Microsoft · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
28% of exam · 6 sample questions below
A company wants to require multi-factor authentication (MFA) for all users accessing a financial application, but only when they sign in from outside the corporate network. Which Microsoft Entra ID feature should be used?
Identity Protection
Conditional Access
Conditional Access policies evaluate various signals in real-time, including user, device, application, and network location. Administrators can configure these policies to mandate specific controls, such as multi-factor authentication (MFA), when certain conditions are met, like a user attempting to access resources from an untrusted network or outside the corporate IP range. This directly addresses the requirement to enforce MFA for users accessing resources under specific conditions.
Privileged Identity Management (PIM)
Self-Service Password Reset (SSPR)
An organization uses Microsoft Entra ID Protection. A user's sign-in is flagged with a risk level of 'High' because of an anonymous IP address. The administrator wants to automatically block the sign-in while allowing the user to self-remediate. Which should be configured?
A Conditional Access policy requiring MFA for high-risk sign-ins
A user risk policy configured to require a password change
A sign-in risk policy configured to block access
Microsoft Entra ID Protection's sign-in risk policy directly evaluates the risk associated with a specific sign-in attempt in real-time. When configured to block access for a detected risk level, such as 'High,' it prevents the user from completing the sign-in immediately. This directly addresses the requirement to automatically block a high-risk sign-in, ensuring immediate protection against potentially compromised credentials and unauthorized access.
An MFA registration policy for all users
A company manages Azure resources for multiple departments. The security team needs to grant IT administrators temporary, just-in-time access to high-privilege roles (e.g., Contributor, Owner) only when needed, with approval workflows. Which Microsoft Entra ID capability should they configure?
Conditional Access
Identity Protection
Privileged Identity Management (PIM)
Azure AD Privileged Identity Management (PIM) is specifically designed to manage, control, and monitor access to important resources within Azure AD, Azure, and other Microsoft online services. It enforces just-in-time (JIT) access, allowing users to activate privileged roles only when needed and for a limited duration. This capability significantly reduces the attack surface by eliminating standing administrative access, requiring explicit activation and often approval workflows for elevated permissions.
Entitlement Management (Identity Governance)
A company uses Microsoft Entra ID and needs to regularly review membership of a group that grants access to a sensitive HR application. The identity team wants to automate quarterly reviews and automatically remove users who fail to respond or are denied by the reviewer. Which Microsoft Entra ID feature should they use?
Conditional Access
Identity Protection
Privileged Identity Management (PIM)
Access Reviews
Microsoft Entra Access Reviews provide a systematic way for organizations to manage access lifecycle by regularly reviewing who has access to various resources. This feature allows administrators to create recurring reviews for group memberships, application assignments, and Microsoft Entra role assignments. Reviewers, such as group owners or managers, can then approve or deny access, with the system automatically removing unresponsive or denied users based on configured settings, ensuring least privilege.
A company uses Microsoft Entra ID and wants to enforce multi-factor authentication (MFA) only for external guest users, while allowing internal employees to sign in without MFA. Which Conditional Access setting should be configured?
Require MFA for all users
Exclude internal users by group
Target the 'Guest or external users' identity type
Conditional Access policies in Microsoft Entra ID provide the precise control needed to enforce requirements based on identity types. By configuring a policy to include the 'Guest or external users' identity type, administrators can specifically mandate multi-factor authentication (MFA) solely for B2B collaboration guests and other external identities. This direct targeting ensures that internal users are not affected, thereby accurately meeting the requirement to enforce MFA exclusively for external users.
Use Identity Protection's user risk policy
A company wants to block all sign-ins using legacy authentication protocols because these protocols do not support multi-factor authentication (MFA). Which component of a Microsoft Entra ID Conditional Access policy should be configured to achieve this?
Cloud apps or actions
Conditions (Client apps)
In Azure AD Conditional Access, the "Conditions" section allows administrators to define specific criteria for policy application. The "Client apps" condition specifically targets the type of client application attempting to access resources, including options to block "Other clients," which encompasses legacy authentication protocols like POP3, IMAP, SMTP, and older Office clients. By selecting this option, organizations can enforce the exclusive use of modern authentication clients, significantly enhancing security by eliminating vulnerabilities associated with less secure, basic authentication methods.
Grant
Session
Want more Describe the capabilities of Microsoft Entra practice?
