Microsoft SC-900 Practice Test Questions and Exam Dumps Part 15 Q281-300

View Full Microsoft SC-900 Exam Dumps and Practice Test Dumps

 

Question 281. Which Microsoft Entra feature allows administrators to provide temporary privileged access to roles?

  1. Microsoft Entra Privileged Identity Management
  2. Microsoft Purview Audit
  3. Microsoft Sentinel
  4. Microsoft Defender for Office 365

Correct Answer: 1. Microsoft Entra Privileged Identity Management.

Explanation:

Microsoft Entra Privileged Identity Management, commonly called PIM, helps organizations manage, control, and monitor access to privileged roles. Instead of giving administrators permanent privileged permissions, eligible users can activate roles only when needed and for a limited period. Depending on the configuration, activation can require additional authentication, approval, or justification. This approach supports the principle of least privilege and reduces the amount of time highly privileged permissions remain active. PIM also provides visibility into privileged role assignments and activity, helping organizations better govern administrative access and reduce unnecessary exposure to privileged accounts.

Question 282. What is the primary purpose of Microsoft Entra Access Reviews?

  1. To scan endpoints for malware
  2. To verify whether users should continue to have access to resources
  3. To create firewall rules
  4. To encrypt databases

Correct Answer: 2. To verify whether users should continue to have access to resources.

Explanation:

Microsoft Entra Access Reviews help organizations periodically review access to groups, applications, and other supported resources. Over time, employees may change departments, responsibilities, or projects, while external users may no longer need access. Access Reviews provide a structured way for designated reviewers to confirm whether users should retain their permissions. This supports good identity governance and the principle of least privilege. Instead of assuming that previously granted access should remain forever, organizations can periodically reassess it and remove access that is no longer justified, reducing unnecessary exposure to organizational resources.

Question 283. Which Microsoft Entra capability can detect potentially risky sign-ins and users?

  1. Microsoft Entra ID Protection
  2. Azure Key Vault
  3. Microsoft Purview Data Map
  4. Microsoft Intune

Correct Answer: 1. Microsoft Entra ID Protection.

Explanation:

Microsoft Entra ID Protection uses identity-related signals to identify potentially risky users and sign-in activity. It can detect patterns associated with compromised identities or suspicious authentication attempts and provide risk information that organizations can use in their identity protection strategy. Administrators can integrate these risk signals with Conditional Access policies to require appropriate actions when risk is detected. For example, a risky sign-in may trigger stronger authentication requirements. ID Protection therefore complements basic authentication by adding risk-based intelligence to identity security, helping organizations respond dynamically rather than treating every sign-in as equally trustworthy.

Question 284. Which Microsoft Entra capability allows organizations to create policies that require MFA based on sign-in conditions?

  1. Microsoft Purview
  2. Conditional Access
  3. Microsoft Sentinel notebooks
  4. Azure Resource Locks

Correct Answer: 2. Conditional Access.

Explanation:

Microsoft Entra Conditional Access enables organizations to create policies that evaluate contextual signals and enforce access requirements. One common use is requiring multifactor authentication when specific conditions are met. Administrators can consider factors such as the user, application, device, location, or risk associated with a sign-in. Conditional Access provides a more flexible approach than applying the exact same access requirement to every user and situation. It can help organizations implement Zero Trust principles by making access decisions based on available context. Conditional Access policies can also be combined with other identity and device-management capabilities.

Question 285. What is the main purpose of Microsoft Entra Security Defaults?

  1. To provide baseline identity security protections with minimal configuration
  2. To replace all Microsoft Defender products
  3. To manage database permissions
  4. To create custom Sentinel dashboards

Correct Answer: 1. To provide baseline identity security protections with minimal configuration.

Explanation:

Microsoft Entra Security Defaults provide a basic set of identity security protections intended to help organizations establish foundational security without requiring extensive policy configuration. These defaults can help protect identities by introducing stronger authentication practices and reducing common identity-related risks. Security Defaults are particularly useful for organizations that need a straightforward starting point for identity security. More advanced environments may use Conditional Access and other Microsoft Entra capabilities when they require more granular control. The important distinction is that Security Defaults provide baseline protections, while Conditional Access enables detailed, condition-based access policies.

