Microsoft

SC-900 Free Practice Questions — Page 3

Question 21

Which Microsoft Purview data classification type supports the use of regular expressions?

A. exact data match (EDM)
B. fingerprint classifier
C. sensitive information types (SITs)
D. trainable classifier
Show Answer
Correct Answer: C
Explanation:
Sensitive information types (SITs) support pattern-based detection using regular expressions, often combined with supporting elements such as keywords, checksums, or confidence levels. Exact Data Match uses hashed source data, fingerprint classifiers use document fingerprints, and trainable classifiers rely on machine learning rather than regex.

Question 22

What should you create to search and export content preserved in an eDiscovery hold?

A. a Microsoft SharePoint Online site
B. a case
C. a Microsoft Exchange Online public folder
D. Azure Files
Show Answer
Correct Answer: B
Explanation:
In Microsoft Purview eDiscovery, you create a case to manage holds, searches, and exports. Content preserved by an eDiscovery hold is searched and exported within the context of an eDiscovery case. The other options are storage or collaboration resources and are not used to manage eDiscovery holds.

Question 23

Which feature is included in Microsoft Entra ID Governance?

A. Identity Protection
B. Privileged Identity Management
C. Permissions Management
D. Verifiable credentials
Show Answer
Correct Answer: B
Explanation:
Microsoft Entra ID Governance includes Privileged Identity Management (PIM) as a governance capability for controlling, approving, and auditing privileged access. Identity Protection, Permissions Management, and Verifiable Credentials are separate Microsoft Entra offerings rather than features of Entra ID Governance.

Question 24

Which two actions can you perform by using Azure Key Vault? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

A. Store secrets.
B. Store Azure Resource Manager (ARM) templates.
C. Implement network security groups (NSGs).
D. Implement Azure DDoS Protection.
E. Store keys.
Show Answer
Correct Answer: A, E
Explanation:
Azure Key Vault is designed to securely store and manage secrets (such as passwords, connection strings, and tokens) and cryptographic keys. It does not store ARM templates, implement NSGs, or provide Azure DDoS Protection.

Question 25

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 25
Show Answer
Correct Answer: Azure Guidance
Explanation:
In the Microsoft Cloud Security Benchmark, implementation instructions such as how to create and configure Azure resources (for example, creating a virtual network) are provided under Azure Guidance. Security Principles are high-level concepts, recommendations are best practices, and mapping relates to external frameworks.

Question 26

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 26
Show Answer
Correct Answer: Yes No Yes
Explanation:
eDiscovery (Standard) supports exporting search results. Integration with Insider Risk Management case creation is an eDiscovery (Premium) feature, not Standard. eDiscovery (Standard) can search Exchange Online locations, including public folders.

Question 27

What Microsoft Purview feature can use machine learning algorithms to detect and automatically protect sensitive items?

A. eDiscovery
B. Data loss prevention
C. Information risks
D. Communication compliance
Show Answer
Correct Answer: B
Explanation:
Microsoft Purview Data Loss Prevention (DLP) uses sensitive information types, classifiers, and machine learning-based trainable classifiers to detect sensitive content and automatically apply protection actions according to DLP policies. eDiscovery is for investigation, Information risks refers to Insider Risk Management, and Communication compliance monitors communications rather than automatically protecting sensitive items.

Question 28

What feature supports email as a method of authenticating users?

A. Microsoft Entra ID Protection
B. Microsoft Entra Multi-Factor Authentication (MFA)
C. self-service password reset (SSPR)
D. Microsoft Entra Password Protection
Show Answer
Correct Answer: C
Explanation:
Self-service password reset (SSPR) supports email as an authentication method for eligible users during the password reset process. Microsoft Entra MFA does not use email as a supported second-factor authentication method. Entra ID Protection is for risk-based identity protection, and Password Protection prevents weak passwords rather than providing authentication methods.

Question 29

When a user authenticates by using passwordless sign-in, what should the user select in the Microsoft Authenticator app?

A. an answer to a security question
B. a number
C. an alphanumeric key
D. a passphrase
Show Answer
Correct Answer: B
Explanation:
Microsoft Authenticator passwordless sign-in uses number matching. The user is shown a number on the sign-in screen and must select or enter the matching number in the Microsoft Authenticator app to approve the sign-in.

Question 30

Which service includes Microsoft Secure Score for Devices?

A. Microsoft Defender for IoT
B. Microsoft Defender for Endpoint
C. Microsoft Defender for Identity
D. Microsoft Defender for Office 365
Show Answer
Correct Answer: B
Explanation:
Microsoft Secure Score for Devices is a feature of Microsoft Defender Vulnerability Management within Microsoft Defender for Endpoint. It assesses the security posture of managed devices and provides recommendations to improve device security. The other services have different security scoring or monitoring capabilities but do not include Secure Score for Devices.

$19

Get all 230 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.