Microsoft

SC-900 Free Practice Questions — Page 9

Question 82

DRAG DROP - Match the Microsoft Purview Insider Risk Management workflow step to the appropriate task. To answer, drag the appropriate step from the column on the left to its task on the right. Each step may be used once, more than once, or not at all. NOTE: Each correct match is worth one point.

Illustration for SC-900 question 82
Show Answer
Correct Answer: Triage → Review and filter alerts. Investigate → Create cases in the Case dashboard. Action → Send a reminder of corporate policies to users.
Explanation:
In Insider Risk Management, alerts are triaged first, escalated to investigation cases if needed, and actions such as policy reminders are taken during the action phase.

Question 83

What is a characteristic of a sensitivity label in Microsoft 365?

A. encrypted
B. restricted to predefined categories
C. persistent
Show Answer
Correct Answer: C
Explanation:
Sensitivity labels are persistent: once applied, the label stays with the content across storage locations and sharing. Labels can apply protection such as encryption, but they are not inherently always encrypted, and they are not restricted to predefined categories.

Question 84

You need to ensure repeatability when creating new resources in an Azure subscription. What should you use?

A. Microsoft Sentinel
B. Azure Policy
C. Azure Batch
D. Azure Blueprints
Show Answer
Correct Answer: D
Explanation:
Azure Blueprints enables repeatable deployment and governance of Azure environments by packaging ARM templates, policies, role assignments, and resource groups into reusable definitions. Azure Policy enforces compliance but does not provide complete repeatable environment deployment. Microsoft Sentinel is a SIEM/SOAR solution, and Azure Batch is for large-scale parallel computing.

Question 85

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 85
Show Answer
Correct Answer: Microsoft 365 compliance center.
Explanation:
Insider Risk Management is configured in the Microsoft 365 Compliance Center (now the Microsoft Purview compliance portal), not the Microsoft 365 admin center, Defender portal, or Defender for Cloud Apps portal.

Question 86

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-900 question 86
Show Answer
Correct Answer: No Yes Yes
Explanation:
Microsoft Purview Information Barriers support Microsoft Teams, SharePoint, and OneDrive. Exchange Online is not supported for Information Barriers policies in the context tested by this question.

Question 87

Which Microsoft Defender for Cloud metric displays the overall security health of an Azure subscription?

A. secure score
B. resource health
C. completed controls
D. the status of recommendations
Show Answer
Correct Answer: A
Explanation:
Microsoft Defender for Cloud Secure Score is the metric that provides an overall assessment of the security posture (security health) of an Azure subscription by aggregating the implementation of security recommendations and controls. Resource Health reports service/resource availability, while completed controls and recommendation status are components rather than the overall metric.

Question 88

You have an Azure subscription that contains multiple resources. You need to assess compliance and enforce standards for the existing resources. What should you use?

A. Azure Blueprints
B. the Anomaly Detector service
C. Microsoft Sentinel
D. Azure Policy
Show Answer
Correct Answer: D
Explanation:
Azure Policy is used to assess compliance of existing Azure resources and enforce organizational standards by evaluating resources against policy definitions and optionally denying or remediating non-compliant configurations. Azure Blueprints packages governance artifacts but is not the primary service for ongoing compliance assessment. Anomaly Detector is an AI service, and Microsoft Sentinel is a SIEM/SOAR security platform.

Question 89

HOTSPOT - Select the answer that correctly completes the sentence.

Illustration for SC-900 question 89
Show Answer
Correct Answer: Azure Monitor workbook templates.
Explanation:
Microsoft Sentinel provides quick insights into data through Azure Monitor workbooks, which offer interactive reports and visualizations. Logic Apps/playbooks are for automation, and Resource Graph Explorer is for Azure resource queries.

Question 90

What are two reasons to deploy multiple virtual networks instead of using just one virtual network? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

A. to meet governance policies
B. to connect multiple types of resources
C. to separate the resources for budgeting
D. to isolate the resources
Show Answer
Correct Answer: A, D
Explanation:
Multiple Azure virtual networks are commonly deployed to enforce organizational governance requirements and to isolate resources for security, compliance, or operational boundaries. Different resource types can coexist within a single virtual network, and budgeting is managed through subscriptions, resource groups, tags, and cost management rather than by creating separate virtual networks.

Question 91

What is the maximum number of resources that Azure DDoS Protection Standard can protect without additional costs?

A. 50
B. 100
C. 500
D. 1000
Show Answer
Correct Answer: B
Explanation:
Azure DDoS Protection Standard pricing historically included protection for up to 100 public IP resources under the fixed monthly charge, with additional protected resources incurring extra cost. Although the service naming has evolved, the exam answer is 100.

$19

Get all 230 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.