View Full Microsoft SC-900 Exam Dumps and Practice Test Dumps
Question 121. Which Microsoft service provides a centralized platform for managing devices and applications?
- Microsoft Intune
- Microsoft Sentinel
- Microsoft Purview
- Azure Key Vault
Correct Answer: 1. Microsoft Intune
Explanation:
Microsoft Intune is a cloud-based endpoint management service that helps organizations manage devices, applications, and security policies. Administrators can use Intune to configure supported devices, deploy applications, establish compliance requirements, and apply configuration policies. Intune can also work with Microsoft Entra ID and other Microsoft security services to support identity-aware device management. For example, an organization can require devices to meet specific security conditions before allowing access to corporate resources. Intune is therefore an important part of Microsoft’s endpoint management strategy and can support Zero Trust by helping organizations verify device security before granting access.
Question 122. What is the primary purpose of an Intune device compliance policy?
- Collect security logs for Sentinel
- Determine whether devices meet defined security requirements
- Encrypt all Microsoft 365 emails
- Manage Azure DNS records
Correct Answer: 2. Determine whether devices meet defined security requirements
Explanation:
Intune device compliance policies define requirements that devices must satisfy to be considered compliant. These requirements can include conditions related to operating system versions, security settings, encryption, password configuration, or other supported device characteristics. Compliance status can then be used together with Microsoft Entra Conditional Access to influence whether a device is allowed to access organizational resources. This creates a connection between endpoint management and identity-based access control. Compliance policies do not simply provide antivirus protection; instead, they establish measurable device conditions that can be evaluated before access is granted to protected applications and services.
Question 123. Which Microsoft Intune capability can deploy applications to managed devices?
- Application management
- Sentinel analytics
- Purview eDiscovery
- Entra Access Reviews
Correct Answer: 1. Application management
Explanation:
Microsoft Intune provides application management capabilities that allow organizations to deploy and manage supported applications on enrolled devices. Administrators can configure applications as required or available depending on organizational needs and can establish policies around application installation and management. Intune application management can also contribute to protecting corporate data on supported devices. By centrally managing applications, organizations can reduce inconsistent configurations and ensure that users have access to approved software. This capability complements device configuration and compliance policies, providing organizations with a broader approach to managing endpoints and the applications that run on them.
Question 124. What is Microsoft Defender for Cloud Apps primarily concerned with?
- Managing physical servers
- Cloud application visibility, governance, and security
- Synchronizing local printers
- Managing Windows passwords
Correct Answer: 2. Cloud application visibility, governance, and security
Explanation:
Microsoft Defender for Cloud Apps focuses on security for cloud applications and services. Organizations often use numerous cloud applications, including services that may not be directly managed by traditional infrastructure teams. Defender for Cloud Apps can help provide visibility into cloud application usage, identify potential risks, and apply governance and security controls. It can also provide information about user activity and support integration with other Microsoft security capabilities. This makes it different from Microsoft Defender for Cloud, which focuses on cloud security posture and workload protection. Understanding this distinction is important when selecting the appropriate Microsoft security solution.
Question 125. Which Microsoft service helps protect identities by detecting potentially risky authentication activity?
- Microsoft Entra ID Protection
- Microsoft Purview Data Map
- Azure Firewall
- Microsoft Defender for Endpoint
Correct Answer: 1. Microsoft Entra ID Protection
Explanation:
Microsoft Entra ID Protection is designed to help organizations identify identity-related risks, including potentially risky users and sign-ins. It uses available signals to identify authentication activity that may indicate compromise or other identity threats. Security teams can use these risk signals together with Microsoft Entra policies and Conditional Access to apply additional controls when appropriate. For example, organizations can require stronger authentication when a sign-in presents elevated risk. ID Protection is specifically focused on identity risk, while Defender for Endpoint focuses primarily on device threats and Microsoft Purview focuses on information governance, protection, and compliance.
Question 126. Which Microsoft security capability helps protect an organization from phishing and malicious email attachments?
- Microsoft Defender for Office 365
- Microsoft Defender for Identity
- Microsoft Entra Connect
- Azure Firewall
Correct Answer: 1. Microsoft Defender for Office 365
Explanation:
Microsoft Defender for Office 365 provides security capabilities designed to protect email and collaboration services from threats such as phishing, malicious links, and malicious attachments. It can analyze messages and related signals to identify potentially harmful content and can provide investigation and response capabilities for security teams. Email attacks remain an important source of credential theft and malware delivery, so protecting collaboration platforms is an important part of a layered security strategy. Defender for Office 365 works alongside other Microsoft Defender products rather than replacing endpoint, identity, or network security controls.
Question 127. Which Microsoft Defender product focuses on detecting suspicious activities associated with identities in Active Directory environments?
- Microsoft Defender for Identity
- Microsoft Defender for Office 365
- Microsoft Defender for Cloud Apps
- Microsoft Defender Antivirus
Correct Answer: 1. Microsoft Defender for Identity
Explanation:
Microsoft Defender for Identity is focused on detecting and investigating identity-related threats associated with on-premises Active Directory environments. It can monitor signals from identity infrastructure and help security teams identify suspicious activities and attack techniques involving accounts, authentication, and domain resources. This information can be correlated with other Microsoft security signals through the broader Defender ecosystem. Defender for Identity differs from Entra ID Protection because it focuses heavily on identity signals associated with on-premises Active Directory, while Entra ID Protection focuses on cloud identity risk and sign-in activity in Microsoft Entra environments.
