{"id":15551,"date":"2026-09-18T05:50:19","date_gmt":"2026-09-18T05:50:19","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15551"},"modified":"2026-09-18T05:50:19","modified_gmt":"2026-09-18T05:50:19","slug":"microsoft-sc-900-practice-test-questions-and-exam-dumps-part2-q21-40","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-900-practice-test-questions-and-exam-dumps-part2-q21-40\/","title":{"rendered":"Microsoft SC-900 Practice Test Questions and Exam Dumps Part2 Q21-40"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-900-exam-dumps\"><b>Microsoft SC-900 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 21. Which Microsoft Entra capability can automatically detect risky sign-ins and users that may have compromised credentials?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra ID Protection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Intune<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Cloud<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Entra ID Protection<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra ID Protection helps organizations detect, investigate, and respond to identity-based risks. It can identify risk associated with users and sign-ins by analyzing signals that may indicate compromised identities or suspicious authentication activity. Security teams can use these risk detections together with Conditional Access policies to require additional verification or block risky access. Intune focuses primarily on device and application management, while Purview focuses on data governance and compliance. Defender for Cloud addresses cloud security posture and workload protection. Therefore, Microsoft Entra ID Protection is the capability specifically designed to identify and help manage identity-related risks.<\/span><\/p>\n<h3><b>Question 22. Which Microsoft Entra feature can provide users with a self-service method to reset their passwords after verifying their identity?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Privileged Identity Management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Self-service password reset<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Access Reviews<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Identity Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Self-service password reset<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra self-service password reset allows users to reset their own passwords when they have forgotten them or when a password needs to be changed, without requiring an administrator to manually perform the reset. Organizations can configure authentication methods and registration requirements so that users can prove their identity before completing the reset process. This capability can reduce help desk workload and improve user productivity. Privileged Identity Management focuses on controlling privileged access, Access Reviews help review access assignments, and Identity Protection focuses on detecting identity risks. Therefore, self-service password reset is the appropriate feature for user-managed password recovery.<\/span><\/p>\n<h3><b>Question 23. What is the primary purpose of Microsoft Entra Privileged Identity Management (PIM)?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide temporary and controlled access to privileged roles<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To store application source code<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To manage DNS zones<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To archive email messages<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To provide temporary and controlled access to privileged roles<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management helps organizations manage, control, and monitor access to privileged roles. Instead of allowing administrators to remain permanently assigned to highly privileged roles, PIM can support just-in-time and time-limited activation. Organizations can also configure requirements such as multifactor authentication, approval, justification, and notifications depending on the role and policy. This reduces the amount of time privileged permissions remain active and can lower the potential impact of compromised privileged accounts. PIM is not designed for source-code storage, DNS management, or email archiving. Its primary purpose is controlled management of privileged identity access.<\/span><\/p>\n<h3><b>Question 24. Which Microsoft Entra feature allows administrators to periodically verify whether users still need their assigned application or group access?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password Hash Synchronization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Access Reviews<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security Defaults<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Self-service password reset<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Access Reviews<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Access Reviews help organizations regularly review whether users, groups, applications, or other identities should continue to have access to resources. Administrators can establish recurring reviews and ask appropriate reviewers to confirm whether access remains necessary. This supports least privilege by helping remove access that is no longer required. Password Hash Synchronization is an identity synchronization capability, Security Defaults provide baseline security settings, and self-service password reset helps users recover their passwords. Therefore, Access Reviews are the appropriate Entra capability when the objective is to periodically validate existing access assignments.<\/span><\/p>\n<h3><b>Question 25. Which Microsoft security capability provides a baseline set of identity and access protections that can be enabled for an organization?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra Security Defaults<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Entra Security Defaults<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Security Defaults provide a basic set of identity security protections intended to help organizations improve their security posture with relatively simple configuration. These defaults can include requirements related to multifactor authentication and protections against common identity-based threats. They are particularly useful for organizations that need baseline security controls without designing a large number of custom Conditional Access policies. Sentinel provides SIEM capabilities, Defender for Endpoint protects endpoint devices, and Purview focuses on data governance and compliance. Therefore, Microsoft Entra Security Defaults are the appropriate capability when a baseline identity security configuration is required.