Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A user reports that they cannot access a sensitive document in SharePoint Online. The administrator checks the document's permissions and sees that the user is not listed directly, but a group they belong to has been granted access. Which identity concept describes this scenario?

⚠ Common exam trap

SC-900 often tests whether candidates can distinguish group-based access control (inheritance via membership) from RBAC (role assignment) and ABAC (attribute-driven, dynamic evaluation) — candidates pick RBAC because both involve granting access, but RBAC is role-centric, not membership-centric.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Group-based access control

The scenario describes group-based access control: the user is not directly granted permission, but inherits access because a security group they belong to has been granted access to the document. This is the standard mechanism in SharePoint Online and Microsoft 365 for scaling permissions management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Role-based access control (RBAC)

    Why it's wrong here

    Role-based access control (RBAC) is a method of restricting network access based on the roles of individual users within an enterprise. In this scenario, access is granted through group membership, not a role-based assignment per se, but RBAC is a subset of group-based access control.

  • ✗

    Privilege escalation

    Why it's wrong here

    Privilege escalation is the act of exploiting a bug, design flaw, or configuration oversight in an operating system or software application to gain elevated access to resources that are normally protected from an application or user. This is not described in the scenario.

  • ✓

    Group-based access control

    Why this is correct

    Group-based access control allows permissions to be assigned to groups rather than individuals, simplifying management. This directly matches the scenario where a user gains access because they belong to a group that has been granted access.

  • ✗

    Attribute-based access control (ABAC)

    Why it's wrong here

    ABAC grants access through policies evaluating attributes such as department, clearance or resource labels, not group membership. Here the group's entry on the access control list is the granting mechanism, which is role-based access control. ABAC would be correct where access decisions depend on dynamic attribute conditions rather than static group assignment.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.