{"id":15556,"date":"2026-09-18T05:49:28","date_gmt":"2026-09-18T05:49:28","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15556"},"modified":"2026-09-18T05:49:28","modified_gmt":"2026-09-18T05:49:28","slug":"microsoft-sc-900-practice-test-questions-and-exam-dumps-part7-q121-140","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-900-practice-test-questions-and-exam-dumps-part7-q121-140\/","title":{"rendered":"Microsoft SC-900 Practice Test Questions and Exam Dumps Part7 Q121-140"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-900-exam-dumps\"><b>Microsoft SC-900 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 121. Which Microsoft service provides a centralized platform for managing devices and applications?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Intune<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure Key Vault<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Intune<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Intune is a cloud-based endpoint management service that helps organizations manage devices, applications, and security policies. Administrators can use Intune to configure supported devices, deploy applications, establish compliance requirements, and apply configuration policies. Intune can also work with Microsoft Entra ID and other Microsoft security services to support identity-aware device management. For example, an organization can require devices to meet specific security conditions before allowing access to corporate resources. Intune is therefore an important part of Microsoft&#8217;s endpoint management strategy and can support Zero Trust by helping organizations verify device security before granting access.<\/span><\/p>\n<h3><b>Question 122. What is the primary purpose of an Intune device compliance policy?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Collect security logs for Sentinel<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether devices meet defined security requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Encrypt all Microsoft 365 emails<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Manage Azure DNS records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Determine whether devices meet defined security requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Intune device compliance policies define requirements that devices must satisfy to be considered compliant. These requirements can include conditions related to operating system versions, security settings, encryption, password configuration, or other supported device characteristics. Compliance status can then be used together with Microsoft Entra Conditional Access to influence whether a device is allowed to access organizational resources. This creates a connection between endpoint management and identity-based access control. Compliance policies do not simply provide antivirus protection; instead, they establish measurable device conditions that can be evaluated before access is granted to protected applications and services.<\/span><\/p>\n<h3><b>Question 123. Which Microsoft Intune capability can deploy applications to managed devices?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Application management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sentinel analytics<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Purview eDiscovery<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Entra Access Reviews<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Application management<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Intune provides application management capabilities that allow organizations to deploy and manage supported applications on enrolled devices. Administrators can configure applications as required or available depending on organizational needs and can establish policies around application installation and management. Intune application management can also contribute to protecting corporate data on supported devices. By centrally managing applications, organizations can reduce inconsistent configurations and ensure that users have access to approved software. This capability complements device configuration and compliance policies, providing organizations with a broader approach to managing endpoints and the applications that run on them.<\/span><\/p>\n<h3><b>Question 124. What is Microsoft Defender for Cloud Apps primarily concerned with?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Managing physical servers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Cloud application visibility, governance, and security<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Synchronizing local printers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Managing Windows passwords<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Cloud application visibility, governance, and security<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Cloud Apps focuses on security for cloud applications and services. Organizations often use numerous cloud applications, including services that may not be directly managed by traditional infrastructure teams. Defender for Cloud Apps can help provide visibility into cloud application usage, identify potential risks, and apply governance and security controls. It can also provide information about user activity and support integration with other Microsoft security capabilities. This makes it different from Microsoft Defender for Cloud, which focuses on cloud security posture and workload protection. Understanding this distinction is important when selecting the appropriate Microsoft security solution.<\/span><\/p>\n<h3><b>Question 125. Which Microsoft service helps protect identities by detecting potentially risky authentication activity?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra ID Protection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview Data Map<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure Firewall<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Entra ID Protection<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra ID Protection is designed to help organizations identify identity-related risks, including potentially risky users and sign-ins. It uses available signals to identify authentication activity that may indicate compromise or other identity threats. Security teams can use these risk signals together with Microsoft Entra policies and Conditional Access to apply additional controls when appropriate. For example, organizations can require stronger authentication when a sign-in presents elevated risk. ID Protection is specifically focused on identity risk, while Defender for Endpoint focuses primarily on device threats and Microsoft Purview focuses on information governance, protection, and compliance.<\/span><\/p>\n<h3><b>Question 126. Which Microsoft security capability helps protect an organization from phishing and malicious email attachments?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Office 365<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Identity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra Connect<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure Firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Defender for Office 365<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Office 365 provides security capabilities designed to protect email and collaboration services from threats such as phishing, malicious links, and malicious attachments. It can analyze messages and related signals to identify potentially harmful content and can provide investigation and response capabilities for security teams. Email attacks remain an important source of credential theft and malware delivery, so protecting collaboration platforms is an important part of a layered security strategy. Defender for Office 365 works alongside other Microsoft Defender products rather than replacing endpoint, identity, or network security controls.<\/span><\/p>\n<h3><b>Question 127. Which Microsoft Defender product focuses on detecting suspicious activities associated with identities in Active Directory environments?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Identity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Office 365<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Cloud Apps<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender Antivirus<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Defender for Identity<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Identity is focused on detecting and investigating identity-related threats associated with on-premises Active Directory environments. It can monitor signals from identity infrastructure and help security teams identify suspicious activities and attack techniques involving accounts, authentication, and domain resources. This information can be correlated with other Microsoft security signals through the broader Defender ecosystem. Defender for Identity differs from Entra ID Protection because it focuses heavily on identity signals associated with on-premises Active Directory, while Entra ID Protection focuses on cloud identity risk and sign-in activity in Microsoft Entra environments.