Microsoft SC-900 Practice Test Questions and Exam Dumps Part8 Q141-160

View Full Microsoft SC-900 Exam Dumps and Practice Test Dumps

 

Question 141. Which Microsoft Entra capability helps organizations manage identities for applications and services without requiring a human user?

  1. Managed identities
  2. Access Reviews
  3. Security Defaults
  4. Microsoft Purview Audit

Correct Answer: 1. Managed identities

Explanation:

Managed identities provide an identity for supported Azure resources so applications and services can authenticate to other supported resources without requiring developers to embed credentials in application code. Azure manages the credentials associated with the identity, reducing the need to create, store, and rotate secrets manually. Administrators can then assign appropriate permissions to the managed identity according to the principle of least privilege. For example, an application could use a managed identity to access a secret stored in Azure Key Vault. This approach can improve security by reducing the exposure of passwords, connection strings, and other long-lived credentials.

Question 142. Which Microsoft Entra object represents an application identity that can be granted permissions to access resources?

  1. Security group
  2. Service principal
  3. Guest user
  4. Conditional Access policy

Correct Answer: 2. Service principal

Explanation:

A service principal represents an application or service identity within Microsoft Entra ID and can be assigned permissions to access supported resources. When an application needs to authenticate and perform actions without a human user, an application identity can be used for that purpose. Administrators should carefully control the permissions assigned to service principals because excessive application permissions can create security risks if the application’s credentials or identity are compromised. Service principals are therefore an important component of application authentication and authorization. They are different from human user accounts because they represent applications or services rather than individual people.

Question 143. What is Microsoft Entra ID primarily responsible for?

  1. Identity and access management
  2. Network packet inspection
  3. Document retention only
  4. Endpoint malware scanning

Correct Answer: 1. Identity and access management

Explanation:

Microsoft Entra ID is Microsoft’s cloud-based identity and access management service. It helps organizations manage users, groups, applications, authentication, and access to resources. Entra ID supports capabilities such as multifactor authentication, Conditional Access, single sign-on, identity protection, privileged identity management, and access governance. These capabilities allow organizations to establish centralized identity controls and apply policies when users and applications request access. Entra ID is not an endpoint antivirus product or a network firewall. Instead, its primary role is helping organizations securely establish identities and control access to applications and resources.

Question 144. Which Microsoft Entra capability can help protect organizations from compromised credentials by evaluating sign-in risk?

  1. Microsoft Entra ID Protection
  2. Microsoft Purview Data Map
  3. Azure Firewall
  4. Microsoft Intune

Correct Answer: 1. Microsoft Entra ID Protection

Explanation:

Microsoft Entra ID Protection provides capabilities for detecting and investigating identity-related risks, including potentially risky sign-ins. Risk signals can help identify authentication activity that may indicate compromised credentials or other suspicious behavior. Organizations can use this information with Microsoft Entra policies to require additional controls when appropriate. For example, a risky sign-in can be subject to stronger authentication or another access decision. This capability supports Zero Trust by allowing access decisions to consider more than a username and password. It complements Conditional Access, which can use identity risk as one of the conditions in an access policy.

Question 145. Which Microsoft Entra feature allows organizations to manage privileged administrative roles with approval or additional authentication requirements?

  1. Microsoft Entra Privileged Identity Management
  2. Microsoft Sentinel
  3. Microsoft Defender Antivirus
  4. Microsoft Purview Audit

Correct Answer: 1. Microsoft Entra Privileged Identity Management

Explanation:

Microsoft Entra Privileged Identity Management, or PIM, helps organizations control privileged access to administrative roles. PIM can support eligible role assignments where users activate privileged access only when needed. Organizations can configure requirements such as multifactor authentication, approval, justification, and time-limited activation depending on their role management policies. This reduces standing privileged access and supports the principle of least privilege. PIM also provides visibility into privileged role assignments and activation activity. By controlling administrative privileges more carefully, organizations can reduce the potential impact of compromised administrator accounts and improve governance over sensitive identity permissions.

Question 146. Which Microsoft Entra feature is most appropriate for reviewing whether guest users still require access?

