{"id":15550,"date":"2026-09-18T05:50:31","date_gmt":"2026-09-18T05:50:31","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15550"},"modified":"2026-09-18T05:50:31","modified_gmt":"2026-09-18T05:50:31","slug":"microsoft-sc-900-practice-test-questions-and-exam-dumps-part1-q1-20","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-900-practice-test-questions-and-exam-dumps-part1-q1-20\/","title":{"rendered":"Microsoft SC-900 Practice Test Questions and Exam Dumps Part1 Q1-20"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-900-exam-dumps\"><b>Microsoft SC-900 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 1. What is the primary purpose of Microsoft Entra ID?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To manage physical network cables<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide identity and access management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To store application source code<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To monitor CPU temperature<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To provide identity and access management<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra ID is Microsoft&#8217;s cloud-based identity and access management service. It helps organizations manage users, groups, applications, devices, and access to resources. Administrators can use Entra ID to authenticate users and control which resources they are allowed to access. It also supports capabilities such as multifactor authentication, Conditional Access, application identities, and single sign-on. These capabilities help organizations establish centralized identity controls across Microsoft cloud services and other applications. Entra ID is therefore fundamentally focused on identity and access rather than physical networking, source-code storage, or hardware monitoring.<\/span><\/p>\n<h3><b>Question 2. Which Microsoft security principle requires users to receive only the permissions necessary to perform their assigned tasks?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Least privilege<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data residency<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> High availability<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network segmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Least privilege<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The principle of least privilege means that users, applications, and services should receive only the permissions required to perform their intended tasks. Limiting permissions reduces the potential impact if an account or application is compromised. For example, a user who only needs to read documents should not automatically receive permission to delete or modify those documents. Least privilege is an important component of identity and security management because excessive permissions can increase security risk. Data residency concerns where information is stored, high availability focuses on service continuity, and network segmentation separates network environments. Therefore, least privilege directly addresses controlled authorization.<\/span><\/p>\n<h3><b>Question 3. Which Microsoft security capability can require users to provide an additional authentication method, such as an authenticator app notification?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Cloud<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra multifactor authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Microsoft Entra multifactor authentication<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra multifactor authentication, commonly referred to as MFA, requires users to provide more than one form of authentication when signing in. Depending on the configuration, a user may provide a password together with an authenticator app approval, security key, or another supported authentication method. MFA strengthens account security because a stolen password alone may not be sufficient to access the account. Microsoft Defender for Cloud focuses on cloud security posture and workload protection, Microsoft Purview focuses on data governance and compliance, and Microsoft Sentinel provides security information and event management capabilities. Therefore, Entra MFA is the relevant authentication capability.<\/span><\/p>\n<h3><b>Question 4. What is the main purpose of Microsoft Entra Conditional Access?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To create physical firewalls<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To apply access decisions based on specified conditions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To compress files<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To create database backups<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To apply access decisions based on specified conditions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access helps organizations control access to resources by evaluating conditions associated with a sign-in request. Administrators can consider factors such as the user, application, device, location, and risk when defining access policies. Depending on the policy, access may be allowed, blocked, or require additional controls such as multifactor authentication. Conditional Access therefore provides a policy-based approach to controlling access rather than relying solely on usernames and passwords. It is not designed to create physical firewalls, compress files, or perform database backups. Its primary purpose is to apply access decisions according to defined conditions.<\/span><\/p>\n<h3><b>Question 5. Which Microsoft service provides cloud-based security information and event management (SIEM) capabilities?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Intune<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra ID<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Microsoft Sentinel<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel is Microsoft&#8217;s cloud-native security information and event management solution. It can collect security-related data from Microsoft services, cloud platforms, applications, devices, and other sources. Security teams can use Sentinel to analyze events, identify suspicious activity, investigate incidents, and create automated responses. Its cloud-native architecture allows organizations to scale security monitoring without deploying and maintaining traditional SIEM infrastructure themselves. Microsoft Intune focuses on device and application management, Microsoft Purview provides data governance and compliance capabilities, and Entra ID manages identities and access. Therefore, Microsoft Sentinel is the appropriate service for SIEM functionality.