{"id":15558,"date":"2026-09-18T05:49:09","date_gmt":"2026-09-18T05:49:09","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15558"},"modified":"2026-09-18T05:49:09","modified_gmt":"2026-09-18T05:49:09","slug":"microsoft-sc-900-practice-test-questions-and-exam-dumps-part-9-q161-180","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-900-practice-test-questions-and-exam-dumps-part-9-q161-180\/","title":{"rendered":"Microsoft SC-900 Practice Test Questions and Exam Dumps Part 9 Q161-180"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-900-exam-dumps\"><b>Microsoft SC-900 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 161. Which concept describes how security responsibilities are divided between a cloud provider and a customer?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Shared responsibility model<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Single sign-on model<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Zero Trust model<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Defense-in-depth model<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Shared responsibility model<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The shared responsibility model explains how security and operational responsibilities are divided between the cloud service provider and the customer. Microsoft is responsible for securing the underlying cloud infrastructure, while customers retain responsibilities that depend on the service they use, such as managing identities, configuring access, protecting data, and maintaining appropriate security settings. The exact division changes between SaaS, PaaS, and IaaS. Understanding this model helps organizations avoid assuming that the cloud provider automatically handles every aspect of security. It also helps customers identify which controls they must configure and maintain themselves.<\/span><\/p>\n<h3><b>Question 162. In a Zero Trust security approach, which principle treats identity as a primary security boundary?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Trust every internal user<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Identity verification and access control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable authentication after login<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow unrestricted network access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Identity verification and access control<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero Trust treats identity as an important security perimeter because users, devices, applications, and workloads can access resources from many locations and networks. Instead of assuming that a user is trusted because they are connected to an internal network, organizations continuously evaluate identity, device state, location, risk, and other signals. Microsoft Entra ID provides identity and access capabilities that support this approach. Strong authentication, Conditional Access, least-privilege access, and identity monitoring can all help enforce Zero Trust principles. This model reduces dependence on traditional network boundaries and focuses security decisions on verified identities and contextual signals.<\/span><\/p>\n<h3><b>Question 163. Which Microsoft Entra authentication method allows users to authenticate against Microsoft Entra ID by validating passwords against on-premises Active Directory?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Pass-through Authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security Defaults<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Passwordless authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Self-service password reset<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Pass-through Authentication<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Pass-through Authentication allows users to sign in to cloud services while their passwords are validated against the organization&#8217;s on-premises Active Directory. Authentication requests are passed to an on-premises agent, which validates the credentials against Active Directory. This can allow organizations to maintain password validation on-premises while using Microsoft Entra ID for cloud identity and access. It differs from Password Hash Synchronization, where a representation of the password hash is synchronized to Microsoft Entra ID. Understanding the distinction is important when selecting an identity architecture based on organizational requirements and authentication needs.<\/span><\/p>\n<h3><b>Question 164. Which Microsoft Entra feature synchronizes a transformed representation of an on-premises user&#8217;s password hash to Microsoft Entra ID?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Federation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Pass-through Authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password Hash Synchronization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Access Reviews<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Password Hash Synchronization<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Password Hash Synchronization, commonly called PHS, synchronizes a hash of the on-premises Active Directory password to Microsoft Entra ID. Microsoft does not synchronize the user&#8217;s actual plain-text password. The synchronized representation enables Microsoft Entra ID to authenticate users for cloud services without contacting the on-premises domain controller for every sign-in. PHS is commonly used to provide a straightforward hybrid identity solution and can also support Microsoft Entra features such as Identity Protection. It is different from Pass-through Authentication, which validates the user&#8217;s password against on-premises Active Directory through authentication agents.<\/span><\/p>\n<h3><b>Question 165. Which identity architecture uses an external identity provider to authenticate users and issue authentication information to Microsoft Entra ID?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Federation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dynamic groups<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> RBAC<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Device compliance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Federation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Federation allows an organization to use an external identity provider or federation service to authenticate users while Microsoft Entra ID provides access to Microsoft cloud resources. In a federated arrangement, Microsoft Entra ID can redirect authentication to the organization&#8217;s federation service, which performs the authentication and returns the required authentication information. This approach can be useful when an organization has existing identity infrastructure or specific authentication requirements. Federation differs from Password Hash Synchronization and Pass-through Authentication because authentication is delegated to a federation service rather than being directly validated through Microsoft Entra&#8217;s synchronized password information.