View Full Microsoft SC-900 Exam Dumps and Practice Test Dumps
Question 1. What is the primary purpose of Microsoft Entra ID?
- To manage physical network cables
- To provide identity and access management
- To store application source code
- To monitor CPU temperature
Correct Answer: 2. To provide identity and access management
Explanation:
Microsoft Entra ID is Microsoft’s cloud-based identity and access management service. It helps organizations manage users, groups, applications, devices, and access to resources. Administrators can use Entra ID to authenticate users and control which resources they are allowed to access. It also supports capabilities such as multifactor authentication, Conditional Access, application identities, and single sign-on. These capabilities help organizations establish centralized identity controls across Microsoft cloud services and other applications. Entra ID is therefore fundamentally focused on identity and access rather than physical networking, source-code storage, or hardware monitoring.
Question 2. Which Microsoft security principle requires users to receive only the permissions necessary to perform their assigned tasks?
- Least privilege
- Data residency
- High availability
- Network segmentation
Correct Answer: 1. Least privilege
Explanation:
The principle of least privilege means that users, applications, and services should receive only the permissions required to perform their intended tasks. Limiting permissions reduces the potential impact if an account or application is compromised. For example, a user who only needs to read documents should not automatically receive permission to delete or modify those documents. Least privilege is an important component of identity and security management because excessive permissions can increase security risk. Data residency concerns where information is stored, high availability focuses on service continuity, and network segmentation separates network environments. Therefore, least privilege directly addresses controlled authorization.
Question 3. Which Microsoft security capability can require users to provide an additional authentication method, such as an authenticator app notification?
- Microsoft Defender for Cloud
- Microsoft Purview
- Microsoft Entra multifactor authentication
- Microsoft Sentinel
Correct Answer: 3. Microsoft Entra multifactor authentication
Explanation:
Microsoft Entra multifactor authentication, commonly referred to as MFA, requires users to provide more than one form of authentication when signing in. Depending on the configuration, a user may provide a password together with an authenticator app approval, security key, or another supported authentication method. MFA strengthens account security because a stolen password alone may not be sufficient to access the account. Microsoft Defender for Cloud focuses on cloud security posture and workload protection, Microsoft Purview focuses on data governance and compliance, and Microsoft Sentinel provides security information and event management capabilities. Therefore, Entra MFA is the relevant authentication capability.
Question 4. What is the main purpose of Microsoft Entra Conditional Access?
- To create physical firewalls
- To apply access decisions based on specified conditions
- To compress files
- To create database backups
Correct Answer: 2. To apply access decisions based on specified conditions
Explanation:
Microsoft Entra Conditional Access helps organizations control access to resources by evaluating conditions associated with a sign-in request. Administrators can consider factors such as the user, application, device, location, and risk when defining access policies. Depending on the policy, access may be allowed, blocked, or require additional controls such as multifactor authentication. Conditional Access therefore provides a policy-based approach to controlling access rather than relying solely on usernames and passwords. It is not designed to create physical firewalls, compress files, or perform database backups. Its primary purpose is to apply access decisions according to defined conditions.
Question 5. Which Microsoft service provides cloud-based security information and event management (SIEM) capabilities?
- Microsoft Intune
- Microsoft Purview
- Microsoft Sentinel
- Microsoft Entra ID
Correct Answer: 3. Microsoft Sentinel
Explanation:
Microsoft Sentinel is Microsoft’s cloud-native security information and event management solution. It can collect security-related data from Microsoft services, cloud platforms, applications, devices, and other sources. Security teams can use Sentinel to analyze events, identify suspicious activity, investigate incidents, and create automated responses. Its cloud-native architecture allows organizations to scale security monitoring without deploying and maintaining traditional SIEM infrastructure themselves. Microsoft Intune focuses on device and application management, Microsoft Purview provides data governance and compliance capabilities, and Entra ID manages identities and access. Therefore, Microsoft Sentinel is the appropriate service for SIEM functionality.
