1
Microsoft Security, Compliance,
and Identity Fundamentals (SC-
900) Advanced Practice Exam
v2.0 – 150 Multiple-Choice
Questions a well detailed one
written and graded
A+ upgraded
SECTION 1: CONCEPTS OF SECURITY, COMPLIANCE, AND IDENTITY (10–15%)
Question 1
A Chief Information Security Officer (CISO) is presenting the Zero Trust security model to the
executive board. She explains that network location should no longer be considered a primary
indicator of trust. Which Zero Trust principle is she emphasizing?
A. Least privilege access
B. Assume breach
, 2
C. Verify explicitly
D. Micro-segmentation
- detailed answer 100% correct :- C
Rationale: "Verify explicitly" is the principle that authentication and authorization should be
performed based on all available data points, regardless of network location. The traditional
perimeter-based trust model relied heavily on network location, but Zero Trust requires
verification at every access request. Least privilege limits permissions, assume breach focuses
on containment, and micro-segmentation limits lateral movement.
Question 2
A database administrator notices that a critical customer database is experiencing performance
degradation. After investigation, they determine that an internal development team
unintentionally ran a heavy query that consumed excessive resources. Which component of the
CIA triad was primarily affected?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
- detailed answer 100% correct :- C
Rationale: Availability ensures that authorized users have timely and reliable access to
resources. The performance degradation and resource consumption affected the database's
availability. Confidentiality concerns unauthorized disclosure, integrity concerns data accuracy,
and non-repudiation prevents denial of actions.
Question 3
A startup is planning to deploy their web application on Azure. They want to understand which
security controls they are responsible for versus which are managed by Microsoft. Which
document should they review?
A. Microsoft Privacy Statement
B. Microsoft Online Services Terms
C. Shared responsibility model documentation
D. Azure Service Level Agreement
, 3
- detailed answer 100% correct :- C
Rationale: The shared responsibility model documentation clearly delineates security
responsibilities between the cloud provider and customer. The Privacy Statement covers data
handling, the Online Services Terms define legal terms, and the SLA covers availability
commitments.
Question 4
A security manager implements a mandatory security awareness training program for all
employees. This is an example of which type of control?
A. Preventative control
B. Detective control
C. Corrective control
D. Deterrent control
- detailed answer 100% correct :- D
Rationale: Deterrent controls are designed to discourage individuals from performing malicious
or unauthorized actions. Security awareness training deters employees from violating security
policies by making them aware of consequences. Preventative controls block incidents,
detective controls identify them, and corrective controls remediate them.
Question 5
A suspicious activity pattern is detected in Azure Sentinel. The security analyst identifies it as a
potential ransomware attack. After containment, they restore affected files from backups. The
restoration process represents which type of control in the incident response lifecycle?
A. Preventative control
B. Detective control
C. Corrective control
D. Deterrent control
- detailed answer 100% correct :- C
Rationale: Corrective controls are designed to minimize the impact of an incident and restore
systems to operational status. Restoring from backups after a ransomware attack is a corrective
action. Preventative controls block incidents, detective controls identify them, and deterrent
controls discourage malicious activity.
, 4
Question 6
An organization's security policy requires that all data transmitted over the internet must be
encrypted. Which component of the CIA triad does this policy primarily protect?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
- detailed answer 100% correct :- A
Rationale: Encryption of data in transit primarily protects confidentiality by preventing
unauthorized parties from reading the data. While encryption can also support integrity, the
primary purpose mentioned in the policy—transmitting data over the internet—is to protect
against eavesdropping, which is a confidentiality concern.
Question 7
In the shared responsibility model, who is responsible for configuring the security settings of a
PaaS application's network access controls?
A. The customer
B. Microsoft
C. A third-party auditor
D. The data center operator
- detailed answer 100% correct :- A
Rationale: In the shared responsibility model, the customer is responsible for "security IN the
cloud," which includes configuring network access controls for applications, regardless of the
service model. Microsoft secures the underlying infrastructure, while auditors assess
compliance.
Question 8
A user receives a OneDrive sharing request from an external partner. The user notices that the
shared document contains the customer's social security numbers. Which security principle
should the user apply when deciding whether to open the document?
