1
Microsoft Security, Compliance,
and Identity Fundamentals (SC-
900) Advanced Practice Exam –
150 Multiple-Choice Questions a
well detailed one
written and graded A+
upgraded
SECTION 1: CONCEPTS OF SECURITY, COMPLIANCE, AND IDENTITY (10–15%)
Question 1
A multinational enterprise is implementing a Zero Trust security model across its hybrid cloud
environment. The security architect mandates that every access request must be authenticated,
authorized, and encrypted—regardless of the request's origin. Which Zero Trust principle does
this requirement primarily embody?
, 2
A. Assume breach
B. Use least privilege access
C. Verify explicitly
D. Micro-segmentation
- detailed answer 100% correct :- C
Rationale: The Zero Trust model operates on three guiding principles: verify explicitly (always
authenticate and authorize based on all available data points), use least privilege access, and
assume breach. The requirement to authenticate and authorize every access request,
irrespective of origin, directly reflects the "verify explicitly" principle. Assume breach focuses on
containment and segmentation, while least privilege limits access rights.
Question 2
According to the shared responsibility model in cloud computing, which party is responsible for
the security configuration of operating systems on Azure Virtual Machines?
A. Microsoft, the cloud service provider
B. The customer
C. A third-party auditor
D. Jointly shared between Microsoft and the customer
- detailed answer 100% correct :- B
Rationale: In the shared responsibility model, the cloud service provider (Microsoft) is
responsible for "security OF the cloud"—physical hardware, data centers, and hosts. The
customer is responsible for "security IN the cloud," which includes data, identities, devices, and
the configuration of operating systems on virtual machines.
Question 3
A security analyst needs to ensure that data transmitted between two Azure regions remains
unaltered during transit. Which component of the CIA triad is the analyst primarily concerned
with?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
, 3
- detailed answer 100% correct :- B
Rationale: Integrity refers to the assurance that data has not been altered or corrupted during
transit or storage. Ensuring data remains unaltered during transmission between regions is a
core integrity concern. Confidentiality protects against unauthorized disclosure, availability
ensures accessibility, and non-repudiation prevents denial of actions.
Question 4
Which Microsoft portal serves as the central hub for accessing audit reports, compliance guides,
and trust documentation for Microsoft Cloud services?
A. Azure Quickstart Center
B. Microsoft 365 Admin Center
C. Service Trust Portal
D. Microsoft Entra Admin Center
- detailed answer 100% correct :- C
Rationale: The Service Trust Portal (STP) is the central repository for Microsoft's audit reports,
compliance documents, and trust-related information. It allows customers to perform due
diligence on Microsoft's cloud services. The Azure Quickstart Center provides deployment
guidance, the Microsoft 365 Admin Center manages tenant administration, and the Entra Admin
Center manages identity services.
Question 5
A security incident has occurred, and the incident response team executes a playbook to
contain the breach and restore affected systems to an operational state. In Compliance
Manager, what type of control is being exercised?
A. Preventative control
B. Detective control
C. Corrective control
D. Deterrent control
- detailed answer 100% correct :- C
Rationale: Corrective actions are designed to minimize the adverse effects of a security
incident. Examples include incident response plans and restoring backups to recover from a
breach. Preventative controls block incidents before they occur, detective controls identify
incidents in progress, and deterrent controls discourage malicious activity.
, 4
Question 6
An organization deploys a firewall rule that blocks inbound traffic from known malicious IP
addresses. This security measure represents which type of control?
A. Detective control
B. Corrective control
C. Preventative control
D. Compensating control
- detailed answer 100% correct :- C
Rationale: A firewall rule that blocks malicious IPs is designed to prevent unauthorized access
before it occurs—this is a classic preventative control. Detective controls actively monitor for
problems (e.g., compliance scanners), corrective controls remediate issues after detection, and
compensating controls provide alternative protection when primary controls are not feasible.
Question 7
What is the primary function of Microsoft Entra ID?
A. Manage Azure firewall configurations exclusively
B. Serve as a cloud-based identity and access management service
C. Provide data loss prevention for Microsoft 365
D. Monitor virtual machine performance
- detailed answer 100% correct :- B
Rationale: Microsoft Entra ID (formerly Azure Active Directory) is a cloud-based identity and
access management service that provides authentication, authorization, and identity
governance. It is not limited to firewall management, DLP, or VM performance monitoring.
Question 8
Which of the following best describes the "assume breach" principle in the Zero Trust model?
A. Organizations should never trust any user, even after authentication
B. Organizations should operate with the expectation that an attacker may already be inside the
environment
C. Organizations should assume all network traffic is malicious
D. Organizations should disable all legacy authentication protocols
Microsoft Security, Compliance,
and Identity Fundamentals (SC-
900) Advanced Practice Exam –
150 Multiple-Choice Questions a
well detailed one
written and graded A+
upgraded
SECTION 1: CONCEPTS OF SECURITY, COMPLIANCE, AND IDENTITY (10–15%)
Question 1
A multinational enterprise is implementing a Zero Trust security model across its hybrid cloud
environment. The security architect mandates that every access request must be authenticated,
authorized, and encrypted—regardless of the request's origin. Which Zero Trust principle does
this requirement primarily embody?
, 2
A. Assume breach
B. Use least privilege access
C. Verify explicitly
D. Micro-segmentation
- detailed answer 100% correct :- C
Rationale: The Zero Trust model operates on three guiding principles: verify explicitly (always
authenticate and authorize based on all available data points), use least privilege access, and
assume breach. The requirement to authenticate and authorize every access request,
irrespective of origin, directly reflects the "verify explicitly" principle. Assume breach focuses on
containment and segmentation, while least privilege limits access rights.
Question 2
According to the shared responsibility model in cloud computing, which party is responsible for
the security configuration of operating systems on Azure Virtual Machines?
A. Microsoft, the cloud service provider
B. The customer
C. A third-party auditor
D. Jointly shared between Microsoft and the customer
- detailed answer 100% correct :- B
Rationale: In the shared responsibility model, the cloud service provider (Microsoft) is
responsible for "security OF the cloud"—physical hardware, data centers, and hosts. The
customer is responsible for "security IN the cloud," which includes data, identities, devices, and
the configuration of operating systems on virtual machines.
Question 3
A security analyst needs to ensure that data transmitted between two Azure regions remains
unaltered during transit. Which component of the CIA triad is the analyst primarily concerned
with?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
, 3
- detailed answer 100% correct :- B
Rationale: Integrity refers to the assurance that data has not been altered or corrupted during
transit or storage. Ensuring data remains unaltered during transmission between regions is a
core integrity concern. Confidentiality protects against unauthorized disclosure, availability
ensures accessibility, and non-repudiation prevents denial of actions.
Question 4
Which Microsoft portal serves as the central hub for accessing audit reports, compliance guides,
and trust documentation for Microsoft Cloud services?
A. Azure Quickstart Center
B. Microsoft 365 Admin Center
C. Service Trust Portal
D. Microsoft Entra Admin Center
- detailed answer 100% correct :- C
Rationale: The Service Trust Portal (STP) is the central repository for Microsoft's audit reports,
compliance documents, and trust-related information. It allows customers to perform due
diligence on Microsoft's cloud services. The Azure Quickstart Center provides deployment
guidance, the Microsoft 365 Admin Center manages tenant administration, and the Entra Admin
Center manages identity services.
Question 5
A security incident has occurred, and the incident response team executes a playbook to
contain the breach and restore affected systems to an operational state. In Compliance
Manager, what type of control is being exercised?
A. Preventative control
B. Detective control
C. Corrective control
D. Deterrent control
- detailed answer 100% correct :- C
Rationale: Corrective actions are designed to minimize the adverse effects of a security
incident. Examples include incident response plans and restoring backups to recover from a
breach. Preventative controls block incidents before they occur, detective controls identify
incidents in progress, and deterrent controls discourage malicious activity.
, 4
Question 6
An organization deploys a firewall rule that blocks inbound traffic from known malicious IP
addresses. This security measure represents which type of control?
A. Detective control
B. Corrective control
C. Preventative control
D. Compensating control
- detailed answer 100% correct :- C
Rationale: A firewall rule that blocks malicious IPs is designed to prevent unauthorized access
before it occurs—this is a classic preventative control. Detective controls actively monitor for
problems (e.g., compliance scanners), corrective controls remediate issues after detection, and
compensating controls provide alternative protection when primary controls are not feasible.
Question 7
What is the primary function of Microsoft Entra ID?
A. Manage Azure firewall configurations exclusively
B. Serve as a cloud-based identity and access management service
C. Provide data loss prevention for Microsoft 365
D. Monitor virtual machine performance
- detailed answer 100% correct :- B
Rationale: Microsoft Entra ID (formerly Azure Active Directory) is a cloud-based identity and
access management service that provides authentication, authorization, and identity
governance. It is not limited to firewall management, DLP, or VM performance monitoring.
Question 8
Which of the following best describes the "assume breach" principle in the Zero Trust model?
A. Organizations should never trust any user, even after authentication
B. Organizations should operate with the expectation that an attacker may already be inside the
environment
C. Organizations should assume all network traffic is malicious
D. Organizations should disable all legacy authentication protocols