{"id":15569,"date":"2026-09-18T05:45:19","date_gmt":"2026-09-18T05:45:19","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15569"},"modified":"2026-09-18T05:45:19","modified_gmt":"2026-09-18T05:45:19","slug":"microsoft-sc-900-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-900-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"Microsoft SC-900 Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-900-exam-dumps\"><b>Microsoft SC-900 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 381. Which Microsoft Entra authentication method allows users to sign in without entering a traditional password by using a security key?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> FIDO2 security key<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password Hash Synchronization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Pass-through Authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Federation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. FIDO2 security key<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FIDO2 security keys provide a passwordless authentication method that uses a physical security key or compatible authenticator to verify a user&#8217;s identity. Instead of relying on a traditional password, the authentication process uses strong cryptographic credentials associated with the authenticator. This can provide resistance against common credential-phishing techniques because the authentication mechanism is designed around the legitimate sign-in context. Microsoft Entra ID supports FIDO2 security keys as part of its passwordless authentication capabilities. Organizations can use this method when they want stronger authentication while reducing reliance on passwords and improving the overall security of user sign-ins.<\/span><\/p>\n<h3><b>Question 382. Which Microsoft Entra capability synchronizes identities from an on-premises directory to Microsoft Entra ID using a lightweight cloud-based synchronization approach?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra Domain Services<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra Cloud Sync<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Identity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Intune<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Microsoft Entra Cloud Sync<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Cloud Sync is designed to synchronize identities between an on-premises Active Directory environment and Microsoft Entra ID using a lightweight, cloud-managed synchronization approach. It can help organizations connect existing directory identities with cloud-based identity services while reducing the amount of synchronization infrastructure that must be maintained locally. Microsoft Entra Cloud Sync is different from Microsoft Entra Domain Services, which provides managed domain services such as domain join and LDAP-related capabilities. Choosing an appropriate synchronization method depends on organizational requirements, directory complexity, supported scenarios, and the capabilities needed for the hybrid identity environment.<\/span><\/p>\n<h3><b>Question 383. Which Microsoft Entra authentication approach validates a user&#8217;s password directly against an on-premises Active Directory environment without synchronizing the password hash to Microsoft Entra ID?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password Hash Synchronization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Pass-through Authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FIDO2<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Windows Hello for Business<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Pass-through Authentication<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Pass-through Authentication allows users to authenticate against an on-premises Active Directory environment while using Microsoft Entra ID for the cloud sign-in experience. During authentication, the user&#8217;s password is validated by an on-premises authentication agent rather than relying on a synchronized password hash for authentication. This differs from Password Hash Synchronization, where a representation of the password hash is synchronized to Microsoft Entra ID. Pass-through Authentication can be useful for organizations that want cloud-based authentication experiences while maintaining password validation against their existing on-premises Active Directory infrastructure.<\/span><\/p>\n<h3><b>Question 384. What is the primary purpose of Password Hash Synchronization in Microsoft Entra ID?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Synchronize a representation of on-premises password hashes to Microsoft Entra ID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Encrypt all files stored in SharePoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace Microsoft Intune<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Create Azure firewall rules<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Synchronize a representation of on-premises password hashes to Microsoft Entra ID<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Password Hash Synchronization, commonly abbreviated PHS, helps organizations provide hybrid identity authentication by synchronizing a representation of users&#8217; on-premises password hashes to Microsoft Entra ID. Microsoft does not synchronize users&#8217; original plaintext passwords. Instead, the synchronization process uses transformed hash information that can support authentication in the cloud. PHS can also contribute to resilience because users can authenticate to cloud services even when the on-premises authentication infrastructure is unavailable, subject to the organization&#8217;s configuration. It is different from Pass-through Authentication, where password validation is performed against the on-premises directory during authentication.<\/span><\/p>\n<h3><b>Question 385. Which Microsoft Entra capability allows an organization to provide users with access to applications using a centralized identity and sign-in experience?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Single sign-on<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure DDoS Protection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview Audit<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure Resource Locks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Single sign-on<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Single sign-on, or SSO, allows users to authenticate once and then access multiple applications without repeatedly entering credentials for every application. Microsoft Entra ID can provide SSO for supported Microsoft and third-party applications, helping organizations centralize identity and access management. SSO can improve the user experience while also giving administrators a central place to apply authentication and access policies. It does not mean that every application becomes inherently secure; organizations should still use appropriate authentication controls, Conditional Access policies, and authorization settings. SSO is primarily an identity-access capability rather than a network or data-protection feature.