Microsoft

SC-900 Free Practice Questions — Page 6

Question 52

What should you use in the Microsoft 365 Defender portal to view security trends and track the protection status of identities?

A. Reports
B. Incidents
C. Hunting
D. Secure score
Show Answer
Correct Answer: A
Explanation:
The Microsoft 365 Defender portal's Reports section is used to view security trends, analytics, and track the protection status of identities and other assets over time. Incidents focuses on active security cases, Hunting is for proactive threat investigation, and Secure score measures security posture rather than providing trend reports.

Question 53

DRAG DROP - You need to identify which cloud service models place the most responsibility on the customer in a shared responsibility model. In which order should you list the service models from the most customer responsibility to the least? To answer, move all models from the list of models to the answer area and arrange them in the correct order.

Illustration for SC-900 question 53
Show Answer
Correct Answer: on-premises datacenter Infrastructure as a Service (IaaS) Platform as a Service (PaaS) Software as a Service (SaaS)
Explanation:
Customer responsibility decreases as you move from on-premises to SaaS. On-premises places nearly all responsibility on the customer, followed by IaaS, then PaaS, while SaaS places the least responsibility on the customer.

Question 54

Which score measures an organization’s progress in completing actions that help reduce risks associated to data protection and regulatory standards?

A. Adoption Score
B. Microsoft Secure Score
C. Secure score in Microsoft Defender for Cloud
D. Compliance score
Show Answer
Correct Answer: D
Explanation:
Compliance score measures an organization's progress in completing recommended improvement actions that reduce risks related to data protection and regulatory compliance. Microsoft Secure Score focuses on security posture, Defender for Cloud Secure Score measures cloud security posture, and Adoption Score measures Microsoft 365 usage and adoption.

Question 55

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 55
Show Answer
Correct Answer: is tied to the lifecycle of the resource that uses it.
Explanation:
A system-assigned managed identity creates a service principal automatically in Microsoft Entra ID that is bound to the Azure resource. It is created and deleted with that resource and cannot be shared across multiple resources.

Question 56

You plan to move resources to the cloud. You are evaluating the use of Infrastructure as a service (IaaS), Platform as a service (PaaS), and Software as a service (SaaS) cloud models. You plan to manage only the data, user accounts, and user devices for a cloud-based app. Which cloud model will you use?

A. SaaS
B. PaaS
C. IaaS
Show Answer
Correct Answer: A
Explanation:
In the SaaS shared responsibility model, the cloud provider manages the application and underlying infrastructure, while the customer is responsible primarily for their data, user accounts/identities, and endpoint devices. Managing only those three areas matches SaaS.

Question 57

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 57
Show Answer
Correct Answer: federation
Explanation:
SSO configured between multiple identity providers is federation, where trust relationships allow authentication across different identity systems. Integration is broader, while password hash synchronization and pass-through authentication are Azure AD sign-in methods, not multi-provider SSO models.

Question 58

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 58
Show Answer
Correct Answer: Yes No No
Explanation:
Device identities are stored in Azure AD (Microsoft Entra ID). A system-assigned managed identity is tied to a single resource and cannot be shared. User-assigned managed identities are independent resources and are not deleted when an attached resource is deleted.

Question 59

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 59
Show Answer
Correct Answer: No No Yes
Explanation:
Logic Apps automate workflows (playbooks), not anomaly detection. Analytics rules correlate alerts into incidents, not workbooks. Microsoft Sentinel hunting queries are aligned with the MITRE ATT&CK framework.

Question 60

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 60
Show Answer
Correct Answer: a security principal
Explanation:
Microsoft Entra ID (Azure AD) roles are assigned to security principals (users, groups, service principals, or managed identities). Management groups and resource groups are Azure resource scopes for Azure RBAC, not assignable identities, and administrative units are containers.

Question 61

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 61
Show Answer
Correct Answer: Yes Yes Yes
Explanation:
Microsoft Entra documentation lists GitHub as an example of a cloud-based identity provider. Federation enables SSO across multiple service providers through trusted identity relationships. A central identity provider provides modern identity services including authentication, authorization, and auditing/monitoring capabilities.

$19

Get all 230 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.