<\/span><\/p>\n<h3><b>Question 128. What is the main purpose of Microsoft Defender Vulnerability Management?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Identify and help prioritize vulnerabilities and security weaknesses<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Manage email retention<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Create guest accounts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Configure Azure subscriptions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Identify and help prioritize vulnerabilities and security weaknesses<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender Vulnerability Management helps organizations discover and understand vulnerabilities and security weaknesses across supported devices and software. Security teams can use vulnerability information to identify areas that may require remediation and prioritize actions based on the organization&#8217;s environment and risk. Vulnerability management is an important preventive security activity because attackers can exploit weaknesses in outdated software, insecure configurations, or other exposed conditions. This capability complements endpoint detection and response because finding a vulnerability is different from detecting an active attack. Organizations can use both approaches to improve the overall security posture of their devices.<\/span><\/p>\n<h3><b>Question 129. Which Microsoft security service is designed to help detect and respond to threats across endpoints, identities, email, and cloud applications?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender XDR<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview Audit<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure Key Vault<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra Cloud Sync<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Defender XDR<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender XDR provides a unified security approach by bringing together signals from multiple Microsoft Defender products. Depending on the services deployed, these signals can include endpoint, identity, email, and cloud application activity. Correlating signals across these areas can help security analysts understand relationships between individual alerts and identify broader attack activity. Defender XDR supports investigation and response by presenting related security information in a more coordinated manner. This cross-domain visibility is valuable because modern attacks can move between identities, devices, applications, and email rather than remaining limited to one technology area.<\/span><\/p>\n<h3><b>Question 130. Which Microsoft security platform is designed to collect security data from multiple sources for centralized analysis?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Intune<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview Labels<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra PIM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Sentinel<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel is a cloud-native SIEM platform that can collect security-related data from many supported sources for centralized monitoring and analysis. These sources can include Microsoft services, cloud platforms, applications, infrastructure, and other supported systems. Centralizing security data allows analysts to correlate events, create detections, investigate incidents, and build dashboards that provide broader visibility. Sentinel also supports automation capabilities that can help streamline response activities. Unlike a security product focused on a single workload, Sentinel can provide a broader security operations view across an organization&#8217;s environment when appropriate data sources are connected.<\/span><\/p>\n<h3><b>Question 131. What is the purpose of Microsoft Sentinel incident management?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Group and manage related security alerts for investigation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Create Microsoft Entra passwords<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Configure document sensitivity labels<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Install endpoint drivers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Group and manage related security alerts for investigation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel incidents provide a structured way to manage security investigations by bringing related alerts and evidence together. A security analyst can investigate an incident to understand what happened, which entities were involved, and whether additional response actions are necessary. Grouping related alerts helps reduce the difficulty of handling large numbers of individual notifications and can provide better context about a potential security event. Incident management is an important part of a security operations process because detection alone is not sufficient; analysts also need a way to investigate, document, prioritize, and respond to potentially harmful activity.<\/span><\/p>\n<h3><b>Question 132. Which Microsoft Sentinel capability can execute a workflow to automate a security response?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Playbook<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sensitivity label<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Retention label<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Access Review<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Playbook<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Microsoft Sentinel playbook is an automated workflow that can be used to perform actions in response to security events. Playbooks are based on Azure Logic Apps and can connect Sentinel with other services to automate supported tasks. For example, a playbook could send notifications, enrich incident information, or perform another predefined response action. Automation can help security teams handle repetitive tasks consistently and reduce the amount of manual work required during an investigation. However, organizations should carefully design automated actions, especially when those actions could affect users, accounts, or production systems.<\/span><\/p>\n<h3><b>Question 133. Which Microsoft Purview capability helps classify information based on its sensitivity?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sensitivity labels<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel incidents<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender Antivirus<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra Connect<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Sensitivity labels<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview sensitivity labels provide a way to classify content according to its sensitivity and organizational handling requirements. Organizations can define labels that represent categories such as public, internal, confidential, or highly confidential information. Depending on configuration, labels can also apply protection controls such as encryption, access restrictions, or content markings. Classification helps users and organizations understand how information should be handled and can work together with other Purview capabilities, including Data Loss Prevention. Sensitivity labels are therefore primarily associated with information classification and protection rather than network security, identity synchronization, or security incident management.<\/span><\/p>\n<h3><b>Question 134. What is the main benefit of Microsoft Purview Data Loss Prevention policies?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Help prevent sensitive information from being shared or exposed improperly<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Provide physical access to data centers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Create Azure virtual networks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace multifactor authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Help prevent sensitive information from being shared or exposed improperly<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Data Loss Prevention policies help organizations identify and protect sensitive information across supported locations and activities. Policies can use sensitive information types, labels, and other conditions to determine when content or activities may present a data loss risk. Depending on the configuration, users can receive policy notifications, activities can be audited, or specific actions can be restricted. DLP is especially useful when organizations need to control how sensitive information is handled across collaboration and productivity environments. It complements sensitivity labels and other information governance capabilities rather than replacing identity or endpoint security controls.