Microsoft

SC-900 Free Practice Questions — Page 7

Question 62

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 62
Show Answer
Correct Answer: No Yes Yes
Explanation:
Information Barriers do not restrict Exchange Online email communication, but they do restrict collaboration/access in SharePoint/OneDrive and prevent file sharing/collaboration in Microsoft Teams via those services.

Question 63

You have an Azure subscription. You need to implement approval-based, time-bound role activation. What should you use?

A. access reviews in Azure AD
B. Azure AD Privileged Identity Management (PIM)
C. Azure AD Identity Protection
D. Conditional access in Azure AD
Show Answer
Correct Answer: B
Explanation:
Azure AD Privileged Identity Management (PIM) provides just-in-time, approval-based, and time-bound activation of privileged roles in Azure and Microsoft Entra ID. Access reviews are for periodic review of access, Identity Protection focuses on risk-based identity security, and Conditional Access enforces access policies rather than privileged role activation.

Question 64

Which portal contains the solution catalog?

A. Microsoft Purview compliance portal
B. Microsoft 365 Defender portal
C. Microsoft 365 admin center
D. Microsoft 365 Apps admin center
Show Answer
Correct Answer: A
Explanation:
The Microsoft 365 Solution Catalog is located in the Microsoft Purview compliance portal, where organizations can discover and manage Microsoft 365 compliance and risk solutions. The other portals serve different administrative or security functions and do not host the Microsoft 365 Solution Catalog.

Question 65

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 65
Show Answer
Correct Answer: Customize navigation
Explanation:
In the Microsoft Purview compliance portal, the Customize navigation option is used to hide or remove features from the left navigation pane for a customized experience.

Question 66

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 66
Show Answer
Correct Answer: Assessments
Explanation:
In Microsoft Compliance Manager, assessments are used to track compliance against grouped controls for a specific regulation, standard, or requirement.

Question 67

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 67
Show Answer
Correct Answer: No No Yes
Explanation:
Security defaults do not require Azure AD Premium licenses, apply tenant-wide rather than to a single user, and require administrators to use MFA.

Question 68

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 68
Show Answer
Correct Answer: Yes No No
Explanation:
Asymmetric encryption uses a public/private key pair. Symmetric encryption uses a shared secret key, not public/private keys. Hashes are one-way and cannot be decrypted to recover the original content.

Question 69

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 69
Show Answer
Correct Answer: integrity
Explanation:
Ensuring retrieved data matches the originally stored data is the security property of integrity, which protects against unauthorized or accidental modification.

Question 70

What should you use to associate the same identity to more than one Azure virtual machine?

A. an Azure AD user account
B. a user-assigned managed identity
C. a system-assigned managed identity
D. an Azure AD security group
Show Answer
Correct Answer: B
Explanation:
A user-assigned managed identity is a standalone Azure resource that can be assigned to multiple Azure resources, including more than one virtual machine. A system-assigned managed identity is tied to a single resource and cannot be shared. Azure AD user accounts and security groups are not managed identities for Azure resources.

Question 71

You have an Azure subscription that contains a Log Analytics workspace. You need to onboard Microsoft Sentinel. What should you do first?

A. Create a hunting query.
B. Correlate alerts into incidents.
C. Connect to your security sources.
D. Create a custom detection rule.
Show Answer
Correct Answer: C
Explanation:
After onboarding Microsoft Sentinel to a Log Analytics workspace, the next foundational step is to connect data sources (security sources) using data connectors so Sentinel can ingest telemetry. Hunting queries, analytics/detection rules, and incident correlation all depend on having data available first.

$19

Get all 230 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.