Focus keyphrase: SC-900 practice questions
Use these SC-900 practice questions to review Microsoft Security, Compliance, and Identity Fundamentals. This set focuses on Microsoft Entra identity features, Zero Trust basics, Microsoft Defender security capabilities, and Microsoft Purview compliance tools.
These questions are original practice items based on public Microsoft exam objectives and official documentation. They are not copied from real exams or exam dumps.
Related practice: Try AZ-305 Questions 41-50 or AI-102 Questions 31-40 after this SC-900 review.
Question 1: Describe the concepts of security, compliance, and identity
Scenario: A company is adopting Zero Trust. Administrators want every access request to be evaluated using signals such as user identity, device health, location, and application context before access is granted. Which Zero Trust principle does this best represent?
Choose one answer.
- Assume breach
- Verify explicitly
- Use perimeter-based trust
- Enable shared administrator accounts
Correct answer: B — Verify explicitly
Explanation: Verify explicitly means authentication and authorization decisions should use all available signals instead of trusting a request simply because it comes from a known network or device. In SC-900 terms, this is the Zero Trust principle most directly tied to continuously evaluating identity, device, location, and risk context.
Why the other options are wrong
- A. Assume breach is also a Zero Trust principle, but it focuses on designing as though compromise may already exist, such as segmenting access and monitoring continuously.
- C. Perimeter-based trust is the older model that Zero Trust moves away from.
- D. Shared administrator accounts reduce accountability and conflict with modern identity security practices.
Exam objective/domain: Describe the concepts of security, compliance, and identity
Official reference: https://learn.microsoft.com/en-us/security/zero-trust/zero-trust-overview
Question 2: Describe the capabilities of Microsoft Entra
Scenario: A security team wants users to complete multifactor authentication only when sign-in conditions are risky, such as an unfamiliar location or a high-risk sign-in. Which Microsoft Entra capability should they configure?
Choose one answer.
- Conditional Access
- Sensitivity labels
- Azure Policy
- Microsoft Purview eDiscovery
Correct answer: A — Conditional Access
Explanation: Microsoft Entra Conditional Access applies access controls, such as requiring multifactor authentication, based on conditions including user, group, location, device, application, and risk signals. It is the exam-relevant feature for adaptive access decisions.
Why the other options are wrong
- B. Sensitivity labels classify and protect content; they do not evaluate sign-in risk.
- C. Azure Policy governs Azure resource configuration, not user sign-in controls.
- D. eDiscovery supports legal and investigation workflows, not real-time access control.
Exam objective/domain: Describe the capabilities of Microsoft Entra
Official reference: https://learn.microsoft.com/en-us/entra/identity/conditional-access/overview
Question 3: Describe the capabilities of Microsoft Entra
Scenario: An organization wants a phishing-resistant sign-in method that can use a hardware security key or platform authenticator instead of a password. Which authentication option best matches this requirement?
Choose one answer.
- SMS-based authentication
- FIDO2 security keys / passkeys
- Security questions
- A temporary access pass as the long-term sign-in method
Correct answer: B — FIDO2 security keys / passkeys
Explanation: FIDO2 security keys and passkeys are passwordless methods that use public key cryptography and are designed to resist phishing. They are a core Microsoft Entra passwordless authentication option.
Why the other options are wrong
- A. SMS can be used for MFA but is not considered phishing-resistant in the same way as FIDO2/passkeys.
- C. Security questions are not a strong phishing-resistant authentication method.
- D. Temporary Access Pass is useful for onboarding or recovery scenarios, but it is not intended as the permanent everyday sign-in method.
Exam objective/domain: Describe the capabilities of Microsoft Entra
Official reference: https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-passwordless
Question 4: Describe the capabilities of Microsoft Entra
Scenario: A help desk team needs to reset passwords for standard users, but it should not receive broad permissions to manage all identity settings. Which Microsoft Entra built-in role is the best fit?
Choose one answer.
- Global Administrator
- Helpdesk Administrator
- Security Reader
- Compliance Administrator
Correct answer: B — Helpdesk Administrator
Explanation: The Helpdesk Administrator role is designed for common support tasks such as resetting passwords for non-administrative users. It follows least privilege better than assigning a broader administrator role.
Why the other options are wrong
- A. Global Administrator is far too broad for password reset support.
