Courseiva

Microsoft Security, Compliance, and Identity Fundamentals SC-900 (SC-900) — Questions 526–600

1279 questions total · 18pages · All types, answers revealed

Page 7

Page 8 of 18

Page 9
526
Multi-Selecteasy

Which TWO features are included in Microsoft Entra ID P2 licensing?

Select 2 answers
A.Passwordless authentication
B.Multifactor authentication (MFA)
C.Single sign-on (SSO) to SaaS apps
D.Microsoft Entra Privileged Identity Management
E.Microsoft Entra Identity Protection
AnswersD, E

Microsoft Entra Privileged Identity Management (PIM) is a robust feature designed to manage, control, and monitor access to critical resources within Microsoft Entra ID, Azure, and other Microsoft Online Services. It provides just-in-time (JIT) and just-enough-administration (JEA) access, significantly reducing the attack surface by limiting the duration and scope of elevated permissions. This advanced capability for privileged access governance is a cornerstone feature of Microsoft Entra ID P2.

Why this answer

Microsoft Entra ID P2 includes Microsoft Entra Privileged Identity Management (D), which provides just-in-time privileged role activation, access reviews, and approval workflows for administrative roles, and Microsoft Entra Identity Protection (E), which delivers risk-based Conditional Access policies, user and sign-in risk detection, and automated remediation of risky identities. These two capabilities are the distinguishing features that separate Entra ID P2 from P1, since P1 already covers the baseline identity features. Passwordless authentication (A), multifactor authentication (B), and single sign-on to SaaS apps (C) are all included in Entra ID P1 (and in large part in the free tier), so they are not exclusive to or introduced by P2 licensing.

Exam trap

The trap here is that candidates often confuse features available in Microsoft Entra ID P1 (like MFA, SSO, and passwordless) with P2-exclusive features, forgetting that P2 adds only advanced identity protection and privileged identity management on top of P1.

527
MCQmedium

A company uses Microsoft Teams and wants to ensure that messages containing offensive language are flagged for review. Which Microsoft Purview solution should be used?

A.Microsoft Purview Information Barriers
B.Microsoft Purview Communication Compliance
C.Microsoft Purview Data Loss Prevention
D.Microsoft Purview Audit
AnswerB

Microsoft Purview Communication Compliance uses machine-learning classifiers to detect offensive language in Microsoft Teams messages, then routes flagged items to reviewers for triage and remediation. This directly satisfies the requirement to flag offensive content for review, unlike retention or eDiscovery solutions, which preserve or search content without policy-based offensive-language detection.

Why this answer

Microsoft Purview Communication Compliance is designed to detect and flag messages containing offensive language, harassment, or other policy violations in Microsoft Teams, Exchange Online, and Yammer. It uses customizable policies and machine learning classifiers to automatically review communications and route flagged items for human review, making it the correct solution for this requirement.

Exam trap

The trap here is that candidates often confuse Communication Compliance with Data Loss Prevention, mistakenly thinking DLP handles offensive content when it actually only protects sensitive data, not language policy violations.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Information Barriers restrict communication and collaboration between specific groups (e.g., to prevent conflicts of interest), but they do not analyze message content for offensive language. Option C is wrong because Microsoft Purview Data Loss Prevention (DLP) focuses on preventing the accidental sharing of sensitive data (e.g., credit card numbers, PII) and does not detect offensive language. Option D is wrong because Microsoft Purview Audit logs user and admin activities for compliance and forensic investigation, but it does not proactively scan or flag message content for offensive language.

528
Drag & Dropmedium

Order the steps to respond to a data breach using Microsoft 365 Defender incident response.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Incident response typically starts with identification, isolation, investigation, containment, then remediation.

529
MCQmedium

Your organization is using Microsoft Sentinel as a SIEM. You want to automatically respond to a high-severity incident by opening a ticket in ServiceNow and notifying the security team via email. What should you create?

A.An automation rule
B.A workbook
C.An analytics rule
D.A watchlist
AnswerA

Automation rules are the core mechanism within Microsoft Sentinel for orchestrating and automating incident response workflows. They are designed to automatically apply actions to incidents upon creation or update, based on specified conditions like severity, tactics, or associated entities. These rules can trigger playbooks, which are logic apps that perform complex tasks such as integrating with external systems like ServiceNow for ticketing, sending email notifications to security teams, or isolating compromised hosts. This capability makes automation rules essential for efficient SOAR operations.

Why this answer

Automation rules in Microsoft Sentinel can be configured to trigger automated responses when an incident is created, such as running a playbook (a Logic App) that opens a ticket in ServiceNow and sends an email notification. Option B is wrong because workbooks are for visualization and reporting, not automation. Option C is wrong because analytics rules generate alerts/incidents based on data queries, but they do not directly perform response actions; instead, automation rules handle the response.

Option D is wrong because watchlists are collections of data for correlation and enrichment, not for automated response.

530
Multi-Selectmedium

Which TWO Microsoft Purview solutions can be used to protect sensitive data in Microsoft Teams?

Select 2 answers
A.Information barriers
B.Communication compliance
C.Data Loss Prevention (DLP)
D.Sensitivity labels
E.eDiscovery
AnswersC, D

DLP policies evaluate Teams chat and channel messages for sensitive information types, blocking or warning on sharing. This protects sensitive data in Teams because policy tips and enforcement act at the point of message transmission, satisfying the requirement to safeguard content within that workload.

Why this answer

Data Loss Prevention (DLP) is correct because Microsoft Purview DLP policies can be scoped to Microsoft Teams chat and channel messages, detecting sensitive information types (for example, credit card or Social Security numbers) and taking protective actions such as blocking the message or generating alerts. Sensitivity labels are correct because they can be applied to Teams sites, channels, and files shared in Teams, and they enforce protection such as encryption and access restrictions that travel with the content. Information barriers are not the best fit here because they restrict communication between groups rather than protect sensitive data content itself.

Communication compliance is designed to detect and remediate inappropriate or risky communications for compliance review, not to apply data protection controls. eDiscovery is used for identifying, preserving, and collecting content for legal or investigative purposes, not for preventing sensitive data exposure.

Exam trap

The trap here is that candidates often confuse Information barriers (which control who can communicate) with DLP (which controls what data can be shared), or they mistakenly think Communication compliance is a protective measure when it is actually a detective and review tool.

531
MCQmedium

Your organization uses Microsoft Entra ID for identity management. You need to enable users to sign in using a QR code from the Microsoft Authenticator app. Which Microsoft Entra feature should you configure?

A.FIDO2 security keys
B.Temporary Access Pass
C.Passwordless sign-in with Microsoft Authenticator
D.My Security-info (https://aka.ms/mysecurityinfo)
AnswerC

Passwordless sign-in with Microsoft Authenticator is a core feature that allows users to sign into Microsoft Entra ID-connected applications without entering a password. When a user attempts to sign in, they are presented with an option to scan a QR code displayed on the sign-in screen using the Microsoft Authenticator app on their mobile device. The app then securely approves the sign-in request, often after a number match confirmation, providing a seamless and secure authentication experience.

Why this answer

The Microsoft Authenticator app supports passwordless sign-in by allowing users to approve a notification or scan a QR code from the sign-in screen. This feature eliminates the need for a password and relies on the Authenticator app as a primary authentication method, which is configured under the Passwordless sign-in with Microsoft Authenticator option in Entra ID.

Exam trap

The trap here is that candidates confuse the QR code scanning capability of the Authenticator app with FIDO2 security keys, but the question specifically asks about using the Microsoft Authenticator app, not a separate hardware device.

How to eliminate wrong answers

Option A is wrong because FIDO2 security keys are hardware-based passwordless credentials that use public-key cryptography, not QR codes from the Microsoft Authenticator app. Option B is wrong because Temporary Access Pass is a time-limited passcode used for onboarding or recovery scenarios, not for QR-code-based sign-in. Option D is wrong because My Security-info (https://aka.ms/mysecurityinfo) is a user portal for managing authentication methods, not a feature that enables QR-code sign-in.

532
MCQhard

A company is implementing Microsoft Purview Communication Compliance to detect inappropriate messages. They need to monitor Microsoft Teams channel messages and chat messages for potential policy violations. Which configuration is required?

A.Enable Microsoft Purview Data Loss Prevention (DLP) policies for Teams.
B.Set up an Exchange Online retention policy to retain Teams messages.
C.Deploy a third-party archiving solution for Teams messages.
D.Configure a Communication Compliance policy that includes Teams messages as the supervised communication channel.
AnswerD

Communication Compliance policies define supervised communication channels, and Microsoft Teams chat and channel messages must be selected as a supervised channel for those messages to be scanned. Without adding Teams, the policy only covers Exchange email and other configured sources.

Why this answer

Communication Compliance in Microsoft Purview is configured by creating a policy that specifies the supervised communication channels, and Microsoft Teams chats and channel messages are selectable channels within that policy. Enabling Teams as a supervised channel is the required configuration to detect inappropriate messages in Teams. DLP, retention, and third-party archiving address different compliance goals.

Exam trap

SC-900 often tests whether candidates confuse DLP (protect sensitive data) with Communication Compliance (detect inappropriate communications); picking DLP for a harassment-detection scenario is the classic wrong answer.

How to eliminate wrong answers

Option A is wrong because DLP policies for Teams focus on preventing sharing of sensitive information (for example, credit card numbers) rather than detecting inappropriate or harassing language, which is the domain of Communication Compliance. Option B is wrong because an Exchange Online retention policy governs how long Teams messages are kept, not whether their content is analyzed for policy violations. Option C is wrong because a third-party archiving solution captures and stores messages for eDiscovery but does not natively perform the machine-learning-based classification that Communication Compliance provides.

533
MCQmedium

Your organization uses Microsoft Entra ID for identity management. You need to implement a solution that allows users to sign in using their social media accounts, such as Google or Facebook. What should you configure?

A.Microsoft Authenticator app for passwordless sign-in
B.Privileged Identity Management
C.External identities (B2B) with social identity providers
D.Self-service password reset
AnswerC

Microsoft Entra External ID, specifically its B2B collaboration capabilities, is the correct solution for enabling external users to access an organization's resources using their existing social identity provider accounts. This feature allows organizations to invite guests who can then sign in using their Google, Facebook, or other configured social accounts, federating these external identities with the inviting Microsoft Entra tenant. It streamlines access for partners and customers without requiring them to create new credentials.

Why this answer

External identities (B2B) in Microsoft Entra ID allow you to configure social identity providers (e.g., Google, Facebook) as federation sources. This enables users to sign in with their existing social accounts by leveraging OAuth 2.0 and OpenID Connect protocols, without needing to create a separate Microsoft account.

Exam trap

The trap here is that candidates confuse 'External identities (B2B) with social identity providers' with 'B2C' or think that passwordless methods like Authenticator can be used to bring in external social users, when in fact Authenticator only works for users already in the Entra ID tenant.

How to eliminate wrong answers

Option A is wrong because the Microsoft Authenticator app for passwordless sign-in is a method for authenticating existing Entra ID users via phone-based approval or biometrics, not for federating external social identity providers. Option B is wrong because Privileged Identity Management (PIM) is a tool for managing, controlling, and monitoring access to privileged roles within Entra ID, not for configuring external identity providers. Option D is wrong because self-service password reset (SSPR) allows users to reset their own passwords for their Entra ID accounts, but it does not enable sign-in using external social identities.

534
MCQhard

A user logs into a corporate laptop by inserting a smart card and entering a PIN. The user then attempts to open a confidential folder. The operating system checks the user's access rights and denies access. Which security concepts are demonstrated in this scenario?

A.Identification and authorization
B.Authentication and authorization
C.Authentication and accounting
D.Identification and authentication
AnswerB

This option is correct because the user's insertion of a smart card and input of a PIN constitute a multi-factor authentication process, verifying their claimed identity. Following successful authentication, the operating system then performs an authorization check, determining whether the authenticated user has the necessary permissions to access the requested folder. The denial of access clearly demonstrates an authorization decision based on established access controls.

Why this answer

The scenario demonstrates authentication (verifying the user's identity via smart card + PIN) and authorization (the OS checking access rights and denying access to the folder). Authentication confirms who the user is, while authorization determines what resources they can access. Option B correctly pairs these two concepts.

Exam trap

The trap here is that candidates confuse 'identification' with 'authentication' — the smart card + PIN is a multi-factor authentication process, not merely identification, and the access check is authorization, not accounting or identification.