<\/span><\/p>\n<h3><b>Question 166. Which Microsoft Entra feature is designed to provide domain services such as domain join, LDAP, and Kerberos authentication without requiring domain controllers to be managed by the customer?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra Domain Services<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra External ID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra PIM<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra ID Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Entra Domain Services<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Domain Services provides managed domain capabilities in Azure, including domain join, LDAP, Kerberos, and NTLM authentication. It is useful for applications and workloads that depend on traditional domain services but do not require an organization to deploy and maintain its own domain controllers in Azure. Microsoft manages the underlying domain service infrastructure while administrators configure appropriate settings and access. Entra Domain Services is different from Microsoft Entra ID itself because Entra ID is primarily a cloud identity and access service, whereas Domain Services provides managed compatibility with traditional Active Directory-dependent applications.<\/span><\/p>\n<h3><b>Question 167. Which Microsoft Entra feature is most appropriate for allowing business users to request access to approved groups and applications through predefined packages?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra entitlement management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra ID Protection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Identity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Secure Score<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Entra entitlement management<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra entitlement management helps organizations manage identity governance by using access packages. An access package can bundle resources such as groups, applications, and SharePoint sites and define policies for how users can request access. Organizations can also establish approval requirements, expiration dates, and other governance controls. This makes entitlement management useful when users need controlled access to multiple resources without administrators manually processing every request. It also supports lifecycle-oriented access governance by helping organizations ensure that access is granted according to defined policies and can be removed when it is no longer required.<\/span><\/p>\n<h3><b>Question 168. What is the primary purpose of a dynamic group in Microsoft Entra ID?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatically add or remove members based on defined attributes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Encrypt every file in Microsoft 365<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace Microsoft Sentinel analytics rules<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Create Azure virtual networks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Automatically add or remove members based on defined attributes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dynamic groups in Microsoft Entra ID can automatically manage group membership based on rules that evaluate user or device attributes. For example, an organization could create a group containing users whose department attribute equals a particular department. When an object&#8217;s attributes change, group membership can be updated automatically according to the configured rule. This reduces manual administration and can support access assignment, application deployment, and policy targeting. Dynamic groups are different from manually managed security groups because administrators do not need to individually add or remove every member when qualifying attributes change.<\/span><\/p>\n<h3><b>Question 169. Which Microsoft Entra capability can assign applications or services to users through group-based licensing and access management?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra groups<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel workbooks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview eDiscovery<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure DDoS Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Entra groups<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra groups can simplify identity and access administration by allowing organizations to manage users collectively. Groups can be used in access assignments and, where supported, group-based licensing can automatically assign Microsoft 365 or other eligible licenses to group members. This approach reduces the need to configure each user individually and helps maintain consistent access as employees join, change roles, or leave the organization. Groups can also be combined with dynamic membership rules to automate membership based on attributes. Administrators should still review group membership and access assignments to ensure users receive only the permissions and licenses they require.<\/span><\/p>\n<h3><b>Question 170. Which Microsoft Entra feature helps organizations create reusable access packages for internal and external users?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Entitlement management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Defender Antivirus<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure Firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Entitlement management<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra entitlement management provides identity governance capabilities for managing access packages. An access package can contain multiple resources and can be assigned to users according to defined policies. Organizations can use this functionality for employees, guests, and other external collaborators when controlled access to resources is required. Policies can include request processes, approval requirements, assignment duration, and expiration. By centralizing these controls, entitlement management helps reduce unmanaged access and provides a structured method for granting resources based on organizational requirements. It is particularly useful when access needs to be requested and governed rather than permanently assigned.<\/span><\/p>\n<h3><b>Question 171. Which Microsoft Entra capability can automate identity-related tasks when employees join, move within, or leave an organization?