Microsoft SC-900 Practice Test Questions and Exam Dumps Part6 Q101-120

View Full Microsoft SC-900 Exam Dumps and Practice Test Dumps

 

Question 101. Which Microsoft security capability helps protect Azure resources from unwanted network traffic by using network security rules?

  1. Azure Network Security Groups
  2. Microsoft Purview Audit
  3. Microsoft Entra Access Reviews
  4. Microsoft Defender for Office 365

Correct Answer: 1. Azure Network Security Groups

Explanation:

Azure Network Security Groups (NSGs) provide network traffic filtering for Azure resources within supported virtual network configurations. An NSG can contain inbound and outbound security rules that allow or deny traffic based on factors such as source, destination, protocol, and port. This helps organizations restrict unnecessary network communication and implement network-level security controls. NSGs are an important part of layered security because they can limit which traffic is allowed to reach resources. They do not replace application security, identity controls, endpoint protection, or firewalls, but instead provide an additional network security layer.

Question 102. What is the primary purpose of Azure Firewall?

  1. Classify confidential documents
  2. Provide centralized, managed network traffic filtering
  3. Review user access permissions
  4. Detect phishing emails

Correct Answer: 2. Provide centralized, managed network traffic filtering

Explanation:

Azure Firewall is a managed, cloud-based network security service designed to control and filter network traffic. Organizations can use it to establish centralized network security policies for Azure environments. Depending on the configuration and capabilities being used, Azure Firewall can control traffic based on network and application-related rules and provide logging that supports monitoring and investigation. It differs from a Network Security Group because Azure Firewall provides a more centralized and advanced firewall capability, while NSGs primarily provide traffic filtering at the network interface and subnet level. Both can contribute to a defense-in-depth network security strategy.

Question 103. Which Microsoft security concept focuses on protecting different layers of an organization’s environment rather than relying on one control?

  1. Single sign-on
  2. Defense in depth
  3. Password synchronization
  4. Data minimization

Correct Answer: 2. Defense in depth

Explanation:

Defense in depth is a security approach that uses multiple layers of protection across an environment. These layers can include identity security, network controls, endpoint protection, application security, data protection, monitoring, and incident response. The purpose is to avoid depending on one security control because any individual control can potentially fail, be misconfigured, or be bypassed. For example, an organization might combine Microsoft Entra authentication controls with endpoint protection, network filtering, Microsoft Purview information protection, and Microsoft Sentinel monitoring. Multiple independent layers can help reduce the likelihood that a single security failure results in a complete compromise.

Question 104. Which authentication method uses biometric information or a device PIN instead of a traditional password?

  1. Windows Hello for Business
  2. Microsoft Sentinel
  3. Microsoft Purview Audit
  4. Azure Firewall

Correct Answer: 1. Windows Hello for Business

Explanation:

Windows Hello for Business provides a modern authentication experience that can use a device-based credential together with a PIN or biometric method such as fingerprint or facial recognition, depending on the device and configuration. The user’s authentication secret is designed to be associated with the device rather than functioning as a traditional reusable password. This can improve security by reducing exposure to password-based attacks. Windows Hello for Business is integrated with Microsoft identity technologies and can support passwordless or password-reduced authentication scenarios. Organizations can configure policies according to their security, device, and identity requirements.

Question 105. What is single sign-on primarily designed to provide?

  1. A separate password for every application
  2. The ability to authenticate once and access multiple authorized applications
  3. Automatic deletion of sensitive information
  4. Network traffic encryption only

Correct Answer: 2. The ability to authenticate once and access multiple authorized applications

Explanation:

Single sign-on, or SSO, allows users to authenticate through a centralized identity provider and then access multiple authorized applications without repeatedly entering credentials for every application. Microsoft Entra ID provides SSO capabilities for many applications and authentication scenarios. SSO can improve the user experience by reducing repeated authentication prompts while also allowing organizations to apply centralized identity and access policies. However, SSO does not automatically grant access to every application; users still need appropriate permissions and application assignments. Organizations can combine SSO with multifactor authentication and Conditional Access to strengthen access security.

Question 106. What is the main purpose of Microsoft Entra Security Defaults?

