identify applications that may not have been formally approved and understand potential risks associated with their use. Defender for Cloud Apps can also provide controls for governing cloud applications and protecting data. It is therefore focused on cloud application security and governance rather than physical infrastructure, financial management, or general endpoint protection.
Question 373. Which Microsoft security metric helps organizations understand their overall security posture through recommendations for reducing security-related risks?
- Microsoft Secure Score
- Microsoft Service Trust Portal
- Microsoft Purview Audit
- Microsoft Entra Domain Services
Correct Answer: 1. Microsoft Secure Score
Explanation:
Microsoft Secure Score provides organizations with a measurement and set of recommendations intended to help improve their security posture across Microsoft services. It evaluates aspects of an organization’s security configuration and identifies actions that can help reduce risk. Security teams can review recommendations, determine which actions are appropriate for their environment, and track progress over time. Secure Score should not be interpreted as a complete measure of every possible security risk, because organizational environments and threat models vary. It is best understood as a practical security-improvement tool that helps organizations prioritize certain recommended security controls.
Question 374. Which Microsoft service provides documentation and information about Microsoft’s security, privacy, and compliance practices?
- Microsoft Sentinel
- Microsoft Service Trust Portal
- Microsoft Intune
- Microsoft Defender for Endpoint
Correct Answer: 2. Microsoft Service Trust Portal
Explanation:
The Microsoft Service Trust Portal provides customers with information and documentation related to Microsoft’s security, privacy, compliance, and regulatory practices for its cloud services. Organizations can use the portal when they need to understand Microsoft’s compliance commitments and review relevant documentation. This information can support internal risk assessments, audits, compliance programs, and vendor evaluations. The Service Trust Portal is different from security products such as Microsoft Sentinel or Defender because its primary purpose is to provide trust and compliance information rather than directly detect threats or manage devices. It is therefore particularly useful for governance and assurance activities.
Question 375. Which Microsoft service is focused on helping organizations manage and understand privacy risks associated with personal data?
- Microsoft Priva
- Microsoft Sentinel
- Azure Firewall
- Microsoft Defender for Endpoint
Correct Answer: 1. Microsoft Priva
Explanation:
Microsoft Priva provides capabilities designed to help organizations identify, understand, and manage privacy risks associated with personal data. Privacy management can involve understanding where personal information exists, identifying potentially risky data-handling activities, and supporting organizational privacy practices. Priva complements Microsoft Purview capabilities that focus on data governance, compliance, information protection, and related requirements. Privacy management is broader than simply preventing unauthorized access to files because organizations may also need to understand how personal data is collected, stored, used, and shared. Microsoft Priva is therefore associated specifically with privacy management rather than endpoint security or network protection.
Question 376. Which Microsoft Purview capability is primarily used to record and search activities performed across Microsoft services for auditing purposes?
- Microsoft Purview Audit
- Microsoft Purview Data Map
- Microsoft Purview eDiscovery
- Microsoft Purview Communication Compliance
Correct Answer: 1. Microsoft Purview Audit
Explanation:
Microsoft Purview Audit provides auditing capabilities that allow organizations to record and search activities across supported Microsoft services. Audit information can help administrators and compliance teams investigate actions performed by users and other entities, support security investigations, and satisfy certain organizational or regulatory requirements. Purview Audit should be distinguished from eDiscovery, which focuses on identifying, preserving, collecting, reviewing, and exporting information for legal or investigative matters. Similarly, Communication Compliance focuses on detecting and managing potentially inappropriate communications. Audit is therefore primarily concerned with maintaining and searching activity records that can provide evidence about actions within an environment.
Question 377. Which Microsoft Purview capability is designed to support legal investigations by helping organizations identify, preserve, collect, review, and export relevant content?
- Data Loss Prevention
- eDiscovery
- Sensitivity Labels
- Data Map
Correct Answer: 2. eDiscovery
Explanation:
Microsoft Purview eDiscovery is designed to support legal, regulatory, and internal investigations involving organizational information. It provides capabilities for identifying potentially relevant content and, depending on the eDiscovery functionality being used, preserving, collecting, reviewing, and exporting information. Legal holds can also be used to help preserve relevant information so that it is not improperly removed during an investigation. eDiscovery is different from Data Loss Prevention, which is primarily intended to help prevent inappropriate sharing or transfer of sensitive information. Understanding this distinction is important because both capabilities deal with organizational data but serve different compliance and investigation purposes.
Question 378. What is the main purpose of Microsoft Purview retention labels?
- Control how long content should be retained and what happens to it afterward
- Encrypt every network packet
- Replace Microsoft Entra ID authentication
- Detect malware on endpoints
Correct Answer: 1. Control how long content should be retained and what happens to it afterward
Explanation:
Microsoft Purview retention labels help organizations apply retention requirements to content according to business, legal, or regulatory needs. A retention label can specify how long content should be retained and can support actions that occur when the retention period is reached, depending on the configured policy and applicable requirements. Retention labels are different from sensitivity labels. Sensitivity labels are primarily concerned with classifying and protecting sensitive information, while retention labels focus on information lifecycle and retention requirements. Organizations can use these capabilities together when they need both protection and governance controls for business records and other important content.
Question 379. Which Microsoft Purview capability helps identify and manage potentially inappropriate or risky communications within an organization?
- Communication Compliance
- Azure DDoS Protection
- Defender for Endpoint
- Network Security Group
Correct Answer: 1. Communication Compliance
Explanation:
Microsoft Purview Communication Compliance helps organizations detect, investigate, and manage potentially inappropriate communications in supported communication environments. Policies can be configured to identify communications that may violate organizational standards, regulatory requirements, or other defined policies. The feature can help organizations review potentially problematic messages while supporting appropriate governance processes. It is distinct from Microsoft Purview Data Loss Prevention, which focuses on preventing or controlling the sharing of sensitive information, and Insider Risk Management, which focuses on identifying potentially risky user activities. Communication Compliance is specifically oriented toward reviewing communications against defined organizational requirements.
Question 380. Which Zero Trust principle requires organizations to grant users and workloads only the permissions necessary to perform their tasks?
- Assume breach
- Verify explicitly
- Use least privilege access
- Defense in depth
Correct Answer: 3. Use least privilege access
Explanation:
The least privilege principle means that users, applications, devices, and workloads should receive only the access permissions necessary to perform their required tasks. Limiting permissions reduces the potential impact if an identity or resource becomes compromised because an attacker may have fewer privileges available to misuse. Least privilege is an important component of Zero Trust and can be implemented through technologies such as role-based access control, privileged identity management, and carefully managed application permissions. It should be applied continuously rather than treated as a one-time configuration because organizational responsibilities, applications, and access requirements can change over time.