Microsoft SC-900 Exam (page: 3)
Microsoft Security, Compliance, and Identity Fundamentals
Updated on: 28-Jul-2025

Viewing Page 3 of 30

HOTSPOT (Drag and Drop is not supported)
Select the answer that correctly completes the sentence.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/external-identities/what-is-b2b



In the Microsoft Cloud Adoption Framework for Azure, which two phases are addressed before the Ready phase? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

  1. Plan
  2. Manage
  3. Adopt
  4. Govern
  5. Define Strategy

Answer(s): A,E


Reference:

https://docs.microsoft.com/en-us/azure/cloud-adoption-framework/overview



HOTSPOT (Drag and Drop is not supported)
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:



HOTSPOT (Drag and Drop is not supported)
Select the answer that correctly completes the sentence.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/security/benchmark/azure/baselines/cloud-services-security-baseline



What is an example of encryption at rest?

  1. encrypting communications by using a site-to-site VPN
  2. encrypting a virtual machine disk
  3. accessing a website by using an encrypted HTTPS connection
  4. sending an encrypted email

Answer(s): B


Reference:

https://docs.microsoft.com/en-us/azure/security/fundamentals/encryption-atrest



Which three statements accurately describe the guiding principles of Zero Trust? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

  1. Define the perimeter by physical locations.
  2. Use identity as the primary security boundary.
  3. Always verify the permissions of a user explicitly.
  4. Always assume that the user system can be breached.
  5. Use the network as the primary security boundary.

Answer(s): B,C,D


Reference:

https://docs.microsoft.com/en-us/security/zero-trust/



HOTSPOT (Drag and Drop is not supported)
Which service should you use to view your Azure secure score? To answer, select the appropriate service in the answer area.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/security-center/secure-score-access-and-track



DRAG DROP (Drag and Drop is not supported)
You are evaluating the compliance score in Microsoft Purview Compliance Manager. Match the compliance score action subcategories to the appropriate actions.
To answer, drag the appropriate action subcategory from the column on the left to its action on the right. Each action subcategory may be used once, more than once, or not at all.
NOTE: Each correct match is worth one point.
Select and Place:

  1. See Explanation section for answer.

Answer(s): A

Explanation:




Box 1: Preventative
Preventative actions address specific risks. For example, protecting information at rest using encryption is a preventative action against attacks and breaches. Separation of duties is a preventative action to manage conflict of interest and guard against fraud.
Box 2: Detective
Detective actions actively monitor systems to identify irregular conditions or behaviors that represent risk, or that can be used to detect intrusions or breaches. Examples include system access auditing and privileged administrative actions. Regulatory compliance audits are a type of detective action used to find process issues.
Box 3: Corrective
Corrective actions try to keep the adverse effects of a security incident to a minimum, take corrective action to reduce the immediate effect, and reverse the damage if possible. Privacy incident response is a corrective action to limit damage and restore systems to an operational state after a breach.


Reference:

https://docs.microsoft.com/en-us/microsoft-365/compliance/compliance-score-calculation



Viewing Page 3 of 30



Share your comments for Microsoft SC-900 exam with other users:

Greg 11/16/2023 6:59:00 AM

hope for the best
UNITED STATES


zazza 6/16/2023 9:08:00 AM

question 21 answer is alerts
ITALY


Synt 5/23/2023 9:33:00 PM

need to view
UNITED STATES


zazza 6/16/2023 10:47:00 AM

question 44 answer is user risk
ITALY