<\/span><\/p>\n<h3><b>Question 386. Which Microsoft Entra feature enables organizations to collaborate with external users by allowing them to access resources using their existing identities?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra B2B collaboration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure Firewall<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview Data Map<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Entra B2B collaboration<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra B2B collaboration enables organizations to securely collaborate with users outside their organization. External users can be invited to access selected organizational resources while using an appropriate external identity. This approach allows organizations to provide controlled access to partners, contractors, vendors, and other collaborators without necessarily creating traditional internal accounts for every external person. Administrators can apply identity and access policies to help protect organizational resources. B2B collaboration should be distinguished from broader external identity capabilities because the specific configuration and scenario determine how external users authenticate and what resources they can access.<\/span><\/p>\n<h3><b>Question 387. Which Microsoft Entra feature can automatically place users into groups based on attributes such as department or job title?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dynamic groups<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure Key Vault<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Secure Score<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Dynamic groups<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dynamic groups in Microsoft Entra ID allow group membership to be automatically determined by user or device attributes. An organization can define membership rules based on properties such as department, job title, location, or other supported attributes. When an object&#8217;s relevant attributes change, group membership can be updated according to the configured rule. This can reduce the need for administrators to manually maintain membership lists and can support scenarios such as assigning applications, licenses, or access based on organizational characteristics. Dynamic groups are therefore useful for automating identity-related group management and keeping access structures aligned with changing directory information.<\/span><\/p>\n<h3><b>Question 388. Which Microsoft Entra capability helps organizations manage access packages that bundle resources for users who need access to specific business functions?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra entitlement management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender Antivirus<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure Firewall<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview Audit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Entra entitlement management<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra entitlement management helps organizations govern access to resources by using access packages and related access-management processes. An access package can bundle resources such as groups, applications, and SharePoint sites so that users can request access to a defined collection of resources. Administrators can establish policies that determine who can request access, who must approve requests, and how long access remains valid. This helps organizations manage access more systematically, particularly when employees, guests, or external collaborators require temporary or role-based access. Entitlement management supports controlled access throughout the lifecycle of an identity&#8217;s resource requirements.<\/span><\/p>\n<h3><b>Question 389. What is the main purpose of Microsoft Entra Privileged Identity Management (PIM)?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Provide permanent administrator access to all users<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Manage and control privileged access to resources<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Scan email attachments<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Classify sensitive documents<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Manage and control privileged access to resources<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management, or PIM, helps organizations manage privileged access to important resources and roles. Instead of giving users permanent administrative permissions, organizations can use eligible roles and activate privileged access when it is needed. Depending on configuration, activation can require controls such as multifactor authentication, approval, justification, or time limits. This approach supports the principle of least privilege by reducing unnecessary standing administrative access. PIM also provides visibility and management capabilities for privileged roles. It is an identity governance and privileged-access capability, rather than a tool for endpoint malware detection or document classification.<\/span><\/p>\n<h3><b>Question 390. Which Microsoft Entra feature can require periodic confirmation that users still need access to a resource?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Access Reviews<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel Workbooks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Safe Links<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure DDoS Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Access Reviews<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Access Reviews help organizations periodically review whether users, groups, applications, or other identities should continue to have access to resources. Regular access reviews can reduce the risk of permissions remaining active after a user&#8217;s responsibilities change or after temporary access is no longer required. Reviewers can evaluate access and take appropriate action according to organizational policies. Access Reviews are particularly useful for guest access and privileged or sensitive resources where access should not remain indefinitely without verification. This capability supports identity governance and the broader Zero Trust principle of continuously evaluating whether access is appropriate.<\/span><\/p>\n<h3><b>Question 391. Which Microsoft Entra capability can evaluate sign-in behavior and identify potentially risky sign-ins or users?