  1. Provide baseline identity security settings for organizations
  2. Create custom Sentinel workbooks
  3. Manage document retention periods
  4. Scan Azure storage for malware

Correct Answer: 1. Provide baseline identity security settings for organizations

Explanation:

Microsoft Entra Security Defaults provide a set of baseline identity security protections intended to help organizations establish foundational security controls. These defaults can help protect identities by enabling security-oriented settings such as multifactor authentication requirements in supported scenarios and protections against legacy authentication. Security Defaults are designed to provide a relatively simple baseline, particularly for organizations that may not have complex Conditional Access requirements. Organizations with more advanced identity security needs can use Conditional Access and other Microsoft Entra capabilities to create more detailed policies. Security Defaults therefore serve as a foundational identity security option.

Question 107. Which Microsoft Entra capability can require multifactor authentication when a particular access condition is met?

  1. Microsoft Entra Conditional Access
  2. Microsoft Purview Data Map
  3. Microsoft Defender for Identity
  4. Azure Key Vault

Correct Answer: 1. Microsoft Entra Conditional Access

Explanation:

Microsoft Entra Conditional Access allows organizations to define policies that control access based on specific conditions and requirements. One common use is requiring multifactor authentication when users access particular applications, resources, or services under defined circumstances. Conditional Access can evaluate signals such as user identity, application, device state, location, and risk before determining whether additional authentication or another control is required. This makes access decisions more adaptive than simply allowing or denying access based on a username and password. Conditional Access is a key Microsoft Entra capability for implementing Zero Trust principles.

Question 108. Which Microsoft Entra feature is designed to manage external users who collaborate with an organization?

  1. Microsoft Entra B2B collaboration
  2. Microsoft Defender Antivirus
  3. Microsoft Sentinel Analytics
  4. Microsoft Purview Audit

Correct Answer: 1. Microsoft Entra B2B collaboration

Explanation:

Microsoft Entra B2B collaboration allows organizations to work with external users such as business partners, contractors, and guests while maintaining control over access to organizational resources. External users can be represented as guest identities and can be assigned appropriate permissions to resources they need. Organizations can apply identity and access policies to these users rather than giving them unrestricted access to internal resources. B2B collaboration supports controlled external collaboration and is an important identity capability for organizations that frequently work with people outside their workforce. Regular access reviews can also help ensure that external access remains appropriate over time.

Question 109. What is role-based access control primarily used to manage?

  1. Permissions based on assigned roles
  2. Email spam filtering
  3. Network packet encryption
  4. Document retention schedules

Correct Answer: 1. Permissions based on assigned roles

Explanation:

Role-based access control, or RBAC, manages permissions by assigning users or other identities to roles that contain defined access rights. Instead of assigning every individual permission separately, administrators can use roles to provide consistent access according to job responsibilities or resource requirements. Azure and Microsoft Entra environments use role-based access concepts to manage access to resources and administrative functions. RBAC supports least privilege when roles are carefully designed and assigned. Organizations should regularly review role assignments because unnecessary permissions can increase security risk, especially when users have administrative or highly privileged roles.

Question 110. Which Microsoft Entra capability helps administrators control access to privileged roles through temporary elevation?

  1. Microsoft Entra Privileged Identity Management
  2. Microsoft Purview Communication Compliance
  3. Microsoft Defender for Cloud Apps
  4. Azure Network Security Groups

Correct Answer: 1. Microsoft Entra Privileged Identity Management

Explanation:

Microsoft Entra Privileged Identity Management, or PIM, helps organizations manage privileged access by reducing unnecessary standing administrative permissions. Users can be assigned as eligible for privileged roles and activate those roles only when they need them. Organizations can configure additional requirements such as multifactor authentication, approval, justification, and activation duration. This approach supports just-in-time privileged access and can reduce the period during which powerful permissions are available. PIM also provides visibility into privileged role assignments and activations, helping administrators monitor how privileged access is being used and identify opportunities to improve access governance.

Question 111. What is the primary purpose of Microsoft Defender for Cloud security recommendations?