A. Assume breach
B. Least privilege
Microsoft Security, Compliance,
and Identity Fundamentals (SC-
900) Advanced Practice Exam
v2.0 – 150 Multiple-Choice
Questions a well detailed one
written and graded
A+ upgraded
SECTION 1: CONCEPTS OF SECURITY, COMPLIANCE, AND IDENTITY (10–15%)
Question 1
A Chief Information Security Officer (CISO) is presenting the Zero Trust security model to the
executive board. She explains that network location should no longer be considered a primary
indicator of trust. Which Zero Trust principle is she emphasizing?
A. Least privilege access
B. Assume breach
, 2
C. Verify explicitly
D. Micro-segmentation
- detailed answer 100% correct :- C
Rationale: "Verify explicitly" is the principle that authentication and authorization should be
performed based on all available data points, regardless of network location. The traditional
perimeter-based trust model relied heavily on network location, but Zero Trust requires
verification at every access request. Least privilege limits permissions, assume breach focuses
on containment, and micro-segmentation limits lateral movement.
Question 2
A database administrator notices that a critical customer database is experiencing performance
degradation. After investigation, they determine that an internal development team
unintentionally ran a heavy query that consumed excessive resources. Which component of the
CIA triad was primarily affected?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
- detailed answer 100% correct :- C
Rationale: Availability ensures that authorized users have timely and reliable access to
resources. The performance degradation and resource consumption affected the database's
availability. Confidentiality concerns unauthorized disclosure, integrity concerns data accuracy,
and non-repudiation prevents denial of actions.
Question 3
A startup is planning to deploy their web application on Azure. They want to understand which
security controls they are responsible for versus which are managed by Microsoft. Which
document should they review?
A. Microsoft Privacy Statement
B. Microsoft Online Services Terms
C. Shared responsibility model documentation
D. Azure Service Level Agreement
, 3
- detailed answer 100% correct :- C
Rationale: The shared responsibility model documentation clearly delineates security
responsibilities between the cloud provider and customer. The Privacy Statement covers data
handling, the Online Services Terms define legal terms, and the SLA covers availability
commitments.
Question 4
A security manager implements a mandatory security awareness training program for all
employees. This is an example of which type of control?
A. Preventative control
B. Detective control
C. Corrective control
D. Deterrent control
- detailed answer 100% correct :- D
Rationale: Deterrent controls are designed to discourage individuals from performing malicious
or unauthorized actions. Security awareness training deters employees from violating security
policies by making them aware of consequences. Preventative controls block incidents,
detective controls identify them, and corrective controls remediate them.
Question 5
A suspicious activity pattern is detected in Azure Sentinel. The security analyst identifies it as a
potential ransomware attack. After containment, they restore affected files from backups. The
restoration process represents which type of control in the incident response lifecycle?
A. Preventative control
B. Detective control
C. Corrective control
D. Deterrent control
- detailed answer 100% correct :- C
Rationale: Corrective controls are designed to minimize the impact of an incident and restore
systems to operational status. Restoring from backups after a ransomware attack is a corrective
action. Preventative controls block incidents, detective controls identify them, and deterrent
controls discourage malicious activity.
, 4
Question 6
An organization's security policy requires that all data transmitted over the internet must be
encrypted. Which component of the CIA triad does this policy primarily protect?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
- detailed answer 100% correct :- A
Rationale: Encryption of data in transit primarily protects confidentiality by preventing
unauthorized parties from reading the data. While encryption can also support integrity, the
primary purpose mentioned in the policy—transmitting data over the internet—is to protect
against eavesdropping, which is a confidentiality concern.
Question 7
In the shared responsibility model, who is responsible for configuring the security settings of a
PaaS application's network access controls?
A. The customer
B. Microsoft
C. A third-party auditor
D. The data center operator
- detailed answer 100% correct :- A
Rationale: In the shared responsibility model, the customer is responsible for "security IN the
cloud," which includes configuring network access controls for applications, regardless of the
service model. Microsoft secures the underlying infrastructure, while auditors assess
compliance.
Question 8
A user receives a OneDrive sharing request from an external partner. The user notices that the
shared document contains the customer's social security numbers. Which security principle
should the user apply when deciding whether to open the document?
A. Assume breach
B. Least privilege