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra ID Protection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure Resource Locks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview Data Map<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure Firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Entra ID Protection<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra ID Protection helps organizations identify and respond to identity-related risks. It can detect signals associated with potentially risky users and sign-ins and can provide risk information that organizations can use with identity and access policies. For example, a sign-in exhibiting characteristics associated with suspicious activity can be evaluated as a potential risk. Organizations can then use appropriate controls, such as Conditional Access policies, to require stronger authentication or take other protective actions. ID Protection is focused on identity risk rather than network filtering, data discovery, or resource configuration management.<\/span><\/p>\n<h3><b>Question 392. Which Microsoft Intune capability determines whether a managed device satisfies organizational requirements before it is allowed to access protected resources?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Compliance policies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Configuration profiles<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> App registrations<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Workbooks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Compliance policies<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Intune compliance policies define requirements that managed devices must meet to be considered compliant. Organizations can evaluate conditions such as operating-system versions, encryption status, password requirements, or other supported security settings. Compliance information can then be used together with Microsoft Entra Conditional Access to help control access to organizational resources. This allows an organization to consider the security state of a device when determining whether access should be permitted. Compliance policies should be distinguished from configuration profiles, which are primarily used to deploy and configure device settings rather than simply evaluate whether a device satisfies defined compliance requirements.<\/span><\/p>\n<h3><b>Question 393. What is the primary purpose of Microsoft Intune configuration profiles?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Configure settings on managed devices<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Detect malicious email links<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Search audit logs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Analyze cloud application usage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Configure settings on managed devices<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Intune configuration profiles allow administrators to deploy and manage settings on enrolled devices. Organizations can use profiles to configure security, system, connectivity, and other supported device settings according to their management requirements. This helps administrators establish consistent configurations across managed devices without manually configuring every endpoint. Configuration profiles differ from compliance policies because compliance policies primarily evaluate whether devices meet defined requirements, while configuration profiles are used to apply settings. Intune provides additional capabilities for application management, endpoint security, enrollment, and device compliance, making it an important component of a broader endpoint-management strategy.<\/span><\/p>\n<h3><b>Question 394. Which Intune capability helps protect organizational data inside mobile applications even when the device itself is not fully managed?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> App protection policies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure Firewall<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel analytics rules<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview Audit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. App protection policies<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Intune app protection policies help protect organizational data within supported applications. They can apply controls to how organizational information is accessed, copied, moved, or shared, depending on the configured policy and application capabilities. This can be useful in scenarios where an organization wants to protect corporate data without requiring every device to be fully enrolled into device management. App protection is therefore focused on the application and data layer rather than directly configuring the operating system. Organizations can combine app protection policies with identity and access controls to create additional safeguards around business information.<\/span><\/p>\n<h3><b>Question 395. Which Microsoft Defender for Endpoint capability helps organizations reduce exposure by identifying vulnerabilities and recommending security improvements?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Vulnerability Management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Safe Links<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Cloud Discovery<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Communication Compliance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Vulnerability Management<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender Vulnerability Management helps organizations identify weaknesses in their endpoints and prioritize actions that can reduce security exposure. It can provide information about vulnerabilities, affected devices, software, and recommended remediation activities. Security teams can use this information to understand which weaknesses require attention and to improve the security posture of their endpoint environment. Vulnerability Management is different from endpoint detection and response, which focuses more directly on detecting and investigating active or suspicious endpoint activity. By addressing vulnerabilities proactively, organizations can reduce opportunities that attackers might otherwise exploit during an attack.<\/span><\/p>\n<h3><b>Question 396. Which Microsoft Defender XDR capability combines related alerts from multiple security products into incidents for investigation?