Question 6. Which Microsoft service is primarily designed to provide extended detection and response (XDR) capabilities across endpoints, identities, email, and cloud applications?
- Microsoft Defender XDR
- Microsoft Purview
- Microsoft Entra ID
- Microsoft Service Health
Correct Answer: 1. Microsoft Defender XDR
Explanation:
Microsoft Defender XDR is designed to provide integrated security protection and detection across multiple areas of an organization’s environment. It can correlate signals from endpoints, identities, email, collaboration services, and applications to help security teams investigate and respond to threats. By combining related signals, Defender XDR can provide broader incident context than a tool focused on a single security layer. Microsoft Purview is primarily associated with data security, governance, risk, and compliance. Entra ID manages identity and access, while Service Health provides information about Microsoft service availability. Therefore, Microsoft Defender XDR is the appropriate platform for XDR capabilities.
Question 7. What is the primary purpose of Microsoft Defender for Cloud?
- To manage payroll systems
- To provide cloud security posture management and workload protection
- To create Microsoft Word documents
- To manage DNS records exclusively
Correct Answer: 2. To provide cloud security posture management and workload protection
Explanation:
Microsoft Defender for Cloud helps organizations improve the security posture of cloud resources and protect workloads across supported environments. It provides capabilities for assessing security configurations, identifying security recommendations, detecting threats, and protecting cloud workloads. Organizations can use it to gain visibility into security risks and improve the configuration of their cloud resources. Its functionality is broader than managing a single infrastructure component such as DNS. Payroll systems and document creation are unrelated to its primary purpose. Therefore, cloud security posture management and workload protection accurately describe the role of Microsoft Defender for Cloud.
Question 8. Which Microsoft service is primarily used to manage and protect organizational data while supporting governance, compliance, and risk management?
- Microsoft Purview
- Microsoft Sentinel
- Microsoft Defender for Endpoint
- Microsoft Entra ID
Correct Answer: 1. Microsoft Purview
Explanation:
Microsoft Purview provides capabilities that help organizations discover, govern, protect, and manage data while addressing compliance and risk requirements. Depending on the solution and configuration, organizations can use Purview capabilities for data classification, sensitivity labeling, data loss prevention, records management, compliance management, and related governance tasks. Microsoft Sentinel is focused on security monitoring and SIEM, Defender for Endpoint focuses on endpoint security, and Entra ID manages identities and access. Therefore, Microsoft Purview is the service most closely associated with organizational data governance, compliance, and information protection.
Question 9. Which Microsoft security solution is designed specifically to protect endpoints such as Windows devices against malware and other threats?
- Microsoft Defender for Endpoint
- Microsoft Purview
- Microsoft Entra ID
- Microsoft Sentinel
Correct Answer: 1. Microsoft Defender for Endpoint
Explanation:
Microsoft Defender for Endpoint is an endpoint security solution designed to help protect devices from cyber threats. It provides capabilities such as threat detection, investigation, vulnerability management, and response for supported endpoints. Security teams can use it to identify suspicious behavior and investigate potential attacks across organizational devices. Microsoft Entra ID focuses on identity and access management, Purview focuses on data governance and compliance, and Sentinel provides SIEM capabilities. Although these services can work together as part of a broader security architecture, Defender for Endpoint is specifically intended for protecting and monitoring endpoints.
Question 10. What is the purpose of role-based access control (RBAC) in Microsoft security solutions?
- To encrypt every network packet
- To assign permissions based on defined roles
- To automatically increase storage capacity
- To replace all authentication methods
Correct Answer: 2. To assign permissions based on defined roles
Explanation:
Role-based access control, or RBAC, assigns permissions to users or other identities according to defined roles. Instead of granting individual permissions separately to every user, administrators can assign a role that contains the permissions required for a particular responsibility. This simplifies permission management and can support the principle of least privilege when roles are designed appropriately. RBAC does not itself encrypt network packets, increase storage capacity, or replace authentication methods. Authentication determines who an identity is, while authorization determines what that identity can access. Therefore, assigning permissions through defined roles is the primary purpose of RBAC.