  1. Microsoft Entra Access Reviews
  2. Microsoft Defender for Endpoint
  3. Azure Key Vault
  4. Microsoft Sentinel Analytics

Correct Answer: 1. Microsoft Entra Access Reviews

Explanation:

Microsoft Entra Access Reviews provide a structured way to periodically review existing access assignments. They are particularly useful for guest users because external collaborators may only need access for a limited period or project. A reviewer can evaluate whether each guest still requires access and take the appropriate action according to organizational policy. This supports least privilege and identity governance by reducing the chance that unnecessary permissions remain active indefinitely. Access Reviews differ from Conditional Access because Conditional Access evaluates access requests using conditions, while Access Reviews focus on periodically confirming whether existing access should continue.

Question 147. What is the main purpose of Conditional Access in Microsoft Entra ID?

  1. Make access decisions based on defined conditions
  2. Store encryption keys
  3. Scan endpoints for malware
  4. Manage document retention

Correct Answer: 1. Make access decisions based on defined conditions

Explanation:

Microsoft Entra Conditional Access provides policy-based controls that can evaluate conditions before allowing access to protected resources. Policies can consider signals such as the user, application, device, location, sign-in risk, and other supported conditions. Based on the policy, an organization can require multifactor authentication, require a compliant device, block access, or apply another supported control. Conditional Access is an important Zero Trust capability because it avoids automatically trusting an authenticated identity. Instead, access can be evaluated using multiple contextual signals and organizational requirements before a user reaches a protected application or resource.

Question 148. Which Microsoft Intune capability helps determine whether a device meets an organization’s security requirements?

  1. Device compliance policies
  2. Sentinel playbooks
  3. Purview eDiscovery
  4. Defender for Office 365

Correct Answer: 1. Device compliance policies

Explanation:

Intune device compliance policies define the conditions a device must satisfy to be considered compliant. Organizations can configure requirements related to supported operating systems, encryption, passwords, security settings, and other device characteristics. Compliance status can then be used by Microsoft Entra Conditional Access to influence whether the device can access organizational resources. This provides an important connection between endpoint management and identity security. A compliance policy does not simply detect malware; instead, it evaluates whether a device meets predefined organizational requirements. This helps organizations establish consistent device security standards before allowing access to sensitive applications and information.

Question 149. Which Microsoft Intune feature allows administrators to apply configuration settings to managed devices?

  1. Device configuration profiles
  2. Microsoft Sentinel incidents
  3. Microsoft Purview Audit
  4. Entra Access Reviews

Correct Answer: 1. Device configuration profiles

Explanation:

Microsoft Intune device configuration profiles allow administrators to apply defined settings to managed devices. Organizations can use profiles to configure supported operating system settings, security options, restrictions, connectivity settings, and other device behaviors. Centralized configuration helps administrators establish consistent standards across managed endpoints instead of requiring users to manually configure each device. Configuration profiles can work alongside compliance policies, application management, and other Intune capabilities. It is important to distinguish configuration from compliance: configuration profiles establish desired settings, while compliance policies evaluate whether devices meet defined requirements.

Question 150. Which Microsoft Defender solution provides security protection for cloud workloads and helps improve cloud security posture?

  1. Microsoft Defender for Cloud
  2. Microsoft Defender for Office 365
  3. Microsoft Defender for Identity
  4. Microsoft Defender for Endpoint

Correct Answer: 1. Microsoft Defender for Cloud

Explanation:

Microsoft Defender for Cloud provides cloud security posture management and workload protection capabilities for supported environments. It can identify security recommendations that help organizations improve configurations and reduce exposure, while workload protection capabilities can help protect supported cloud resources. Defender for Cloud is broader than a product focused on one workload such as email or endpoints. Its posture management capabilities help organizations understand areas where security controls can be strengthened. It can also support multi-cloud scenarios depending on the connected environment and available capabilities, making it useful for organizations operating across different cloud platforms.

Question 151. Which Microsoft Defender product focuses on protecting users from threats delivered through email and collaboration services?