Question 286. Which Microsoft Defender for Office 365 feature helps protect users from malicious email attachments?

  1. Safe Attachments
  2. Access Reviews
  3. Data Map
  4. Privileged Identity Management

Correct Answer: 1. Safe Attachments.

Explanation:

Microsoft Defender for Office 365 Safe Attachments helps protect users from potentially malicious attachments delivered through email and supported collaboration services. The capability examines attachments and uses security analysis to identify potentially harmful content before it reaches users in an unsafe form. This is particularly useful because attackers frequently use malicious documents or files as an initial delivery mechanism. Safe Attachments works alongside other Defender for Office 365 capabilities, such as Safe Links, which focuses on malicious URLs. Together, these controls help reduce the risk associated with common email-based attack techniques.

Question 287. Which Microsoft Defender for Office 365 capability helps protect users when they select potentially malicious URLs?

  1. Secure Score
  2. Safe Links
  3. Compliance Manager
  4. Data Lifecycle Management

Correct Answer: 2. Safe Links.

Explanation:

Safe Links is a Microsoft Defender for Office 365 capability designed to help protect users from malicious or suspicious URLs. Links in email and supported collaboration content can be checked when users interact with them, helping identify destinations associated with threats. This provides an additional layer of protection against phishing and other attacks that attempt to direct users to harmful websites. Safe Links and Safe Attachments address different parts of the threat: Safe Links focuses primarily on URLs, while Safe Attachments focuses on potentially dangerous files. Both contribute to protecting users from common messaging-based attacks.

Question 288. What is the primary security function of Microsoft Defender for Identity?

  1. Detecting identity-related threats and suspicious activity
  2. Managing cloud storage quotas
  3. Creating sensitivity labels
  4. Managing application licenses

Correct Answer: 1. Detecting identity-related threats and suspicious activity.

Explanation:

Microsoft Defender for Identity helps organizations identify suspicious activity and threats associated with identities and identity infrastructure. It can analyze signals related to authentication and identity behavior to help detect activities that may indicate compromise or attacks. This capability is especially relevant in environments where attackers attempt to move through an organization by compromising accounts or abusing identity infrastructure. Defender for Identity contributes to Microsoft’s broader extended detection and response ecosystem, where identity signals can be correlated with endpoint, email, and other security information to provide a more complete understanding of an incident.

Question 289. Which Microsoft Defender for Cloud capability helps protect cloud workloads such as servers, databases, and containers?

  1. Workload protections
  2. Access Reviews
  3. Sensitivity labels
  4. Authentication Methods

Correct Answer: 1. Workload protections.

Explanation:

Microsoft Defender for Cloud provides workload protection capabilities designed to help protect supported cloud resources and workloads. Depending on the workload and enabled capabilities, this can include security protections and threat detection for resources such as servers, databases, containers, and other supported services. Workload protection is different from cloud security posture management, which focuses more on identifying configuration weaknesses and improving the overall security posture. Defender for Cloud brings these areas together so organizations can assess their environment while also applying appropriate protections to supported workloads that may contain important business data and applications.

Question 290. What does Cloud Discovery in Microsoft Defender for Cloud Apps help organizations identify?

  1. Which cloud applications are being used within the organization
  2. Which users have administrator passwords
  3. Which database tables require indexing
  4. Which devices need replacement batteries

Correct Answer: 1. Which cloud applications are being used within the organization.

Explanation:

Cloud Discovery in Microsoft Defender for Cloud Apps helps organizations gain visibility into cloud application usage. It can help identify applications being used across an organization’s environment and provide information that can support security and governance decisions. This visibility is useful because employees may use cloud services that have not been formally approved or assessed by the organization. Understanding the cloud application landscape can help security teams evaluate risk, identify potentially unsanctioned applications, and determine where additional controls may be appropriate. Cloud Discovery therefore contributes to visibility and governance of cloud application usage.

Question 291. What is the purpose of Microsoft Purview sensitivity labels?

