Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A user logs into a company's financial application using their Microsoft Entra ID credentials. After successful sign-in, the application displays a dashboard with data for only the regions the user is authorized to manage. Which two security concepts are demonstrated in this scenario? (Select all that apply.)

⚠ Common exam trap

Watch out — candidates often confuse authentication (verifying identity) with authorization (granting permissions), and may incorrectly select accounting or non-repudiation because they associate logging in with tracking or non-denial, but the scenario explicitly describes identity verification and access restriction, not logging or signature-based proof.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Authentication

Authentication is demonstrated because the user proves their identity by logging in with Microsoft Entra ID credentials, confirming they are who they claim to be. Authorization is demonstrated because after authentication, the application restricts the dashboard to show only data for regions the user is permitted to manage, enforcing access control based on assigned permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Authentication

    Why this is correct

    When a user enters credentials to access a financial application, the system performs authentication. This crucial initial step verifies the user's claimed identity by comparing the provided username and password against stored records. Successful authentication confirms 'who' the user is, granting them entry to the system.

  • Authorization

    Why this is correct

    Following successful authentication, authorization determines the specific resources and actions an authenticated user is permitted to access within the financial application. It involves checking the user's assigned roles and permissions against the requested operation or data. This process ensures that even an authenticated user can only perform tasks and view information they are explicitly allowed to, enforcing the principle of least privilege.

  • Accounting

    Why it's wrong here

    Accounting, often referred to as auditing, involves logging and tracking user activities and resource consumption *after* a user has been authenticated and authorized. This process records details such as what resources were accessed, when, and by whom, for security analysis, compliance, and billing purposes. It does not pertain to the initial verification of identity or the granting of access permissions.

    When this WOULD be correct

    A question that asks: 'An organization needs to track which users accessed sensitive data and when. Which security concept ensures this tracking?' would make Accounting correct.

  • Non-repudiation

    Why it's wrong here

    Non-repudiation is a security service that ensures a party cannot deny having performed a specific action, such as sending a message or executing a transaction. It typically relies on cryptographic mechanisms like digital signatures to provide irrefutable proof of origin and integrity. While critical for secure transactions within the application, it is not the primary mechanism involved in the initial login process itself, which focuses on identity verification.

    When this WOULD be correct

    A user submits a purchase order using a digital signature. Later, the user claims they never submitted it. Non-repudiation would be the correct answer if the question asked which security concept prevents the user from denying the submission.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

AuthenticationCorrect answer

Why this is correct

When a user enters credentials to access a financial application, the system performs authentication. This crucial initial step verifies the user's claimed identity by comparing the provided username and password against stored records. Successful authentication confirms 'who' the user is, granting them entry to the system.

AccountingWrong answer — click to see why

Why this is wrong here

Accounting refers to tracking user activities for auditing or billing purposes, but the scenario only describes logging in and viewing authorized data, not recording or reviewing actions.

★ When this WOULD be the correct answer

A question that asks: 'An organization needs to track which users accessed sensitive data and when. Which security concept ensures this tracking?' would make Accounting correct.

Why candidates choose this

Candidates may confuse 'accounting' with 'account' (as in user account) or think that logging in implies some form of activity tracking, but accounting specifically involves logging and reviewing actions, not just authentication or authorization.

Non-repudiationWrong answer — click to see why

Why this is wrong here

Non-repudiation ensures that a user cannot deny having performed an action, typically through digital signatures or audit logs. This scenario only involves logging in and viewing data, with no action that requires proof of origin or integrity.

★ When this WOULD be the correct answer

A user submits a purchase order using a digital signature. Later, the user claims they never submitted it. Non-repudiation would be the correct answer if the question asked which security concept prevents the user from denying the submission.

Why candidates choose this

Candidates may confuse non-repudiation with authentication or authorization because all involve identity and access, but non-repudiation specifically deals with undeniable proof of actions, not just verifying identity or permissions.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.