<\/span><\/p>\n<h3><b>Question 6. Which Microsoft service is primarily designed to provide extended detection and response (XDR) capabilities across endpoints, identities, email, and cloud applications?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender XDR<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra ID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Service Health<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Defender XDR<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender XDR is designed to provide integrated security protection and detection across multiple areas of an organization&#8217;s environment. It can correlate signals from endpoints, identities, email, collaboration services, and applications to help security teams investigate and respond to threats. By combining related signals, Defender XDR can provide broader incident context than a tool focused on a single security layer. Microsoft Purview is primarily associated with data security, governance, risk, and compliance. Entra ID manages identity and access, while Service Health provides information about Microsoft service availability. Therefore, Microsoft Defender XDR is the appropriate platform for XDR capabilities.<\/span><\/p>\n<h3><b>Question 7. What is the primary purpose of Microsoft Defender for Cloud?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To manage payroll systems<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide cloud security posture management and workload protection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To create Microsoft Word documents<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To manage DNS records exclusively<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To provide cloud security posture management and workload protection<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Cloud helps organizations improve the security posture of cloud resources and protect workloads across supported environments. It provides capabilities for assessing security configurations, identifying security recommendations, detecting threats, and protecting cloud workloads. Organizations can use it to gain visibility into security risks and improve the configuration of their cloud resources. Its functionality is broader than managing a single infrastructure component such as DNS. Payroll systems and document creation are unrelated to its primary purpose. Therefore, cloud security posture management and workload protection accurately describe the role of Microsoft Defender for Cloud.<\/span><\/p>\n<h3><b>Question 8. Which Microsoft service is primarily used to manage and protect organizational data while supporting governance, compliance, and risk management?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra ID<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Purview<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview provides capabilities that help organizations discover, govern, protect, and manage data while addressing compliance and risk requirements. Depending on the solution and configuration, organizations can use Purview capabilities for data classification, sensitivity labeling, data loss prevention, records management, compliance management, and related governance tasks. Microsoft Sentinel is focused on security monitoring and SIEM, Defender for Endpoint focuses on endpoint security, and Entra ID manages identities and access. Therefore, Microsoft Purview is the service most closely associated with organizational data governance, compliance, and information protection.<\/span><\/p>\n<h3><b>Question 9. Which Microsoft security solution is designed specifically to protect endpoints such as Windows devices against malware and other threats?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra ID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Defender for Endpoint<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint is an endpoint security solution designed to help protect devices from cyber threats. It provides capabilities such as threat detection, investigation, vulnerability management, and response for supported endpoints. Security teams can use it to identify suspicious behavior and investigate potential attacks across organizational devices. Microsoft Entra ID focuses on identity and access management, Purview focuses on data governance and compliance, and Sentinel provides SIEM capabilities. Although these services can work together as part of a broader security architecture, Defender for Endpoint is specifically intended for protecting and monitoring endpoints.<\/span><\/p>\n<h3><b>Question 10. What is the purpose of role-based access control (RBAC) in Microsoft security solutions?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To encrypt every network packet<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To assign permissions based on defined roles<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To automatically increase storage capacity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace all authentication methods<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To assign permissions based on defined roles<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Role-based access control, or RBAC, assigns permissions to users or other identities according to defined roles. Instead of granting individual permissions separately to every user, administrators can assign a role that contains the permissions required for a particular responsibility. This simplifies permission management and can support the principle of least privilege when roles are designed appropriately. RBAC does not itself encrypt network packets, increase storage capacity, or replace authentication methods. Authentication determines who an identity is, while authorization determines what that identity can access. Therefore, assigning permissions through defined roles is the primary purpose of RBAC.<\/span><\/p>\n<h3><b>Question 11. Which Microsoft capability allows a user to sign in once and then access multiple supported applications without repeatedly entering credentials?