Microsoft

SC-900 Free Practice Questions

This is the free Microsoft SC-900 practice question bank — 120 of 224 total questions, each with a full explanation, free to read with no signup required. Updated 2026-04-24.

Every answer is verified against official Microsoft documentation — see our methodology.

Question 1

You are comparing features between Microsoft Defender for Office 365 Plan 1 and Plan 2. Which feature is only available in Defender for Office 365 Plan 2?

A. Attack simulation training
B. zero-day malware detection
C. anti-phishing protection
D. volume-based attack protection
Show Answer
Correct Answer: A
Explanation:
Attack simulation training (phishing simulations and user training) is a Defender for Office 365 Plan 2–only capability. Plan 1 includes core protections like anti-phishing, zero-day malware detection, and volume-based attack protection, but not simulation/training features.

Question 2

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 2
Show Answer
Correct Answer: Azure portal.
Explanation:
Microsoft Defender for Cloud is an Azure-native service, and its plans are enabled and managed at the subscription or resource level within the Azure portal.

Question 4

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 4
Show Answer
Correct Answer: Intel profiles.
Explanation:
Defender TI vulnerability articles link to related intelligence context, including Intel profiles, rather than scores or projects.

Question 5

Which Microsoft Purview feature allows users to identify content that should be protected?

A. Sensitivity Labels
B. Data loss prevention
C. eDiscovery
D. Insider Risks
Show Answer
Correct Answer: A
Explanation:
Sensitivity Labels in Microsoft Purview are specifically designed to help users identify, classify, and label content that should be protected, enabling appropriate protection controls such as encryption and access restrictions. The other options focus on preventing data exfiltration, investigations, or risk monitoring rather than identification of sensitive content.

Question 6

Which type of identity can be used with an Azure service and will be deleted automatically when the service is deleted?

A. user-assigned managed identity
B. service principal
C. user
D. system-assigned managed identity
Show Answer
Correct Answer: D
Explanation:
A system-assigned managed identity is tied directly to an Azure resource. It is created automatically when enabled on the service and is deleted automatically when that service is deleted. User-assigned managed identities, service principals, and users persist independently of the service.

Question 7

In the shared responsibility model, for what is Microsoft responsible when managing Azure virtual machines?

A. Updating the firmware of the disk controller.
B. Updating installed applications.
C. Configuring the permissions for shared folders.
D. Updating the operating system.
Show Answer
Correct Answer: A
Explanation:
In Azure IaaS virtual machines, Microsoft is responsible for the underlying physical infrastructure, including datacenters, hardware, networking, and firmware. Tasks such as updating the firmware of disk controllers fall under Microsoft's responsibility, while the customer manages the guest OS, applications, and access configurations.

Question 8

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 8
Show Answer
Correct Answer: No Yes Yes
Explanation:
Microsoft Defender for Cloud is an Azure service and is not included with Microsoft 365 E5. Defender for Cloud includes CSPM capabilities to assess and improve cloud security posture. With enhanced security features enabled, Defender for Cloud can perform vulnerability assessments on virtual machines.

Question 9

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 9
Show Answer
Correct Answer: Permission classifications
Explanation:
The Entra Permissions Management portal provides access to permission classification features used to categorize and assess permissions. Other options are accessed through different Entra or security portals.

Question 10

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 10
Show Answer
Correct Answer: create cases.
Explanation:
eDiscovery (Standard) extends Content search by adding case management, allowing you to create cases to organize searches, holds, and exports. Other options belong to Premium features or different workflows.

Question 11

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 11
Show Answer
Correct Answer: analytics
Explanation:
Microsoft Sentinel uses analytics rules to generate alerts and automatically correlate related alerts into incidents.

$19

Get all 224 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.