  1. Microsoft Defender for Office 365
  2. Microsoft Defender for Cloud Apps
  3. Microsoft Defender for Identity
  4. Microsoft Defender for Cloud

Correct Answer: 1. Microsoft Defender for Office 365

Explanation:

Microsoft Defender for Office 365 focuses on protecting Microsoft 365 email and collaboration services from threats such as phishing, malicious attachments, malicious links, and related attacks. It provides security capabilities that can help detect suspicious content and support investigation and response. Email protection is particularly important because attackers frequently use malicious messages to steal credentials or deliver malware. Defender for Office 365 is one component of the broader Microsoft Defender ecosystem. It complements endpoint, identity, cloud application, and security operations capabilities rather than attempting to provide all security functions by itself.

Question 152. Which Microsoft Defender solution provides protection for endpoints such as laptops and servers?

  1. Microsoft Defender for Endpoint
  2. Microsoft Defender for Office 365
  3. Microsoft Defender for Cloud Apps
  4. Microsoft Defender for Identity

Correct Answer: 1. Microsoft Defender for Endpoint

Explanation:

Microsoft Defender for Endpoint provides endpoint security capabilities for supported devices such as laptops, desktops, and servers. It can help detect, investigate, and respond to endpoint threats while providing visibility into device security. The service also integrates with vulnerability management and broader Microsoft Defender capabilities. Endpoint security is an important layer because compromised devices can be used to steal credentials, execute malware, or access organizational resources. Defender for Endpoint should be used as part of a layered security strategy that also addresses identity, email, cloud applications, data, network controls, and centralized security monitoring.

Question 153. Which Microsoft Defender solution is designed to identify suspicious activity involving on-premises Active Directory identities?

  1. Microsoft Defender for Identity
  2. Microsoft Defender for Endpoint
  3. Microsoft Defender for Office 365
  4. Microsoft Defender for Cloud Apps

Correct Answer: 1. Microsoft Defender for Identity

Explanation:

Microsoft Defender for Identity is designed to help organizations identify suspicious identity activity associated with on-premises Active Directory environments. It can monitor relevant signals and help security teams detect techniques that attackers may use against identity infrastructure, accounts, and domain resources. This information can contribute to investigations across the Microsoft Defender ecosystem. Defender for Identity has a different focus from Entra ID Protection, which primarily addresses cloud identity risk and sign-in signals. Understanding the distinction allows security teams to use the appropriate Microsoft security capability depending on whether the identity activity originates in cloud or on-premises identity infrastructure.

Question 154. Which Microsoft Defender capability helps organizations investigate vulnerabilities in software installed on endpoints?

  1. Defender Vulnerability Management
  2. Defender for Office 365
  3. Defender for Identity
  4. Microsoft Entra PIM

Correct Answer: 1. Defender Vulnerability Management

Explanation:

Microsoft Defender Vulnerability Management helps organizations discover and assess vulnerabilities and security weaknesses affecting supported devices and software. It provides information that can help security teams understand which weaknesses may require remediation and prioritize improvements. Vulnerability management is a preventive security activity because it focuses on weaknesses that attackers could potentially exploit. This differs from threat detection, which focuses on identifying suspicious or malicious activity that may already be occurring. By combining vulnerability management with endpoint protection and other security controls, organizations can reduce opportunities for attackers to exploit outdated software and insecure configurations.

Question 155. Which Microsoft security service provides a unified view of security alerts across multiple Defender products?

  1. Microsoft Defender XDR
  2. Microsoft Purview Compliance Manager
  3. Microsoft Entra Connect
  4. Azure Firewall

Correct Answer: 1. Microsoft Defender XDR

Explanation:

Microsoft Defender XDR provides a unified security experience by bringing together signals and alerts from multiple Microsoft Defender products. Depending on the environment, these signals can involve endpoints, identities, email and collaboration services, and cloud applications. Correlating information from multiple security domains can provide analysts with additional context and help them understand whether separate alerts are connected to the same incident. This can simplify investigation and improve response coordination. Defender XDR is different from Microsoft Sentinel, which serves as a broader SIEM platform capable of collecting and analyzing security data from Microsoft and other supported sources.

