SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A user reports that they cannot access a sensitive document in SharePoint Online. The administrator checks the document's permissions and sees that the user is not listed directly, but a group they belong to has been granted access. Which identity concept describes this scenario?
⚠ Common exam trap
SC-900 often tests whether candidates can distinguish group-based access control (inheritance via membership) from RBAC (role assignment) and ABAC (attribute-driven, dynamic evaluation) — candidates pick RBAC because both involve granting access, but RBAC is role-centric, not membership-centric.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Group-based access control
The scenario describes group-based access control: the user is not directly granted permission, but inherits access because a security group they belong to has been granted access to the document. This is the standard mechanism in SharePoint Online and Microsoft 365 for scaling permissions management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Role-based access control (RBAC)
Why it's wrong here
Role-based access control (RBAC) is a method of restricting network access based on the roles of individual users within an enterprise. In this scenario, access is granted through group membership, not a role-based assignment per se, but RBAC is a subset of group-based access control.
- ✗
Privilege escalation
Why it's wrong here
Privilege escalation is the act of exploiting a bug, design flaw, or configuration oversight in an operating system or software application to gain elevated access to resources that are normally protected from an application or user. This is not described in the scenario.
- ✓
Group-based access control
Why this is correct
Group-based access control allows permissions to be assigned to groups rather than individuals, simplifying management. This directly matches the scenario where a user gains access because they belong to a group that has been granted access.
- ✗
Attribute-based access control (ABAC)
Why it's wrong here
ABAC grants access through policies evaluating attributes such as department, clearance or resource labels, not group membership. Here the group's entry on the access control list is the granting mechanism, which is role-based access control. ABAC would be correct where access decisions depend on dynamic attribute conditions rather than static group assignment.
Go deeper
Related to this question
Learn chapter
Cross-Tenant Access Settings
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
Key term
Security group
A security group is a virtual firewall that controls inbound and outbound traffic to AWS resources, such as EC2 instances, based on defined rules.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.