How to eliminate wrong answers

Option A is wrong because identification alone (e.g., presenting a username) is not sufficient; the scenario includes a PIN and smart card, which are authentication factors, and the access check is authorization, not just identification. Option C is wrong because accounting (tracking resource usage, e.g., logging or auditing) is not demonstrated; no logs or usage records are mentioned. Option D is wrong because identification (e.g., claiming an identity) is not explicitly shown; the user authenticates via smart card + PIN, and the access check is authorization, not just authentication.

535
MCQmedium

Refer to the exhibit. A user reports being unable to access Exchange Online from their personal laptop. The sign-in log shows failure due to device non-compliance. What should you configure to allow access while maintaining security?

A.Create a Conditional Access policy requiring compliant device
B.Reset the user's password
C.Block all personal devices
D.Enable MFA for the user
AnswerA

Creating a Conditional Access policy that requires a compliant device directly addresses access issues stemming from device non-compliance. This policy evaluates the device's security posture, as determined by an MDM solution like Microsoft Intune, ensuring it meets predefined organizational security standards (e.g., OS version, encryption, antivirus status). Access to protected resources is then granted only if the device is marked as compliant, thereby enforcing a secure endpoint environment.

Why this answer

The sign-in log indicates the failure is due to device non-compliance, meaning the user's personal laptop does not meet your organization's compliance policies (e.g., missing antivirus, encryption, or required updates). Creating a Conditional Access policy that requires a compliant device will block access from non-compliant devices while allowing access from compliant ones, maintaining security by enforcing device health checks before granting access to Exchange Online.

Exam trap

The trap here is that candidates often confuse device compliance with authentication factors like MFA or password resets, but the sign-in log explicitly states the failure is due to device non-compliance, so the solution must enforce device health, not just user identity verification.

How to eliminate wrong answers

Option B is wrong because resetting the user's password addresses credential compromise, not device compliance; the failure is due to the device not meeting compliance requirements, not an incorrect password. Option C is wrong because blocking all personal devices is overly restrictive and not necessary; Conditional Access can selectively allow compliant personal devices while blocking non-compliant ones, preserving user productivity. Option D is wrong because enabling MFA strengthens authentication but does not enforce device compliance; the sign-in failure is specifically due to device non-compliance, not a lack of multi-factor authentication.

536
MCQhard

A company needs to provide a developer with temporary, time-bound administrative access to Azure resources to debug a production issue. The access must require approval from the manager and automatically expire after 4 hours. Which Microsoft Entra capability should they use?

A.Privileged Identity Management (PIM)
B.Conditional Access
C.Identity Protection
D.Entitlement Management
AnswerA

Privileged Identity Management (PIM) in Microsoft Entra ID Governance is specifically designed to manage, control, and monitor access to important resources. It enables just-in-time (JIT) activation of privileged roles, allowing users to activate administrative permissions only when needed and for a predefined, limited duration. This includes requiring approval for activation and providing comprehensive audit trails, directly addressing the requirement for temporary, time-bound administrative access.

Why this answer

Privileged Identity Management (PIM) provides just-in-time (JIT) privileged access to Azure resources with time-bound activation, approval workflows, and automatic expiration. This directly matches the requirement for temporary, manager-approved administrative access that expires after 4 hours.

Exam trap

The trap here is confusing Entitlement Management (which manages access to apps/groups via access packages) with PIM (which manages time-bound role activation for Azure resources), leading candidates to pick D when the scenario explicitly requires Azure resource administrative access with automatic expiration.

How to eliminate wrong answers

Option B (Conditional Access) is wrong because it enforces access policies based on signals like location or device compliance, not time-bound role activation with approval. Option C (Identity Protection) is wrong because it detects and remediates identity-based risks like leaked credentials, not manages privileged access. Option D (Entitlement Management) is wrong because it governs access to applications and groups via access packages, not Azure resource roles with automatic expiration.

537
MCQmedium

A company uses Microsoft Purview Compliance Manager to improve their compliance posture. They are preparing for a SOC 2 audit and need to score compliance with SOC 2 controls, track improvement actions, and assign tasks to responsible teams. Which component of Compliance Manager should they use to assign and track specific actions to improve their compliance score?

A.Assessment
B.Control
C.Improvement action
D.Template
AnswerC

Improvement actions are the discrete tasks Compliance Manager generates against assessed controls; each can be assigned to an owner, given a due date and tracked to completion, which directly raises the compliance score for the SOC 2 assessment.

Why this answer

Improvement actions in Compliance Manager are the specific, actionable tasks that directly impact your compliance score. They represent the steps you need to take (e.g., configuring a policy, enabling logging) to satisfy a control. By assigning these actions to responsible teams and tracking their completion status, you can systematically improve your score and demonstrate progress during a SOC 2 audit.

Exam trap

The trap here is that candidates confuse 'Control' (the requirement) with 'Improvement action' (the task to meet the requirement), leading them to select B, even though controls are not directly assignable or trackable as individual tasks.

How to eliminate wrong answers

Option A is wrong because an Assessment is a container that groups controls from a specific regulation (like SOC 2) and tracks your overall compliance score, but it does not provide the granular, assignable tasks needed to drive improvement. Option B is wrong because a Control is a specific requirement from the regulation (e.g., 'Access must be logged'), but it is not the actionable item you assign to a team; the control is satisfied by completing one or more improvement actions. Option D is wrong because a Template is a reusable blueprint that defines the controls and improvement actions for a regulation (e.g., SOC 2 template), but it is not the mechanism for assigning and tracking individual tasks.

538
Multi-Selecteasy

Which TWO of the following are capabilities of Microsoft Purview Data Loss Prevention?

Select 2 answers
A.Define retention periods for documents.
B.Search for content in Exchange Online mailboxes.
C.Block sharing of sensitive data via email.
D.Automatically apply sensitivity labels to content.
E.Provide policy tips to users when they attempt to share sensitive data.
AnswersC, E

Microsoft Purview Data Loss Prevention (DLP) policies are specifically designed to identify and prevent the unauthorized sharing of sensitive information, including via email. These policies can detect specific sensitive information types, such as credit card numbers or national ID numbers, within email content or attachments. Upon detection, a configured DLP policy can automatically block the email from being sent, thereby preventing the exfiltration of critical data.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is designed to detect and prevent the accidental or intentional sharing of sensitive information. Option C is correct because DLP policies can block the sharing of sensitive data via email by inspecting content in transit and applying actions such as blocking the message. Option E is correct because DLP can display policy tips to users in real time, warning them before they share sensitive data and allowing them to override the block with justification.

Exam trap

The trap here is that candidates confuse DLP with other Microsoft Purview solutions: they may think DLP defines retention periods (Records Management), searches content (eDiscovery), or applies sensitivity labels (Information Protection), when in fact DLP focuses on preventing data loss through monitoring and blocking actions, not on lifecycle management or labeling.

539
MCQhard

Your company is adopting a Zero Trust network architecture. You need to implement microsegmentation for workloads running in Azure. Which Azure service should you use?

A.Azure Network Security Groups (NSGs)
B.Azure Firewall
C.Azure App Service
D.Azure Front Door
AnswerA

Azure Network Security Groups (NSGs) are fundamental for implementing a Zero Trust network architecture by enabling microsegmentation. NSGs allow administrators to define granular inbound and outbound security rules that filter network traffic to and from Azure resources within a virtual network, such as VMs and subnets. This capability ensures that only explicitly authorized traffic can flow between specific workloads, enforcing the 'never trust, always verify' principle at the network layer and significantly reducing the attack surface.

Why this answer

Azure Network Security Groups (NSGs) are the correct service for implementing microsegmentation because they allow you to create granular, stateful filtering rules based on source/destination IP addresses, ports, and protocols at the subnet or individual virtual machine (NIC) level. This enables east-west traffic segmentation between workloads within the same virtual network, which is a core principle of Zero Trust network architecture.

Exam trap

The trap here is that candidates often confuse Azure Firewall (a perimeter security service) with NSGs (a microsegmentation tool), mistakenly thinking a centralized firewall can achieve the same east-west traffic isolation that NSGs provide at the subnet/NIC level.

How to eliminate wrong answers

Option B (Azure Firewall) is wrong because it is a centralized, stateful firewall as a service that operates at the network perimeter or between virtual networks, not at the individual workload or subnet level required for microsegmentation. Option C (Azure App Service) is wrong because it is a platform-as-a-service (PaaS) for hosting web applications and APIs, not a network security or segmentation tool. Option D (Azure Front Door) is wrong because it is a global, scalable entry point for web traffic using HTTP/HTTPS load balancing and application delivery, not a service for internal workload segmentation.

540
MCQhard

A company uses Microsoft Entra ID. They have a critical application that requires additional security. The security team wants to enforce multifactor authentication (MFA) for every access to the application, but they also want users to reauthenticate with MFA if a session lasts longer than 60 minutes, regardless of device compliance. Which Conditional Access control should the administrator configure?

A.Grant control: Require multifactor authentication
B.Session control: Sign-in frequency
C.Session control: Application enforced restrictions
D.Grant control: Require device to be marked as compliant
AnswerB

Sign-in frequency is a session control that forces reauthentication after a set interval, here 60 minutes, irrespective of device compliance state. MFA is then re-enforced at each reauthentication, matching the requirement for periodic MFA regardless of compliance.

Why this answer

The requirement to force reauthentication with MFA after a specific time period (60 minutes) is a session-level control, not a grant control. The 'Sign-in frequency' session control in Conditional Access allows administrators to define how often a user must reauthenticate, including re-prompting for MFA, regardless of device compliance. This directly meets the scenario's need for a time-based reauthentication policy.

Exam trap

The trap here is that candidates confuse 'Grant controls' (which enforce conditions at sign-in) with 'Session controls' (which manage behavior after sign-in), leading them to select 'Require multifactor authentication' instead of 'Sign-in frequency' for time-based reauthentication.

How to eliminate wrong answers

Option A is wrong because 'Grant control: Require multifactor authentication' enforces MFA at initial sign-in but does not enforce reauthentication after a session duration; it lacks the time-based re-prompting capability. Option C is wrong because 'Session control: Application enforced restrictions' relies on the application itself to enforce policies (e.g., via device-based conditional access in Exchange Online), not on Entra ID to force reauthentication after a fixed time. Option D is wrong because 'Grant control: Require device to be marked as compliant' checks device health at sign-in but does not enforce a session timeout or reauthentication frequency, and the scenario explicitly states 'regardless of device compliance'.

541
MCQeasy

A user reports they cannot access the company portal from their personal device. The device is not enrolled in Microsoft Intune. The admin wants to ensure only compliant devices can access corporate resources. What should the admin configure?

A.Conditional Access policy requiring device compliance
B.Enable password writeback
C.Enable Identity Protection sign-in risk policy
D.Microsoft Entra Privileged Identity Management
AnswerA

Conditional Access policies evaluate specific conditions, such as device state, before granting access to cloud applications like the company portal. By requiring a device to be marked as compliant by Microsoft Intune, these policies ensure that only devices meeting organizational security standards (e.g., OS version, encryption, antivirus) can access sensitive resources. This directly addresses a user's inability to access the portal if their device fails compliance checks, making it the correct solution.

Why this answer

A is correct because a Conditional Access policy can require device compliance before granting access to corporate resources. When the device is not enrolled in Microsoft Intune, it cannot report compliance status, so the policy blocks access. This ensures only managed, compliant devices can access the company portal.

Exam trap

The trap here is that candidates confuse device compliance policies with sign-in risk policies or identity governance features, mistakenly thinking risk-based controls or PIM can enforce device health, when only Conditional Access with Intune compliance can block non-enrolled personal devices.

How to eliminate wrong answers

Option B is wrong because password writeback is a feature for on-premises password synchronization to Entra ID, not for controlling device access. Option C is wrong because Identity Protection sign-in risk policy evaluates user sign-in risk (e.g., anonymous IP, leaked credentials), not device compliance. Option D is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation, not device-level access control.

542
Multi-Selecthard

A company wants to implement a Zero Trust security model. Which TWO of the following are core principles of Zero Trust?

Select 2 answers
A.Trust based on network location
B.Verify explicitly
C.Perimeter-based security
D.Implicit trust for internal users
E.Least privilege access
AnswersB, E

Verify explicitly is a core Zero Trust principle: every access request is authenticated and authorised using all available signals — identity, device, location and risk — before granting access. This satisfies the model's requirement to never trust implicitly based on network location alone.

Why this answer

Option B (Verify explicitly) is correct because Zero Trust requires every access request to be authenticated and authorized based on all available data points—user identity, device health, location, and workload—rather than assuming trust from network position. Option E (Least privilege access) is correct because Zero Trust limits user and workload access to only what is needed for the task, typically enforced through just-in-time and just-enough-access policies and micro-segmentation. Option A (Trust based on network location) is wrong because Zero Trust explicitly rejects the idea that being inside a corporate network grants trust.

