Microsoft sc-900 ExaM PrEParation and PracticE 2026
UPdatE WitH coMPLEtE QUEstions and corrEct dEtaiLEd
ansWErs (VErifiEd ansWErs) |aLrEadY GradEd
a+|Brand nEW VErsion!!
Microsoft is renaming Azure Active Directory to What? - ansWEr-Microsoft Entra ID
What does data residency refer to in the context of security compliance?
A:The ownership of data and what can be done with it.
B: The process of adhering to specific laws and guidelines designed to safeguard data.
C: The physical location where data is housed. - ansWEr-C: The physical location where
data is housed.
In IT define compliance - ansWEr-adhering to rules, standards, and regulations to ensure
the protection and privacy of data
For compliance what are geopolitical laws. - ansWEr-Laws that impact how data is
housed and processed and by which industry
What is a On-premises datacenter - ansWEr-The technology is on site. This includes the
hardware that stores and protects the data. Therefore, the responsibility and liability for
implementing security and compliance falls on the business.
True or False
Cloud-based services share responsibility between the customer and cloud provider -
ansWEr-True
,What is Infrastructure as a service (IaaS) - ansWEr-The customer is provided with online
architecture for data centers, computing power, and network facilities for which they are
not responsible for the cloud.
(the most hands-on service for users available in the cloud.)
What is the customer responsible for Infrastructure as a service (IaaS) - ansWEr-A
customer of IaaS is responsible for most concerns are physical hardware, installing and
maintaining the operating system, creating the network, and ensuring a backup is in
place.
Most importantly, the user is responsible for understanding and implementing the
appropriate industry and geographical compliance requirements
What is Platform as service (PaaS) - ansWEr-A cloud computing service that provides
the hardware and the operating system and is responsible for updating and maintaining
both for the customer
What is Software as a service (SaaS) - ansWEr-public cloud providers create and deliver
applications over the internet through the browser, while the customer is responsible for
the devices and accounts for the applications.
The service provider is responsible for knowing and adhering to laws and regulations,
while the customer is responsible for adhering to the agreements made with the SaaS
provider.
What is the service provider and the customer responsible for in Software as a service
(SaaS) - ansWEr-The service provider is responsible for knowing and adhering to laws
and regulations, while the customer is responsible for adhering to the agreements made
with the SaaS provider.
Which of the following metrics is concerned with the permissible level of downtime for a
business process in the event of an unforeseen incident?
A: Recovery Time Objective (RTO)
B: Recovery Point Objective (RPO)
C: Business Continuity Management (BCM) - ansWEr-A: Recovery Time Objective (RTO)
,Correct. Recovery Time Objective (RTO) is a metric that measures the permissible level
of downtime for a business process.
Define Zero Trust model - ansWEr-Zero trust embraces the philosophy of "trust no one,
verify everything." It involves treating all devices, users, functions, and services as
potentially untrustworthy, whether inside or outside the network.
This approach protects critical assets and data by validating and authorizing each
access request. (In the past, devices within a network were often inherently trusted,
leading to potential vulnerabilities. For example, attackers could employ lateral
movement in an attack without detection) Just an example
What are the 3 Zero Trust model operates based on three core guiding principles -
ansWEr-Verify explicitly
Least privileged access
Assume breach
What is Verify Explicitly (Identify their steps) - ansWEr-Verify explicitly:
Step 1: network request is thoroughly assessed using all available data points.
Step 2: Then we must determine the source of the request before granting access.
Step 3: Finally we must provide legitimate access patterns before access is given.
What is Least privileged access: - ansWEr-Least privileged access: This principle
ensures that users and devices are granted only the minimum level of access required to
complete their tasks.
It uses both just-in-time access(JIT), which allows access only for a specific time frame.
And just-enough-access (JEA), which grants the precise permissions necessary for a
given task.
, Define: Assume breach - ansWEr-Assume breach: A fundamental aspect of zero trust is
designing the network as if a breach has already occurred.
This involves limiting mobility within the network and encrypting sensitive data to
mitigate potential damage in case of a security breach.
What are the advantages of the the Zero Trust model - ansWEr-Enhanced security
Improved data protection
Flexibility for remote work
For advantages of the Zero Trust Model, Define Enhanced Security - ansWEr-the Zero
Trust model significantly strengthens security and reduces the attack surface, making it
harder for malicious actors to infiltrate a network.
For advantages of the Zero Trust Model, Define Improved Data Protection - ansWEr-Zero
trust ensures that critical information is protected with strict access controls, encryption,
and continuous monitoring, thereby minimizing the risk of data breaches
For advantages of the Zero Trust Model, Define Flexibility for remote work - ansWEr-
Employees can securely access company resources from dispersed locations without
compromising security and don't have to travel to an office. (This allows more freedom to
recruit workers across the area/world).
What are the Disadvantages of the Zero Trust model - ansWEr-Complexity: requires a
deep understanding of IT security principles and use security tools.
Cost:
Usability: often a trade-off between usability and security.
EX: (security measures, such as multi-factor authentication, can impact user experience
and requires careful implementations.)