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Single sign-on<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data Loss Prevention<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security posture management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network segmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Single sign-on<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Single sign-on, or SSO, allows users to authenticate once and then access multiple applications that trust the same identity provider without repeatedly entering credentials. Microsoft Entra ID provides SSO capabilities for supported Microsoft and third-party applications. This can improve the user experience while also allowing administrators to maintain centralized identity policies. SSO does not itself provide data loss prevention, security posture management, or network segmentation. Those capabilities address different security concerns. Therefore, when the requirement is to allow users to authenticate once and access multiple applications without repeated sign-ins, single sign-on is the appropriate capability.<\/span><\/p>\n<h3><b>Question 12. What is the primary purpose of Microsoft Intune?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide DNS resolution<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To manage devices and applications<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide SIEM analytics<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace Microsoft Entra ID<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To manage devices and applications<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Intune is a cloud-based endpoint management service that helps organizations manage devices, applications, and related security policies. Administrators can use Intune to configure devices, enforce compliance requirements, deploy applications, manage mobile devices, and support endpoint security policies. Intune works with Microsoft Entra ID and other Microsoft security services but does not replace identity management. SIEM capabilities are provided by Microsoft Sentinel, while DNS resolution is a networking function. Therefore, device and application management is the primary purpose of Microsoft Intune within Microsoft&#8217;s broader security and management ecosystem.<\/span><\/p>\n<h3><b>Question 13. Which security concept assumes that no user, device, application, or network location should automatically be trusted?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Zero Trust<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> High availability<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data residency<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Backup and recovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Zero Trust<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero Trust is a security approach based on the principle that access should not be automatically trusted simply because a user or device is inside an organization&#8217;s network. Instead, access requests should be evaluated using relevant signals such as identity, device health, application, location, and risk. Authentication and authorization are continuously important components of this approach. Zero Trust commonly emphasizes verifying explicitly, using least privilege, and assuming that a security breach can occur. High availability focuses on service continuity, data residency concerns geographic storage requirements, and backup and recovery focus on restoring data or services. Therefore, Zero Trust is the correct concept.<\/span><\/p>\n<h3><b>Question 14. Which Microsoft security principle recommends continuously verifying identities and access requests instead of automatically trusting previously authenticated users?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume breach<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data minimization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Capacity planning<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Resource tagging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Assume breach<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Assume breach is one of the core ideas associated with Microsoft&#8217;s Zero Trust security approach. It means organizations should operate with the expectation that a security breach could occur and should therefore design controls to limit the impact of compromised identities, devices, or applications. This mindset encourages strong authentication, least-privilege access, monitoring, segmentation, and rapid detection and response. Data minimization concerns limiting the amount of personal or sensitive data collected, while capacity planning concerns infrastructure resources. Resource tagging is an administrative practice. Therefore, assume breach is the security principle that reflects preparing for the possibility that attackers may already have access.<\/span><\/p>\n<h3><b>Question 15. Which Microsoft security capability can help prevent sensitive information from being shared or transmitted inappropriately?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Cloud<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra ID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview Data Loss Prevention<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Microsoft Purview Data Loss Prevention<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Data Loss Prevention, or DLP, helps organizations identify, monitor, and protect sensitive information so that it is not shared or transmitted in ways that violate organizational policies. DLP policies can be used to detect sensitive information and apply actions or restrictions depending on the circumstances and configured rules. This can help organizations reduce the risk of accidental or intentional data exposure. Defender for Cloud focuses on cloud security, Entra ID focuses on identity and access, and Sentinel focuses on security monitoring and SIEM. Therefore, Microsoft Purview DLP is the capability specifically associated with preventing inappropriate handling of sensitive data.<\/span><\/p>\n<h3><b>Question 16. What is the primary purpose of sensitivity labels in Microsoft Purview?