Option C (Perimeter-based security) is wrong because Zero Trust moves away from a castle-and-moat perimeter model toward identity-centric controls. Option D (Implicit trust for internal users) is wrong because Zero Trust assumes breach and requires continuous verification, never granting implicit trust to internal users.

Exam trap

SC-900 often tests the distinction between traditional perimeter security assumptions (trust by location, implicit trust) and the three Zero Trust principles, tricking candidates who confuse 'trust but verify' with 'verify explicitly'.

543
MCQhard

Refer to the exhibit. You are reviewing a Microsoft Purview sensitivity label configuration. A user reports that a document containing a sensitive info type with confidence 80 was not automatically labeled. What is the most likely cause?

A.The user has overridden the label application.
B.The encryption is disabled.
C.The encryption template ID is missing.
D.The auto-labeling policy is not configured to apply this label.
AnswerD

While a sensitivity label defines the specific protection settings, such as encryption and access controls, its mere existence does not automatically apply it to content. For automatic application, a distinct auto-labeling policy must be created and configured within Microsoft Purview to identify sensitive information based on specific conditions and then apply this particular label. The label definition itself is separate from its deployment via an auto-labeling policy.

Why this answer

Auto-labeling in Microsoft Purview requires a specific auto-labeling policy to be configured and published to the user or location. Even if a sensitivity label exists and a sensitive info type (SIT) is detected with high confidence, the label will not be applied automatically unless an auto-labeling policy is explicitly set to apply that label to documents matching the SIT. The user's report indicates the label was not applied, which points to the policy not being configured, not a user override or encryption issue.

Exam trap

The trap here is that candidates often confuse the existence of a sensitivity label with the configuration of an auto-labeling policy, assuming that if a label is published, it will automatically apply to matching content, but in reality, auto-labeling requires a separate policy to be explicitly configured.

How to eliminate wrong answers

Option A is wrong because the user overriding the label would require the label to have been applied first, and the user would have to manually change it; the scenario states the label was not applied at all. Option B is wrong because encryption being disabled does not prevent auto-labeling; encryption is a label action, not a prerequisite for label application. Option C is wrong because a missing encryption template ID would cause an error when applying encryption, but it would not prevent the label from being applied; the label could still be applied without encryption.

544
MCQhard

Your company uses Microsoft Purview to manage data across Azure, on-premises SQL Server, and Amazon S3. You need to create a unified map of all data sources and their sensitivity labels. Which Microsoft Purview feature should you use?

A.Microsoft Purview Data Sharing
B.Microsoft Purview Data Map
C.Microsoft Purview Data Estate Insights
D.Microsoft Purview Data Catalog
AnswerB

The Microsoft Purview Data Map is the foundational component that automatically discovers, scans, and classifies data across hybrid environments, including Azure, on-premises, and multi-cloud sources. It creates a unified, graph-based metadata store of an organization's entire data estate, enabling comprehensive understanding and governance. This core capability is essential for building a holistic view of data assets and their relationships, which is fundamental to managing data across Azure.

Why this answer

Microsoft Purview Data Map is the correct feature because it provides a unified, automated map of data assets across hybrid and multi-cloud environments (Azure, on-premises SQL Server, and Amazon S3). It automatically scans and classifies data sources, applies sensitivity labels, and maintains a centralized metadata repository, enabling a holistic view of the data landscape and its sensitivity.

Exam trap

The trap here is that candidates often confuse the Microsoft Purview Data Catalog (which is the searchable inventory) with the Data Map (which is the underlying metadata and classification engine), leading them to select Option D instead of B.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Sharing is a feature for securely sharing data in-place across organizations or within an organization, not for creating a unified map of data sources and sensitivity labels. Option C is wrong because Microsoft Purview Data Estate Insights provides monitoring, analytics, and reporting on data estate health and usage, but it does not create the foundational map of data sources and labels; it relies on the Data Map. Option D is wrong because Microsoft Purview Data Catalog is a component that builds on the Data Map to enable data discovery and search, but the core mapping and labeling of data sources is performed by the Data Map itself.

545
MCQeasy

A company wants to ensure that data is not altered during transmission between a client and a server. They use TLS encryption. Which security goal does this primarily address?

A.Confidentiality
B.Integrity
C.Availability
D.Non-repudiation
AnswerB

Integrity guarantees that data remains accurate, complete, and unaltered throughout its entire lifecycle, especially during transmission. This means preventing unauthorized or accidental modification, deletion, or corruption of data. Mechanisms such as cryptographic hashing (e.g., SHA-256) and digital signatures are commonly employed to detect any tampering, ensuring the data received is identical to the data sent.

Why this answer

TLS (Transport Layer Security) uses message authentication codes (MACs) and cryptographic hashing to ensure that data is not tampered with during transit. While TLS also provides confidentiality through encryption, the specific goal of preventing alteration during transmission is integrity. Therefore, option B is correct because integrity guarantees that the data received is exactly what was sent, unchanged by any intermediary.

Exam trap

The trap here is that candidates often assume TLS only provides confidentiality (encryption) and forget that TLS also explicitly ensures integrity through MACs or AEAD, leading them to incorrectly select 'Confidentiality' (Option A) when the question specifically asks about preventing alteration.

How to eliminate wrong answers

Option A is wrong because confidentiality is about preventing unauthorized access to data (secrecy), not about detecting or preventing alteration; TLS achieves confidentiality through symmetric encryption, but the question specifically asks about preventing alteration. Option C is wrong because availability ensures that systems and data are accessible when needed, which is unrelated to data integrity during transmission; TLS does not address availability. Option D is wrong because non-repudiation prevents a party from denying an action (e.g., using digital signatures), whereas TLS does not inherently provide non-repudiation—it focuses on secure communication, not proof of origin.

546
MCQeasy

Your organization wants to use Microsoft Defender for Cloud Apps to detect anomalous user behavior across cloud applications. Which feature should you enable?

A.Anomaly detection policies
B.App connectors
C.Secure Score
D.Cloud Discovery
AnswerA

Anomaly detection policies in Microsoft Defender for Cloud Apps use behavioural analytics and threat intelligence to flag unusual activity such as impossible travel, mass downloads or suspicious admin operations across connected cloud applications, satisfying the anomalous-behaviour detection requirement.

Why this answer

Anomaly detection policies in Microsoft Defender for Cloud Apps use machine learning and behavioral analytics to establish a baseline of normal user activity and then trigger alerts for deviations, such as impossible travel, unusual data exfiltration, or risky sign-in patterns. This directly addresses the requirement to detect anomalous user behavior across cloud applications.

Exam trap

The trap here is that candidates often confuse 'Cloud Discovery' (which identifies shadow IT) with 'anomaly detection' (which focuses on user behavior), or they mistakenly think 'App connectors' are needed for behavioral monitoring, when in fact connectors enable data ingestion but not the behavioral analysis itself.

How to eliminate wrong answers

Option B is wrong because App connectors are used to connect Defender for Cloud Apps to specific cloud applications via APIs for visibility and control, not to detect anomalous user behavior. Option C is wrong because Secure Score is a security posture measurement tool that assesses configurations and recommends improvements, not a real-time behavioral detection feature. Option D is wrong because Cloud Discovery analyzes traffic logs to identify shadow IT and cloud app usage, but it does not focus on anomalous user behavior detection.

547
MCQmedium

A company uses Microsoft 365 and needs to classify and protect sensitive documents by applying encryption and visual markings (headers/footers) based on the content's sensitivity. They also want to automatically revoke access to documents that leave the organization. Which Microsoft Purview solution should they configure?

A.Microsoft Purview Data Lifecycle Management
B.Microsoft Purview Information Protection
C.Microsoft Purview Communication Compliance
D.Microsoft Purview Audit
AnswerB

Microsoft Purview Information Protection applies sensitivity labels that enforce encryption and visual markings, and its protection persists with the file so access can be revoked when documents leave the organisation. This directly satisfies the classification, marking and revocation requirements in the stem.

Why this answer

Microsoft Purview Information Protection (B) is the correct solution because it provides the capabilities to classify and protect sensitive documents using sensitivity labels. These labels can enforce encryption and apply visual markings like headers and footers based on content sensitivity. Additionally, Information Protection supports automatic revocation of access to documents that leave the organization through features like rights management and conditional access policies.

Exam trap

The trap here is that candidates may confuse Data Lifecycle Management (retention/deletion) with Information Protection (classification/encryption), or mistakenly think Communication Compliance or Audit can enforce document-level protection and revocation.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Lifecycle Management focuses on retaining and deleting data based on policies, not on classifying, encrypting, or applying visual markings to documents. Option C is wrong because Microsoft Purview Communication Compliance is designed to detect and manage inappropriate communications (e.g., harassment, insider trading) within emails and messages, not to classify or protect document content with encryption or markings. Option D is wrong because Microsoft Purview Audit provides logging and investigation of user and admin activities, not the ability to classify, encrypt, or revoke access to documents.

548
MCQhard

Refer to the exhibit. You are reviewing Microsoft Entra sign-in logs. Which statement is true?

A.jdoe's sign-in had no risk detected.
B.jdoe's sign-in failed Conditional Access.
C.asmith's sign-in was likely from an application or service principal.
D.asmith's sign-in had a high risk level.
AnswerC

asmith's sign-in was indeed likely from an application or service principal, as indicated by the 'NonInteractiveUser' sign-in type. This specific type signifies that the authentication request originated from a client application, script, or service principal, rather than a direct interactive session initiated by a human user, facilitating automated access to resources.

Why this answer

The sign-in log entry for asmith shows an 'Application' sign-in type, which indicates the authentication was performed by an application or service principal rather than a user. In Microsoft Entra ID, sign-ins from applications or service principals are logged with a distinct sign-in type, and the exhibit displays 'Application' for asmith's entry, confirming this.

Exam trap

The trap here is that candidates may assume all sign-in logs represent user sign-ins and overlook the 'Sign-in type' column, leading them to misinterpret the risk level or Conditional Access status for a service principal entry.

How to eliminate wrong answers

Option A is wrong because the sign-in log for jdoe shows a 'Risk level' of 'Medium', indicating risk was detected, not 'No risk'. Option B is wrong because the sign-in log for jdoe shows 'Conditional Access' status as 'Success', not 'Failure', meaning Conditional Access policies were satisfied. Option D is wrong because the sign-in log for asmith shows a 'Risk level' of 'Low', not 'High'.

549
MCQeasy

A user authenticates to a company's network by entering their password and then approving a push notification on their mobile phone. After authentication, the user attempts to access a shared folder containing financial reports. The access is denied because the user's account is not a member of the 'Finance' group. Which security concept is demonstrated when the user is denied access to the folder?

A.Authentication
B.Authorization
C.Non-repudiation
D.Accounting
AnswerB

Authorization is the security process that determines what actions an authenticated user or system is permitted to perform on a resource. After a user successfully proves their identity, the system evaluates their assigned rights and privileges, often based on roles or group memberships. In this scenario, denying access to a folder because the user lacks the necessary group membership is a direct application of an authorization policy, enforcing access control based on established permissions.

Why this answer

Authorization is the security concept that determines what resources a user is allowed to access after their identity has been verified. In this scenario, the user successfully authenticated but was denied access to the financial reports folder because their account lacked the necessary permissions—specifically, membership in the 'Finance' group. This access control decision is the essence of authorization, which enforces policies based on identity attributes like group membership.

Exam trap

The trap here is that candidates confuse authentication (proving who you are) with authorization (what you are allowed to do), especially when the question includes a multi-factor authentication step that seems to 'grant' access, but the denial is purely an authorization failure.

Why the other options are wrong

A

The user was denied access due to insufficient permissions (not being in the Finance group), which is an authorization decision, not authentication. Authentication only verifies identity, which already succeeded via password and push notification.

C

Non-repudiation ensures that a user cannot deny having performed an action, such as signing a document. The scenario describes access denial due to group membership, which is about authorization, not non-repudiation.

D

Accounting refers to tracking user activities and resource usage (e.g., logging access attempts), not to controlling access based on group membership. The denial here is due to lack of authorization, not accounting.

When would these options actually be correct?

A

Authentication would be correct if the question described a scenario where the user fails to prove their identity, such as entering an incorrect password or failing a biometric scan, and is therefore denied access to the network.

C

A user signs a digital contract using a private key, and later claims they did not sign it. The system provides proof of the signature, preventing denial. This demonstrates non-repudiation.