Question 156. Which Microsoft Sentinel feature provides a visual way to analyze security data and trends?

  1. Workbooks
  2. Service principals
  3. Sensitivity labels
  4. Device compliance policies

Correct Answer: 1. Workbooks

Explanation:

Microsoft Sentinel workbooks provide interactive visualizations that help security teams understand collected security information. Workbooks can display data using charts, tables, graphs, and other visual components, allowing analysts and administrators to examine trends and security conditions more easily. They can be useful for operational monitoring, investigation, reporting, and management-level visibility. Workbooks do not themselves replace analytics rules or incident management. Instead, they provide a visual layer for understanding the information available in Sentinel. Organizations can use existing workbook templates or create customized visualizations according to their security monitoring requirements.

Question 157. What is the main purpose of Microsoft Sentinel analytics rules?

  1. Detect potentially suspicious activity in collected data
  2. Manage Microsoft 365 licenses
  3. Create guest identities
  4. Encrypt Azure storage automatically

Correct Answer: 1. Detect potentially suspicious activity in collected data

Explanation:

Microsoft Sentinel analytics rules define detection logic that can identify potentially suspicious activity within collected security data. When the conditions of an enabled rule are met, Sentinel can generate an alert that may contribute to a security incident. Analytics rules allow organizations to establish detections based on their specific monitoring requirements and threat scenarios. They are therefore an important component of Sentinel’s SIEM functionality. Analytics rules depend on relevant data being available in Sentinel, which means organizations must also configure appropriate data sources and connectors to obtain the information needed for effective detection.

Question 158. Which Microsoft Purview capability is used to identify and manage information that may be relevant to a legal case?

  1. eDiscovery
  2. Microsoft Intune
  3. Microsoft Defender Antivirus
  4. Microsoft Entra Cloud Sync

Correct Answer: 1. eDiscovery

Explanation:

Microsoft Purview eDiscovery provides capabilities for identifying, collecting, reviewing, and managing electronic information that may be relevant to legal or compliance matters. Authorized users can use eDiscovery processes to locate relevant content across supported data sources and manage information according to case requirements. Depending on the scenario, preservation and review capabilities can also be used to help maintain relevant information during an investigation. eDiscovery is different from Data Loss Prevention because DLP focuses on protecting sensitive information from inappropriate handling, while eDiscovery focuses on information discovery and investigation for legal and compliance purposes.

Question 159. Which Microsoft Purview capability helps organizations control how sensitive information is handled across supported services?

  1. Data Loss Prevention
  2. Azure DDoS Protection
  3. Microsoft Entra PIM
  4. Microsoft Defender for Identity

Correct Answer: 1. Data Loss Prevention

Explanation:

Microsoft Purview Data Loss Prevention helps organizations detect and protect sensitive information by applying policies to supported activities and locations. DLP policies can use sensitive information types, sensitivity labels, and other conditions to identify activities that may represent a data loss risk. Depending on policy configuration, organizations can notify users, audit activity, or restrict certain actions. This allows organizations to establish consistent rules for handling sensitive data. DLP is one part of a broader information protection strategy and can work together with sensitivity labels, retention capabilities, auditing, and other Microsoft Purview solutions.

Question 160. Which Microsoft Purview capability helps organizations apply a classification that indicates how a document or email should be handled?

  1. Sensitivity labels
  2. Sentinel analytics rules
  3. Azure Firewall rules
  4. Entra Security Defaults

Correct Answer: 1. Sensitivity labels

Explanation:

Microsoft Purview sensitivity labels allow organizations to classify supported content according to its sensitivity and handling requirements. Labels can communicate how information should be treated and, depending on configuration, can apply protection such as encryption, access controls, or content markings. For example, an organization may define separate labels for public, internal, confidential, and highly confidential information. Sensitivity labels can also work with other Purview capabilities, including Data Loss Prevention, to support consistent information protection. Their primary purpose is classification and protection of information rather than monitoring security incidents, configuring networks, or managing user authentication.