Microsoft

SC-900 Free Practice Questions — Page 11

Question 103

What is a function of Conditional Access session controls?

A. enforcing device compliance
B. enforcing client app compliance
C. enable limited experiences, such as blocking download of sensitive information
D. prompting multi-factor authentication (MFA)
Show Answer
Correct Answer: C
Explanation:
Conditional Access session controls are used after authentication to govern what users can do during an active session, such as restricting downloads or providing limited access within cloud apps. Device compliance, client app compliance, and MFA are Conditional Access policy conditions or grant controls rather than session controls.

Question 104

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 104
Show Answer
Correct Answer: Yes Yes No
Explanation:
Authorization determines what level of access a user has to a resource. Authentication verifies a user's identity. Permissions such as reading and writing files are part of authorization, not authentication.

Question 105

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 105
Show Answer
Correct Answer: authentication
Explanation:
Signing in involves verifying a user's credentials to prove identity, which is authentication. Authorization determines what an authenticated user can access.

Question 106

What can be created in Active Directory Domain Services (AD DS)?

A. line-of-business (LOB) applications that require modern authentication
B. computer accounts
C. software as a service (SaaS) applications that require modern authentication
D. mobile devices
Show Answer
Correct Answer: B
Explanation:
Active Directory Domain Services (AD DS) stores and manages directory objects such as users, groups, and computer accounts. Modern authentication application registrations (LOB or SaaS apps) and mobile device objects are associated with Microsoft Entra ID rather than AD DS.

Question 107

DRAG DROP - Match the types of compliance score actions to the appropriate tasks. To answer, drag the appropriate action type from the column on the left to its task on the right. Each type may be used once, more than once, or not at all. NOTE: Each correct match is worth one point.

Illustration for SC-900 question 107
Show Answer
Correct Answer: Use encryption to protect data at rest. → Preventative Actively monitor systems to identify irregularities that might represent risks. → Detective
Explanation:
Preventative actions reduce the likelihood of incidents (for example, encryption). Detective actions identify potential issues through monitoring.

Question 108

Which pillar of identity relates to tracking the resources accessed by a user?

A. authorization
B. auditing
C. administration
D. authentication
Show Answer
Correct Answer: B
Explanation:
Auditing is the identity pillar concerned with tracking and logging user activity, including which resources a user accesses. Authorization determines what a user is allowed to access, authentication verifies identity, and administration manages identity systems.

Question 109

DRAG DROP - Match the pillars of Zero Trust to the appropriate requirements. To answer, drag the appropriate pillar from the column on the left to its requirement on the right. Each pillar may be used once, more than once, or not at all. NOTE: Each correct match is worth one point.

Illustration for SC-900 question 109
Show Answer
Correct Answer: Networks → Must be segmented Identities → Must be verified by using strong authentication Data → Must be classified, labeled, and encrypted based on its attributes
Explanation:
In the Zero Trust model, networks are segmented to limit lateral movement, identities are continuously verified with strong authentication, and data is protected through classification, labeling, and encryption.

Question 110

Which compliance feature should you use to identify documents that are employee resumes?

A. pre-trained classifiers
B. Activity explorer
C. eDiscovery
D. Content explorer
Show Answer
Correct Answer: A
Explanation:
Pre-trained classifiers in Microsoft Purview are designed to automatically identify specific document categories, including employee resumes. Activity explorer monitors user activities, eDiscovery is for legal discovery, and Content explorer displays classified content but is not the feature used to identify resumes.

Question 111

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Hot Area:

Illustration for SC-900 question 111
Show Answer
Correct Answer: No Yes Yes
Explanation:
Microsoft Sentinel supports many third-party and Microsoft data connectors, Azure Monitor workbooks can visualize Sentinel data, and hunting enables proactive threat identification before alerts are triggered.

Question 112

What are three uses of Microsoft Cloud App Security? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

A. to discover and control the use of shadow IT
B. to provide secure connections to Azure virtual machines
C. to protect sensitive information hosted anywhere in the cloud
D. to provide pass-through authentication to on-premises applications
E. to prevent data leaks to noncompliant apps and limit access to regulated data
Show Answer
Correct Answer: A, C, E
Explanation:
Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security) is used to discover and manage shadow IT, protect sensitive information across cloud services through visibility and governance, and enforce policies that prevent data leakage and restrict access to regulated data. It does not provide secure VM connections (Azure Bastion does that) or pass-through authentication for on-premises applications (handled by Microsoft Entra ID features).

$19

Get all 230 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.