D

A user accesses a file server, and the system logs the access attempt, including timestamp, user identity, and file accessed. The question asks which concept is demonstrated by the logging of this activity.

Why candidates pick the wrong answer

A

Candidates often confuse authentication and authorization because both involve access control. They may think that being denied access is related to identity verification, not realizing that authentication already passed.

C

Candidates may confuse non-repudiation with authorization because both involve security controls, but non-repudiation focuses on accountability for actions, not access rights.

D

Candidates may confuse 'accounting' with 'access control' because both involve user actions and permissions, but accounting is about auditing and logging, not enforcing access decisions.

550
MCQmedium

A company uses Microsoft Entra ID. They want to ensure that users who are traveling to a high-risk country, based on the sign-in IP address, are prompted for multi-factor authentication before accessing the company's CRM application. Which Microsoft Entra ID feature should they configure?

A.Conditional Access
B.Identity Protection
C.Privileged Identity Management
D.Azure AD Join
AnswerA

Conditional Access policies are the primary mechanism in Microsoft Entra ID for enforcing access decisions based on various conditions, including user location. Administrators can define "Named locations" using IP ranges or countries/regions, then create policies that require specific controls, such as multi-factor authentication (MFA), when users attempt to access applications from outside these trusted locations. This directly addresses the requirement to enforce location-based MFA for application access.

Why this answer

Conditional Access is the correct feature because it allows administrators to create policies that evaluate sign-in signals—such as the user's location derived from the IP address—and enforce access controls like requiring multi-factor authentication (MFA) before granting access to a specific application (e.g., the CRM app). By configuring a Conditional Access policy with a location condition targeting high-risk countries, the company can ensure that only users signing in from those IP ranges are prompted for MFA, while other sign-ins proceed normally.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based MFA (which uses machine learning on user behavior) with Conditional Access's location-based MFA (which uses static IP-to-country mapping), leading them to select Identity Protection when the question explicitly specifies a high-risk country based on IP address rather than a risk score.

Why the other options are wrong

B

Identity Protection provides risk detection and remediation, but it does not enforce access controls like MFA prompts. Conditional Access is required to apply policies based on sign-in risk or location.

C

Privileged Identity Management (PIM) manages, controls, and monitors access to privileged roles in Microsoft Entra ID, but it does not enforce location-based multi-factor authentication prompts for specific applications.

D

Azure AD Join is used to join devices to Azure AD for single sign-on and management, not to enforce conditional access policies based on sign-in risk or location.

When would these options actually be correct?

B

Identity Protection would be correct if the question asked: 'Which feature identifies and reports risky sign-ins, such as those from anonymous IP addresses or atypical travel, but does not enforce access policies?'

C

A company needs to manage just-in-time privileged access to Azure AD roles, requiring approval and time-bound activation for administrators. PIM would be the correct feature to configure.

D

An exam question asking how to enable single sign-on and device management for corporate-owned Windows devices that are not domain-joined, with the goal of applying device-based conditional access policies.

Why candidates pick the wrong answer

B

Candidates confuse Identity Protection's risk detection capabilities with the policy enforcement that Conditional Access provides, assuming risk detection alone can trigger MFA.

C

Candidates may confuse PIM's role-based access controls with Conditional Access policies, assuming that managing privileged roles includes controlling authentication requirements based on risk.

D

Candidates may confuse Azure AD Join with Azure AD Conditional Access because both involve device identity and access control, but Azure AD Join is about device registration, not policy enforcement.

551
MCQeasy

A company needs to allow external business partners to securely access internal SharePoint Online sites and Teams channels. The partners use various identity providers, including Microsoft Entra ID and Google. The company wants to manage these external users in their directory and assign access policies. Which Microsoft Entra ID capability should they use?

A.Microsoft Entra B2C (Business to Customer)
B.Microsoft Entra External ID (B2B Collaboration)
C.Microsoft Entra Domain Services
D.Microsoft Entra Identity Protection
AnswerB

Microsoft Entra External ID (B2B Collaboration) is the correct solution, specifically designed for securely collaborating with external business partners. It allows guest users from partner organizations to use their existing corporate or social identities to access specific applications and resources within your Microsoft Entra tenant. This integrates partners directly into your organization's access management framework, providing controlled and managed access to internal systems.

Why this answer

Microsoft Entra External ID (B2B Collaboration) is the correct capability because it allows the company to invite external business partners (B2B users) from any identity provider, including Microsoft Entra ID and Google, into their own Microsoft Entra directory. This enables the company to manage these external users in their directory, assign conditional access policies, and grant them secure access to internal SharePoint Online sites and Teams channels without requiring a separate application or customer-facing identity system.

Exam trap

The trap here is that candidates often confuse Microsoft Entra B2C (for customers) with B2B Collaboration (for business partners), leading them to select B2C because both involve external users, but B2C is for consumer-facing apps, not for granting access to internal resources like SharePoint and Teams.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra B2C (Business to Customer) is designed for customer-facing applications where external users sign in with social or local identities, not for managing business partners in the company's directory with access to internal resources like SharePoint and Teams. Option C is wrong because Microsoft Entra Domain Services provides managed domain services like LDAP, Kerberos, and NTLM for legacy applications, not for inviting and managing external business partners. Option D is wrong because Microsoft Entra Identity Protection is a security tool that detects identity-based risks and vulnerabilities, not a capability for inviting or managing external users.

552
MCQmedium

A security team wants to discover all cloud applications being used by employees, including unsanctioned file sharing and collaboration apps. They plan to analyze traffic logs from their network firewall to identify usage patterns and assess each app's risk level. Which feature of Microsoft Defender for Cloud Apps should they enable?

A.Cloud Discovery
B.App Connectors
C.Conditional Access App Control
D.Information Protection
AnswerA

Microsoft Defender for Cloud Apps' Cloud Discovery feature is specifically engineered to provide comprehensive visibility into all cloud applications accessed by users within an organization. It accomplishes this by ingesting and analyzing traffic logs from firewalls and proxy servers, extracting details about accessed URLs and IP addresses. This process enables the identification of both sanctioned and unsanctioned (shadow IT) cloud services, building a complete catalog of an organization's cloud app landscape and assessing associated risks.

Why this answer

Cloud Discovery is the correct feature because it analyzes traffic logs from network firewalls and proxies to identify all cloud applications in use, including unsanctioned ones. It uses the Microsoft Defender for Cloud Apps catalog to assess each app's risk level based on factors like security posture, compliance certifications, and industry standards. This directly matches the scenario of discovering unsanctioned file sharing and collaboration apps from firewall logs.

Exam trap

The trap here is that candidates confuse Cloud Discovery (passive log analysis for unsanctioned app discovery) with App Connectors (active API integration for sanctioned app monitoring), leading them to choose B because they think 'connecting to apps' is needed to discover them.

How to eliminate wrong answers

Option B (App Connectors) is wrong because App Connectors are used to connect directly to sanctioned cloud apps (like Office 365, Salesforce) via APIs to pull data for monitoring and governance, not to discover unsanctioned apps from firewall logs. Option C (Conditional Access App Control) is wrong because it enforces real-time access policies on sanctioned apps using reverse proxy, not for discovering unknown apps from traffic logs. Option D (Information Protection) is wrong because it focuses on classifying and protecting sensitive data within files and emails, not on discovering cloud app usage patterns from network traffic.

553
Multi-Selecthard

Which TWO of the following are supported identity types for Microsoft Entra External ID? (Select two.)

Select 2 answers
A.OAuth 2.0 token identities
B.Social identities (e.g., Google, Facebook)
C.X.509 certificate-based identities
D.Enterprise identities from SAML/WS-Federation identity providers
E.Biometric identities (fingerprint, face)
AnswersB, D

Microsoft Entra External ID (formerly Azure AD External ID) fully supports social identities, enabling users to sign in to applications using their existing credentials from popular social identity providers like Google, Facebook, and Microsoft accounts. This capability simplifies the registration and login process for external users, leveraging their familiar accounts. These identities are managed by the respective social providers, with claims securely passed to the application via standard protocols like OpenID Connect.

Why this answer

Microsoft Entra External ID supports social identities such as Google and Facebook (option B), allowing consumers to sign in with existing accounts from these providers via built-in identity providers. It also supports enterprise identities from SAML/WS-Federation identity providers (option D), enabling federation with external organizations' IdPs for B2B collaboration scenarios. These two identity types are core to External ID's design for customer and partner access.

OAuth 2.0 token identities (A) describe a protocol flow, not a supported identity type. X.509 certificate-based identities (C) are not a native External ID identity type. Biometric identities (E) are handled by the device/authenticator, not defined as an External ID identity type.

Exam trap

The trap here is that candidates confuse authentication methods (like biometrics or certificates) with identity provider types, or assume OAuth 2.0 tokens are an identity type rather than a protocol used to exchange identity information.

554
MCQeasy

You need to ensure that sensitive documents in Microsoft SharePoint Online are automatically classified and protected when they contain credit card numbers. What should you configure?

A.A sensitivity label with auto-labeling for Microsoft Purview Information Protection
B.A retention policy for SharePoint
C.A data loss prevention (DLP) policy
D.A retention label for regulatory compliance
AnswerA

Sensitivity labels with auto-labeling are specifically designed within Microsoft Purview Information Protection to automatically classify and apply protective measures to documents. They leverage sensitive information types and trainable classifiers to identify content, then enforce encryption, visual markings, and access restrictions, ensuring proactive data protection from creation and throughout its lifecycle.

Why this answer

A sensitivity label with auto-labeling for Microsoft Purview Information Protection is correct because it can automatically classify and protect documents based on sensitive content, such as credit card numbers, using built-in sensitive information types. This ensures that when a document in SharePoint Online contains credit card data, it is automatically labeled with encryption and usage restrictions without manual intervention.

Exam trap

The trap here is that candidates often confuse DLP policies with auto-labeling, but DLP policies only monitor and block data sharing, whereas auto-labeling with sensitivity labels actually classifies and protects the content itself.

How to eliminate wrong answers

Option B is wrong because a retention policy for SharePoint is designed to retain or delete content based on time, not to classify or protect documents based on sensitive data like credit card numbers. Option C is wrong because a data loss prevention (DLP) policy can detect and block sharing of sensitive data, but it does not automatically classify or apply protection (e.g., encryption) to the documents themselves; it only enforces rules on data in transit or at rest. Option D is wrong because a retention label for regulatory compliance is used to manage data retention and disposal, not to automatically classify or protect documents based on sensitive content like credit card numbers.

555
MCQmedium

Your company is implementing data loss prevention (DLP) policies in Microsoft Purview. You need to create a policy that prevents users from sharing credit card numbers via email to external recipients. The policy should only apply to users in the Finance department. Which action should you take?

A.Create a retention label and apply auto-labeling for Finance
B.Create a sensitivity label and publish it to Finance users
C.Copy the default DLP template for financial data and modify it
D.Create a DLP policy, select the Finance user location, and add the credit card number condition
AnswerD

Creating a new Data Loss Prevention (DLP) policy is the direct and most effective method for preventing the unauthorized sharing of sensitive data. By selecting the Finance user location, the policy is precisely scoped to the relevant individuals, and adding the credit card number condition ensures that the policy specifically targets and enforces actions against this critical sensitive information type, directly addressing the company's objective.

Why this answer

To apply a DLP policy to specific users, you select their group (e.g., Finance) as a location when creating the policy. This ensures only Finance users are affected. Option A is wrong because auto-labeling with retention labels does not enforce DLP rules.

Option B is wrong because sensitivity labels classify data but do not block sharing. Option C is wrong because copying a default template may not allow precise scoping to Finance users; creating a new policy from scratch with location selection is more accurate.

556
Multi-Selectmedium

Which THREE of the following are capabilities of Microsoft Entra ID Governance?

Select 3 answers
A.Self-service password reset
B.Access reviews
C.Privileged Identity Management
D.Entitlement management
E.Conditional access
AnswersB, C, D

Access reviews are a capability within Microsoft Entra Identity Governance that allows organizations to efficiently manage group memberships, access to enterprise applications, and roles. They enable administrators, or even resource owners, to periodically review who has access to what resources, ensuring that only authorized users maintain appropriate permissions and helping to prevent privilege creep. This systematic validation of access rights is a core component of maintaining a strong security posture and meeting compliance requirements.

