This is the free Microsoft SC-900 practice question bank —
120 of 230 total questions, each with a full explanation, free to
read with no signup required. Updated 2026-08-06.
Every answer is verified against official Microsoft documentation —
see our methodology.
Question 1
HOTSPOT
-
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
No
Yes
Explanation: Azure DDoS Protection mitigates volumetric, protocol, and resource-layer DDoS attacks, not man-in-the-middle attacks. DDoS Network Protection is not enabled by default (only Basic protection is included). It does protect against protocol attacks.
Question 2
What is a feature of Microsoft Defender for Cloud Apps?
A. cloud workload protection platform (CWPP)
B. automated investigation and response (AIR)
C. SaaS security posture management (SSPM)
D. cloud security posture management (CSPM)
Show Answer
Correct Answer: C
Explanation: Microsoft Defender for Cloud Apps is a CASB solution that includes SaaS security posture management (SSPM) capabilities for assessing and improving the security configuration of SaaS applications. CWPP and CSPM are core capabilities of Microsoft Defender for Cloud, while AIR is primarily associated with other Microsoft Defender products such as Defender for Endpoint and Defender for Office 365.
Question 3
You company is evaluating various security products, including a security information and event management (SIEM) solution.
You need to provide information about the functionality of SIEM solutions.
What is a function of a SIEM solution?
A. the ability to review network activity and provide reports about which applications and services can communicate
B. an alerting system that triggers an alert when users reach their Azure spending limit
C. the ability to review logs and provide reports about malicious activity
D. automated incident remediation
Show Answer
Correct Answer: C
Explanation: A SIEM (Security Information and Event Management) collects, correlates, and analyzes security logs from multiple sources to detect suspicious or malicious activity and generate alerts and reports. Reviewing logs and reporting on malicious activity is a core SIEM capability. Network communication policy reporting is not its primary function, cost alerts are unrelated to SIEM, and automated incident remediation is primarily a SOAR capability, though some platforms integrate both.
Question 4
HOTSPOT
-
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: 1. No
2. No
3. Yes
Explanation: The Service Trust Portal is for compliance documentation, audit reports, and trust information. Federated trust is configured through Microsoft Entra ID, and vulnerability disclosures are handled through Microsoft security channels rather than the Service Trust Portal.
Question 5
What is the role of Microsoft Purview insider risk management in maintaining the compliance status of a company?
A. to detect and prevent communication policy breaches
B. to audit and assess the company's resources to ensure ongoing compliance with data regulations and standards
C. to detect potentially harmful user activities and assign risk scores to the activities
D. to find, preserve, and export content from various locations in response to legal, regulatory, and corporate requests for data
Show Answer
Correct Answer: C
Explanation: Microsoft Purview Insider Risk Management identifies potentially risky user activities using signals across Microsoft 365 and assigns risk scores to help investigators prioritize and respond to insider risks. The other options describe different Microsoft Purview capabilities: communication compliance (A), compliance/audit and assessment (B), and eDiscovery (D).
Question 6
HOTSPOT
-
Select the answer that correctly completes the sentence.
Show Answer
Correct Answer: Jupyter notebooks
Explanation: Microsoft Sentinel integrates Jupyter notebooks for advanced hunting, analytics, and Python-based machine learning. Data connectors ingest data, playbooks automate responses, and workbooks provide visualization.
Question 7
HOTSPOT
-
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
No
Yes
Explanation: Atypical travel and anonymous IP address are sign-in risk detections. Leaked credentials indicate a compromised user account and are classified as a user risk.
Question 8
You are comparing features between Microsoft Defender for Office 365 Plan 1 and Plan 2.
Which feature is only available in Defender for Office 365 Plan 2?
A. Attack simulation training
B. zero-day malware detection
C. anti-phishing protection
D. volume-based attack protection
Show Answer
Correct Answer: A
Explanation: Attack simulation training is a Microsoft Defender for Office 365 Plan 2 feature. Plan 1 includes core protections such as zero-day malware detection (Safe Attachments), anti-phishing protection, and protections against bulk/high-volume email attacks, while Plan 2 adds advanced investigation, threat hunting, and attack simulation capabilities.
Question 9
HOTSPOT
-
Select the answer that correctly completes the sentence.
Show Answer
Correct Answer: Azure portal.
Explanation: Microsoft Defender for Cloud plans are enabled and managed at the Azure subscription/resource level through Microsoft Defender for Cloud in the Azure portal.
Question 10
HOTSPOT
-
Select the answer that correctly completes the sentence.
Show Answer
Correct Answer: a priority score.
Explanation: Defender Threat Intelligence vulnerability articles include a priority score to help assess remediation urgency. Intel profiles, Intel projects, and Microsoft Secure Score are separate features and are not included as part of vulnerability articles.
$19
Get all 230 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.