Microsoft SC-900 Practice Test Questions and Exam Dumps Part 13 Q241-260

View Full Microsoft SC-900 Exam Dumps and Practice Test Dumps

 

Question 241. Which Microsoft Entra capability allows an organization to provide temporary access to resources through predefined access packages?

  1. Entitlement management
  2. Microsoft Entra Domain Services
  3. Password Hash Synchronization
  4. Security Defaults

Correct Answer: 1. Entitlement management

Explanation:

Microsoft Entra entitlement management helps organizations govern access through access packages. An access package can contain resources such as groups, applications, and SharePoint sites, along with policies that determine who can request access, whether approval is required, and how long access should remain active. This makes entitlement management useful for situations where access needs to be granted temporarily or according to defined business rules. It can also support external collaboration scenarios. By automating aspects of access requests and expiration, entitlement management helps reduce unnecessary standing access and supports identity governance and the principle of least privilege.

Question 242. Which Microsoft Entra feature can automatically remove access when a user’s eligibility for a particular access package expires?

  1. Entitlement management
  2. Microsoft Sentinel
  3. Defender for Endpoint
  4. Azure Key Vault

Correct Answer: 1. Entitlement management

Explanation:

Microsoft Entra entitlement management can use access package policies that define how long users may retain assigned access. When an assignment reaches its configured expiration, access can be removed according to the policy. This provides an important governance mechanism because access does not necessarily remain indefinitely after a user no longer needs it. Expiration controls can be especially useful for temporary projects, external collaborators, contractors, and sensitive resources. Administrators can also configure approval and review requirements. The overall purpose is to manage access throughout its lifecycle rather than simply granting permissions permanently.

Question 243. Which Microsoft Entra feature can automatically execute identity lifecycle tasks based on employee joiner, mover, and leaver events?

  1. Lifecycle Workflows
  2. Access Reviews
  3. Security Defaults
  4. Microsoft Entra Domain Services

Correct Answer: 1. Lifecycle Workflows

Explanation:

Microsoft Entra Lifecycle Workflows help automate identity lifecycle processes for users throughout different stages of employment. Organizations can configure workflows to perform supported tasks when employees join, change roles, or leave the organization. Automating these activities can improve consistency and reduce the amount of repetitive manual administration required from identity teams. For example, onboarding workflows can help prepare accounts and access, while offboarding workflows can assist with removing or restricting access. Lifecycle Workflows complement access governance features such as entitlement management and Access Reviews, providing a broader framework for managing identities throughout their organizational lifecycle.

Question 244. Which Microsoft Entra capability helps administrators periodically confirm that users still need access to a resource?

  1. Access Reviews
  2. Managed identities
  3. Authentication Methods
  4. Cloud Sync

Correct Answer: 1. Access Reviews

Explanation:

Microsoft Entra Access Reviews provide a structured way for organizations to periodically verify whether users should continue to have access to resources. Reviewers can evaluate memberships in groups, access to applications, or other supported resources and confirm whether access remains appropriate. This is particularly useful for privileged groups, guest users, and sensitive applications. Access Reviews support least privilege by helping identify unnecessary permissions that may accumulate over time. They are different from entitlement management, which governs how access is requested and assigned, while Access Reviews focus on periodically validating whether existing access should continue.

Question 245. Which Microsoft Entra capability can synchronize identities between on-premises directories and Microsoft Entra ID without requiring the traditional Microsoft Entra Connect synchronization engine?

  1. Microsoft Entra Cloud Sync
  2. Microsoft Entra PIM
  3. Conditional Access
  4. Microsoft Entra ID Protection

Correct Answer: 1. Microsoft Entra Cloud Sync

Explanation:

Microsoft Entra Cloud Sync provides a lightweight, cloud-managed approach for synchronizing identities from supported on-premises Active Directory environments with Microsoft Entra ID. It uses provisioning agents and cloud configuration rather than relying exclusively on the traditional synchronization architecture. Cloud Sync can be useful when organizations need flexible synchronization scenarios or want more configuration to be managed from the cloud. It is important to distinguish Cloud Sync from Microsoft Entra Connect, which is another hybrid identity synchronization solution. Both can synchronize identities, but they use different architectures and have different capabilities and deployment considerations.