Why this answer

Entitlement management (D) is a core Entra ID Governance capability that lets organizations manage the lifecycle of access through access packages, catalogs, and policies, automating granting, revoking, and expiration of access for internal and external users. Access reviews (B) are also part of Entra ID Governance, enabling periodic recertification of group memberships, application assignments, and privileged role assignments to ensure users retain only the access they need. Privileged Identity Management (C) is included in Entra ID Governance, providing just-in-time privileged access, approval workflows, access reviews, and audit history for Microsoft Entra roles, Azure resources, and other workloads.

Self-service password reset (A) is an Entra ID authentication feature, not a governance capability, and Conditional Access (E) is an Entra ID access-control policy engine, so neither belongs to the Entra ID Governance feature set.

Exam trap

The trap here is that candidates often confuse security features like Conditional Access or SSPR with governance capabilities, but Microsoft Entra ID Governance specifically focuses on identity lifecycle management, access reviews, entitlement management, and privileged identity management, not on authentication or policy enforcement.

557
MCQmedium

A company with Microsoft 365 wants employees to access corporate applications from their personal Android and iOS devices. The security team requires that these devices be enrolled in mobile device management (MDM) for compliance policies, and that company data can be selectively wiped from the device without affecting personal data. Which Microsoft Entra device identity type should they configure for these personal devices?

A.Microsoft Entra registered
B.Microsoft Entra joined
C.Microsoft Entra hybrid joined
D.Microsoft Entra managed
AnswerA

Microsoft Entra registered devices are typically personal devices (Bring Your Own Device - BYOD) that users want to access corporate resources from. This identity type allows devices to be enrolled in Mobile Device Management (MDM) solutions like Microsoft Intune, enabling conditional access policies and selective wipe capabilities to protect organizational data without fully controlling the user's personal device.

Why this answer

Microsoft Entra registered is the correct device identity type for personal (BYOD) devices because it supports enrollment in MDM for compliance policies and enables selective wipe of company data without affecting personal data. This identity type registers the device with Entra ID without requiring organizational ownership, allowing users to access corporate applications while maintaining personal data separation.

Exam trap

The trap here is that candidates often confuse 'Microsoft Entra joined' with 'Microsoft Entra registered' because both involve device identity, but Entra joined implies full organizational control and no selective wipe capability, making it unsuitable for BYOD scenarios.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra joined is designed for organization-owned devices that are fully managed by the organization, not for personal BYOD devices, and it does not support selective wipe of only company data. Option C is wrong because Microsoft Entra hybrid joined requires on-premises Active Directory domain join and is intended for organization-owned devices that need both on-premises and cloud access, not for personal devices. Option D is wrong because 'Microsoft Entra managed' is not a valid device identity type in Microsoft Entra; the valid types are Entra registered, Entra joined, and hybrid Entra joined.

558
Multi-Selecteasy

Which two scenarios are examples of using Microsoft Entra business-to-business (B2B) collaboration? (Choose two.)

Select 2 answers
A.A user from a partner organization is invited to access a SharePoint Online site.
B.An employee uses their Microsoft Entra ID to sign in to a third-party SaaS application.
C.Two internal departments share resources within the same tenant.
D.A vendor employee uses their own work email to access a Power BI dashboard shared by your company.
E.Customers use their Facebook accounts to sign in to a company's web application.
AnswersA, D

This scenario exemplifies Microsoft Entra B2B collaboration, where an organization extends access to its internal resources, such as a SharePoint Online site, to an external user from a partner organization. By inviting the partner user, a guest account is created in the inviting organization's Microsoft Entra tenant, allowing the external user to authenticate with their existing corporate credentials and securely access the shared resource. This facilitates secure inter-organizational cooperation.

Why this answer

Microsoft Entra B2B collaboration allows you to invite external users from partner organizations to access your company's resources, such as a SharePoint Online site. The invited user authenticates using their own home tenant credentials, and a B2B guest user object is created in your directory to represent them.

Exam trap

The trap here is confusing B2B collaboration (inviting external business partners with work/school accounts) with B2C collaboration (allowing consumers to sign in with social identities like Facebook or Google), leading candidates to incorrectly select Option E.

559
MCQhard

You are a compliance administrator for Contoso, a multinational company that uses Microsoft 365. The company has the following requirements: 1. Automatically retain all documents containing personally identifiable information (PII) for 7 years. 2. Prevent users from sharing PII via email with external recipients unless they provide a business justification. 3. Monitor and alert when users access sensitive data outside of business hours. 4. Generate a compliance score for GDPR and ISO 27001. You need to configure the appropriate Microsoft Purview solutions. For each requirement, match the correct solution. Which combination of solutions should you use?

A.Information Protection for retention; DLP for sharing; Data Lifecycle Management for monitoring; Compliance Manager for scoring
B.Data Lifecycle Management for retention; Communication Compliance for sharing; Insider Risk Management for monitoring; Compliance Manager for scoring
C.Data Lifecycle Management for retention; DLP for sharing; Insider Risk Management for monitoring; Compliance Manager for scoring
D.Information Protection for retention; eDiscovery for sharing; Insider Risk Management for monitoring; Compliance Manager for scoring
AnswerC

Each component maps to one requirement: Data Lifecycle Management applies retention labels for the 7-year PII hold; DLP blocks external email sharing with justification override; Insider Risk Management detects out-of-hours access; Compliance Manager scores GDPR and ISO 27001 posture.

Why this answer

Requirement 1 (retain PII for 7 years) is met by a retention label or policy from Data Lifecycle Management (not Information Protection, which is for classification). Requirement 2 (prevent sharing without justification) is met by a Data Loss Prevention (DLP) policy that can block sharing and require user override with business justification. Requirement 3 (monitor access outside business hours) is met by Insider Risk Management, which can detect anomalous access patterns.

Requirement 4 (compliance score) is met by Compliance Manager. Option A is wrong because Information Protection labels are for classification, not retention; also monitoring access outside hours needs Insider Risk Management, not DLP. Option B is wrong because Communication Compliance is for monitoring communications, not for preventing sharing via email; DLP is needed for that.

Option D is wrong because eDiscovery is for legal discovery, not for access monitoring.

560
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You need to detect anomalous user behavior such as impossible travel. Which type of policy should you configure?

A.Anomaly detection policy
B.Activity policy
C.App discovery policy
D.Session policy
AnswerA

Microsoft Defender for Cloud Apps' anomaly detection policies leverage machine learning and User Behavior Analytics (UBA) to identify unusual activities that deviate from a user's learned baseline. These policies are specifically designed to detect sophisticated threats like impossible travel, where a user logs in from geographically distant locations in an impossibly short timeframe, or unusual login locations, failed logins, and suspicious activities, by continuously monitoring and analyzing user and entity behavior.

Why this answer

Anomaly detection policies in Microsoft Defender for Cloud Apps use machine learning and behavioral analytics to establish a baseline of normal user activity and then flag deviations such as impossible travel (e.g., a user logging in from New York and then from London within an unrealistic time frame). This policy type is specifically designed to detect suspicious patterns like credential theft or account compromise without requiring predefined rules.

Exam trap

Microsoft often tests the distinction between rule-based policies (Activity policies) and machine-learning-based anomaly detection, leading candidates to choose Activity policy because they think they can manually define 'impossible travel' rules, but in practice, anomaly detection is the only automated way to handle such dynamic behavioral patterns.

How to eliminate wrong answers

Option B is wrong because Activity policies are rule-based and require you to define specific conditions (e.g., number of downloads from a location) to trigger alerts; they cannot automatically detect unknown anomalous patterns like impossible travel. Option C is wrong because App discovery policies are used to identify shadow IT by analyzing traffic logs to discover cloud apps in use, not to monitor user behavior for anomalies. Option D is wrong because Session policies control real-time user actions within a session (e.g., blocking downloads) based on risk, but they do not perform historical behavioral analysis to detect impossible travel.

561
MCQmedium

A company uses Microsoft Entra ID and requires that all guest users from a partner organization must sign in using Microsoft Authenticator for MFA. The partner organization manages their own identities. What should you configure?

A.Enable Microsoft Entra ID Protection and configure MFA registration policy for guests
B.Use Microsoft Entra ID Governance to require access reviews for guests
C.Configure cross-tenant access settings to trust MFA from the partner's Microsoft Entra ID tenant
D.Create a Conditional Access policy that requires MFA for guest users
AnswerC

Cross-tenant access settings offer granular control over how users from other Microsoft Entra ID tenants interact with your resources. By configuring inbound trust settings, your tenant can be explicitly set to accept multi-factor authentication claims issued by the partner's home tenant. This crucial capability eliminates redundant MFA prompts for guest users, allowing your organization to leverage the partner's security controls and provide a seamless, yet secure, access experience.

Why this answer

Cross-tenant access settings in Microsoft Entra ID allow you to trust MFA claims from an external partner's tenant. Since the partner manages their own identities, trusting their MFA ensures that guest users from that partner organization can satisfy MFA requirements using their own Microsoft Authenticator without needing to register again in your tenant.

Exam trap

The trap here is that candidates often assume a Conditional Access policy (Option D) is the standard way to enforce MFA for guests, but they overlook the cross-tenant trust mechanism that allows the partner to manage their own MFA without guest user registration in the resource tenant.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Protection's MFA registration policy applies to users in your own tenant, not to guest users from a partner organization that manages their own identities. Option B is wrong because access reviews are used to periodically review and certify guest access, not to enforce MFA authentication requirements. Option D is wrong because a Conditional Access policy requiring MFA for guest users would force them to register for MFA in your tenant, which contradicts the requirement that the partner organization manages their own identities and that guests sign in using their own Microsoft Authenticator.

562
MCQhard

A security architect is implementing a Zero Trust security model. The architect insists that the network perimeter should not be trusted and that security controls must be applied to all traffic, even within the corporate network. They also emphasize the need for continuous monitoring and detection of threats as if a breach has already occurred. Which Zero Trust principle is the architect primarily applying?

A.Verify explicitly
B.Least privilege access
C.Assume breach
D.Trust but verify
AnswerC

"Assume breach" is a foundational Zero Trust principle that mandates organizations operate under the constant premise that their network and resources have already been compromised or will inevitably be. This mindset drives proactive security measures such as micro-segmentation, continuous threat detection, robust incident response planning, and regular security posture assessments. It shifts focus from perimeter defense to protecting individual resources and minimizing the blast radius of any successful attack, making it central to a resilient Zero Trust architecture.

Why this answer

The architect's emphasis on not trusting the network perimeter and applying security controls to all traffic, combined with continuous monitoring as if a breach has already occurred, directly aligns with the 'Assume breach' principle of Zero Trust. This principle operates on the mindset that a breach is inevitable or has already happened, thus requiring constant verification and monitoring of all network traffic, even within the corporate network, rather than relying on a trusted internal zone.

Exam trap

Microsoft often tests the distinction between 'Assume breach' and 'Verify explicitly' by describing a scenario that includes both continuous monitoring and strict access controls, leading candidates to confuse the proactive verification requirement with the reactive breach-assumption mindset.

How to eliminate wrong answers

Option A is wrong because 'Verify explicitly' focuses on authenticating and authorizing every access request based on all available data points (e.g., user identity, device health, location), but it does not inherently assume that a breach has already occurred; it is about strict verification at each access attempt. Option B is wrong because 'Least privilege access' is about granting only the minimum permissions necessary for a user or system to perform a task, which is a separate pillar of Zero Trust that does not directly address the continuous monitoring and breach-assumption mindset described in the scenario. Option D is wrong because 'Trust but verify' is an outdated security model that assumes trust is granted initially and then verified periodically; Zero Trust explicitly rejects this approach by stating that no entity should be trusted by default, even inside the network.

563
MCQmedium

A company wants to reduce the risk of privileged account misuse. They need to provide temporary, time-bound access to administrative roles in Microsoft Entra ID (Microsoft Entra ID) and require approval from a manager before granting the access. Which Microsoft Entra capability should they use?

A.Conditional Access policies
B.Microsoft Entra Privileged Identity Management (PIM)
C.Identity Protection
D.Entra ID Governance (Access Reviews)
AnswerB

Microsoft Entra Privileged Identity Management (PIM) directly addresses the risk of privileged account misuse by implementing just-in-time (JIT) access. It enables users to activate privileged roles only when needed, for a limited duration, and often requires an explicit approval workflow before elevation. This significantly reduces the attack surface by eliminating standing privileged access and provides comprehensive auditing of all privilege activations.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) provides just-in-time (JIT) privileged access by allowing administrators to activate roles for a limited, time-bound duration. It also supports approval workflows, requiring a manager's approval before role activation is granted, directly addressing the need for temporary, approved access to administrative roles.

Exam trap

The trap here is that candidates often confuse PIM with Conditional Access or Access Reviews, mistakenly thinking those services can enforce time-bound approvals, but only PIM combines JIT activation with an approval workflow for privileged roles.