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Lifecycle Workflows<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel workbooks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure Firewall<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview eDiscovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Lifecycle Workflows<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Lifecycle Workflows help automate identity lifecycle processes associated with employees joining an organization, changing roles, or leaving. Organizations can configure workflows to perform supported tasks at appropriate stages of a user&#8217;s lifecycle. Automating these activities can reduce repetitive administrative work and help ensure that identity-related processes are performed consistently. For example, onboarding tasks may include preparing accounts or assigning appropriate resources, while offboarding processes can help remove or restrict access. Lifecycle Workflows complement broader identity governance capabilities by connecting identity lifecycle events with repeatable administrative actions.<\/span><\/p>\n<h3><b>Question 172. Which authentication approach is specifically designed to resist phishing by using cryptographic credentials associated with a device or security key?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> FIDO2 passwordless authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Basic password authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security Defaults only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Email-based authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. FIDO2 passwordless authentication<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FIDO2 authentication uses public-key cryptography and can provide phishing-resistant authentication without requiring users to enter traditional passwords. A compatible security key or platform authenticator protects the private key, while the corresponding public key is registered with the service. During authentication, the authenticator performs a cryptographic operation rather than sending a reusable password to the service. This makes credential theft through common phishing techniques significantly more difficult. Microsoft Entra ID supports passwordless authentication methods, including FIDO2 security keys, allowing organizations to strengthen authentication while also reducing dependence on traditional passwords.<\/span><\/p>\n<h3><b>Question 173. Which Microsoft Entra capability allows administrators to define stronger authentication requirements for specific sensitive resources or scenarios?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Conditional Access authentication strengths<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dynamic groups<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Access Reviews<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password Hash Synchronization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Conditional Access authentication strengths<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Conditional Access authentication strengths allow organizations to require specific levels or combinations of authentication methods for selected access scenarios. For example, access to a highly sensitive application can be configured to require a stronger or phishing-resistant authentication method rather than accepting every available MFA method. This provides more precise control than simply requiring generic multifactor authentication. Authentication strengths can be incorporated into Conditional Access policies alongside conditions such as user, application, device, location, and risk. This helps organizations align authentication requirements with the sensitivity of the resource and the security context of the sign-in.<\/span><\/p>\n<h3><b>Question 174. Which Microsoft Intune capability ensures that only devices meeting defined security requirements can access protected organizational resources?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Device compliance policies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel workbooks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Purview eDiscovery<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure DDoS Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Device compliance policies<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Intune device compliance policies define requirements that devices must meet to be considered compliant. Conditions can include operating system requirements, encryption status, password configuration, threat protection, and other supported security settings. Compliance information can then be used with Microsoft Entra Conditional Access to restrict access when a device does not meet organizational requirements. This creates an important connection between device management and identity-based access control. Instead of automatically trusting a device simply because it belongs to the organization, administrators can require evidence that the device satisfies defined security conditions before allowing access to protected resources.<\/span><\/p>\n<h3><b>Question 175. What is the primary purpose of Microsoft Intune enrollment?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Register devices for management by the organization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Create Microsoft Sentinel incidents<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Discover sensitive information in documents<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace Azure Active Directory with a firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Register devices for management by the organization<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Intune enrollment brings a device under organizational management so administrators can apply configuration, compliance, application, and security policies. After enrollment, Intune can manage supported settings and provide information about the device&#8217;s management state. Enrollment is therefore an important starting point for endpoint management because the organization needs a management relationship before it can consistently apply many policies. Enrollment should be distinguished from compliance: enrollment makes the device manageable, while compliance policies determine whether the device satisfies defined security requirements. Conditional Access can then use compliance information as part of access decisions.<\/span><\/p>\n<h3><b>Question 176. Which Microsoft Defender for Endpoint capability helps reduce the attack surface by controlling or restricting behaviors commonly exploited by attackers?