- C. Security Reader can view security-related information but does not provide password reset capability.
- D. Compliance Administrator is for compliance-related management, not help desk password resets.
Exam objective/domain: Describe the capabilities of Microsoft Entra
Official reference: https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference
Question 5: Describe the capabilities of Microsoft security solutions
Scenario: A cloud administrator wants recommendations to improve the security posture of Azure workloads and visibility into workload protection across cloud resources. Which Microsoft service should they use?
Choose one answer.
- Microsoft Defender for Cloud
- Microsoft Purview Data Lifecycle Management
- Microsoft Entra ID Protection
- Microsoft Priva
Correct answer: A — Microsoft Defender for Cloud
Explanation: Microsoft Defender for Cloud provides cloud security posture management and workload protection capabilities. It surfaces recommendations, secure score-style posture insights, and protections for Azure and supported multicloud workloads.
Why the other options are wrong
- B. Data Lifecycle Management helps retain and delete data according to policy, not protect cloud workloads.
- C. Entra ID Protection focuses on identity risks, not broad cloud workload posture.
- D. Microsoft Priva focuses on privacy risk management and subject rights requests.
Exam objective/domain: Describe the capabilities of Microsoft security solutions
Official reference: https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-cloud-introduction
Question 6: Describe the capabilities of Microsoft security solutions
Scenario: A security operations team wants incidents that correlate signals from endpoints, email, identities, and cloud apps so analysts can investigate attacks across the Microsoft security ecosystem. Which solution provides this unified XDR experience?
Choose one answer.
- Microsoft Defender XDR
- Microsoft Purview Audit
- Azure Cost Management
- Microsoft Entra Verified ID
Correct answer: A — Microsoft Defender XDR
Explanation: Microsoft Defender XDR correlates alerts and incidents across Microsoft Defender products, including endpoint, identity, email/collaboration, and cloud app signals. That unified detection and response capability is exactly what the scenario describes.
Why the other options are wrong
- B. Purview Audit records user and admin activities for audit and investigation, but it is not the unified XDR product.
- C. Azure Cost Management is for spend analysis and optimization.
- D. Verified ID supports decentralized identity credentials, not security incident correlation.
Exam objective/domain: Describe the capabilities of Microsoft security solutions
Official reference: https://learn.microsoft.com/en-us/defender-xdr/microsoft-365-defender
Question 7: Describe the capabilities of Microsoft compliance solutions
Scenario: A legal department wants labels that users can apply to documents and emails to mark confidentiality, and those labels may also enforce encryption or content markings. Which Microsoft Purview feature should be used?
Choose one answer.
- Sensitivity labels
- Conditional Access policies
- Privileged Identity Management
- Attack simulation training
Correct answer: A — Sensitivity labels
Explanation: Microsoft Purview sensitivity labels classify and protect data in documents, emails, containers, and other supported locations. Labels can apply visual markings and protection settings such as encryption.
Why the other options are wrong
- B. Conditional Access controls access to apps and resources; it does not label content.
- C. Privileged Identity Management manages privileged role activation, not document classification.
- D. Attack simulation training helps train users against phishing, not classify data.
Exam objective/domain: Describe the capabilities of Microsoft compliance solutions
Official reference: https://learn.microsoft.com/en-us/purview/sensitivity-labels
Question 8: Describe the capabilities of Microsoft compliance solutions
Scenario: A compliance team needs to detect potentially risky user activities, such as unusual data movement or policy violations, while using workflows designed to protect user privacy during investigations. Which Microsoft Purview solution fits?
Choose one answer.
- Insider Risk Management
- Microsoft Defender for Cloud Apps only
- Microsoft Entra Connect Sync
- Microsoft Teams Rooms Pro Management
Correct answer: A — Insider Risk Management
Explanation: Microsoft Purview Insider Risk Management helps organizations detect, investigate, and act on risky user activity while using controls and workflows intended to support privacy and compliance requirements.
Why the other options are wrong
- B. Defender for Cloud Apps can provide cloud app discovery and app protection signals, but the privacy-centered insider risk workflow is Purview Insider Risk Management.
- C. Entra Connect Sync synchronizes identities between on-premises Active Directory and Microsoft Entra ID.
- D. Teams Rooms Pro Management manages meeting room devices, not insider risk investigations.
