Microsoft

SC-900 Free Practice Questions — Page 10

Question 92

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 92
Show Answer
Correct Answer: Microsoft Defender for Cloud
Explanation:
Microsoft Defender for Cloud provides cloud workload protection (CWPP) and cloud security posture management for Azure and hybrid cloud resources.

Question 93

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 93
Show Answer
Correct Answer: Azure Key Vault
Explanation:
Azure Key Vault is the Azure cloud service designed to securely store and manage application secrets, keys, and certificates.

Question 94

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 94
Show Answer
Correct Answer: Yes Yes Yes
Explanation:
Defender for Cloud provides threat protection for Azure Storage, foundational CSPM is available for onboarded Azure subscriptions, and Defender for Cloud assesses the security posture of Azure and on-premises/hybrid workloads.

Question 96

Which security feature is available in the free mode of Microsoft Defender for Cloud?

A. threat protection alerts
B. just-in-time (JIT) VM access to Azure virtual machines
C. vulnerability scanning of virtual machines
D. secure score
Show Answer
Correct Answer: D
Explanation:
The free (foundational/CSPM) capabilities of Microsoft Defender for Cloud include Secure Score, which provides a measurement of an organization's security posture and recommendations. Threat protection alerts, just-in-time VM access, and integrated vulnerability assessment are Defender plan (paid) capabilities.

Question 97

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 97
Show Answer
Correct Answer: Yes Yes Yes
Explanation:
In the Microsoft Entra ID/Azure AD context, passwordless authentication methods include Microsoft Authenticator (a software-based authenticator for passwordless phone sign-in), Windows Hello for Business, and FIDO2 security keys.

Question 98

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 98
Show Answer
Correct Answer: Yes No Yes
Explanation:
Azure AD B2C supports social and enterprise identity providers for external users. B2C users are stored in a separate Azure AD B2C tenant, not the organization's Azure AD directory. Azure AD B2C supports custom branding of authentication pages.

Question 99

Which three authentication methods can Azure AD users use to reset their password? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

A. mobile app notification
B. text message to a phone
C. security questions
D. certificate
E. picture password
Show Answer
Correct Answer: A, B, C
Explanation:
Azure AD (Microsoft Entra ID) Self-Service Password Reset supports authentication methods including mobile app notification, text message to a phone, and security questions (where enabled). Certificate authentication and picture passwords are not supported SSPR verification methods.

Question 100

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 100
Show Answer
Correct Answer: Yes No Yes
Explanation:
Hybrid identity supports syncing on-premises Active Directory identities to Azure AD (Microsoft Entra ID). Accounts created in Azure AD do not automatically sync back to on-premises Active Directory. In hybrid environments, authentication can be handled by Azure AD or a federated identity provider.

Question 101

What can you use to ensure that all the users in a specific group must use multi-factor authentication (MFA) to sign to Azure Active Directory (Azure AD)?

A. Azure Policy
B. a communication compliance policy
C. a Conditional Access policy
D. a user risk policy
Show Answer
Correct Answer: C
Explanation:
Conditional Access policies can target specific users or groups and require multi-factor authentication as a sign-in control. Azure Policy governs Azure resource compliance, communication compliance policies relate to Microsoft Purview, and user risk policies respond to identity risk rather than generally enforcing MFA for a group.

Question 102

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 102
Show Answer
Correct Answer: No Yes Yes
Explanation:
Identity Protection detects leaked credentials and can trigger MFA through risk-based Conditional Access policies. It does not add users to groups based on risk level.

$19

Get all 230 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.