Question 246. Which Microsoft Entra capability allows an application to authenticate to Azure services without storing a client secret in application code?

  1. Managed identity
  2. Access Review
  3. Dynamic group
  4. Security Defaults

Correct Answer: 1. Managed identity

Explanation:

Managed identities provide Azure resources with an identity that can authenticate to supported services without requiring developers to store credentials such as passwords or client secrets in application code. Azure manages the identity’s credentials, reducing the administrative burden associated with credential storage and rotation. Administrators can assign appropriate permissions to the managed identity so the application receives only the access it needs. This supports the principle of least privilege and reduces the risk of credentials being exposed in source code or configuration files. Managed identities are particularly useful when applications need to access Azure resources such as Key Vault, storage, or databases.

Question 247. Which identity object represents an application or service that needs to authenticate to Microsoft Entra ID?

  1. Service principal
  2. Security group
  3. Dynamic group
  4. Access package

Correct Answer: 1. Service principal

Explanation:

A service principal represents an application or service identity within Microsoft Entra ID. It allows an application to authenticate and receive authorization to access resources according to permissions assigned to that identity. Service principals are commonly used by applications, automation tools, and services that need to access Azure or Microsoft resources programmatically. They should be granted only the permissions necessary for their tasks. A service principal differs from a managed identity because managed identities provide an Azure-managed identity lifecycle for supported Azure resources, while service principals are application identities that can be used in broader authentication scenarios.

Question 248. Which Microsoft Entra capability can help detect users whose accounts may have been compromised?

  1. Identity Protection
  2. Group-based licensing
  3. Lifecycle Workflows
  4. Domain Services

Correct Answer: 1. Identity Protection

Explanation:

Microsoft Entra ID Protection helps organizations detect identity-related risks, including potentially compromised users and risky sign-ins. It uses signals and detections to identify activities that may indicate credential compromise or other identity threats. Organizations can review risk information and use Conditional Access policies to apply appropriate responses, such as requiring additional authentication or blocking access when risk conditions meet configured thresholds. Identity Protection therefore connects identity threat detection with access control. It differs from Microsoft Defender for Identity, which focuses heavily on identity threats associated with on-premises Active Directory environments and can provide signals into broader security investigations.

Question 249. Which Microsoft Entra capability can require multifactor authentication when a user attempts to access a sensitive application?

  1. Conditional Access
  2. Microsoft Entra Cloud Sync
  3. Dynamic Groups
  4. Microsoft Entra Domain Services

Correct Answer: 1. Conditional Access

Explanation:

Microsoft Entra Conditional Access allows organizations to create policies that evaluate access requests using conditions such as users, applications, device state, location, risk, and other available signals. One common control is requiring multifactor authentication when users access sensitive applications. Conditional Access can therefore provide contextual access decisions rather than simply allowing or denying users based on their identity alone. Administrators can create different policies for different applications and scenarios. Conditional Access is an important Zero Trust capability because it supports the principle of verifying access requests using relevant contextual information before granting access to protected resources.

Question 250. Which Microsoft Entra feature provides baseline security settings such as requiring multifactor authentication for administrative accounts?

  1. Security Defaults
  2. Microsoft Entra PIM
  3. Access Reviews
  4. Azure Policy

Correct Answer: 1. Security Defaults

Explanation:

Microsoft Entra Security Defaults provide a basic set of identity security protections designed to help organizations establish foundational security controls. These defaults can include requirements related to multifactor authentication, protection of privileged accounts, and blocking legacy authentication methods. Security Defaults are intended to provide a simpler baseline for organizations that do not need the more detailed customization available through Conditional Access policies. Conditional Access offers more granular control over users, applications, locations, devices, and authentication requirements. Security Defaults are therefore best understood as a foundational security configuration rather than a replacement for every advanced identity governance and access scenario.

Question 251. Which Microsoft Entra feature can help administrators manage privileged roles by making them eligible rather than permanently active?

