Microsoft

SC-900 Free Practice Questions — Page 12

Question 113

HOTSPOT - Select the answer that correctly completes the sentence. Hot Area:

Illustration for SC-900 question 113
Show Answer
Correct Answer: The Microsoft 365 compliance center
Explanation:
The Microsoft 365 compliance center (now called the Microsoft Purview compliance portal) is the central location for managing information protection, information governance, and data loss prevention (DLP) policies.

Question 114

Which type of alert can you manage from the Microsoft 365 Defender portal?

A. Microsoft Defender for Storage
B. Microsoft Defender for SQL
C. Microsoft Defender for Endpoint
D. Microsoft Defender for IoT
Show Answer
Correct Answer: C
Explanation:
The Microsoft 365 Defender portal (now part of Microsoft Defender XDR) aggregates and manages alerts from Microsoft Defender for Endpoint along with other Microsoft 365 security products. Defender for Storage and Defender for SQL are managed through Microsoft Defender for Cloud, and Defender for IoT has its own management experience.

Question 115

What should you use to ensure that the members of an Azure Active Directory group use multi-factor authentication (MFA) when they sign in?

A. Azure role-based access control (Azure RBAC)
B. Azure Active Directory (Azure AD) Privileged Identity Management (PIM)
C. Azure Active Directory (Azure AD) Identity Protection
D. a conditional access policy
Show Answer
Correct Answer: D
Explanation:
Conditional Access policies are the recommended way to require Azure AD (Microsoft Entra ID) Multi-Factor Authentication for specific users or groups during sign-in. They can target Azure AD groups and enforce MFA based on sign-in conditions. Azure RBAC manages resource permissions, PIM provides just-in-time privileged access, and Identity Protection evaluates risk but does not by itself enforce MFA for a group without policy configuration.

Question 116

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Hot Area:

Illustration for SC-900 question 116
Show Answer
Correct Answer: Yes Yes Yes
Explanation:
Applying system updates and enabling MFA improve Microsoft Defender for Cloud secure score through security recommendations, and secure score can aggregate/evaluate resources across multiple Azure subscriptions.

Question 117

Which two Azure resources can a network security group (NSG) be associated with? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

A. a virtual network subnet
B. a network interface
C. a resource group
D. a virtual network
E. an Azure App Service web app
Show Answer
Correct Answer: A, B
Explanation:
An Azure Network Security Group (NSG) can be associated with either a virtual network subnet or an individual network interface (NIC). It cannot be directly associated with a virtual network, resource group, or Azure App Service web app.

Question 118

What can you use to provide threat detection for Azure SQL Managed Instance?

A. Microsoft Secure Score
B. application security groups
C. Microsoft Defender for Cloud
D. Azure Bastion
Show Answer
Correct Answer: C
Explanation:
Microsoft Defender for Cloud provides Microsoft Defender for SQL, which offers threat detection, vulnerability assessment, and alerts for suspicious activities on Azure SQL Managed Instance. The other options do not provide SQL threat detection: Secure Score measures security posture, application security groups organize network security rules, and Azure Bastion provides secure RDP/SSH access.

Question 119

What can you use to view the Microsoft Secure Score for Devices?

A. Microsoft Defender for Cloud Apps
B. Microsoft Defender for Endpoint
C. Microsoft Defender for Identity
D. Microsoft Defender for Office 365
Show Answer
Correct Answer: B
Explanation:
Microsoft Secure Score for Devices is viewed through Microsoft Defender for Endpoint (specifically the Defender Vulnerability Management dashboard in the Microsoft Defender portal). Defender for Cloud Apps, Defender for Identity, and Defender for Office 365 focus on different workloads and do not provide the Secure Score for Devices view.

Question 120

Which two cards are available in the Microsoft 365 Defender portal? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

A. Devices at risk
B. Compliance Score
C. Service Health
D. User Management
E. Users at risk
Show Answer
Correct Answer: A, E
Explanation:
The Microsoft 365 Defender portal home/dashboard includes security-focused cards such as Devices at risk and Users at risk. Compliance Score is part of Microsoft Purview compliance, Service Health is in the Microsoft 365 admin center, and User Management is an administrative function rather than a Defender portal card.

Question 121

HOTSPOT - Select the answer that correctly completes the sentence. Hot Area:

Illustration for SC-900 question 121
Show Answer
Correct Answer: incidents
Explanation:
In Microsoft 365 Defender, alerts are grouped into incidents. Opening an incident lets you view the related alerts and identify the affected devices.

Question 122

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Hot Area:

Illustration for SC-900 question 122
Show Answer
Correct Answer: No Yes No
Explanation:
Windows Hello for Business uses device-bound credentials with PIN or biometrics, not the Microsoft Authenticator app. A PIN is a valid Windows Hello for Business sign-in method. Credentials are device-specific and do not sync across a user's devices.

$19

Get all 230 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.