  1. Identify ways to improve the security configuration of cloud resources
  2. Create user passwords
  3. Classify Microsoft Word documents
  4. Manage employee payroll

Correct Answer: 1. Identify ways to improve the security configuration of cloud resources

Explanation:

Microsoft Defender for Cloud can provide security recommendations that identify configuration weaknesses, missing protections, or other conditions that may increase the security risk of cloud resources. These recommendations can help administrators understand which areas may need remediation and prioritize improvements. For example, a recommendation may identify a resource that lacks an appropriate security configuration or protection. Recommendations are part of security posture management and should be considered alongside an organization’s risk requirements. They do not automatically mean that a resource is compromised; rather, they provide guidance for improving the security posture of supported cloud resources.

Question 112. Which Microsoft Defender capability helps identify vulnerabilities and security weaknesses on endpoints?

  1. Microsoft Defender Vulnerability Management
  2. Microsoft Purview eDiscovery
  3. Microsoft Entra Cloud Sync
  4. Azure DDoS Protection

Correct Answer: 1. Microsoft Defender Vulnerability Management

Explanation:

Microsoft Defender Vulnerability Management helps organizations identify vulnerabilities and security weaknesses across supported devices and software. It can provide visibility into weaknesses that may require remediation and can help security teams prioritize actions based on the organization’s environment and risk. This capability is closely associated with endpoint security because vulnerabilities on devices can provide attackers with opportunities to compromise systems. Vulnerability management is different from antivirus protection: antivirus focuses on detecting and responding to malicious software and related threats, while vulnerability management focuses on identifying weaknesses that attackers could potentially exploit.

Question 113. Which Microsoft Defender capability is designed to help protect endpoints from malware and other threats?

  1. Microsoft Defender Antivirus
  2. Microsoft Purview Audit
  3. Microsoft Entra Access Reviews
  4. Microsoft Sentinel Workbooks

Correct Answer: 1. Microsoft Defender Antivirus

Explanation:

Microsoft Defender Antivirus provides malware and threat protection for supported Windows devices and is an important component of endpoint security. It can help detect, prevent, and respond to malicious software and other known or suspicious threats. Defender Antivirus can work together with broader Microsoft Defender capabilities to provide endpoint visibility and protection. Endpoint security should not depend on antivirus alone, because modern attacks can involve stolen identities, vulnerabilities, malicious email, and cloud services. Organizations can therefore combine Defender Antivirus with Defender for Endpoint, identity protection, network controls, and security monitoring to establish layered protection.

Question 114. What is the main function of Microsoft Sentinel in a security operations environment?

  1. Serve as a cloud-native SIEM and security orchestration platform
  2. Replace all endpoint antivirus software
  3. Manage employee benefits
  4. Synchronize Active Directory passwords only

Correct Answer: 1. Serve as a cloud-native SIEM and security orchestration platform

Explanation:

Microsoft Sentinel is a cloud-native security information and event management, or SIEM, platform that helps organizations collect, analyze, detect, investigate, and respond to security events. It can connect to multiple data sources and use analytics rules to identify potentially suspicious activity. Sentinel also provides investigation tools, dashboards, automation capabilities, and integrations that support security operations. Because it can collect information from Microsoft and non-Microsoft sources, Sentinel can provide broader visibility than a security product focused on a single workload. It is commonly used to centralize security monitoring and coordinate investigation and response activities.

Question 115. What is the purpose of Microsoft Sentinel data connectors?

  1. Connect Sentinel to supported data sources so security information can be collected
  2. Create Microsoft Entra guest accounts
  3. Encrypt Office documents
  4. Configure Windows Hello

Correct Answer: 1. Connect Sentinel to supported data sources so security information can be collected

Explanation:

Microsoft Sentinel data connectors help connect the SIEM platform to supported data sources so relevant security information can be collected for monitoring and analysis. Sources can include Microsoft services, cloud platforms, applications, devices, and other supported systems. Once data is available in Sentinel, analytics rules and investigation tools can use that information to identify potentially suspicious activity. Connecting appropriate sources is important because security teams need sufficient visibility to detect and investigate threats effectively. The exact data collected depends on the connector and its configuration, so organizations should select sources based on their monitoring and security requirements.