  1. Privileged Identity Management
  2. Microsoft Entra Cloud Sync
  3. Microsoft Entra External ID
  4. Self-Service Password Reset

Correct Answer: 1. Privileged Identity Management

Explanation:

Microsoft Entra Privileged Identity Management allows administrators to manage privileged role assignments using eligibility and just-in-time activation. Instead of keeping an administrator permanently active in a highly privileged role, an eligible user can activate the role when it is needed, subject to configured requirements such as multifactor authentication, approval, justification, and time limits. This reduces standing administrative privilege and supports least privilege. PIM can also provide visibility into role assignments and activation activity. The goal is not to eliminate administrative roles but to make privileged access more controlled, temporary, and auditable.

Question 252. Which Microsoft security principle states that users should receive only the permissions required to perform their work?

  1. Least privilege
  2. Assume breach
  3. Defense in depth
  4. Shared responsibility

Correct Answer: 1. Least privilege

Explanation:

Least privilege means granting identities only the permissions necessary to perform their required tasks. This principle applies to users, administrators, applications, services, and other identities. Limiting permissions can reduce the potential damage caused by compromised credentials, accidental actions, or malicious activity. Microsoft technologies such as role-based access control, Privileged Identity Management, Access Reviews, and entitlement management can help organizations implement least-privilege practices. Permissions should also be reviewed periodically because users and applications may change roles or requirements. Removing unnecessary access helps reduce the attack surface and limits the opportunities available to an attacker after an account is compromised.

Question 253. Which Microsoft security principle assumes that an attacker could already be present inside an organization’s environment?

  1. Assume breach
  2. Single sign-on
  3. Shared responsibility
  4. Federation

Correct Answer: 1. Assume breach

Explanation:

Assume breach is one of the fundamental principles of Zero Trust. It requires organizations to design security controls with the possibility that an attacker may already have obtained access to a user account, device, application, or network segment. Instead of relying entirely on perimeter security, organizations use layered controls such as least privilege, segmentation, continuous monitoring, strong authentication, endpoint protection, and threat detection. This approach helps limit lateral movement and reduce the impact of successful compromises. Assume breach does not mean that organizations expect every system to be compromised; rather, it encourages preparation for compromise so that defenses remain effective when prevention fails.

Question 254. Which Microsoft security principle requires access decisions to consider identity, device state, location, risk, and other relevant signals?

  1. Verify explicitly
  2. Assume breach
  3. Trust by default
  4. Open access

Correct Answer: 1. Verify explicitly

Explanation:

Verify explicitly is a Zero Trust principle that requires organizations to evaluate relevant information before granting access. Instead of automatically trusting a request because it comes from a known user or internal network, access decisions can consider identity, device health, location, application, resource sensitivity, and risk. Microsoft Entra Conditional Access is an important technology for implementing this approach because it can evaluate multiple signals and apply appropriate controls. The principle helps organizations reduce the risk of compromised credentials and unmanaged devices. It also supports adaptive security because access requirements can change depending on the context of each request.

Question 255. Which Microsoft Defender solution provides security capabilities across endpoints, identities, email, and applications through a unified platform?

  1. Microsoft Defender XDR
  2. Microsoft Purview
  3. Microsoft Intune
  4. Azure Key Vault

Correct Answer: 1. Microsoft Defender XDR

Explanation:

Microsoft Defender XDR provides an integrated security platform that correlates signals and incidents across supported Microsoft security products. Depending on the environment, this can include protection and detection capabilities for endpoints, identities, email and collaboration services, and other areas. By correlating related alerts, Defender XDR can provide security teams with a more complete view of an attack and help them investigate and respond efficiently. This differs from Microsoft Purview, which focuses primarily on data governance, compliance, and information protection, and Intune, which focuses on device and application management. Defender XDR is centered on threat detection, investigation, and response.

Question 256. Which Microsoft Defender solution is specifically focused on protecting identities in on-premises Active Directory environments?