How to eliminate wrong answers

Option A is wrong because Conditional Access policies enforce access controls based on conditions like location or device compliance, but they do not provide time-bound role activation or approval workflows for privileged roles. Option C is wrong because Identity Protection detects and responds to identity-based risks (e.g., leaked credentials, sign-in anomalies), but it does not manage privileged role activation or require approval for role assignment. Option D is wrong because Entra ID Governance (Access Reviews) enables periodic review of existing role assignments to ensure they are still needed, but it does not provide temporary, time-bound activation with an approval process.

564
MCQmedium

Your organization uses Microsoft Purview Records Management to manage high-value contracts. You need to ensure that once a contract is declared as a record, it cannot be modified or deleted by any user, including administrators. Which type of record should you use?

A.Disposition review
B.Event-based retention policy
C.Retention label with default settings
D.Regulatory record
AnswerD

A regulatory record in Microsoft Purview is specifically designed to meet stringent regulatory compliance requirements for absolute immutability. Once an item is declared a regulatory record, it becomes permanently locked, preventing any modification or deletion by any user, including global administrators. This level of unalterable preservation ensures the content's integrity and authenticity throughout its lifecycle, making it suitable for the most demanding legal and regulatory obligations.

Why this answer

Regulatory records provide the highest level of protection and cannot be modified or deleted by any user, including administrators. Option A is wrong because disposition review is a process for reviewing content before deletion, not a record type that locks content. Option B is wrong because event-based retention policies apply retention based on a trigger event, but they do not prevent modification or deletion once declared a record.

Option C is wrong because a retention label with default settings does not lock the record; it only applies retention settings without regulatory protections.

565
MCQmedium

A financial services company uses Microsoft 365 and must comply with PCI DSS. They want to automatically prevent users from sending emails that contain credit card numbers to external recipients. If a user tries to send such an email, the system should block the message and notify the user with a policy tip. Which Microsoft Purview solution should they configure?

A.Data Loss Prevention (DLP)
B.Communication Compliance
C.Information Protection
D.Insider Risk Management
AnswerA

Data Loss Prevention in Microsoft Purview inspects email content for sensitive information types such as credit card numbers, blocks messages to external recipients, and shows policy tips to the sender. This matches the PCI DSS requirement to prevent outbound card data automatically.

Why this answer

Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect and block sensitive data, such as credit card numbers, in transit (e.g., email). DLP policies can be configured with conditions to match credit card number patterns (using a built-in sensitive info type) and set actions to block the message and display a policy tip to the sender, meeting the PCI DSS compliance requirement.

Exam trap

The trap here is that candidates often confuse Information Protection (labels/encryption) with DLP, but Information Protection does not provide real-time blocking of outbound data; it only applies protection after classification, whereas DLP actively monitors and blocks data in motion.

How to eliminate wrong answers

Option B is wrong because Communication Compliance is designed to detect and remediate inappropriate or policy-violating communications (e.g., harassment, insider trading), not to block sensitive data like credit card numbers in email. Option C is wrong because Information Protection (e.g., sensitivity labels and encryption) focuses on classifying and protecting data at rest or in transit via encryption, but it does not automatically block outbound emails containing credit card numbers or provide policy tips. Option D is wrong because Insider Risk Management is used to detect, investigate, and act on risky user activities (e.g., data theft, leaks) based on analytics, not to enforce real-time blocking of specific data patterns in email.

566
MCQeasy

A security analyst receives an alert from Microsoft Sentinel indicating a potential ransomware attack. The analyst needs to quickly understand the full scope of the attack, including all affected accounts and devices. Which Microsoft Sentinel feature should they use?

A.Analytics rules
B.Workbooks
C.Playbooks
D.Incident investigation
AnswerD

The incident investigation graph in Microsoft Sentinel is a crucial tool that provides security analysts with a visual, interactive representation of an alert or incident's scope and context. It dynamically maps entities like users, hosts, and IP addresses, showing their relationships and connections to related alerts and events. This graphical view is essential for understanding the attack chain, identifying affected assets, and effectively determining the overall impact and progression of a security event.

Why this answer

D is correct because Microsoft Sentinel's incident investigation feature provides a visual, interactive graph that maps relationships between entities (e.g., accounts, devices, IP addresses) involved in an incident. This allows the analyst to quickly see the full scope of a ransomware attack by exploring all affected resources and their connections, rather than relying on static reports or automated responses.

Exam trap

The trap here is that candidates often confuse 'incident investigation' with 'workbooks' or 'playbooks,' assuming that any visual tool or automated action can provide attack scope, when in fact only the investigation graph offers entity-level relationship mapping for a specific incident.

How to eliminate wrong answers

Option A is wrong because Analytics rules are used to generate alerts based on predefined detection logic (e.g., KQL queries), not to investigate the scope of an ongoing incident. Option B is wrong because Workbooks are interactive dashboards that provide aggregated visualizations and metrics, but they do not offer entity-level relationship mapping for a specific incident. Option C is wrong because Playbooks are automated response workflows (often based on Azure Logic Apps) that execute actions like blocking IPs or isolating devices, but they do not provide the investigative context needed to understand the full attack scope.

567
MCQhard

Your organization has implemented Microsoft Entra ID Governance. You need to review and attest to the access rights of users in a specific group every quarter. The group contains both direct members and members from nested groups. Which Microsoft Entra feature should you use to automate this review?

A.Lifecycle workflows
B.Access reviews
C.Privileged Identity Management
D.Entitlement management
AnswerB

Microsoft Entra access reviews are a critical component of identity governance, specifically designed to enable organizations to efficiently manage access by regularly reviewing who has access to what resources. They allow designated reviewers, such as group owners or managers, to periodically attest to the continued necessity of access for users to groups, applications, or roles. This process ensures that access remains appropriate, adheres to the principle of least privilege, and helps maintain compliance with organizational policies and regulatory requirements.

Why this answer

Access Reviews in Microsoft Entra ID Governance allow you to create recurring reviews of group membership, including both direct members and transitive members from nested groups. This feature automates the attestation process by sending reviewers notifications and tracking their decisions, ensuring compliance with quarterly review requirements.

Exam trap

The trap here is confusing Entitlement Management (which handles access requests and packages) with Access Reviews (which handle periodic attestation), leading candidates to pick D when the question explicitly requires a recurring review and attestation workflow.

How to eliminate wrong answers

Option A is wrong because Lifecycle Workflows automate joiner-mover-leaver processes (e.g., provisioning/deprovisioning accounts), not periodic access attestation. Option C is wrong because Privileged Identity Management (PIM) focuses on just-in-time activation and oversight of privileged roles, not recurring reviews of standard group membership. Option D is wrong because Entitlement Management manages access packages and catalogs for requesting resources, but does not natively provide recurring attestation workflows for existing group members.

568
MCQhard

Your organization uses Microsoft Intune and Microsoft Entra ID. You need to enforce that only compliant and managed devices can access corporate email in Microsoft 365. Additionally, if a device is jailbroken, access should be blocked. You also want to provide a seamless sign-in experience for compliant devices. You have Microsoft Entra ID P1 licenses. What should you configure?

A.Configure Mobile Application Management (MAM) policies to restrict access.
B.Configure Azure AD Join for all devices and enable device registration.
C.Create a Conditional Access policy in Microsoft Entra ID that requires device compliance and use Intune compliance policies to block jailbroken devices, with seamless SSO.
D.Configure Microsoft Defender for Endpoint to detect jailbroken devices.
AnswerC

Conditional Access enforces the compliance requirement at authentication time, granting or denying access based on Intune device state, so jailbroken devices flagged non-compliant are blocked. Intune compliance policies supply that device signal, while Microsoft Entra join with seamless SSO satisfies the seamless sign-in constraint. Entra ID P1 licences cover Conditional Access.

Why this answer

To enforce that only compliant and managed devices access corporate email, and to block jailbroken devices, the correct approach is a Conditional Access policy in Microsoft Entra ID that requires device compliance, combined with Intune compliance policies that detect and block jailbroken devices. Enabling seamless SSO provides the desired sign-in experience for compliant devices. This combination satisfies all stated requirements with Entra ID P1 licensing.

Exam trap

SC-900 often tests the confusion between MAM (app-level protection) and Conditional Access with device compliance (device-level access control), leading candidates to choose MAM when device compliance and jailbreak blocking are required.

How to eliminate wrong answers

Option A is wrong because MAM policies protect app data and can restrict access at the app level, but they do not enforce device compliance or block jailbroken devices for email access in the way Conditional Access with compliance policies does. Option B is wrong because Azure AD Join and device registration alone do not enforce compliance or block jailbroken devices; they are prerequisites for management, not access controls. Option D is wrong because Microsoft Defender for Endpoint can detect jailbroken devices but does not by itself enforce access control to Microsoft 365 email; it must be integrated with Conditional Access and Intune compliance to block access.

569
Multi-Selecteasy

Which TWO of the following are identity-related security best practices recommended by Microsoft? (Choose two.)

Select 2 answers
A.Share passwords with team members for critical accounts
B.Implement Conditional Access policies
C.Use single sign-on (SSO) without MFA
D.Disable sign-in logs to reduce storage costs
E.Enable multi-factor authentication (MFA)
AnswersB, E

Conditional Access evaluates signals such as user, device and location to grant, block or challenge access at sign-in. This satisfies the question's requirement for a Microsoft-recommended identity security practise, enforcing least-privilege access through policy rather than static permissions.

Why this answer

Option B is correct because Microsoft recommends Conditional Access policies in Microsoft Entra ID to evaluate signals such as user, device, location, and risk, and then enforce appropriate access controls (for example, requiring MFA or compliant devices) before granting access to resources. Option E is correct because enabling multi-factor authentication (MFA) is a core Microsoft identity best practice that adds a second verification factor beyond a password, dramatically reducing the risk of credential compromise and account takeover. Options A, C, and D are not best practices: sharing passwords for critical accounts violates the principle of individual accountability and non-repudiation, using SSO without MFA still leaves accounts protected only by a single factor, and disabling sign-in logs removes the audit and monitoring data needed to detect and investigate suspicious authentication activity.

Exam trap

SC-900 often tests the misconception that SSO alone is sufficient security — candidates pick 'SSO without MFA' because SSO sounds secure, ignoring that MFA is the critical second factor.

570
Multi-Selectmedium

Which TWO of the following are capabilities of Microsoft Purview Information Protection? (Choose two.)

Select 2 answers
A.Classify and label sensitive data
B.Block external sharing of files
C.Detect malware in email attachments
D.Apply encryption based on sensitivity labels
E.Monitor user activities in real-time
AnswersA, D

Microsoft Purview Information Protection (MPIP) is a foundational component that enables organizations to identify, categorize, and apply sensitivity labels to data across various locations, including Microsoft 365 services, on-premises file shares, and third-party cloud apps. This classification helps in understanding the data landscape and applying appropriate protection measures, making it a core capability.

Why this answer

Microsoft Purview Information Protection (MIP) enables organizations to classify and label sensitive data based on content inspection and policy rules. It also applies encryption and usage restrictions directly through sensitivity labels, ensuring data is protected regardless of where it is stored or shared.

Exam trap

The trap here is confusing Microsoft Purview Information Protection (which focuses on classification, labeling, and encryption) with other security solutions like DLP, Defender, or Audit, leading candidates to select options that are valid but belong to different services.

571
MCQhard

Refer to the exhibit. You are reviewing Microsoft Entra sign-in logs for a user. The user successfully signed in from a mobile device running iOS, located in the US, with medium risk level. The sign-in did not require MFA. You have a Conditional Access policy that requires MFA for all users when sign-in risk is medium or higher. Why was MFA not triggered?

A.The Conditional Access policy may exclude 'Mobile Apps and Desktop clients' client apps.
B.The device is not compliant, so MFA was not required.
C.The sign-in risk level is medium, which is below the threshold.
D.The user is not assigned to the Conditional Access policy.
AnswerA

Conditional Access policies offer granular control over client applications. If a policy requiring MFA is specifically configured to apply only to 'Browser' client apps, then sign-ins originating from 'Mobile Apps and Desktop clients' would be explicitly excluded from that policy's enforcement. This allows the sign-in to proceed without triggering the MFA requirement, as the policy's scope does not encompass that particular client type. Such exclusions are common for compatibility or specific use cases.

Why this answer

The Conditional Access policy can be configured to exclude specific client apps, such as 'Mobile Apps and Desktop clients'. If the policy excludes these client apps, the sign-in from an iOS mobile device would not be subject to the MFA requirement, even though the sign-in risk is medium. The sign-in logs confirm MFA was not required, indicating the policy did not apply to this client app type.