Practice this domain37% of exam · 6 sample questions below
A security administrator is using Microsoft Defender for Cloud to improve the security posture of Azure resources. The administrator wants to view a consolidated assessment of compliance with industry standards such as CIS and NIST. Which feature should be used?
Regulatory compliance dashboard
The Regulatory compliance dashboard in Microsoft Defender for Cloud provides a centralized view of an organization's compliance posture against various industry standards and regulatory benchmarks, such as CIS, NIST, and PCI DSS. It continuously assesses the environment, mapping security controls to specific requirements within these frameworks and clearly indicating which controls pass or fail. This dashboard is specifically designed to help organizations understand and improve their adherence to external regulations by offering actionable recommendations and detailed compliance reports.
Secure Score
Azure Policy
Microsoft Sentinel
An organization uses Microsoft 365 Defender. The security team receives an alert about a potential malware outbreak on multiple endpoints, and they need an integrated view that correlates signals from various Microsoft security solutions. Which Microsoft 365 Defender portal component provides this unified view?
Microsoft Defender for Cloud
Microsoft 365 Defender portal (security.microsoft.com)
The Microsoft 365 Defender portal (security.microsoft.com) is the centralized management console for the Microsoft 365 Defender suite. It provides a unified XDR (eXtended Detection and Response) experience, correlating signals from Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Microsoft Defender for Cloud Apps. This integration enables security teams to investigate and respond to sophisticated multi-stage attacks across endpoints, email, identities, and applications from a single pane of glass, streamlining incident management.
Azure Sentinel
Microsoft Defender for Identity
A security team is evaluating Microsoft security solutions to monitor user activities across multiple SaaS applications, including Salesforce and Dropbox, for signs of compromised accounts and data exfiltration. Which solution is specifically designed for this purpose?
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB), providing comprehensive visibility, control, and threat protection for sanctioned and unsanctioned cloud applications. It directly monitors user activities within SaaS applications like Salesforce or Dropbox, detecting anomalous behavior, preventing data exfiltration, and enforcing compliance policies. This solution is purpose-built to address the unique security challenges posed by cloud application usage, offering real-time controls and deep insights into data movement and user interactions.
Microsoft Defender for Endpoint
Microsoft Sentinel
Microsoft 365 Defender
A company manages Azure virtual machines and on-premises servers. The security team needs a single dashboard that provides a secure score and actionable recommendations to improve the security posture across both environments. Which Microsoft solution should be used?
Microsoft 365 Defender portal
Microsoft Defender for Cloud
Microsoft Defender for Cloud is the correct solution because it provides comprehensive Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) capabilities across Azure, on-premises, and multi-cloud environments. It delivers a secure score, actionable security recommendations, and advanced threat protection for virtual machines and servers, regardless of their hosting location. By integrating with Azure Arc, Defender for Cloud extends its security management and monitoring to on-premises servers, ensuring consistent security posture across the entire hybrid infrastructure.
Microsoft Sentinel
Microsoft Defender for Cloud Apps
A company has deployed Microsoft 365 Defender to unify threat detection and response. Which two components are included within the Microsoft 365 Defender integrated solution? (Select all that apply.)
Microsoft Defender for Endpoint
Microsoft Defender for Endpoint is a foundational component of Microsoft 365 Defender, providing robust endpoint detection and response (EDR) capabilities across various operating systems. It offers next-generation protection, automated investigation and remediation, and vulnerability management, integrating its rich telemetry directly into the unified M365 Defender portal. This integration enables comprehensive visibility and coordinated threat response across devices, ensuring endpoints are protected from sophisticated attacks.
Microsoft Defender for Cloud
Microsoft Defender for Office 365
Microsoft Defender for Office 365 is an integral service within the Microsoft 365 Defender suite, specifically designed to safeguard email, collaboration tools, and files from advanced threats. It provides robust protection against phishing, business email compromise (BEC), malware, and zero-day attacks through features like Safe Attachments and Safe Links across Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams. Its telemetry and alerts are seamlessly integrated, contributing to a holistic view of an organization's threat landscape.
Microsoft Sentinel
A security analyst is using Microsoft 365 Defender to investigate a sophisticated multi-stage attack. The analyst needs to query data across endpoints, email, and identity logs to identify the attacker's behavior patterns and correlate events. Which Microsoft 365 Defender capability should the analyst use?
