Courseiva

Microsoft Security, Compliance, and Identity Fundamentals SC-900 (SC-900) — Questions 1276–1279

1279 questions total · 18pages · All types, answers revealed

Page 17

Page 18 of 18

1276
MCQhard

Refer to the exhibit. A security analyst runs the KQL query in Microsoft Defender for Endpoint. The query returns no results. What is the most likely cause?

A.The device has a risk score of zero
B.The device runs macOS
C.The analyst lacks permissions to view the device
D.The device is not onboarded to Defender for Endpoint
AnswerD

The DeviceInfo table in Microsoft Defender for Endpoint exclusively stores records for devices that have been successfully onboarded and are actively reporting sensor data. If a device has not completed the onboarding process, or if its Defender for Endpoint sensor is not functioning or reporting, no corresponding entry will exist within the DeviceInfo table. Therefore, a KQL query attempting to retrieve information for such a device would correctly return an empty result set, indicating the absence of that device's data in the platform.

Why this answer

The KQL query in Microsoft Defender for Endpoint returns no results because the device is not onboarded. Defender for Endpoint can only report on devices that have been enrolled and are actively sending telemetry. If a device is not onboarded, no data exists for it in the security portal, so any query targeting that device will return empty results.

Exam trap

The trap here is that candidates may think a missing result is due to permissions or OS incompatibility, but the core prerequisite for any Defender for Endpoint query is that the device must be onboarded and actively reporting telemetry.

How to eliminate wrong answers

Option A is wrong because a risk score of zero does not prevent a query from returning results; it simply indicates no detected threats, but the device would still appear in query results. Option B is wrong because Microsoft Defender for Endpoint supports macOS devices, and a macOS device can be onboarded and queried successfully. Option C is wrong because if the analyst lacked permissions, the query would typically return an access denied error or no results at all, but the most common and direct cause for no results when a device is known to exist is that it has never been onboarded.

1277
MCQeasy

Refer to the exhibit. The JSON shows a Conditional Access policy. What is the primary purpose of this policy?

A.Block legacy authentication protocols
B.Require MFA for all applications
C.Disable the policy for emergency access
D.Allow only iOS devices
AnswerA

The policy's "Client apps" condition is configured to target "Other clients," which is the category encompassing applications that utilize legacy authentication protocols such as POP, IMAP, SMTP, and older versions of Office clients that do not support modern authentication. By combining this specific client app condition with a "Block access" grant control, the policy effectively prevents users from authenticating via these less secure, legacy protocols. This significantly enhances security by forcing the use of modern authentication methods.

Why this answer

The policy targets 'Block legacy authentication' by applying a condition that blocks authentication attempts using legacy protocols (e.g., POP3, IMAP4, SMTP, ActiveSync) which do not support modern authentication methods like MFA. This is a common security measure to prevent credential-stuffing and password-spray attacks that exploit the lack of MFA enforcement in legacy protocols.

Exam trap

The trap here is that candidates often confuse 'blocking legacy authentication' with 'requiring MFA' — the policy blocks the protocol entirely rather than prompting for an additional factor, which is a distinct control in Conditional Access.

How to eliminate wrong answers

Option B is wrong because the policy does not require MFA; it explicitly blocks authentication entirely, not just requiring an additional factor. Option C is wrong because the policy does not include any exclusion for emergency access accounts (e.g., break-glass accounts) — it applies to all users unless a separate exclusion is configured. Option D is wrong because the policy does not filter by device platform (iOS) — it targets authentication protocol, not device type.

1278
MCQmedium

A global company uses Microsoft Teams and SharePoint Online. They need to automatically detect and prevent sharing of intellectual property files containing 'Project X' with external users. What should they configure?

A.Microsoft Entra ID Access Reviews
B.Microsoft Purview Sensitivity Labels
C.Microsoft Purview Data Loss Prevention policy for SharePoint and OneDrive
D.Microsoft Defender for Cloud Apps Session Policy
AnswerC

Microsoft Purview Data Loss Prevention (DLP) policies for SharePoint and OneDrive are specifically engineered to identify, monitor, and protect sensitive information across these services. These policies utilize sensitive information types (SITs), keywords, and trainable classifiers to detect specific data patterns, such as credit card numbers or national IDs, and can then automatically block sharing, notify administrators, or apply encryption to prevent unauthorized data exfiltration.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies for SharePoint and OneDrive can be configured to automatically detect files containing sensitive content (e.g., 'Project X') and block sharing with external users. DLP policies inspect content at rest and during sharing actions, applying rules to prevent unauthorized external access.

Exam trap

The trap here is that candidates often confuse Sensitivity Labels (which classify and protect data) with DLP policies (which enforce actions like blocking sharing), but DLP is the correct tool for automatic detection and prevention of specific content sharing with external users.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Access Reviews are used for periodic review of user access rights, not for real-time detection and prevention of content sharing. Option B is wrong because Microsoft Purview Sensitivity Labels classify and protect data with encryption or markings but do not automatically detect and block sharing of specific content like 'Project X' with external users; they require manual or automated labeling but lack the policy-driven blocking of DLP. Option D is wrong because Microsoft Defender for Cloud Apps Session Policy controls user sessions in real-time (e.g., read-only access) but does not natively detect and block sharing of intellectual property files based on content inspection; it focuses on app-level access controls rather than content-based DLP.

1279
MCQmedium

Your company is implementing a hybrid identity solution with Microsoft Entra ID. Users report that they can sign in to Microsoft 365 but cannot access on-premises applications that are configured for integrated Windows authentication. You need to ensure seamless single sign-on (SSO) for both cloud and on-premises resources. What should you implement?

A.Implement Passthrough Authentication.
B.Deploy Active Directory Federation Services (AD FS).
C.Enable Microsoft Entra seamless SSO.
D.Configure password hash synchronization.
AnswerC

Enabling Microsoft Entra seamless SSO is the correct solution as it provides automatic sign-in for users on corporate domain-joined devices connected to the corporate network. It achieves this by leveraging Kerberos, allowing users to silently authenticate to both cloud-based Microsoft Entra ID applications and on-premises applications configured for Integrated Windows Authentication (IWA) without re-entering their credentials. This mechanism ensures a true single sign-on experience across the hybrid environment.

Why this answer

Microsoft Entra seamless SSO (Seamless SSO) is the correct choice because it automatically signs users in when they are on corporate devices connected to the corporate network, using Kerberos delegation to provide single sign-on for both cloud resources (like Microsoft 365) and on-premises applications configured for Integrated Windows Authentication (IWA). This eliminates the need for users to re-enter credentials when accessing on-premises apps after authenticating to the cloud.

Exam trap

The trap here is that candidates often confuse Passthrough Authentication or password hash synchronization with providing SSO for on-premises applications, but neither includes the Kerberos delegation required for Integrated Windows Authentication, which is the specific need in this scenario.

How to eliminate wrong answers

Option A is wrong because Passthrough Authentication validates passwords against on-premises Active Directory but does not provide the Kerberos-based SSO needed for Integrated Windows Authentication to on-premises applications; it only handles cloud authentication. Option B is wrong because Active Directory Federation Services (AD FS) is a more complex, on-premises federation solution that can provide SSO, but it is overkill for this scenario and not the simplest or recommended approach when Seamless SSO can achieve the same goal with less infrastructure. Option D is wrong because password hash synchronization only synchronizes password hashes to the cloud for cloud authentication and does not enable Kerberos-based SSO for on-premises IWA applications.

Page 17

Page 18 of 18