Exam trap

The trap here is that candidates assume a medium risk level always triggers MFA, overlooking the client apps exclusion condition that can bypass the policy for specific device types.

How to eliminate wrong answers

Option B is wrong because device compliance is not a condition in the described policy; the policy only requires MFA based on sign-in risk, not device compliance. Option C is wrong because the policy explicitly requires MFA when sign-in risk is medium or higher, and the sign-in risk is medium, so the threshold is met. Option D is wrong because the user successfully signed in, and the policy applies to 'all users' unless specifically excluded; the logs show the policy did not trigger, which points to a client app exclusion rather than user assignment.

572
MCQeasy

Your organization needs to prevent sensitive data in SharePoint Online from being shared externally. Which Microsoft Purview solution should you use?

A.Data Loss Prevention (DLP)
B.eDiscovery
C.Sensitivity labels
D.Insider Risk Management
AnswerA

Data Loss Prevention (DLP) policies are specifically designed to identify, monitor, and protect sensitive information across various locations, including SharePoint Online. By configuring DLP policies, organizations can automatically detect content containing sensitive information types, such as credit card numbers or national ID numbers, and then apply protective actions. These actions can include blocking external sharing, notifying administrators, or even encrypting the content, thereby directly preventing unauthorized data exfiltration.

Why this answer

Data Loss Prevention (DLP) is the correct Microsoft Purview solution because it is specifically designed to detect and prevent the unauthorized sharing of sensitive data, such as credit card numbers or personally identifiable information (PII), by applying policies that can block external sharing in SharePoint Online. DLP policies can be configured to scan content in real-time and enforce actions like blocking access or sending notifications when sensitive data is detected in external sharing scenarios.

Exam trap

The trap here is that candidates often confuse sensitivity labels with DLP, assuming labels alone can block sharing, but labels only apply protection (e.g., encryption) and require DLP policies to enforce sharing restrictions.

How to eliminate wrong answers

Option B (eDiscovery) is wrong because eDiscovery is used for searching, holding, and exporting content for legal or investigative purposes, not for preventing data sharing in real-time. Option C (Sensitivity labels) is wrong because while sensitivity labels can classify and protect data with encryption or visual markings, they do not natively enforce external sharing blocks on their own; they require integration with DLP or conditional access policies to prevent sharing. Option D (Insider Risk Management) is wrong because it focuses on identifying and investigating risky user activities (e.g., data exfiltration by insiders) through analytics and alerts, rather than proactively blocking external sharing of sensitive data.

573
MCQeasy

An organization uses Microsoft Defender for Endpoint (MDE). The security team wants to identify devices that have not received a security update in the last 30 days. Which report should they use?

A.Threat analytics report
B.Device health report
C.Vulnerability management dashboard
D.Microsoft Secure Score report
AnswerB

The Device health report within Microsoft Defender for Endpoint provides a comprehensive overview of the security posture and operational status of managed devices. This report specifically includes critical information such as the status of security updates, antivirus protection, firewall configuration, and sensor health. Organizations can leverage this report to quickly identify devices that are missing essential security updates, thereby addressing potential vulnerabilities and ensuring compliance.

Why this answer

The Device health report in Microsoft Defender for Endpoint provides a list of devices and their last security update status, including the date of the last update. This report directly answers the requirement to identify devices that have not received a security update in the last 30 days by showing the 'Last update' column and allowing filtering by update age.

Exam trap

The trap here is that candidates confuse the Vulnerability management dashboard (which shows vulnerabilities) with a report that tracks update installation recency, but the dashboard does not provide a simple list of devices by last update date.

How to eliminate wrong answers

Option A is wrong because the Threat analytics report focuses on active threats, vulnerabilities, and attack campaigns, not on the update compliance status of individual devices. Option C is wrong because the Vulnerability management dashboard shows discovered vulnerabilities and their severity across devices, but it does not directly report on whether a security update has been installed within a specific time window. Option D is wrong because Microsoft Secure Score measures an organization's security posture based on configuration and control implementation, not the update recency of individual endpoints.

574
MCQeasy

A company implements a sign-in process where a user must provide their password and then enter a temporary code sent to their mobile phone. Which security principle is this process primarily enforcing?

A.Authorization
B.Authentication
C.Accounting
D.Non-repudiation
AnswerB

Combining a password with a one-time code sent to the user's phone verifies identity through two different factors, which is authentication. Authorisation governs what a verified user may access, so this process satisfies the requirement of proving who the user is.

Why this answer

The process of verifying a user's identity by requiring both a password (something they know) and a temporary code sent to their mobile phone (something they have) is a classic implementation of multi-factor authentication (MFA). Authentication is the security principle that confirms the identity of a user, device, or system before granting access. This sign-in flow directly enforces authentication by combining two distinct factors to prove the user is who they claim to be.

Exam trap

The trap here is that candidates often confuse authentication (proving identity) with authorization (granting permissions), especially when the question describes a multi-step sign-in process that seems to 'allow access' — but the core principle being enforced is identity verification, not access control.

Why the other options are wrong

A

The process described (password + temporary code) is about verifying identity, not granting permissions. Authorization determines what an authenticated user is allowed to do, not how they prove who they are.

C

The sign-in process described (password + temporary code) is a method of verifying identity, which is authentication. Accounting refers to tracking user activities and resource usage, not verifying identity.

D

Non-repudiation ensures that a party cannot deny having performed an action, typically through digital signatures or audit trails. The described sign-in process (password + temporary code) is about verifying identity (authentication), not preventing denial of actions.

When would these options actually be correct?

A

A question asking: 'After a user logs in, the system checks whether they can access a specific file. Which security principle is being applied?' — here Authorization is correct because it controls access rights after identity is verified.

C

A question that asks: 'Which security principle is primarily enforced when an organization logs user access times, data modifications, and resource usage for auditing purposes?' would make Accounting the correct answer.

D

An exam question might ask: 'A company uses digital signatures on all financial transactions to ensure that employees cannot deny authorizing payments. Which security principle is this?' In that case, non-repudiation would be correct because it provides proof of origin and integrity.

Why candidates pick the wrong answer

A

Candidates may confuse authentication (proving identity) with authorization (granting permissions), especially when the scenario involves multiple steps and they think the code is 'authorizing' access.

C

Candidates may confuse 'accounting' with 'authentication' because both are part of AAA (Authentication, Authorization, Accounting) and the term 'account' appears in both contexts, leading to a mix-up.

D

Candidates may confuse authentication with non-repudiation because both involve identity verification. However, non-repudiation goes further by providing evidence that can be used to prove an action occurred, which is not the primary goal of the sign-in process described.

575
MCQeasy

Your company is implementing a passwordless authentication strategy. You want users to be able to sign in using the Microsoft Authenticator app on their mobile devices. Which Microsoft Entra feature should you enable?

A.Windows Hello for Business
B.Passwordless phone sign-in with Microsoft Authenticator
C.FIDO2 security keys
D.Temporary Access Pass
AnswerB

Passwordless phone sign-in with Microsoft Authenticator leverages the user's mobile device as a second factor and a cryptographic key. When attempting to sign in, the user receives a notification on their Authenticator app, which they approve by matching a number or using biometrics, effectively eliminating the need to type a password. This method offers a convenient, secure, and widely applicable passwordless experience across various applications and services integrated with Azure Active Directory.

Why this answer

Passwordless phone sign-in with Microsoft Authenticator allows users to sign in without entering a password by approving a notification or entering a number displayed on the screen. This directly aligns with the requirement to use the Microsoft Authenticator app on mobile devices for a passwordless authentication strategy.

Exam trap

The trap here is that candidates may confuse 'passwordless' with any non-password method, but the question specifically requires the Microsoft Authenticator app, which eliminates Windows Hello for Business (device-bound) and FIDO2 (hardware-bound) as valid options.

How to eliminate wrong answers

Option A is wrong because Windows Hello for Business is a biometric or PIN-based credential tied to a specific Windows device, not a mobile app-based solution. Option C is wrong because FIDO2 security keys are hardware-based external devices (e.g., USB keys) that require physical possession, not the Microsoft Authenticator app on a mobile phone. Option D is wrong because Temporary Access Pass is a time-limited passcode used for onboarding or recovery scenarios, not a persistent passwordless sign-in method using the Authenticator app.

576
MCQhard

A company receives a subject rights request (SRR) from a customer under GDPR, asking for the deletion of all personal data held about them. The compliance team needs a tool to orchestrate the discovery of this data across Microsoft 365 and other systems, and to track the response and fulfillment of the request. Which Microsoft Purview solution should they use?

A.Microsoft Purview eDiscovery
B.Microsoft Purview Audit
C.Microsoft Purview Data Lifecycle Management (retention labels)
D.Microsoft Priva (Privacy Management)
AnswerD

Microsoft Priva (Privacy Management) is purpose-built to streamline the complex process of responding to Subject Rights Requests (SRRs). It offers automated data discovery across Microsoft 365, Azure, and other connected data sources, identifying personal data relevant to a specific data subject. Priva provides a comprehensive workflow for review, redaction, collaboration, and secure fulfillment, ensuring compliance with global privacy regulations like GDPR and and CCPA.

Why this answer

Microsoft Priva (Privacy Management) is the correct solution because it is specifically designed to help organizations manage subject rights requests (SRRs) under regulations like GDPR. It automates the discovery of personal data across Microsoft 365 and connected systems, provides a workflow to track the request lifecycle, and facilitates the fulfillment of actions such as deletion. This directly addresses the compliance team's need to orchestrate discovery and track response for an SRR.

Exam trap

The trap here is that candidates often confuse eDiscovery (which handles legal holds and litigation) with privacy management (which handles subject rights requests), but eDiscovery lacks the automated SRR workflow and privacy-specific orchestration that Priva provides.

Why the other options are wrong

A

eDiscovery is designed for legal discovery of content in litigation or investigations, not for orchestrating and tracking subject rights requests under GDPR. It lacks the workflow automation and privacy-specific features needed to manage SRR fulfillment across multiple systems.

B

Microsoft Purview Audit is designed for logging and investigating user and admin activity, not for orchestrating discovery or tracking fulfillment of subject rights requests under GDPR.

C

Data Lifecycle Management (retention labels) is used to classify and manage data retention and deletion policies, not to orchestrate discovery of personal data across systems or track subject rights request fulfillment.

When would these options actually be correct?

A

A company receives a legal hold notice for an ongoing lawsuit and needs to search for and preserve relevant emails and documents across Microsoft 365. Microsoft Purview eDiscovery would be the correct solution to identify, hold, and export that content.

B

A company needs to investigate a potential security incident by reviewing all user actions (e.g., file access, sign-ins) across Microsoft 365 over the past 90 days. Which Microsoft Purview solution should they use?

C

A company needs to automatically apply retention or deletion policies to documents based on their content (e.g., financial records) to comply with internal data governance policies. The question would ask for a solution to manage data retention and deletion lifecycle.

Why candidates pick the wrong answer

A

Candidates may confuse the data search aspect of eDiscovery with the data discovery needed for SRRs, not realizing that SRR management requires dedicated privacy workflow tools like Priva.

B

Candidates may confuse auditing with the ability to track data for compliance, or assume that audit logs can help locate personal data, but Audit does not provide data discovery or request management capabilities.

C

Candidates may confuse retention labels with data deletion capabilities, assuming that labeling data for deletion is equivalent to managing SRR fulfillment, but SRR requires cross-system discovery and workflow tracking, not just policy-based deletion.

577
MCQmedium

A company requires that all sensitive data in Microsoft Teams messages be automatically encrypted and labeled with a 'Confidential' tag. Which Microsoft Purview solution should they use?

A.Microsoft Purview Data Loss Prevention (DLP)
B.Microsoft Purview Data Lifecycle Management
C.Microsoft Purview Information Protection
D.Microsoft Purview Compliance Manager
AnswerC

Microsoft Purview Information Protection (MPIP) is the correct solution because it enables organizations to classify, label, and protect sensitive data across its lifecycle and various locations. Sensitivity labels, a core component of MPIP, can be configured with automatic labeling policies that detect specific sensitive information types (SITs) or trainable classifiers. Upon detection, these labels can apply visual markings, encryption, and access restrictions, ensuring that sensitive data in Microsoft Teams is consistently protected regardless of where it resides or travels.

Why this answer

Microsoft Purview Information Protection provides sensitivity labels such as 'Confidential' and applies encryption to content based on those labels. Labels can be applied manually or automatically to Teams messages and files, and encryption is enforced through the label's protection settings. This directly satisfies the requirement to encrypt and label sensitive Teams data.