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To classify and protect sensitive organizational information<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To assign IP addresses to devices<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To monitor CPU utilization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To create virtual machines<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To classify and protect sensitive organizational information<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Sensitivity labels in Microsoft Purview help organizations classify information according to its sensitivity and apply appropriate protection policies. For example, an organization can use labels to identify information as confidential or highly sensitive and then configure protections such as encryption, access controls, or content markings where supported. Labels help users and administrators understand how information should be handled while enabling consistent protection policies. They are not designed to assign IP addresses, monitor CPU utilization, or create virtual machines. Therefore, classifying and protecting sensitive organizational information is the primary purpose of sensitivity labels.<\/span><\/p>\n<h3><b>Question 17. Which Microsoft service can collect security data from multiple sources and provide automated investigation and response capabilities as part of a security operations platform?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Word<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Intune<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Microsoft Sentinel<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel is a cloud-native security operations platform that provides SIEM and security orchestration, automation, and response capabilities. It can ingest security data from Microsoft services, third-party systems, applications, and infrastructure, allowing security teams to analyze events and investigate incidents from a centralized platform. Automation capabilities can help perform response actions when defined conditions are met. Intune focuses on endpoint management, while Purview focuses on data governance and compliance. Microsoft Word is a productivity application and is not a security operations platform. Therefore, Sentinel is the appropriate Microsoft service for centralized security monitoring and automated response workflows.<\/span><\/p>\n<h3><b>Question 18. Which authentication method provides phishing-resistant authentication by using a physical security key or compatible device-based credential?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password-only authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security key authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Username without authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Shared account credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Security key authentication<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security key authentication can provide strong, phishing-resistant authentication by using hardware-based credentials or compatible device-based authentication technologies. These methods are designed to prevent attackers from simply capturing a reusable password through a fraudulent website. Security keys can use standards such as FIDO2 and can provide a strong authentication factor without relying solely on passwords. Password-only authentication is more vulnerable to phishing and credential theft, while shared credentials reduce accountability and increase security risk. Therefore, security key authentication is an appropriate example of a strong authentication method designed to resist phishing attacks.<\/span><\/p>\n<h3><b>Question 19. Which Microsoft security concept focuses on ensuring that access is granted only after the identity and relevant security conditions have been evaluated?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Verify explicitly<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data archiving<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Resource scaling<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Storage replication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Verify explicitly<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Verify explicitly is a core principle of Microsoft&#8217;s Zero Trust approach. It means that organizations should authenticate and authorize access based on relevant information rather than automatically trusting a request because of its network location or previous access. Signals such as identity, device state, location, application, and risk can contribute to access decisions. This approach helps organizations make access controls more context-aware and reduces reliance on implicit trust. Data archiving, resource scaling, and storage replication address other operational requirements and do not describe an identity-security principle. Therefore, verify explicitly is the correct concept for evaluating access based on available security signals.<\/span><\/p>\n<h3><b>Question 20. Which Microsoft security solution provides a centralized platform for discovering, classifying, governing, and protecting organizational data across supported environments?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra ID<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Microsoft Purview<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview provides a broad set of capabilities for discovering, classifying, governing, protecting, and managing organizational data. It supports organizations in addressing information protection, data governance, compliance, and risk requirements across supported data sources and environments. Capabilities can include data classification, sensitivity labels, data loss prevention, compliance management, and governance features. Microsoft Sentinel is focused on security operations and SIEM, Defender for Endpoint protects endpoints, and Entra ID manages identities and access. Therefore, Microsoft Purview is the Microsoft security and compliance solution that best matches the requirement for centralized data discovery, classification, governance, and protection.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-900 Exam Dumps and Practice Test Dumps &nbsp; Question 1. What is the primary purpose of Microsoft Entra ID? To manage physical network cables To provide identity and access management To store application source code To monitor CPU temperature Correct Answer: 2. To provide identity and access management Explanation: Microsoft Entra ID [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15550"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15550"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15550\/revisions"}],"predecessor-version":[{"id":15590,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15550\/revisions\/15590"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15550"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15550"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15550"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}