Question 128. What is the main purpose of Microsoft Defender Vulnerability Management?
- Identify and help prioritize vulnerabilities and security weaknesses
- Manage email retention
- Create guest accounts
- Configure Azure subscriptions
Correct Answer: 1. Identify and help prioritize vulnerabilities and security weaknesses
Explanation:
Microsoft Defender Vulnerability Management helps organizations discover and understand vulnerabilities and security weaknesses across supported devices and software. Security teams can use vulnerability information to identify areas that may require remediation and prioritize actions based on the organization’s environment and risk. Vulnerability management is an important preventive security activity because attackers can exploit weaknesses in outdated software, insecure configurations, or other exposed conditions. This capability complements endpoint detection and response because finding a vulnerability is different from detecting an active attack. Organizations can use both approaches to improve the overall security posture of their devices.
Question 129. Which Microsoft security service is designed to help detect and respond to threats across endpoints, identities, email, and cloud applications?
- Microsoft Defender XDR
- Microsoft Purview Audit
- Azure Key Vault
- Microsoft Entra Cloud Sync
Correct Answer: 1. Microsoft Defender XDR
Explanation:
Microsoft Defender XDR provides a unified security approach by bringing together signals from multiple Microsoft Defender products. Depending on the services deployed, these signals can include endpoint, identity, email, and cloud application activity. Correlating signals across these areas can help security analysts understand relationships between individual alerts and identify broader attack activity. Defender XDR supports investigation and response by presenting related security information in a more coordinated manner. This cross-domain visibility is valuable because modern attacks can move between identities, devices, applications, and email rather than remaining limited to one technology area.
Question 130. Which Microsoft security platform is designed to collect security data from multiple sources for centralized analysis?
- Microsoft Sentinel
- Microsoft Intune
- Microsoft Purview Labels
- Microsoft Entra PIM
Correct Answer: 1. Microsoft Sentinel
Explanation:
Microsoft Sentinel is a cloud-native SIEM platform that can collect security-related data from many supported sources for centralized monitoring and analysis. These sources can include Microsoft services, cloud platforms, applications, infrastructure, and other supported systems. Centralizing security data allows analysts to correlate events, create detections, investigate incidents, and build dashboards that provide broader visibility. Sentinel also supports automation capabilities that can help streamline response activities. Unlike a security product focused on a single workload, Sentinel can provide a broader security operations view across an organization’s environment when appropriate data sources are connected.
Question 131. What is the purpose of Microsoft Sentinel incident management?
- Group and manage related security alerts for investigation
- Create Microsoft Entra passwords
- Configure document sensitivity labels
- Install endpoint drivers
Correct Answer: 1. Group and manage related security alerts for investigation
Explanation:
Microsoft Sentinel incidents provide a structured way to manage security investigations by bringing related alerts and evidence together. A security analyst can investigate an incident to understand what happened, which entities were involved, and whether additional response actions are necessary. Grouping related alerts helps reduce the difficulty of handling large numbers of individual notifications and can provide better context about a potential security event. Incident management is an important part of a security operations process because detection alone is not sufficient; analysts also need a way to investigate, document, prioritize, and respond to potentially harmful activity.
Question 132. Which Microsoft Sentinel capability can execute a workflow to automate a security response?
- Playbook
- Sensitivity label
- Retention label
- Access Review
Correct Answer: 1. Playbook
Explanation:
A Microsoft Sentinel playbook is an automated workflow that can be used to perform actions in response to security events. Playbooks are based on Azure Logic Apps and can connect Sentinel with other services to automate supported tasks. For example, a playbook could send notifications, enrich incident information, or perform another predefined response action. Automation can help security teams handle repetitive tasks consistently and reduce the amount of manual work required during an investigation. However, organizations should carefully design automated actions, especially when those actions could affect users, accounts, or production systems.
Question 133. Which Microsoft Purview capability helps classify information based on its sensitivity?
- Sensitivity labels
- Microsoft Sentinel incidents
- Microsoft Defender Antivirus
- Microsoft Entra Connect
Correct Answer: 1. Sensitivity labels
Explanation:
Microsoft Purview sensitivity labels provide a way to classify content according to its sensitivity and organizational handling requirements. Organizations can define labels that represent categories such as public, internal, confidential, or highly confidential information. Depending on configuration, labels can also apply protection controls such as encryption, access restrictions, or content markings. Classification helps users and organizations understand how information should be handled and can work together with other Purview capabilities, including Data Loss Prevention. Sensitivity labels are therefore primarily associated with information classification and protection rather than network security, identity synchronization, or security incident management.
Question 134. What is the main benefit of Microsoft Purview Data Loss Prevention policies?