<\/span><\/p>\n<h3><b>Question 135. Which Microsoft Purview solution helps organizations assess compliance against regulations and standards?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Compliance Manager<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Defender for Endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra ID Protection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure Firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Compliance Manager<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Compliance Manager helps organizations assess and manage their compliance posture against relevant regulations, standards, and organizational requirements. It provides assessments, improvement actions, and tracking capabilities that can help organizations understand where additional work may be needed. Compliance Manager does not itself guarantee that an organization is compliant. Instead, it provides a structured framework for identifying actions, assigning responsibilities, documenting progress, and improving compliance readiness. Organizations can use it as part of a broader governance program that includes policies, technical controls, employee processes, documentation, and regular reviews.<\/span><\/p>\n<h3><b>Question 136. Which principle is most closely associated with limiting administrative permissions to only what is required?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Least privilege<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume breach<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Single sign-on<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Public access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Least privilege<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege requires that users, administrators, applications, and services receive only the permissions necessary to perform their authorized responsibilities. Administrative accounts are especially important because excessive privileges can significantly increase the impact of a compromised credential. Microsoft Entra Privileged Identity Management can support this principle by enabling eligible administrators to activate privileged roles only when needed. Role-based access control can also help define appropriate permissions. Applying least privilege requires regular review because responsibilities and access requirements change over time. Removing unnecessary permissions can reduce opportunities for attackers to misuse compromised accounts.<\/span><\/p>\n<h3><b>Question 137. Which Zero Trust principle encourages organizations to design security controls assuming that an attacker could already be inside the environment?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume breach<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Trust internal networks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow unrestricted access<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Assume breach<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Zero Trust principle \u201cAssume breach\u201d encourages organizations to operate as though a compromise may already exist somewhere within their environment. This approach leads organizations to continuously monitor activity, segment resources, protect identities, restrict privileges, and investigate suspicious behavior. The purpose is not to assume that every user is malicious, but to avoid relying on the assumption that internal network location automatically makes a request trustworthy. Microsoft security capabilities such as Defender, Sentinel, Entra ID, and network security controls can provide different layers of protection that support this principle and reduce the impact of potential compromises.<\/span><\/p>\n<h3><b>Question 138. What is the primary purpose of multifactor authentication?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Require multiple forms of verification to strengthen identity security<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store application secrets<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Manage data retention<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Scan network packets<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Require multiple forms of verification to strengthen identity security<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multifactor authentication, or MFA, strengthens authentication by requiring users to provide more than one type of verification. These factors can involve something the user knows, something the user has, or something the user is. For example, a password may be combined with an authenticator approval or another supported authentication method. MFA helps reduce the impact of stolen passwords because an attacker may still need the additional authentication factor. Microsoft Entra ID supports MFA and can integrate it with Conditional Access policies, allowing organizations to require stronger authentication under specific circumstances rather than treating every access request identically.<\/span><\/p>\n<h3><b>Question 139. Which Microsoft Entra feature can periodically ask reviewers to confirm whether access should continue?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Access Reviews<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security Defaults<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password Hash Synchronization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Windows Hello for Business<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Access Reviews<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Access Reviews help organizations periodically evaluate whether users or other identities should continue to have access to specific resources. Reviewers can examine assigned access and confirm whether it remains appropriate. This is especially useful for external users, group memberships, applications, and sensitive resources where access should not remain indefinitely without review. Access Reviews support identity governance and least privilege by helping organizations identify unnecessary or outdated permissions. They are different from Conditional Access, which evaluates access requests, because Access Reviews focus on periodically reviewing existing access assignments.<\/span><\/p>\n<h3><b>Question 140. Which Microsoft service can help organizations manage security recommendations across Azure and other supported cloud resources?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Cloud<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview Communication Compliance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra External ID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Office 365<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Defender for Cloud<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Cloud helps organizations improve security posture across supported cloud resources by providing security recommendations, posture management capabilities, and workload protection features. Recommendations can identify configurations or security conditions that may require attention, allowing administrators to prioritize remediation according to organizational risk. Defender for Cloud can also provide protection capabilities for supported workloads. It should be distinguished from Microsoft Defender for Cloud Apps, which focuses primarily on cloud application visibility and security. Defender for Cloud is therefore an important Microsoft solution for managing and improving security across cloud environments.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-900 Exam Dumps and Practice Test Dumps &nbsp; Question 121. Which Microsoft service provides a centralized platform for managing devices and applications? Microsoft Intune Microsoft Sentinel Microsoft Purview Azure Key Vault Correct Answer: 1. Microsoft Intune Explanation: Microsoft Intune is a cloud-based endpoint management service that helps organizations manage devices, applications, and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15556"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15556"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15556\/revisions"}],"predecessor-version":[{"id":15584,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15556\/revisions\/15584"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15556"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15556"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15556"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}