Question 11. Which Microsoft capability allows a user to sign in once and then access multiple supported applications without repeatedly entering credentials?
- Single sign-on
- Data Loss Prevention
- Security posture management
- Network segmentation
Correct Answer: 1. Single sign-on
Explanation:
Single sign-on, or SSO, allows users to authenticate once and then access multiple applications that trust the same identity provider without repeatedly entering credentials. Microsoft Entra ID provides SSO capabilities for supported Microsoft and third-party applications. This can improve the user experience while also allowing administrators to maintain centralized identity policies. SSO does not itself provide data loss prevention, security posture management, or network segmentation. Those capabilities address different security concerns. Therefore, when the requirement is to allow users to authenticate once and access multiple applications without repeated sign-ins, single sign-on is the appropriate capability.
Question 12. What is the primary purpose of Microsoft Intune?
- To provide DNS resolution
- To manage devices and applications
- To provide SIEM analytics
- To replace Microsoft Entra ID
Correct Answer: 2. To manage devices and applications
Explanation:
Microsoft Intune is a cloud-based endpoint management service that helps organizations manage devices, applications, and related security policies. Administrators can use Intune to configure devices, enforce compliance requirements, deploy applications, manage mobile devices, and support endpoint security policies. Intune works with Microsoft Entra ID and other Microsoft security services but does not replace identity management. SIEM capabilities are provided by Microsoft Sentinel, while DNS resolution is a networking function. Therefore, device and application management is the primary purpose of Microsoft Intune within Microsoft’s broader security and management ecosystem.
Question 13. Which security concept assumes that no user, device, application, or network location should automatically be trusted?
- Zero Trust
- High availability
- Data residency
- Backup and recovery
Correct Answer: 1. Zero Trust
Explanation:
Zero Trust is a security approach based on the principle that access should not be automatically trusted simply because a user or device is inside an organization’s network. Instead, access requests should be evaluated using relevant signals such as identity, device health, application, location, and risk. Authentication and authorization are continuously important components of this approach. Zero Trust commonly emphasizes verifying explicitly, using least privilege, and assuming that a security breach can occur. High availability focuses on service continuity, data residency concerns geographic storage requirements, and backup and recovery focus on restoring data or services. Therefore, Zero Trust is the correct concept.
Question 14. Which Microsoft security principle recommends continuously verifying identities and access requests instead of automatically trusting previously authenticated users?
- Assume breach
- Data minimization
- Capacity planning
- Resource tagging
Correct Answer: 1. Assume breach
Explanation:
Assume breach is one of the core ideas associated with Microsoft’s Zero Trust security approach. It means organizations should operate with the expectation that a security breach could occur and should therefore design controls to limit the impact of compromised identities, devices, or applications. This mindset encourages strong authentication, least-privilege access, monitoring, segmentation, and rapid detection and response. Data minimization concerns limiting the amount of personal or sensitive data collected, while capacity planning concerns infrastructure resources. Resource tagging is an administrative practice. Therefore, assume breach is the security principle that reflects preparing for the possibility that attackers may already have access.
Question 15. Which Microsoft security capability can help prevent sensitive information from being shared or transmitted inappropriately?
- Microsoft Defender for Cloud
- Microsoft Entra ID
- Microsoft Purview Data Loss Prevention
- Microsoft Sentinel
Correct Answer: 3. Microsoft Purview Data Loss Prevention
Explanation:
Microsoft Purview Data Loss Prevention, or DLP, helps organizations identify, monitor, and protect sensitive information so that it is not shared or transmitted in ways that violate organizational policies. DLP policies can be used to detect sensitive information and apply actions or restrictions depending on the circumstances and configured rules. This can help organizations reduce the risk of accidental or intentional data exposure. Defender for Cloud focuses on cloud security, Entra ID focuses on identity and access, and Sentinel focuses on security monitoring and SIEM. Therefore, Microsoft Purview DLP is the capability specifically associated with preventing inappropriate handling of sensitive data.
