Microsoft

SC-900 Free Practice Questions — Page 4

Question 32

Which Microsoft portal provides information about how Microsoft cloud services comply with regulatory standard, such as International Organization for Standardization (ISO)?

A. the Microsoft 365 admin center
B. Azure Cost Management + Billing
C. Microsoft Service Trust Portal
D. the Microsoft Purview compliance portal
Show Answer
Correct Answer: C
Explanation:
The Microsoft Service Trust Portal provides documentation and reports on how Microsoft cloud services comply with regulatory and industry standards such as ISO, SOC, and GDPR. The other portals focus on administration, billing, or managing an organization’s own compliance, not Microsoft’s compliance.

Question 33

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 33
Show Answer
Correct Answer: a cloud infrastructure entitlement management (CIEM) solution.
Explanation:
Microsoft Entra Permissions Management provides visibility and control over permissions and entitlements across cloud infrastructures, which defines a CIEM solution.

Question 34

Which solution performs security assessments and automatically generates alerts when a vulnerability is found?

A. cloud security posture management (CSPM)
B. DevSecOps
C. cloud workload protection platform (CWPP)
D. security information and event management (SIEM)
Show Answer
Correct Answer: A
Explanation:
Cloud Security Posture Management (CSPM) solutions continuously assess cloud resources for misconfigurations, compliance gaps, and security weaknesses, and they generate notifications/alerts or recommendations when vulnerabilities or risky settings are identified. SIEM focuses on log/event correlation, CWPP protects workloads at runtime, and DevSecOps is a practice rather than a security assessment solution.

Question 35

Which Microsoft Purview solution can be used to identify data leakage?

A. insider risk management
B. Compliance Manager
C. communication compliance
D. eDiscovery
Show Answer
Correct Answer: A
Explanation:
Microsoft Purview Insider Risk Management is specifically designed to detect, investigate, and mitigate insider-related risks such as data leakage, data exfiltration, and policy violations. The other options focus on compliance posture (Compliance Manager), monitoring inappropriate communications (Communication Compliance), or legal discovery (eDiscovery), not proactive identification of data leakage.

Question 36

DRAG DROP - Match the types of Conditional Access signals to the appropriate definitions. To answer, drag the appropriate Conditional Access signal type from the column on the left to its definition on the right. Each signal type may be used once, more than once, or not at all. NOTE: Each correct match is worth one point.

Illustration for SC-900 question 36
Show Answer
Correct Answer: User risk Sign-in risk
Explanation:
User risk measures the likelihood that an identity or account is compromised. Sign-in risk measures the likelihood that a specific authentication attempt is not authorized by the identity owner.

Question 37

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 37
Show Answer
Correct Answer: continuously
Explanation:
Microsoft Defender for Cloud continuously monitors and assesses Azure resources to identify security issues in near real time.

Question 38

When you enable Azure AD Multi-Factor Authentication (MFA), how many factors are required for authentication?

A. 1
B. 2
C. 3
D. 4
Show Answer
Correct Answer: B
Explanation:
Azure AD Multi-Factor Authentication requires more than one authentication factor. By definition, MFA uses two or more factors, and in typical Azure AD MFA scenarios this means two factors (something you know plus something you have or are).

Question 39

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 39
Show Answer
Correct Answer: Microsoft Service Trust Portal
Explanation:
The Microsoft Service Trust Portal is the public site where Microsoft publishes audit reports, compliance certifications, and security and privacy information for Microsoft cloud services.

Question 40

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 40
Show Answer
Correct Answer: Yes Yes No
Explanation:
Conditional Access is configured through policies in Microsoft Entra ID. Policies can evaluate device platform (Windows, iOS, Android, etc.) to allow or block access. Conditional Access can target users, security groups, or roles, but not Microsoft 365 groups.

Question 41

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 41
Show Answer
Correct Answer: A user-assigned managed identity
Explanation:
User-assigned managed identities can be shared across multiple Azure web apps, allowing them to use the same identity. System-assigned identities are unique to each app and cannot be shared.

$19

Get all 224 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.