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Attack Surface Reduction rules<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview eDiscovery<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel workbooks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Service Trust Portal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Attack Surface Reduction rules<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attack Surface Reduction rules in Microsoft Defender for Endpoint help organizations reduce opportunities for attackers to exploit common behaviors and techniques. Depending on the rule, organizations can restrict activities associated with malicious documents, scripts, credential theft, or other attack techniques. These controls are designed as preventive security measures and can complement antivirus, endpoint detection, vulnerability management, and other Defender capabilities. Administrators should test and appropriately configure rules because overly restrictive policies can affect legitimate business applications. Attack Surface Reduction is therefore an important part of endpoint security that focuses on preventing or limiting risky behaviors before they lead to successful compromise.<\/span><\/p>\n<h3><b>Question 177. Which Microsoft Defender XDR capability allows security analysts to query security data across supported Microsoft security sources?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Advanced hunting<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Access Reviews<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sensitivity labels<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Group-based licensing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Advanced hunting<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Advanced hunting in Microsoft Defender XDR provides a query-based investigation capability that allows security analysts to examine security data across supported Microsoft security products. Analysts can use queries to investigate suspicious activity, search for indicators, identify patterns, and explore relationships between events. It can be particularly useful when an analyst needs to investigate beyond the information presented in a predefined incident view. Advanced hunting supports proactive threat hunting as well as investigation activities. Its purpose is different from automated detection rules because analysts can formulate queries to explore available telemetry and investigate specific security questions.<\/span><\/p>\n<h3><b>Question 178. Which Microsoft Sentinel capability uses behavioral analytics to help identify unusual activities associated with users and entities?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User and Entity Behavior Analytics (UEBA)<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Group-based licensing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sensitivity labeling<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Device enrollment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. User and Entity Behavior Analytics (UEBA)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User and Entity Behavior Analytics, or UEBA, helps Microsoft Sentinel identify unusual behavior by analyzing activities associated with users, hosts, IP addresses, applications, and other entities. Rather than relying only on fixed signatures, behavioral analytics can establish patterns and help identify activity that differs from expected behavior. This can provide useful context during security investigations, especially when an account appears to behave differently from its normal pattern. UEBA does not replace other detection methods; it complements analytics rules, threat intelligence, and incident investigation. Analysts can use behavioral insights to prioritize and investigate potentially suspicious activities.<\/span><\/p>\n<h3><b>Question 179. Which Microsoft Sentinel capability can provide context about known malicious indicators such as suspicious IP addresses or domains?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Threat intelligence<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Device enrollment<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Group-based licensing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sensitivity labels<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Threat intelligence<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat intelligence provides information about known or suspected malicious indicators and can help security teams add context to security events. Indicators may include IP addresses, domains, URLs, file hashes, or other observable artifacts associated with threats. Microsoft Sentinel can use threat intelligence as part of security monitoring and investigation so analysts can compare observed activity with known threat information. This context can help improve detection and investigation efficiency, although threat intelligence should be evaluated for quality, relevance, and freshness. It works alongside analytics rules, incidents, automation, and other security capabilities rather than replacing them.<\/span><\/p>\n<h3><b>Question 180. Which Microsoft Sentinel feature can automatically execute a sequence of actions in response to a security event?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Playbooks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Workbooks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data connectors<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Analytics rules<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Playbooks<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel playbooks are automated workflows that can execute actions in response to security events or other triggers. They are commonly built using Azure Logic Apps and can perform tasks such as sending notifications, creating or updating records, enriching information, or interacting with other services. Playbooks help security teams reduce repetitive manual work and standardize response procedures. They are different from analytics rules, which are primarily used to detect suspicious activity and generate alerts or incidents. Workbooks are mainly used for visualization and analysis, while data connectors help bring relevant data into Sentinel for monitoring and investigation.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-900 Exam Dumps and Practice Test Dumps &nbsp; Question 161. Which concept describes how security responsibilities are divided between a cloud provider and a customer? Shared responsibility model Single sign-on model Zero Trust model Defense-in-depth model Correct Answer: 1. Shared responsibility model Explanation: The shared responsibility model explains how security and operational [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15558"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15558"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15558\/revisions"}],"predecessor-version":[{"id":15582,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15558\/revisions\/15582"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15558"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15558"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15558"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}