Microsoft Security, Compliance, and Identity Fundamentals SC-900 Exam Questions

Page: 1 / 14
Total 215 questions
Question 1

What should you use in the Microsoft 365 security center to view security trends and track the protection status of identities?



Answer : B

In the Microsoft 365 security center/Microsoft 365 Defender portal, the Reports area is designed to provide organization-wide visibility into security posture and activity over time. Microsoft describes the Reports experience as enabling you to ''view security trends and track the protection status across identities, endpoints, email & collaboration, and cloud apps.'' Within Reports, the Identity section aggregates signals from Microsoft Entra ID protection and related identity defenses so security teams can monitor trends such as risky sign-ins, user risk, MFA adoption/registration, and other identity protection metrics. These curated, read-only dashboards are aimed at measuring protection status and changes over time, helping you validate the impact of controls and prioritize remediation.

By contrast, Attack simulator is used to run user training simulations (e.g., phishing) and is not intended for posture trend reporting. Hunting (Advanced hunting) lets analysts query raw telemetry for investigations, not to provide summarized trend dashboards. Incidents correlates alerts into incident records for triage and response, rather than showing long-term trends and protection status views. Therefore, to view security trends and track the protection status of identities, the correct place is Reports in the Microsoft 365 security center/Microsoft 365 Defender portal.


Question 2

Which Microsoft portal provides information about how Microsoft cloud services comply with regulatory standard, such as International Organization for Standardization (ISO)?



Answer : C

The Microsoft Service Trust Portal contains details about Microsoft's implementation of controls and processes that protect our cloud services and the customer data therein.


https://docs.microsoft.com/en-us/microsoft-365/compliance/get-started-with-service-trust-portal?view=o365- worldwide

Question 3

Which Microsoft Purview data classification type supports the use of regular expressions?



Answer : C

Sensitive Information Types (SITs) support regular expressions (regex), which allow for custom pattern matching to detect sensitive content like credit card numbers, social security numbers, or custom identifiers. Regex is fundamental to the detection logic within SITs.

SCI Extract: 'Sensitive information types use pattern matching techniques, including regular expressions, keyword matches, and checksums to identify sensitive data.'


Question 4

What can you use to provide threat detection for Azure SQL Managed Instance?



Answer : C

For Azure data services such as Azure SQL Managed Instance, Microsoft provides threat detection and protection through Microsoft Defender for Cloud (via Microsoft Defender for SQL). Microsoft documentation states that Defender for Cloud ''provides advanced threat protection for your SQL resources,'' including Azure SQL Database and Azure SQL Managed Instance, by ''continuously monitoring for anomalous activities and potential SQL injection, brute force, and exploitation attempts.'' When enabled, the plan ''generates security alerts when suspicious activities are detected,'' and these alerts can be surfaced in Defender for Cloud, forwarded to Microsoft Sentinel, or integrated with workflows for response. Microsoft Secure Score is a security posture metric, application security groups are for network segmentation in Azure, and Azure Bastion provides secure RDP/SSH over TLS---none of these deliver database-specific threat detection. Therefore, to provide threat detection for Azure SQL Managed Instance, you use Microsoft Defender for Cloud (Defender for SQL).


Question 5

You have an Azure subscription that contains a virtual network named Vnet1. VNet1 contains a virtual machine named VM1 that runs Windows Server and is publicly accessible.

You suspect that VM1 has been the target of a malicious network attack.

You need to monitor network traffic to VM1, collect attack metrics, such as the SYN packet count, and automatically generate alerts if another attack begins. The solution must minimize administrative effort.

What should you use?



Answer : C


Question 6

What can you use to provision Azure resources across multiple subscriptions in a consistent manner?



Answer : B

Azure Blueprints allow cloud architects and central IT to define a repeatable set of Azure resources and governance artifacts---including Azure Policy assignments, role assignments (RBAC), resource groups, and ARM/Bicep templates---and then deploy them consistently across subscriptions. Microsoft's guidance describes Blueprints as a way to ''orchestrate the deployment of various resource templates and other artifacts'' to establish standards, patterns, and compliance for environments at scale. This is distinct from Azure Policy, which evaluates and enforces configuration but does not package multi-artifact environments; Microsoft Sentinel and Defender are security analytics/protection services rather than provisioning frameworks. Thus, for consistent provisioning across multiple subscriptions, the prescribed solution is Azure Blueprints.


Question 7

What is a feature of Microsoft Defender for Cloud Apps?



Answer : C


Page:    1 / 14   
Total 215 questions