Exam trap

SC-900 often tests the boundary between labeling/encryption and policy enforcement — candidates pick DLP when the question explicitly requires applying a label and encrypting the content.

How to eliminate wrong answers

Option A is wrong because DLP detects and blocks or warns on sharing of sensitive content but does not itself apply persistent encryption or sensitivity labels to messages. Option B is wrong because Data Lifecycle Management handles retention and deletion policies, not labeling or encryption. Option D is wrong because Compliance Manager assesses compliance posture against regulations and tracks improvement actions — it does not label or encrypt content.

578
MCQhard

Your organization is implementing Microsoft Entra Internet Access (formerly Microsoft Entra Internet Access). You need to secure access to public internet apps by enforcing traffic routing through Microsoft's network. Which feature should you enable?

A.Conditional Access
B.Global Secure Access
C.DDoS protection
D.Network segmentation
AnswerB

Microsoft Entra Global Secure Access is Microsoft's unified Security Service Edge (SSE) solution, designed to extend identity-centric security to network access. It functions as a cloud-delivered proxy, routing both internet-bound and private application traffic through Microsoft's global network security perimeter. This capability enables comprehensive traffic inspection, policy enforcement, and threat protection for all network flows, directly addressing the need for secure traffic routing and robust network security for an organization's users and devices.

Why this answer

Microsoft Entra Internet Access (part of Global Secure Access) routes traffic from users and devices through the Microsoft network to enforce security policies for public internet apps. Enabling Global Secure Access allows you to configure traffic forwarding profiles that redirect internet-bound traffic through Microsoft Entra Internet Access, ensuring consistent policy enforcement and threat protection.

Exam trap

The trap here is that candidates often confuse Conditional Access (an identity-based policy tool) with network-level traffic routing, not realizing that Global Secure Access is the specific feature designed to enforce traffic routing through Microsoft's network for internet-bound apps.

How to eliminate wrong answers

Option A is wrong because Conditional Access is an identity-driven policy engine that enforces access controls based on signals like user, device, and location, but it does not route traffic through Microsoft's network. Option C is wrong because DDoS protection (Azure DDoS Protection) mitigates distributed denial-of-service attacks at the network layer, not traffic routing or secure access to internet apps. Option D is wrong because network segmentation (e.g., virtual networks, subnets) isolates network traffic within an organization's infrastructure but does not redirect internet-bound traffic through Microsoft's network.

579
Multi-Selecthard

Which THREE are features of Microsoft Purview Data Loss Prevention (DLP)?

Select 3 answers
A.DLP policies for Exchange Online
B.Endpoint DLP for Windows 10/11
C.Policy tips in Outlook
D.Sensitivity label auto-classification
E.Insider risk management analytics
AnswersA, B, C

DLP policies are fundamental to protecting sensitive information transmitted via email. These policies scan email content, attachments, and subject lines for sensitive information types (SITs) or custom keywords before messages are sent or received. Upon detection, a policy can block the email, quarantine it for review, or simply warn the sender, thereby preventing unauthorized sharing of confidential data outside the organization. This capability is a core feature of Microsoft Purview Data Loss Prevention.

Why this answer

Microsoft Purview DLP natively supports DLP policies for Exchange Online (A), which let you detect sensitive information such as credit card or HIPAA data in email and take actions like block, encrypt, or notify; this is a core workload covered by Purview DLP. Endpoint DLP for Windows 10/11 (B) is also a feature of Purview DLP, extending policy enforcement to devices so users can't copy sensitive content to USB drives, print it, or paste it into unauthorized apps. Policy tips in Outlook (C) are a Purview DLP feature that surfaces inline notifications to users when they attempt to send content that violates a DLP policy, helping educate and prevent data loss.

Sensitivity label auto-classification (D) belongs to Microsoft Purview Information Protection (sensitivity labels), not DLP, even though labels can be used as DLP conditions. Insider risk management analytics (E) is a separate Microsoft Purview solution focused on detecting risky user behavior, not a DLP feature.

Exam trap

The trap here is that candidates confuse DLP's ability to use sensitivity labels as conditions with the auto-classification feature of MIP, leading them to select option D, while option E is a distractor that sounds like a DLP feature but belongs to a different Purview solution.

580
MCQhard

You are a compliance officer at a healthcare organization that uses Microsoft 365. The organization must comply with HIPAA regulations. You have Microsoft Purview, Microsoft Defender for Cloud Apps, and Microsoft Intune. You need to ensure that all devices accessing patient health information (PHI) are compliant with the organization's security policies, which require device encryption, a minimum OS version, and the use of a compliant mobile device management (MDM) provider. Currently, some devices are not managed by Intune. You need to enforce that only compliant devices can access PHI stored in SharePoint Online. What should you do?

A.Create a device compliance policy in Microsoft Intune and assign it to all users
B.Deploy an app protection policy in Microsoft Intune to restrict data access
C.Configure a conditional access policy in Microsoft Entra ID to require compliant devices
D.Create a DLP policy in Microsoft Purview to block access from non-compliant devices
AnswerC

A Microsoft Entra ID conditional access policy with the compliant device grant control blocks unmanaged devices from SharePoint Online, enforcing encryption, minimum OS version and MDM enrolment. Intune compliance policies supply the device state that the policy evaluates.

Why this answer

Conditional Access in Microsoft Entra ID is the policy engine that evaluates signals such as device compliance state at sign-in time and can grant, block, or require remediation. By creating a CA policy that requires a compliant device (or hybrid Azure AD joined device) for the SharePoint Online cloud app, only devices that satisfy the Intune compliance policy (encryption, minimum OS, MDM enrollment) can reach PHI.

Exam trap

SC-900 often tests the boundary between Intune compliance policies (which only classify devices) and Conditional Access (which actually enforces access) — candidates pick the Intune policy thinking it blocks access on its own.

How to eliminate wrong answers

Option A is wrong because a compliance policy alone only marks devices as compliant or not — it does not enforce any access decision, so non-compliant devices would still reach SharePoint. Option B is wrong because app protection policies (MAM) protect data within apps on unmanaged devices but do not gate access to SharePoint Online based on device compliance. Option D is wrong because Microsoft Purview DLP policies detect and block sensitive information flows, but they cannot evaluate device compliance state or act as an authentication gate.

581
MCQhard

A company runs critical applications on Windows Server virtual machines in Azure and on-premises. The security team wants to reduce the exposure of administrative ports (e.g., RDP, SSH) by requiring administrators to request just-in-time (JIT) access. The request should require approval from a central team, and the port should be opened only for a limited time. Which Microsoft security solution provides this JIT capability for both Azure and on-premises servers (when connected via Azure Arc)?

A.Microsoft Entra Privileged Identity Management (PIM)
B.Microsoft Defender for Identity
C.Microsoft Defender for Cloud (with just-in-time VM access)
D.Microsoft Defender for Cloud Apps
AnswerC

Microsoft Defender for Cloud provides advanced threat protection and security posture management for hybrid cloud workloads, including Windows Server virtual machines. Its Just-in-Time (JIT) VM access feature specifically addresses the requirement by allowing temporary, controlled access to management ports like RDP. This significantly reduces the attack surface by keeping these ports closed by default, only opening them for a limited time upon approval, which is crucial for securing critical applications.

Why this answer

Microsoft Defender for Cloud's just-in-time (JIT) VM access capability reduces exposure to administrative ports (RDP, SSH) by locking down inbound traffic to Azure VMs and Azure Arc-enabled on-premises servers. It requires administrators to request access, which can be configured to require approval from a central team, and automatically opens the specified ports for a limited time before closing them again. This directly matches the scenario's need for JIT access with approval and time-limited port opening across hybrid environments.

Exam trap

The trap here is that candidates confuse Privileged Identity Management (PIM) with just-in-time VM access because both involve 'just-in-time' and 'approval,' but PIM controls role activation in Azure AD/Entra ID, not network-level port access to virtual machines.

Why the other options are wrong

A

Microsoft Entra PIM manages just-in-time privileged access to Azure AD roles and Azure resources, but it does not provide JIT access to administrative ports (RDP/SSH) on virtual machines, whether in Azure or on-premises via Azure Arc.

B

Microsoft Defender for Identity is an on-premises security solution that detects identity threats using Active Directory signals, but it does not provide just-in-time (JIT) access control for administrative ports on VMs.

D

Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that focuses on securing cloud applications, not on managing just-in-time access to administrative ports on VMs. It does not provide JIT VM access capabilities.

When would these options actually be correct?

A

A question asks: 'Which Microsoft solution provides just-in-time and time-bound privileged role assignments for Azure AD roles, such as Global Administrator, with approval workflows?' In that context, Microsoft Entra PIM is the correct answer.

B

A question asking which Microsoft solution detects and investigates advanced attacks against on-premises Active Directory environments, such as pass-the-hash or golden ticket attacks, would have Microsoft Defender for Identity as the correct answer.

D

A question asks: 'Which Microsoft solution provides visibility and control over shadow IT, enforces data loss prevention policies, and detects anomalous behavior in cloud applications like Microsoft 365 and Salesforce?' In that scenario, Microsoft Defender for Cloud Apps would be the correct answer.

Why candidates pick the wrong answer

A

Candidates associate 'just-in-time' and 'approval' with PIM, but they overlook that PIM handles role-based access, not network-level port access for VMs.

B

Candidates may confuse 'Identity' in the name with identity-based access control, mistakenly thinking it includes JIT access management for administrative ports.

D

Candidates may confuse the 'just-in-time' concept with other security solutions, or assume that Defender for Cloud Apps includes JIT capabilities because it is part of the Microsoft Defender suite and deals with access control.

582
Matchingmedium

Match each Azure security service to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Enforce organizational standards and assess compliance

Define repeatable Azure resources and policies

Unified security management and threat protection

Cloud-native SIEM and SOAR solution

Securely store and manage secrets and keys

Why these pairings

Common confusions involve mixing up the purposes of security management (Defender for Cloud), SIEM/SOAR (Sentinel), and secret management (Key Vault).

583
MCQmedium

A company runs virtual machines in Azure and also maintains on-premises servers connected via Azure Arc. The security team needs a single dashboard to view security recommendations, detect misconfigurations, and track a secure score across both environments. They also want to enable advanced threat protection features such as just-in-time (JIT) VM access and file integrity monitoring for these workloads. Which Microsoft security solution should they implement?

A.Microsoft Defender for Cloud
B.Microsoft Sentinel
C.Microsoft Defender for Endpoint
D.Microsoft Defender for Cloud Apps
AnswerA

Microsoft Defender for Cloud provides a unified secure score, recommendations, and misconfiguration detection across Azure and Azure Arc-connected servers, plus JIT VM access and file integrity monitoring. This satisfies the single-dashboard and advanced threat protection requirements for both environments.

Why this answer

Microsoft Defender for Cloud provides a unified dashboard that displays security recommendations, misconfigurations, and a secure score across both Azure and on-premises workloads connected via Azure Arc. It also includes advanced threat protection features like just-in-time (JIT) VM access and file integrity monitoring, making it the correct choice for this scenario.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a CSPM and workload protection platform) with Microsoft Sentinel (a SIEM), but the question explicitly asks for a single dashboard for security posture, secure score, and advanced threat protection features like JIT and file integrity monitoring, which are exclusive to Defender for Cloud.

Why the other options are wrong

B

Microsoft Sentinel is a SIEM and SOAR solution for collecting and analyzing security logs, not a dashboard for security recommendations, misconfigurations, or secure score across hybrid environments. It does not provide just-in-time VM access or file integrity monitoring.

C

Microsoft Defender for Endpoint focuses on endpoint detection and response (EDR) for devices, not on providing a unified dashboard for security recommendations, misconfigurations, secure score, or advanced cloud workload protections like JIT VM access and file integrity monitoring across hybrid environments.

D

Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) focused on SaaS application security, not on providing a unified dashboard for VM secure score, misconfigurations, or advanced threat protection like JIT VM access and file integrity monitoring across Azure and on-premises servers.

When would these options actually be correct?

B

A company needs to aggregate security events from multiple sources (e.g., Azure, on-premises, third-party) for threat detection, incident response, and automated orchestration. The question would specify log collection, correlation, and alerting across diverse data sources.

C

A company needs to protect endpoints (e.g., workstations, servers) from advanced threats, with capabilities like antivirus, EDR, and threat hunting. The question would specify endpoint security, not hybrid cloud workload management or secure score.

D

A company uses multiple SaaS applications (e.g., