SC-900 Sample Questions

SC-900 Sample Questions & Answers

Microsoft's broader security solutions, from core Azure infrastructure services to Sentinel, get the most attention, ahead of Entra ID's authentication and access management, Purview compliance capabilities, and basic security and identity concepts.

Launch the full SC-900 simulator →

Showing 8 of 17 free samples.

  1. Question 1Beginner

    Describe the concepts of security, compliance, and identity · Describe the Zero-Trust model

    A global financial institution is re-evaluating its security posture after a recent audit. The Chief Information Security Officer (CISO) wants to adopt a strategy that assumes every access request is a potential breach, regardless of where the request originates. Which security model should the CISO implement to meet this requirement?

    Show answer & explanation

    Correct answer: B

    The Zero Trust model is built on the guiding principles of 'Verify explicitly', 'Use least privileged access', and 'Assume breach'. It assumes that no traffic is trusted by default, regardless of whether it is inside or outside the network perimeter.

  2. Question 2Intermediate

    Describe the concepts of security, compliance, and identity · Describe the shared responsibility model

    A cloud architect is designing a solution hosted on Azure Platform as a Service (PaaS). According to the shared responsibility model, which of the following responsibilities is retained solely by the customer?

    Show answer & explanation

    Correct answer: C

    In all cloud deployment models (IaaS, PaaS, SaaS), the customer is always responsible for their information and data, as well as the devices (endpoints) and accounts/identities.

  3. Question 3Intermediate

    Describe the concepts of security, compliance, and identity · Describe encryption and hashing

    A security analyst is reviewing the organization's encryption strategy. They need to ensure that data stored in Azure Blob Storage cannot be read if the physical disks are stolen from the datacenter. Which type of encryption addresses this specific threat?

    Show answer & explanation

    Correct answer: A

    Encryption at rest protects data that is stored on physical media (like disks). It ensures that even if the physical media is accessed or stolen, the data remains unreadable without the decryption key.

  4. Question 4Beginner

    Describe the concepts of security, compliance, and identity · Define identity as the primary security perimeter

    True or False: In a modern security posture, the network is considered the primary security perimeter.

    Show answer & explanation

    Correct answer: B

    False. In modern cloud computing, identity is the primary security perimeter. Users access resources from various networks and locations, making the traditional network perimeter less effective as the primary control point.

  5. Question 5Beginner

    Describe the concepts of security, compliance, and identity · Describe how security policies and initiatives improve cloud security posture

    A startup is adopting Microsoft Azure and wants to follow best practices for cloud adoption. They need a comprehensive set of documentation, implementation guidance, best practices, and tools. Which framework should they consult?

    Show answer & explanation

    Correct answer: C

    The Microsoft Cloud Adoption Framework for Azure is a full lifecycle framework that provides documentation, implementation guidance, best practices, and tools to accelerate cloud adoption.

  6. Question 6Intermediate

    Describe the concepts of security, compliance, and identity · Describe defense-in-depth

    An organization is implementing a defense-in-depth strategy. They have secured the physical datacenter and the network perimeter. Which layer of defense should they address next to ensure that only authorized users can access resources?

    Show answer & explanation

    Correct answer: B

    In the defense-in-depth model, the Identity and Access layer controls access to infrastructure and change control. It follows the perimeter layer and ensures only authenticated and authorized identities can proceed.

    flowchart TD Physical --> Identity[Identity & Access] Identity --> Perimeter Perimeter --> Network Network --> Compute Compute --> App App --> Data

  7. Question 7AdvancedSelect 3

    Describe the capabilities of Microsoft Entra · Describe Conditional Access

    A security administrator needs to configure Microsoft Entra Conditional Access to require Multi-Factor Authentication (MFA) for all users attempting to access the Azure portal from outside the corporate network. Which three components must be defined in the policy? (Select THREE)

    Show answer & explanation

    Correct answers: A, B, C

    This defines the target resource, such as 'Microsoft Azure Management' (Azure portal).

    Assignments determine who the policy applies to (e.g., All Users or specific groups).

    This defines the enforcement action, such as 'Require multi-factor authentication'.

    graph LR Signals[Signals] -->|Evaluated by| Engine[Decision Engine] Engine -->|Enforces| Control[Access Control] Control -->|Allow/Block/MFA| App[Cloud App]

  8. Question 8Intermediate

    Describe the capabilities of Microsoft Entra · Describe hybrid identity

    A company is migrating to Microsoft Entra ID and wants to ensure that users can reset their own passwords without calling the helpdesk. However, any password change made in the cloud must be immediately reflected in the on-premises Active Directory. Which feature must be enabled?

    Show answer & explanation

    Correct answer: D

    Password writeback is a feature of Microsoft Entra Connect that allows password changes in the cloud (like via SSPR) to be written back to the on-premises Active Directory in real-time.

Ready for the real thing?

The full SC-900 simulator has every exam-style question, timed mode, and instant scoring.

Go to the SC-900 simulator →