<\/span><\/p>\n<h3><b>Question 26. What is the primary purpose of Microsoft Defender for Office 365?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To manage Azure virtual networks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To protect email and collaboration services against threats<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To manage physical servers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace Microsoft Entra ID<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To protect email and collaboration services against threats<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Office 365 helps protect organizations from threats targeting email and collaboration services. Its capabilities can help detect and respond to threats such as phishing, malicious links, malicious attachments, and other email-based attacks. It can also provide security features for supported Microsoft 365 collaboration workloads. Defender for Office 365 is part of Microsoft&#8217;s broader security ecosystem and can integrate with other Defender solutions. It is not intended to manage Azure virtual networks or physical servers, and it does not replace Entra ID. Therefore, protecting email and collaboration services is its primary purpose.<\/span><\/p>\n<h3><b>Question 27. Which Microsoft Defender solution is primarily designed to protect identities and detect identity-based threats across an organization?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Identity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Cloud<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Office 365<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Defender for Identity<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Identity is designed to help organizations detect and investigate identity-based threats, particularly those involving identity infrastructure and directory environments. It can identify suspicious activities associated with compromised accounts, credential theft, reconnaissance, and other identity-related attack techniques. Defender for Endpoint focuses on devices, Defender for Office 365 focuses on email and collaboration threats, and Defender for Cloud focuses on cloud security posture and workload protection. These services can work together as part of a broader security architecture, but Defender for Identity is specifically focused on identity threat detection and investigation.<\/span><\/p>\n<h3><b>Question 28. Which Microsoft Defender solution provides vulnerability management and threat protection capabilities for organizational endpoint devices?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Identity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Office 365<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Cloud Apps<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Defender for Endpoint<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint provides security capabilities for endpoint devices, including threat detection, endpoint protection, vulnerability management, investigation, and response. It helps security teams monitor devices and identify malicious or suspicious activity while also providing information about endpoint security weaknesses. Defender for Identity is focused on identity-related threats, Defender for Office 365 protects email and collaboration workloads, and Defender for Cloud Apps focuses on cloud application visibility and control. Therefore, when the requirement is specifically endpoint vulnerability management and threat protection, Microsoft Defender for Endpoint is the appropriate solution.<\/span><\/p>\n<h3><b>Question 29. What is the primary purpose of Microsoft Defender for Cloud Apps?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide visibility and control over cloud applications<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To manage Windows Update settings only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace Microsoft Sentinel<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide physical data center security<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To provide visibility and control over cloud applications<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Cloud Apps helps organizations gain visibility into cloud applications and apply security controls around their use. It can help security teams discover cloud application usage, assess risks, monitor activities, and apply policies to protect organizational information. This is particularly useful in environments where employees use multiple cloud services and administrators need greater visibility into application activity. Defender for Cloud Apps is different from Sentinel, which provides SIEM capabilities, and Intune, which manages devices and applications. Therefore, providing visibility and control over cloud applications is the primary purpose of Defender for Cloud Apps.<\/span><\/p>\n<h3><b>Question 30. Which Microsoft service provides cloud security posture management capabilities for resources across Azure and supported multicloud environments?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Cloud<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra ID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Intune<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Defender for Cloud<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Cloud provides cloud security posture management capabilities that help organizations assess and improve the security configuration of their cloud resources. It can provide recommendations, security assessments, and protection capabilities across supported Azure and multicloud environments. This allows security and operations teams to identify configuration weaknesses and prioritize improvements. Microsoft Purview focuses on data governance and compliance, Entra ID focuses on identity and access, and Intune focuses on endpoint management. Therefore, Defender for Cloud is the Microsoft service that best matches the requirement for cloud security posture management across supported environments.<\/span><\/p>\n<h3><b>Question 31. Which Microsoft security feature can help enforce a requirement that administrators use multifactor authentication when accessing sensitive resources?