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Incident correlation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dynamic group membership<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data retention<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Device enrollment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Incident correlation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender XDR can correlate related security alerts from different Microsoft security products and organize them into incidents. This helps analysts understand that several individual alerts may represent different parts of the same attack rather than unrelated events. A unified incident view can provide additional context about affected users, devices, applications, messages, and other entities. Correlation can reduce alert fragmentation and help security teams investigate threats more efficiently. Instead of examining every signal separately, analysts can use the broader incident context to understand relationships between events and determine appropriate investigation or response actions.<\/span><\/p>\n<h3><b>Question 397. Which Microsoft Purview feature uses labels to classify sensitive information and can apply protection settings to supported content?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sensitivity labels<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Retention labels<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Audit logs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> eDiscovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Sensitivity labels<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview sensitivity labels help organizations classify and protect sensitive information. Labels can represent organizational classifications such as confidential or highly confidential, and depending on configuration, they can apply protection controls such as encryption, access restrictions, or content markings. Sensitivity labels can be applied to supported documents, emails, and other content. They differ from retention labels, which are primarily concerned with information lifecycle and retention requirements. Organizations can use sensitivity labels as part of a broader information-protection strategy to help ensure that sensitive content receives appropriate handling and protection throughout its lifecycle.<\/span><\/p>\n<h3><b>Question 398. Which Microsoft Purview capability is designed to prevent sensitive information from being shared or transferred in ways that violate organizational policies?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data Loss Prevention<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> eDiscovery<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Service Trust Portal<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Priva<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Data Loss Prevention<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Data Loss Prevention, commonly called DLP, helps organizations identify and protect sensitive information by detecting activities that may violate defined data-handling policies. DLP policies can identify sensitive information types and apply appropriate actions when users attempt activities such as sharing or transferring sensitive data. Depending on configuration, the system may provide alerts, warnings, or other controls. DLP is different from sensitivity labels because DLP focuses on detecting and controlling potentially inappropriate data-handling activities, while sensitivity labels primarily classify and protect content. Organizations can use both capabilities together to establish layered information-protection controls.<\/span><\/p>\n<h3><b>Question 399. Which Microsoft Purview capability helps organizations manage records according to business, legal, or regulatory requirements?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Records Management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Defender for Endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Azure Firewall<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Records Management<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Records Management helps organizations manage information as records according to business, legal, and regulatory requirements. It supports the application of retention and disposition rules to information that needs to be managed throughout its lifecycle. Records management can help organizations establish consistent processes for retaining important information and eventually disposing of it when permitted by applicable requirements. This is different from simply storing files indefinitely because organizations often need defined governance around how long information should remain available and when it can be securely disposed of. Records Management is therefore an important component of information governance.<\/span><\/p>\n<h3><b>Question 400. Which Zero Trust principle requires organizations to authenticate and authorize users and devices based on relevant signals before granting access?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume breach<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Verify explicitly<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use least privilege access<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Defense in depth<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Verify explicitly<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Zero Trust principle of Verify explicitly means that access decisions should be based on relevant identity, device, application, location, risk, and other available signals rather than automatically trusting a user or device. Authentication establishes identity, while authorization determines whether the identified entity should receive access to a particular resource. Technologies such as Microsoft Entra ID, multifactor authentication, Conditional Access, Intune compliance information, and identity-risk signals can contribute to these decisions. The principle helps organizations move away from implicit trust and toward continuously evaluated access. It works together with least privilege and Assume breach to form the core Zero Trust approach.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-900 Exam Dumps and Practice Test Dumps &nbsp; Question 381. Which Microsoft Entra authentication method allows users to sign in without entering a traditional password by using a security key? FIDO2 security key Password Hash Synchronization Pass-through Authentication Federation Correct Answer: 1. FIDO2 security key Explanation: FIDO2 security keys provide a passwordless [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15569"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15569"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15569\/revisions"}],"predecessor-version":[{"id":15571,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15569\/revisions\/15571"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15569"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15569"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15569"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}