  1. To classify and help protect sensitive organizational information
  2. To assign Azure administrator roles
  3. To detect endpoint malware
  4. To create network subnets

Correct Answer: 1. To classify and help protect sensitive organizational information.

Explanation:

Microsoft Purview sensitivity labels help organizations classify information according to its sensitivity and apply appropriate protection settings. For example, an organization may define categories such as public, internal, confidential, or highly confidential and associate protection controls with those classifications. Depending on the configuration, labels can help control how sensitive information is handled and shared. Sensitivity labels are part of Microsoft’s broader information protection capabilities and are different from retention labels, which focus on how long information should be retained and managed. Proper classification can improve visibility and help organizations apply consistent data protection practices.

Question 292. Which Microsoft Purview capability can help prevent sensitive information from being shared inappropriately?

  1. Data Loss Prevention
  2. Microsoft Entra PIM
  3. Microsoft Sentinel Workbooks
  4. Azure DDoS Protection

Correct Answer: 1. Data Loss Prevention.

Explanation:

Microsoft Purview Data Loss Prevention, or DLP, helps organizations identify and protect sensitive information by applying policies to supported locations and activities. DLP policies can detect certain types of sensitive information and take configured actions when organizational rules are violated. Depending on the scenario, actions may include blocking an activity, restricting sharing, generating alerts, or notifying users. DLP is therefore focused on reducing inappropriate exposure or transfer of sensitive information. It complements sensitivity labels and other information-protection capabilities by applying policy-based controls to help protect data while it is being used, shared, or transmitted.

Question 293. Which Microsoft Purview capability is designed to manage how long certain content should be retained?

  1. Data Lifecycle Management
  2. Defender for Endpoint
  3. Microsoft Entra ID Protection
  4. Microsoft Sentinel

Correct Answer: 1. Data Lifecycle Management.

Explanation:

Microsoft Purview Data Lifecycle Management helps organizations manage the retention and disposal of information according to organizational requirements. Retention policies and retention labels can be used to establish rules about how long certain content should be retained and what should happen when the retention period ends, depending on the configuration and applicable workload. This supports information governance by preventing organizations from keeping information indefinitely without purpose while also helping preserve information that must be retained. Data Lifecycle Management is distinct from DLP, which primarily focuses on preventing inappropriate sharing or movement of sensitive information.

Question 294. Which Microsoft Purview capability is specifically designed to help organizations identify and manage potential insider risks?

  1. Insider Risk Management
  2. Azure Firewall
  3. Microsoft Entra Domain Services
  4. Microsoft Defender Antivirus

Correct Answer: 1. Insider Risk Management.

Explanation:

Microsoft Purview Insider Risk Management helps organizations identify and investigate potentially risky activities associated with users while taking privacy and organizational requirements into account. Insider risk scenarios can involve accidental or intentional activities that could expose sensitive information. The capability can use signals and defined policies to help identify potentially concerning behavior for further investigation. It is not simply an employee-monitoring tool; organizations need appropriate governance and privacy controls when implementing insider-risk processes. Insider Risk Management is part of Microsoft’s broader Purview compliance and data-governance capabilities and focuses specifically on risks arising from activities involving organizational users.

Question 295. What is the primary purpose of Microsoft Purview Communication Compliance?

  1. To help organizations identify potentially inappropriate communications
  2. To configure Azure virtual networks
  3. To manage endpoint antivirus signatures
  4. To assign privileged roles

Correct Answer: 1. To help organizations identify potentially inappropriate communications.

Explanation:

Microsoft Purview Communication Compliance helps organizations identify and review potentially inappropriate or policy-violating communications in supported communication environments. Organizations can define policies designed to identify content that may require review, such as certain inappropriate language, regulatory concerns, or other organizational policy issues. The capability supports compliance processes by helping designated reviewers examine flagged communications. It does not replace security products that detect malware or identity services that control access. Communication Compliance belongs to the Microsoft Purview compliance ecosystem and focuses on helping organizations manage communication-related compliance risks.

