Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A company uses Microsoft 365 E5. An employee's corporate laptop is infected with keylogging malware that captures the employee's credentials. The attacker uses these credentials to sign in to Exchange Online and forward sensitive emails to an external account. Under the shared responsibility model, who is primarily responsible for the security incident?

⚠ Common exam trap

It's easy for candidates to assume Microsoft is fully responsible for all security in a SaaS model, overlooking that the customer must secure user devices, enforce strong authentication (like MFA), and manage account hygiene.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The customer is responsible because they control user devices, accounts, and access policies.

Under the shared responsibility model, the customer is responsible for securing user devices, managing user accounts, and configuring access policies. In this scenario, the keylogging malware on the employee's corporate laptop is a customer-side endpoint security issue, and the attacker used stolen credentials to access Exchange Online. Microsoft is responsible for the security of the cloud infrastructure (e.g., physical data centers, network, and hypervisor), but not for threats originating from compromised customer-managed devices or user accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft is responsible because they provide the cloud service and must protect against all threats.

    Why it's wrong here

    Microsoft's responsibility under the Shared Responsibility Model for SaaS is to secure the underlying infrastructure, network controls, and the application itself. They protect the cloud from threats to its foundational components, but not necessarily customer data within the cloud if the customer misconfigures access or fails to secure their endpoints. Therefore, Microsoft does not protect against all threats, especially those originating from customer-managed areas like identities and devices.

  • The customer is responsible because they control user devices, accounts, and access policies.

    Why this is correct

    The customer organization retains primary responsibility for securing their user identities, endpoint devices like laptops, and the data stored within Microsoft 365. This includes implementing strong authentication policies, managing device compliance, configuring data loss prevention, and enforcing access controls. These elements fall directly under the customer's administrative control and configuration within the cloud service.

  • Both Microsoft and the customer share equal responsibility for all layers of the service.

    Why it's wrong here

    While responsibility is indeed shared in cloud computing, it is not equally distributed across all layers of the service. The Shared Responsibility Model clearly delineates specific areas where Microsoft is accountable (e.g., physical infrastructure, network, hypervisor) and distinct areas where the customer is accountable (e.g., data, identities, devices, configurations), making an "equal" split for all layers inaccurate.

  • Neither party is responsible because the employee bypassed security controls.

    Why it's wrong here

    An employee bypassing security controls does not absolve the customer organization of its fundamental security responsibilities. The customer is accountable for implementing robust security policies, deploying endpoint protection, enforcing multi-factor authentication, and providing user training to prevent such bypasses, as well as for monitoring and responding to incidents that arise from user actions. The organization must design controls to mitigate human error or malicious intent.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.