  1. Microsoft Defender for Identity
  2. Microsoft Defender for Office 365
  3. Microsoft Defender for Cloud Apps
  4. Microsoft Defender for Endpoint

Correct Answer: 1. Microsoft Defender for Identity

Explanation:

Microsoft Defender for Identity focuses on detecting identity-based threats involving on-premises Active Directory environments. It monitors identity-related activity and can help security teams identify suspicious behavior such as reconnaissance, credential theft, and lateral movement. Its signals can also contribute to Microsoft Defender XDR investigations, allowing identity-related activity to be correlated with threats detected in other areas. Defender for Identity is different from Defender for Endpoint, which focuses on endpoint devices, and Defender for Office 365, which protects email and collaboration workloads. Understanding these product boundaries is important when learning the Microsoft security portfolio.

Question 257. Which Microsoft Defender solution protects email and collaboration services against phishing, malware, and other threats?

  1. Microsoft Defender for Office 365
  2. Microsoft Defender for Identity
  3. Microsoft Defender for Cloud
  4. Microsoft Defender for Endpoint

Correct Answer: 1. Microsoft Defender for Office 365

Explanation:

Microsoft Defender for Office 365 provides security capabilities for supported Microsoft 365 email and collaboration workloads. It helps protect users against threats such as phishing, malicious links, malicious attachments, and other communication-based attacks. Capabilities such as Safe Links and Safe Attachments provide additional protection against common attack vectors. Defender for Office 365 can also support investigation and response activities related to email threats. It should not be confused with Defender for Endpoint, which focuses on devices, or Defender for Identity, which focuses on identity threats associated with Active Directory. Each Defender product addresses a specific security area while contributing to the broader Defender ecosystem.

Question 258. Which Microsoft Defender solution provides security posture management and workload protection for cloud resources?

  1. Microsoft Defender for Cloud
  2. Microsoft Defender for Office 365
  3. Microsoft Defender for Identity
  4. Microsoft Defender for Endpoint

Correct Answer: 1. Microsoft Defender for Cloud

Explanation:

Microsoft Defender for Cloud provides cloud security capabilities that include security posture management and workload protection. Its posture management capabilities can identify configuration risks and provide recommendations for improving the security state of cloud resources. Workload protection can provide additional security capabilities for supported resources such as servers, containers, databases, and storage. Defender for Cloud is therefore focused on protecting cloud environments and workloads rather than email, traditional identity infrastructure, or endpoint devices. Understanding this distinction helps administrators select the appropriate Microsoft Defender solution for a particular security requirement.

Question 259. Which Microsoft Defender solution provides visibility and control over the use of cloud applications within an organization?

  1. Microsoft Defender for Cloud Apps
  2. Microsoft Defender for Identity
  3. Microsoft Defender for Endpoint
  4. Microsoft Defender for Office 365

Correct Answer: 1. Microsoft Defender for Cloud Apps

Explanation:

Microsoft Defender for Cloud Apps provides visibility, governance, and security controls for cloud applications. Its capabilities can help organizations discover cloud applications, assess application risk, monitor usage, and apply appropriate controls. Cloud Discovery is particularly useful for identifying applications being used across an environment, including applications that may not have been formally approved. Defender for Cloud Apps is distinct from Defender for Cloud, which focuses on cloud infrastructure and workload security. It is also different from Defender for Office 365, which focuses primarily on Microsoft 365 email and collaboration threats. The product helps organizations manage risks associated with cloud application usage.

Question 260. Which Microsoft Defender solution is primarily responsible for protecting endpoint devices against malware and other endpoint threats?

  1. Microsoft Defender for Endpoint
  2. Microsoft Defender for Cloud Apps
  3. Microsoft Defender for Identity
  4. Microsoft Defender for Office 365

Correct Answer: 1. Microsoft Defender for Endpoint

Explanation:

Microsoft Defender for Endpoint provides endpoint security capabilities designed to protect supported devices against malware, suspicious activity, and other threats. It includes capabilities such as endpoint detection and response, vulnerability management, attack surface reduction, and threat investigation. The service can help security teams identify suspicious activity on devices and take appropriate response actions. Defender for Endpoint works as part of the broader Microsoft Defender ecosystem and can share signals with Defender XDR for cross-domain investigations. Its primary focus is endpoint protection and detection, distinguishing it from the Defender services dedicated to cloud applications, identities, or Microsoft 365 communications.