Question 296. What is Microsoft Purview Audit primarily used for?

  1. Recording and searching relevant user and administrative activities
  2. Blocking distributed denial-of-service attacks
  3. Deploying mobile applications
  4. Creating cloud network gateways

Correct Answer: 1. Recording and searching relevant user and administrative activities.

Explanation:

Microsoft Purview Audit provides capabilities for searching and reviewing supported audit activities within Microsoft environments. Audit records can help organizations investigate actions performed by users and administrators, support compliance requirements, and understand events that occurred within supported services. For example, an investigation may require determining when a particular action occurred or which account performed an activity. Audit information can therefore provide valuable evidence during security investigations and compliance reviews. It is important to distinguish auditing from prevention: audit records document activities, while other Microsoft security controls are responsible for preventing or blocking particular actions.

Question 297. What is Microsoft Purview eDiscovery primarily designed to support?

  1. Identifying, collecting, reviewing, and managing electronically stored information for investigations or legal matters
  2. Deploying antivirus software
  3. Configuring conditional access
  4. Managing DNS records

Correct Answer: 1. Identifying, collecting, reviewing, and managing electronically stored information for investigations or legal matters.

Explanation:

Microsoft Purview eDiscovery provides capabilities that help organizations locate, collect, review, and manage electronically stored information for investigations, legal proceedings, and other organizational matters. eDiscovery can help authorized personnel identify relevant content across supported data sources and work with that information through an established review process. It is different from general auditing because eDiscovery focuses on finding and managing potentially relevant content, while auditing records activities. eDiscovery may also work alongside legal hold capabilities when information needs to be preserved. Organizations should configure these processes according to their legal, compliance, and governance requirements.

Question 298. Which Microsoft security metric provides recommendations that can help an organization improve its security posture?

  1. Microsoft Secure Score
  2. Microsoft Purview eDiscovery
  3. Microsoft Entra Access Reviews
  4. Azure Key Vault

Correct Answer: 1. Microsoft Secure Score.

Explanation:

Microsoft Secure Score provides an assessment-oriented view of security posture and offers improvement actions that organizations can consider. It helps security teams understand areas where security controls may be strengthened and provides recommendations associated with supported Microsoft security capabilities. Secure Score is not a guarantee that an organization is secure, nor does achieving a particular score eliminate all threats. Instead, it provides a structured way to identify security improvement opportunities. Organizations can use the information to prioritize actions, track progress, and understand how implementing recommended security controls may improve their overall security posture.

Question 299. What is the primary purpose of Microsoft Purview Compliance Manager?

  1. To help organizations assess and manage compliance activities and improvement actions
  2. To scan endpoints for malware
  3. To create Azure virtual machines
  4. To manage email attachments

Correct Answer: 1. To help organizations assess and manage compliance activities and improvement actions.

Explanation:

Microsoft Purview Compliance Manager helps organizations assess compliance-related requirements and manage improvement actions associated with regulations, standards, and organizational controls. It can provide assessments, improvement actions, and other information that helps organizations understand their compliance posture. Compliance Manager does not automatically make an organization compliant with every applicable law or regulation. Instead, it provides tools and guidance that can support compliance management. Organizations still need to determine which requirements apply to their specific operations and maintain appropriate policies, processes, evidence, and governance beyond the technical controls represented within the platform.

Question 300. Which principle of Zero Trust requires organizations to make access decisions based on multiple signals rather than automatically trusting a user or device?

  1. Verify explicitly
  2. Assume breach
  3. Trust all internal users
  4. Disable authentication

Correct Answer: 1. Verify explicitly.

Explanation:

The Zero Trust principle of “verify explicitly” means organizations should authenticate and authorize access by considering available signals and context instead of automatically trusting a user, device, or network location. Relevant signals can include identity, device health, location, application, data sensitivity, and risk. This approach recognizes that an account being inside a corporate network does not automatically make its activity trustworthy. Microsoft security capabilities such as Entra Conditional Access can help implement this principle by evaluating contextual information before granting access. Verify explicitly works together with the other Zero Trust principles, including using least privilege and assuming breach.