Question 16. What is the primary purpose of sensitivity labels in Microsoft Purview?
- To classify and protect sensitive organizational information
- To assign IP addresses to devices
- To monitor CPU utilization
- To create virtual machines
Correct Answer: 1. To classify and protect sensitive organizational information
Explanation:
Sensitivity labels in Microsoft Purview help organizations classify information according to its sensitivity and apply appropriate protection policies. For example, an organization can use labels to identify information as confidential or highly sensitive and then configure protections such as encryption, access controls, or content markings where supported. Labels help users and administrators understand how information should be handled while enabling consistent protection policies. They are not designed to assign IP addresses, monitor CPU utilization, or create virtual machines. Therefore, classifying and protecting sensitive organizational information is the primary purpose of sensitivity labels.
Question 17. Which Microsoft service can collect security data from multiple sources and provide automated investigation and response capabilities as part of a security operations platform?
- Microsoft Word
- Microsoft Sentinel
- Microsoft Intune
- Microsoft Purview
Correct Answer: 2. Microsoft Sentinel
Explanation:
Microsoft Sentinel is a cloud-native security operations platform that provides SIEM and security orchestration, automation, and response capabilities. It can ingest security data from Microsoft services, third-party systems, applications, and infrastructure, allowing security teams to analyze events and investigate incidents from a centralized platform. Automation capabilities can help perform response actions when defined conditions are met. Intune focuses on endpoint management, while Purview focuses on data governance and compliance. Microsoft Word is a productivity application and is not a security operations platform. Therefore, Sentinel is the appropriate Microsoft service for centralized security monitoring and automated response workflows.
Question 18. Which authentication method provides phishing-resistant authentication by using a physical security key or compatible device-based credential?
- Password-only authentication
- Security key authentication
- Username without authentication
- Shared account credentials
Correct Answer: 2. Security key authentication
Explanation:
Security key authentication can provide strong, phishing-resistant authentication by using hardware-based credentials or compatible device-based authentication technologies. These methods are designed to prevent attackers from simply capturing a reusable password through a fraudulent website. Security keys can use standards such as FIDO2 and can provide a strong authentication factor without relying solely on passwords. Password-only authentication is more vulnerable to phishing and credential theft, while shared credentials reduce accountability and increase security risk. Therefore, security key authentication is an appropriate example of a strong authentication method designed to resist phishing attacks.
Question 19. Which Microsoft security concept focuses on ensuring that access is granted only after the identity and relevant security conditions have been evaluated?
- Verify explicitly
- Data archiving
- Resource scaling
- Storage replication
Correct Answer: 1. Verify explicitly
Explanation:
Verify explicitly is a core principle of Microsoft’s Zero Trust approach. It means that organizations should authenticate and authorize access based on relevant information rather than automatically trusting a request because of its network location or previous access. Signals such as identity, device state, location, application, and risk can contribute to access decisions. This approach helps organizations make access controls more context-aware and reduces reliance on implicit trust. Data archiving, resource scaling, and storage replication address other operational requirements and do not describe an identity-security principle. Therefore, verify explicitly is the correct concept for evaluating access based on available security signals.
Question 20. Which Microsoft security solution provides a centralized platform for discovering, classifying, governing, and protecting organizational data across supported environments?
- Microsoft Sentinel
- Microsoft Defender for Endpoint
- Microsoft Purview
- Microsoft Entra ID
Correct Answer: 3. Microsoft Purview
Explanation:
Microsoft Purview provides a broad set of capabilities for discovering, classifying, governing, protecting, and managing organizational data. It supports organizations in addressing information protection, data governance, compliance, and risk requirements across supported data sources and environments. Capabilities can include data classification, sensitivity labels, data loss prevention, compliance management, and governance features. Microsoft Sentinel is focused on security operations and SIEM, Defender for Endpoint protects endpoints, and Entra ID manages identities and access. Therefore, Microsoft Purview is the Microsoft security and compliance solution that best matches the requirement for centralized data discovery, classification, governance, and protection.