Automated investigation and response
Threat analytics
Advanced hunting
Advanced hunting is a powerful, proactive threat hunting tool within Microsoft 365 Defender that allows security analysts to explore raw organizational data using Kusto Query Language (KQL). It aggregates data from endpoints, email, identity, and cloud apps, enabling custom queries to uncover sophisticated threats, identify anomalous behaviors, and correlate events across diverse security domains that automated systems might miss. This capability is crucial for deep investigations and creating custom detection rules.
Action center
Want more Describe the capabilities of Microsoft security solutions practice?
Practice this domain22% of exam · 6 sample questions below
A multinational corporation must comply with the General Data Protection Regulation (GDPR). They use Microsoft Purview Compliance Manager to manage compliance activities. The compliance manager wants to automatically assign each control to the appropriate team member for remediation. What should they configure?
Create new assessments for each regulation
Configure improvement actions with owners
Configuring improvement actions with owners in Microsoft Purview Compliance Manager is the direct mechanism for operationalizing compliance requirements. These actions represent specific tasks derived from controls and regulations, such as implementing a data encryption policy or updating a privacy notice. Assigning an owner ensures accountability, facilitates the delegation of remediation efforts, and enables tracking of progress and evidence submission, directly addressing the need to comply with regulations like GDPR.
Set up connectors to import external risk data
Use the Microsoft 365 admin center to delegate tasks
A company is subject to a legal hold for an ongoing investigation. The IT administrator must prevent the deletion of any documents related to this case across SharePoint Online and OneDrive, overriding any existing deletion policies. Which Microsoft Purview capability should the administrator use?
Data Lifecycle Management
eDiscovery (Premium)
eDiscovery (Premium) is the correct service for placing content on legal hold. It enables organizations to identify, preserve, collect, process, and review electronically stored information (ESI) for legal or investigative purposes. A key feature is the ability to apply eDiscovery holds to specific content locations, such as mailboxes and SharePoint sites, which prevents the permanent deletion of data, even if existing retention policies would otherwise dictate its removal. This ensures data integrity for ongoing investigations.
Audit (Premium)
Communication Compliance
A company wants to automatically apply a 'Confidential' sensitivity label to any document that contains a credit card number, and also encrypt the document as part of the label. Which two components must be configured to achieve this? (Choose two.)
A sensitivity label with encryption settings
Correct. The sensitivity label must define the protection (encryption) that will be applied to documents containing credit card numbers.
A DLP policy that detects sensitive info
An auto-labeling policy
Correct. The auto-labeling policy applies the sensitivity label automatically to documents that match specified conditions (e.g., containing a credit card number).
A data classification dashboard
A company must retain all customer contracts for 10 years to comply with industry regulations. After 10 years, the contracts must be permanently deleted. Which Microsoft Purview solution should be used to automate this process?
Data Loss Prevention (DLP)
Data Lifecycle Management
Data Lifecycle Management (DLM) in Microsoft 365 utilizes retention labels and policies to govern the entire lifecycle of data, from creation to deletion. It enables organizations to define specific retention periods, such as 10 years for customer contracts, ensuring compliance with legal or regulatory obligations. After the retention period expires, DLM policies can automatically dispose of the data, streamlining information governance and reducing risk.
eDiscovery
Information Protection
A healthcare organization uses Microsoft 365 and wants to prevent users from sending emails that contain patient health information (PHI) to external recipients. Which Microsoft Purview solution should they implement?
Data Lifecycle Management
Data Loss Prevention (DLP)
Microsoft 365 Data Loss Prevention (DLP) policies are specifically designed to identify, monitor, and protect sensitive information across various locations, including Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams. These policies leverage sensitive information types, labels, or keywords to detect data such as patient records or financial details. Upon detection, DLP can automatically block sharing, warn users with policy tips, or encrypt content, thereby preventing accidental or malicious data exfiltration in real-time.
Insider Risk Management
eDiscovery
A multinational corporation must retain all financial records for 7 years and then permanently delete them. The compliance officer wants to ensure that even a global administrator cannot modify or delete the retention policy. Which Microsoft Purview solution and configuration should they use?
eDiscovery (Standard)
Compliance Manager
Data Lifecycle Management with a preservation lock
Data Lifecycle Management (DLM), specifically through Microsoft 365 retention policies, allows organizations to define how long content is retained or deleted. For financial records requiring mandatory retention, a retention policy can be configured to preserve content for a specified period. Applying a preservation lock to this policy makes it immutable, preventing anyone, including administrators, from turning off the policy, deleting it, or making it less restrictive, thus ensuring compliance with stringent regulatory requirements for long-term record retention.