Question 116. Which Microsoft security service can correlate alerts across endpoints, identities, email, and cloud applications?

  1. Microsoft Defender XDR
  2. Microsoft Purview Compliance Manager
  3. Azure Key Vault
  4. Microsoft Entra Cloud Sync

Correct Answer: 1. Microsoft Defender XDR

Explanation:

Microsoft Defender XDR is designed to correlate security signals across multiple Microsoft Defender products and provide a unified view of related threats. Depending on the organization’s configuration and licensing, these signals can involve endpoints, identities, email and collaboration services, and cloud applications. Correlation can help analysts understand whether seemingly separate alerts are connected to the same attack campaign or incident. This reduces the need to investigate every signal independently and can provide broader attack context. Defender XDR is therefore particularly useful for coordinated threat detection and investigation across multiple security domains.

Question 117. Which Microsoft security solution is specifically designed to protect cloud applications and provide visibility into their use?

  1. Microsoft Defender for Cloud Apps
  2. Microsoft Defender for Identity
  3. Microsoft Defender for Endpoint
  4. Microsoft Purview Audit

Correct Answer: 1. Microsoft Defender for Cloud Apps

Explanation:

Microsoft Defender for Cloud Apps provides security visibility and control for cloud applications. Organizations frequently use many cloud services, including applications that may not be fully managed by traditional IT infrastructure. Defender for Cloud Apps can help organizations discover cloud application usage, understand related risks, and apply appropriate security controls. It can also integrate with other Microsoft security solutions to provide broader visibility into user activity and data protection scenarios. Its focus is cloud applications rather than endpoint devices, on-premises identity infrastructure, or general compliance auditing, making it an important component of cloud security.

Question 118. Which Microsoft Purview feature is most appropriate for identifying specific types of sensitive information, such as credit card numbers?

  1. Sensitive Information Types
  2. Security Defaults
  3. Microsoft Sentinel Analytics Rules
  4. Azure Firewall

Correct Answer: 1. Sensitive Information Types

Explanation:

Microsoft Purview Sensitive Information Types, or SITs, help identify patterns associated with specific categories of sensitive information. Examples can include credit card numbers, financial information, identification numbers, and other types of regulated or confidential data. These detections can be used by Microsoft Purview capabilities such as Data Loss Prevention to apply organizational policies. Sensitive Information Types can use patterns and additional conditions to improve identification accuracy. They are therefore different from sensitivity labels: SITs help detect and identify sensitive data patterns, while sensitivity labels are used to classify and protect content according to organizational requirements.

Question 119. Which Microsoft Purview capability can help preserve information that may be relevant to a legal investigation?

  1. eDiscovery and legal hold capabilities
  2. Azure DDoS Protection
  3. Microsoft Defender Antivirus
  4. Microsoft Entra Cloud Sync

Correct Answer: 1. eDiscovery and legal hold capabilities

Explanation:

Microsoft Purview eDiscovery includes capabilities that can support legal and compliance investigations, including processes for identifying and preserving relevant information. Depending on the scenario and configuration, organizations can place appropriate holds to help prevent relevant content from being removed while an investigation or legal process is underway. eDiscovery can also support searching, collecting, reviewing, and managing information relevant to a case. These capabilities should be used according to applicable laws, organizational policies, and appropriate authorization. The goal is to support defensible information discovery and preservation rather than general-purpose data backup.

Question 120. Which Microsoft security principle states that access should be limited even after a user has successfully authenticated?

  1. Least privilege
  2. Public access
  3. Perimeter trust
  4. Anonymous access

Correct Answer: 1. Least privilege

Explanation:

Least privilege means that successfully authenticating a user does not automatically give that user unrestricted access. Instead, the user should receive only the permissions necessary to perform their authorized tasks. This distinction is important because authentication establishes identity, while authorization determines what that identity is permitted to do. By limiting permissions, organizations can reduce the potential impact of compromised accounts, insider mistakes, and unauthorized activity. Microsoft technologies such as RBAC, Microsoft Entra PIM, Access Reviews, and Conditional Access can support different aspects of this approach. Least privilege is therefore an important component of Zero Trust and effective identity governance.