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra Conditional Access<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview Records Management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender Antivirus only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel Workbook<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Entra Conditional Access<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access can be configured to require multifactor authentication when users meet specified conditions. For example, an organization can create a policy that requires administrators or users accessing sensitive applications to complete MFA before access is granted. Conditional Access evaluates sign-in conditions and then applies the configured access control. This provides a flexible way to enforce authentication requirements based on identity, application, device, location, risk, or other supported signals. Purview Records Management handles information governance, Defender Antivirus provides endpoint malware protection, and Sentinel workbooks visualize security data. Therefore, Conditional Access is the appropriate feature.<\/span><\/p>\n<h3><b>Question 32. What is the main purpose of Microsoft Security Copilot?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace all Microsoft security services<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To assist security professionals with security-related tasks using AI capabilities<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide physical network cabling<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To manage database indexes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To assist security professionals with security-related tasks using AI capabilities<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Security Copilot is designed to assist security professionals with security operations and related tasks by using AI capabilities. It can help analyze security information, summarize incidents, investigate threats, and support security workflows depending on the available integrations and configuration. It is intended to augment security professionals rather than automatically replace an organization&#8217;s entire security architecture or eliminate the need for human oversight. Physical networking and database management are outside its primary purpose. Therefore, assisting security professionals with security-related tasks through AI capabilities accurately describes the role of Microsoft Security Copilot.<\/span><\/p>\n<h3><b>Question 33. Which Microsoft Purview capability can identify sensitive information types such as credit card numbers or national identification numbers?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sensitive Information Types<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra roles<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Defender antivirus signatures<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure Monitor metrics<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Sensitive Information Types<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Sensitive Information Types are used to identify specific categories of sensitive information within supported content and data sources. Examples can include financial information, identification numbers, and other predefined or custom patterns. These detections can then be used by capabilities such as Data Loss Prevention to apply appropriate policies. Sensitive Information Types are therefore an important building block for identifying data that requires additional protection. Entra roles manage identity permissions, Defender antivirus signatures relate to malware detection, and Azure Monitor metrics provide operational monitoring data. Consequently, Sensitive Information Types are the correct Purview capability for identifying sensitive data patterns.<\/span><\/p>\n<h3><b>Question 34. Which Microsoft Purview feature helps organizations create policies that can detect and restrict the sharing of sensitive information?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data Loss Prevention<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Access Reviews<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security Defaults<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Privileged Identity Management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Data Loss Prevention<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Data Loss Prevention policies help organizations identify sensitive information and apply rules that control how that information can be used or shared. DLP can help reduce accidental disclosure by detecting sensitive data in supported locations and applying configured actions, notifications, or restrictions. Organizations can create policies based on sensitive information types, labels, users, locations, and other conditions. Access Reviews and Privileged Identity Management are identity-focused controls, while Security Defaults provide baseline identity protections. Therefore, Data Loss Prevention is the appropriate Purview capability for creating policies that help prevent inappropriate sharing of sensitive information.<\/span><\/p>\n<h3><b>Question 35. Which Microsoft service provides governance and compliance solutions that can help organizations assess their compliance posture against regulatory and organizational requirements?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview Compliance Manager<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra Connect<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender Antivirus<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Purview Compliance Manager<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Compliance Manager helps organizations assess and manage compliance activities against applicable regulations, standards, and organizational requirements. It provides assessments, improvement actions, and information that can help organizations understand their compliance posture and identify areas that require attention. It is designed to support compliance management rather than directly provide endpoint malware protection or identity synchronization. Defender for Endpoint focuses on endpoint security, Entra Connect is associated with identity synchronization between environments, and Defender Antivirus provides malware protection. Therefore, Purview Compliance Manager is the appropriate service when the objective is to assess and improve an organization&#8217;s compliance posture.<\/span><\/p>\n<h3><b>Question 36. What does the principle of least privilege recommend when assigning permissions to users?