UPdatE WitH coMPLEtE QUEstions and corrEct dEtaiLEd
ansWErs (VErifiEd ansWErs) |aLrEadY GradEd
a+|Brand nEW VErsion!!
Microsoft is renaming Azure Active Directory to What? - ansWEr-Microsoft Entra ID
What does data residency refer to in the context of security compliance?
A:The ownership of data and what can be done with it.
B: The process of adhering to specific laws and guidelines designed to safeguard data.
C: The physical location where data is housed. - ansWEr-C: The physical location where
data is housed.
In IT define compliance - ansWEr-adhering to rules, standards, and regulations to ensure
the protection and privacy of data
For compliance what are geopolitical laws. - ansWEr-Laws that impact how data is
housed and processed and by which industry
What is a On-premises datacenter - ansWEr-The technology is on site. This includes the
hardware that stores and protects the data. Therefore, the responsibility and liability for
implementing security and compliance falls on the business.
True or False
Cloud-based services share responsibility between the customer and cloud provider -
ansWEr-True
,What is Infrastructure as a service (IaaS) - ansWEr-The customer is provided with online
architecture for data centers, computing power, and network facilities for which they are
not responsible for the cloud.
(the most hands-on service for users available in the cloud.)
What is the customer responsible for Infrastructure as a service (IaaS) - ansWEr-A
customer of IaaS is responsible for most concerns are physical hardware, installing and
maintaining the operating system, creating the network, and ensuring a backup is in
place.
Most importantly, the user is responsible for understanding and implementing the
appropriate industry and geographical compliance requirements
What is Platform as service (PaaS) - ansWEr-A cloud computing service that provides
the hardware and the operating system and is responsible for updating and maintaining
both for the customer
What is Software as a service (SaaS) - ansWEr-public cloud providers create and deliver
applications over the internet through the browser, while the customer is responsible for
the devices and accounts for the applications.
The service provider is responsible for knowing and adhering to laws and regulations,
while the customer is responsible for adhering to the agreements made with the SaaS
provider.
What is the service provider and the customer responsible for in Software as a service
(SaaS) - ansWEr-The service provider is responsible for knowing and adhering to laws
and regulations, while the customer is responsible for adhering to the agreements made
with the SaaS provider.
Which of the following metrics is concerned with the permissible level of downtime for a
business process in the event of an unforeseen incident?
A: Recovery Time Objective (RTO)
B: Recovery Point Objective (RPO)
C: Business Continuity Management (BCM) - ansWEr-A: Recovery Time Objective (RTO)
,Correct. Recovery Time Objective (RTO) is a metric that measures the permissible level
of downtime for a business process.
Define Zero Trust model - ansWEr-Zero trust embraces the philosophy of "trust no one,
verify everything." It involves treating all devices, users, functions, and services as
potentially untrustworthy, whether inside or outside the network.
This approach protects critical assets and data by validating and authorizing each
access request. (In the past, devices within a network were often inherently trusted,
leading to potential vulnerabilities. For example, attackers could employ lateral
movement in an attack without detection) Just an example
What are the 3 Zero Trust model operates based on three core guiding principles -
ansWEr-Verify explicitly
Least privileged access
Assume breach
What is Verify Explicitly (Identify their steps) - ansWEr-Verify explicitly:
Step 1: network request is thoroughly assessed using all available data points.
Step 2: Then we must determine the source of the request before granting access.
Step 3: Finally we must provide legitimate access patterns before access is given.
What is Least privileged access: - ansWEr-Least privileged access: This principle
ensures that users and devices are granted only the minimum level of access required to
complete their tasks.
It uses both just-in-time access(JIT), which allows access only for a specific time frame.
And just-enough-access (JEA), which grants the precise permissions necessary for a
given task.
, Define: Assume breach - ansWEr-Assume breach: A fundamental aspect of zero trust is
designing the network as if a breach has already occurred.
This involves limiting mobility within the network and encrypting sensitive data to
mitigate potential damage in case of a security breach.
What are the advantages of the the Zero Trust model - ansWEr-Enhanced security
Improved data protection
Flexibility for remote work
For advantages of the Zero Trust Model, Define Enhanced Security - ansWEr-the Zero
Trust model significantly strengthens security and reduces the attack surface, making it
harder for malicious actors to infiltrate a network.
For advantages of the Zero Trust Model, Define Improved Data Protection - ansWEr-Zero
trust ensures that critical information is protected with strict access controls, encryption,
and continuous monitoring, thereby minimizing the risk of data breaches
For advantages of the Zero Trust Model, Define Flexibility for remote work - ansWEr-
Employees can securely access company resources from dispersed locations without
compromising security and don't have to travel to an office. (This allows more freedom to
recruit workers across the area/world).
What are the Disadvantages of the Zero Trust model - ansWEr-Complexity: requires a
deep understanding of IT security principles and use security tools.
Cost:
Usability: often a trade-off between usability and security.
EX: (security measures, such as multi-factor authentication, can impact user experience
and requires careful implementations.)