- Help prevent sensitive information from being shared or exposed improperly
- Provide physical access to data centers
- Create Azure virtual networks
- Replace multifactor authentication
Correct Answer: 1. Help prevent sensitive information from being shared or exposed improperly
Explanation:
Microsoft Purview Data Loss Prevention policies help organizations identify and protect sensitive information across supported locations and activities. Policies can use sensitive information types, labels, and other conditions to determine when content or activities may present a data loss risk. Depending on the configuration, users can receive policy notifications, activities can be audited, or specific actions can be restricted. DLP is especially useful when organizations need to control how sensitive information is handled across collaboration and productivity environments. It complements sensitivity labels and other information governance capabilities rather than replacing identity or endpoint security controls.
Question 135. Which Microsoft Purview solution helps organizations assess compliance against regulations and standards?
- Compliance Manager
- Defender for Endpoint
- Microsoft Entra ID Protection
- Azure Firewall
Correct Answer: 1. Compliance Manager
Explanation:
Microsoft Purview Compliance Manager helps organizations assess and manage their compliance posture against relevant regulations, standards, and organizational requirements. It provides assessments, improvement actions, and tracking capabilities that can help organizations understand where additional work may be needed. Compliance Manager does not itself guarantee that an organization is compliant. Instead, it provides a structured framework for identifying actions, assigning responsibilities, documenting progress, and improving compliance readiness. Organizations can use it as part of a broader governance program that includes policies, technical controls, employee processes, documentation, and regular reviews.
Question 136. Which principle is most closely associated with limiting administrative permissions to only what is required?
- Least privilege
- Assume breach
- Single sign-on
- Public access
Correct Answer: 1. Least privilege
Explanation:
Least privilege requires that users, administrators, applications, and services receive only the permissions necessary to perform their authorized responsibilities. Administrative accounts are especially important because excessive privileges can significantly increase the impact of a compromised credential. Microsoft Entra Privileged Identity Management can support this principle by enabling eligible administrators to activate privileged roles only when needed. Role-based access control can also help define appropriate permissions. Applying least privilege requires regular review because responsibilities and access requirements change over time. Removing unnecessary permissions can reduce opportunities for attackers to misuse compromised accounts.
Question 137. Which Zero Trust principle encourages organizations to design security controls assuming that an attacker could already be inside the environment?
- Assume breach
- Trust internal networks
- Allow unrestricted access
- Disable monitoring
Correct Answer: 1. Assume breach
Explanation:
The Zero Trust principle “Assume breach” encourages organizations to operate as though a compromise may already exist somewhere within their environment. This approach leads organizations to continuously monitor activity, segment resources, protect identities, restrict privileges, and investigate suspicious behavior. The purpose is not to assume that every user is malicious, but to avoid relying on the assumption that internal network location automatically makes a request trustworthy. Microsoft security capabilities such as Defender, Sentinel, Entra ID, and network security controls can provide different layers of protection that support this principle and reduce the impact of potential compromises.
Question 138. What is the primary purpose of multifactor authentication?
- Require multiple forms of verification to strengthen identity security
- Store application secrets
- Manage data retention
- Scan network packets
Correct Answer: 1. Require multiple forms of verification to strengthen identity security
Explanation:
Multifactor authentication, or MFA, strengthens authentication by requiring users to provide more than one type of verification. These factors can involve something the user knows, something the user has, or something the user is. For example, a password may be combined with an authenticator approval or another supported authentication method. MFA helps reduce the impact of stolen passwords because an attacker may still need the additional authentication factor. Microsoft Entra ID supports MFA and can integrate it with Conditional Access policies, allowing organizations to require stronger authentication under specific circumstances rather than treating every access request identically.
Question 139. Which Microsoft Entra feature can periodically ask reviewers to confirm whether access should continue?
- Access Reviews
- Security Defaults
- Password Hash Synchronization
- Windows Hello for Business
Correct Answer: 1. Access Reviews
Explanation:
Microsoft Entra Access Reviews help organizations periodically evaluate whether users or other identities should continue to have access to specific resources. Reviewers can examine assigned access and confirm whether it remains appropriate. This is especially useful for external users, group memberships, applications, and sensitive resources where access should not remain indefinitely without review. Access Reviews support identity governance and least privilege by helping organizations identify unnecessary or outdated permissions. They are different from Conditional Access, which evaluates access requests, because Access Reviews focus on periodically reviewing existing access assignments.
Question 140. Which Microsoft service can help organizations manage security recommendations across Azure and other supported cloud resources?
- Microsoft Defender for Cloud
- Microsoft Purview Communication Compliance
- Microsoft Entra External ID
- Microsoft Defender for Office 365
Correct Answer: 1. Microsoft Defender for Cloud
Explanation:
Microsoft Defender for Cloud helps organizations improve security posture across supported cloud resources by providing security recommendations, posture management capabilities, and workload protection features. Recommendations can identify configurations or security conditions that may require attention, allowing administrators to prioritize remediation according to organizational risk. Defender for Cloud can also provide protection capabilities for supported workloads. It should be distinguished from Microsoft Defender for Cloud Apps, which focuses primarily on cloud application visibility and security. Defender for Cloud is therefore an important Microsoft solution for managing and improving security across cloud environments.