Exam objective/domain: Describe the capabilities of Microsoft compliance solutions
Official reference: https://learn.microsoft.com/en-us/purview/insider-risk-management
Question 9: Describe the capabilities of Microsoft compliance solutions
Scenario: An auditor asks for a dashboard that maps regulatory controls to Microsoft 365 settings and provides improvement actions to help track compliance work. Which tool should the team use?
Choose one answer.
- Microsoft Purview Compliance Manager
- Microsoft Secure Score only
- Azure Advisor
- Microsoft Entra Permissions Management
Correct answer: A — Microsoft Purview Compliance Manager
Explanation: Microsoft Purview Compliance Manager provides assessments, control mapping, and improvement actions for compliance frameworks and regulations. It is the SC-900-aligned answer for tracking compliance posture and remediation tasks.
Why the other options are wrong
- B. Microsoft Secure Score focuses on security posture recommendations, not regulatory compliance assessments.
- C. Azure Advisor provides optimization recommendations for Azure resources, not Microsoft 365 compliance assessments.
- D. Permissions Management focuses on cloud infrastructure entitlement management.
Exam objective/domain: Describe the capabilities of Microsoft compliance solutions
Official reference: https://learn.microsoft.com/en-us/purview/compliance-manager
Question 10: Describe the capabilities of Microsoft security solutions
Scenario: A Microsoft 365 administrator wants a prioritized list of recommended security actions and a score that reflects the tenant’s security posture. Which feature should they review?
Choose one answer.
- Microsoft Secure Score
- Microsoft Purview Communication Compliance
- Azure Service Health
- Microsoft Entra External ID
Correct answer: A — Microsoft Secure Score
Explanation: Microsoft Secure Score measures security posture and recommends actions that can improve protection across Microsoft 365 and related services. It is commonly tested as a security posture improvement feature.
Why the other options are wrong
- B. Communication Compliance helps detect and remediate inappropriate or risky communications, not provide an overall security posture score.
- C. Azure Service Health reports Azure service incidents and advisories.
- D. External ID supports external user and customer identity scenarios, not security posture scoring.
Exam objective/domain: Describe the capabilities of Microsoft security solutions
Official reference: https://learn.microsoft.com/en-us/defender-xdr/microsoft-secure-score
Answer key summary
| Question | Correct answer | Topic |
|---|---|---|
| 1 | B. Verify explicitly | Describe the concepts of security, compliance, and identity |
| 2 | A. Conditional Access | Describe the capabilities of Microsoft Entra |
| 3 | B. FIDO2 security keys / passkeys | Describe the capabilities of Microsoft Entra |
| 4 | B. Helpdesk Administrator | Describe the capabilities of Microsoft Entra |
| 5 | A. Microsoft Defender for Cloud | Describe the capabilities of Microsoft security solutions |
| 6 | A. Microsoft Defender XDR | Describe the capabilities of Microsoft security solutions |
| 7 | A. Sensitivity labels | Describe the capabilities of Microsoft compliance solutions |
| 8 | A. Insider Risk Management | Describe the capabilities of Microsoft compliance solutions |
| 9 | A. Microsoft Purview Compliance Manager | Describe the capabilities of Microsoft compliance solutions |
| 10 | A. Microsoft Secure Score | Describe the capabilities of Microsoft security solutions |
Quick study notes for SC-900 practice questions
- Zero Trust is usually summarized as verify explicitly, use least-privileged access, and assume breach.
- Microsoft Entra questions often test identity, access management, roles, Conditional Access, MFA, and passwordless authentication.
- Microsoft Defender questions often ask which security tool protects cloud workloads, endpoints, identities, email, or apps.
- Microsoft Purview questions usually map to compliance, data governance, information protection, risk management, audit, and eDiscovery.
Sources
- Microsoft SC-900 study guide
- Microsoft Zero Trust overview
- Microsoft Entra Conditional Access overview
- Passwordless authentication options in Microsoft Entra ID
- Microsoft Entra built-in roles permissions reference
- Microsoft Defender for Cloud introduction
- Microsoft Defender XDR overview
- Microsoft Purview sensitivity labels
- Microsoft Purview Insider Risk Management
- Microsoft Purview Compliance Manager
- Microsoft Secure Score