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give every user administrator permissions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give users only the permissions they need<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow unrestricted access within the organization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Give users only the permissions they need<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege recommends granting users, applications, and services only the permissions required to perform their legitimate responsibilities. This reduces the potential impact of compromised accounts and limits opportunities for unauthorized actions. For example, a user who only needs to view reports should not automatically receive permission to modify or delete the underlying data. Organizations can implement least privilege through role-based access control, Conditional Access, privileged identity management, and other security mechanisms. Granting administrator permissions to everyone or allowing unrestricted access contradicts this principle. Therefore, giving users only the permissions they need is the correct interpretation of least privilege.<\/span><\/p>\n<h3><b>Question 37. Which Microsoft security concept is most closely associated with using multiple layers of security controls so that failure of one control does not necessarily compromise the entire environment?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Defense in depth<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data residency<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Single sign-on<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Defense in depth<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Defense in depth is a security strategy that uses multiple layers of controls to protect systems and information. Instead of relying on a single security mechanism, organizations can combine identity protection, endpoint security, network controls, data protection, monitoring, and incident response. If one control fails or is bypassed, additional layers may still detect, block, or limit the attack. This approach can reduce the likelihood that a single security failure leads directly to a major compromise. Data residency concerns where data is stored, SSO concerns authentication convenience, and data compression concerns storage or transmission efficiency. Therefore, defense in depth is the correct concept.<\/span><\/p>\n<h3><b>Question 38. Which Microsoft service is designed to provide security recommendations and improve the security posture of Azure resources?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Cloud<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Teams<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Exchange Online<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra Connect<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Defender for Cloud<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Cloud provides security posture management capabilities that can help organizations identify security recommendations for their cloud resources. These recommendations can highlight configuration weaknesses, missing protections, or other areas where security controls could be improved. Security teams can use this information to prioritize remediation activities and improve their overall cloud security posture. Microsoft Teams and Exchange Online are collaboration and communication services, while Entra Connect is used for identity synchronization scenarios. Therefore, Defender for Cloud is the appropriate Microsoft service when an organization needs security recommendations and posture management for cloud resources.<\/span><\/p>\n<h3><b>Question 39. Which Microsoft Entra capability can provide reports and information about risky users and risky sign-ins?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra ID Protection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Intune App Protection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview eDiscovery<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure Storage Explorer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Entra ID Protection<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra ID Protection provides visibility into identity risks by identifying potentially risky users and sign-in activities. It uses signals and detections to help organizations investigate situations where an identity may have been compromised or where a sign-in appears suspicious. Administrators can use risk information to support remediation actions and integrate identity risk with access policies such as Conditional Access. Intune App Protection focuses on application data protection, Purview eDiscovery supports investigations involving organizational content, and Storage Explorer is an administrative tool for storage resources. Therefore, Entra ID Protection is the appropriate capability for identifying risky users and sign-ins.<\/span><\/p>\n<h3><b>Question 40. Which Microsoft security approach combines identity, endpoint, email, application, and cloud security capabilities to provide a coordinated defense against threats?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender XDR<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Word<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Power BI<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Azure DevOps only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Defender XDR<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender XDR brings together security signals and capabilities across multiple areas of an organization&#8217;s environment, including endpoints, identities, email, applications, and other supported workloads. Correlating information across these areas can help security teams understand the broader context of an attack instead of investigating each security signal independently. This integrated approach can improve threat detection, investigation, and response workflows. Individual Microsoft services may focus on particular security domains, but Defender XDR is designed to coordinate protection and detection across multiple Microsoft security solutions. Therefore, Microsoft Defender XDR is the appropriate answer for a coordinated, cross-domain security approach.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-900 Exam Dumps and Practice Test Dumps &nbsp; Question 21. Which Microsoft Entra capability can automatically detect risky sign-ins and users that may have compromised credentials? Microsoft Entra ID Protection Microsoft Intune Microsoft Purview Microsoft Defender for Cloud Correct Answer: 1. Microsoft Entra ID Protection Explanation: Microsoft Entra ID Protection helps organizations [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15551"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15551"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15551\/revisions"}],"predecessor-version":[{"id":15589,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15551\/revisions\/15589"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15551"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15551"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15551"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}