Microsoft

SC-900 Free Practice Questions — Page 7

Question 62

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 62
Show Answer
Correct Answer: Yes No No
Explanation:
Asymmetric encryption uses a public/private key pair. Symmetric encryption uses a single shared secret key, not a key pair. Hashing is one-way; original content cannot be retrieved by decryption.

Question 63

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 63
Show Answer
Correct Answer: integrity.
Explanation:
This describes data integrity: ensuring data remains accurate and unchanged between storage and retrieval.

Question 64

What should you use to associate the same identity to more than one Azure virtual machine?

A. an Azure AD user account
B. a user-assigned managed identity
C. a system-assigned managed identity
D. an Azure AD security group
Show Answer
Correct Answer: B
Explanation:
To associate the same identity with more than one Azure virtual machine, you must use a user-assigned managed identity. User-assigned managed identities are standalone Azure AD identities that can be created independently and assigned to multiple Azure resources. In contrast, system-assigned managed identities are tied to a single resource and cannot be shared, and Azure AD users or security groups are not designed for managed identity authentication from Azure resources.

Question 65

You have an Azure subscription that contains a Log Analytics workspace. You need to onboard Microsoft Sentinel. What should you do first?

A. Create a hunting query.
B. Correlate alerts into incidents.
C. Connect to your security sources.
D. Create a custom detection rule.
Show Answer
Correct Answer: C
Explanation:
After enabling Microsoft Sentinel on a Log Analytics workspace, the first essential step is to connect your security data sources using data connectors. Sentinel cannot generate alerts, incidents, hunting queries, or detection rules until log data is ingested from security sources.

Question 66

Microsoft 365 Endpoint data loss prevention (Endpoint DLP) can be used on which operating systems?

A. Windows 10 and newer only
B. Windows 10 and newer and Android only
C. Windows 10 and newer and macOS only
D. Windows 10 and newer, Android, and macOS
Show Answer
Correct Answer: C
Explanation:
Microsoft 365 Endpoint Data Loss Prevention supports onboarded Windows 10 and Windows 11 devices, as well as onboarded macOS devices (supported versions). It does not support Android or iOS for Endpoint DLP, which are covered by other mobile management or app protection capabilities. Therefore, the correct option is Windows 10 and newer and macOS only.

Question 67

Which three forms of verification can be used with Azure AD Multi-Factor Authentication (MFA)? Each correct answer presents a complete solution. NOTE: Each correct answer is worth one point.

A. security questions
B. the Microsoft Authenticator app
C. SMS messages
D. a smart card
E. Windows Hello for Business
Show Answer
Correct Answer: B, C, E
Explanation:
Azure AD Multi-Factor Authentication supports multiple additional verification methods. Valid options include the Microsoft Authenticator app, SMS messages, and Windows Hello for Business. Security questions are used for self-service password reset (SSPR), not MFA, and smart cards are not an Azure AD MFA verification method.

Question 68

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 68
Show Answer
Correct Answer: No No Yes
Explanation:
Azure DDoS Protection focuses on volumetric, protocol, and resource-layer DDoS attacks—not MITM attacks. It is not enabled by default and must be explicitly configured. It does provide protection against protocol attacks.

Question 69

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 69
Show Answer
Correct Answer: access and application control
Explanation:
Access and application control in Microsoft Defender for Cloud blocks malware and unwanted applications using allowlists/blocklists and reduces the network attack surface through just-in-time and controlled access to Azure VM management ports.

Question 70

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 70
Show Answer
Correct Answer: Yes Yes No
Explanation:
SSPR supports multiple authentication methods, including email (which can be an external email address) and Microsoft Authenticator app notifications. SSPR is designed for users who cannot sign in, so prior authentication to Azure AD is not required.

Question 71

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 71
Show Answer
Correct Answer: No No Yes
Explanation:
Information Barriers restrict or prevent communication between users or groups; they do not detect inappropriate language. Communication Compliance monitors communications (emails, Teams, etc.), not files stored directly in SharePoint Online. Communication Compliance can scan both internal and external emails in Exchange Online for policy violations.

$19

Get all 224 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.