SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A new security administrator is learning about core security concepts. They ask you to explain the difference between authentication and authorization. Which statement best describes authorization?
⚠ Common exam trap
Watch out — candidates often confuse authentication, which verifies identity, with authorization, which determines access rights after identity is established.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It is the process of determining what resources an authenticated user is permitted to access.
Authorization is the process of determining what an authenticated user is allowed to do. After authentication verifies identity, authorization checks permissions and policies to grant or deny access to resources. The other options describe authentication, encryption, and auditing, which are distinct security concepts. Understanding this distinction is fundamental in Microsoft identity and access management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It is the process of verifying a user's identity by checking their credentials.
Why it's wrong here
This describes authentication, not authorization. Authentication confirms who a user is by validating credentials such as a password, certificate, or biometric. In this scenario, the administrator needs to understand authorization, which occurs after identity is proven and determines what resources the user can access. Confusing the two concepts is a common mistake, but this option specifically defines the wrong term.
- ✗
It is the process of auditing and logging user activity for compliance purposes.
Why it's wrong here
Auditing and logging record user actions but do not define authorization. Authorization is the decision-making process that grants or denies access to resources. Logging can capture the results of authorization decisions, but it is a monitoring function, not the access control mechanism itself. This option confuses a detective control with the preventive control that authorization represents.
- ✓
It is the process of determining what resources an authenticated user is permitted to access.
Why this is correct
Authorization determines the level of access an authenticated identity has to resources. After authentication proves identity, authorization evaluates permissions, group memberships, and policies to allow or deny actions. In this scenario, explaining that authorization controls what a user can do accurately distinguishes it from authentication, which only confirms identity. This definition aligns with Microsoft security fundamentals terminology.
- ✗
It is the process of encrypting data both at rest and in transit.
Why it's wrong here
Encryption protects data confidentiality but is not related to authorization. Authorization is about access control decisions after authentication. Encryption does not determine which resources a user can access; it only makes data unreadable to unauthorized parties. This option describes a data protection mechanism, not an identity and access concept, so it does not answer the question about authorization.
Go deeper
Related to this question
Learn chapter
Named Locations in Conditional Access
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
Key term
Identity and access management
Identity and access management (IAM) is the security discipline that ensures the right individuals access the right resources at the right times for the right reasons.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.