Information Protection with sensitivity labels
Want more Describe the capabilities of Microsoft compliance solutions practice?
Practice this domain13% of exam · 6 sample questions below
A security analyst is explaining the core principles of information security to a new team member. Which principle ensures that data is not modified by unauthorized parties?
Confidentiality
Integrity
Integrity is the fundamental security principle that ensures data remains accurate, complete, and unaltered by unauthorized parties throughout its lifecycle. It guarantees that information has not been tampered with, either accidentally or maliciously, maintaining its trustworthiness and reliability. Mechanisms such as cryptographic hashing, digital signatures, and robust access controls are employed to detect or prevent unauthorized modifications, thereby preserving the validity and consistency of the data.
Availability
Non-repudiation
A company is moving its on-premises database to Azure SQL Database. According to the shared responsibility model, which security tasks remain the responsibility of the customer?
Patching the physical servers hosting the database
Managing access controls and authentication for database users
The customer retains responsibility for managing user identities, permissions, and authentication to the database.
Securing the hypervisor running the virtual machines
Hardening the network firewalls at the datacenter perimeter
A security architect is adopting a new security model that assumes breach and verifies every access request. The model eliminates implicit trust and requires continuous validation. Which security model is being implemented?
Defense in Depth
Zero Trust
Zero Trust is a modern security model that fundamentally shifts from perimeter-based security to a 'never trust, always verify' approach. It mandates explicit verification for every access request, regardless of whether the request originates inside or outside the traditional network perimeter. This model assumes breach and continuously validates identity, device health, and other contextual factors before granting and maintaining access to resources.
Least Privilege
Shared Responsibility
A company is migrating its on-premises workloads to Azure. The CISO wants to understand the division of security responsibilities between Microsoft and the customer across cloud service models. For which cloud service model does the customer have the most security responsibility?
Software as a Service (SaaS)
Platform as a Service (PaaS)
Infrastructure as a Service (IaaS)
Infrastructure as a Service (IaaS) is the correct choice for migrating existing on-premises workloads to Azure because it provides the most control over the underlying operating systems, applications, and data, closely mirroring an on-premises environment. In IaaS, the customer is responsible for securing the operating system, applications, network configuration, and data, while Azure manages the physical infrastructure, virtualization, and networking fabric. This model facilitates a "lift-and-shift" approach, allowing the CISO to maintain significant security responsibility and control over their familiar stack within the cloud.
On-premises
A company's security policy requires that customer data must only be accessible by authorized sales representatives. Which security principle does this requirement directly enforce?
Integrity
Availability
Confidentiality
Confidentiality is the fundamental security principle that ensures information is not disclosed to unauthorized individuals, entities, or processes. It directly addresses the requirement of limiting access to customer data only to those who are explicitly authorized, typically through mechanisms like encryption, access control lists (ACLs), and the principle of least privilege. This principle is paramount for protecting sensitive information from unauthorized viewing or exposure, aligning perfectly with the stated security policy.
Non-repudiation
A company uses Microsoft Entra ID and has multiple departments with separate organizational units (OUs) in its on-premises Active Directory. The help desk team needs to be able to reset passwords for users only in the Finance department. What feature should be used to delegate this administrative scope?
Dynamic groups
Administrative Units
Administrative Units (AUs) in Microsoft Entra ID are specifically designed to enable scoped administration by defining a subset of users, groups, or devices. For a company with multiple departments, AUs allow the delegation of administrative roles, such as User Administrator or Group Administrator, to manage only the identities within a particular department's AU. This ensures that departmental administrators can perform necessary management tasks without gaining tenant-wide privileges, adhering to the principle of least privilege.
Conditional Access policies
Privileged Identity Management (PIM)
Want more Describe the concepts of security, compliance, and identity practice?
Practice this domainThe SC-900 exam has 50 questions and must be completed in 60 minutes. The passing score is 700/1000.
Conceptual questions on security, compliance, and identity concepts in Microsoft and Azure environments.
The exam covers 4 domains: Describe the capabilities of Microsoft Entra, Describe the capabilities of Microsoft security solutions, Describe the capabilities of Microsoft compliance solutions, Describe the concepts of security, compliance, and identity. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Microsoft SC-900 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.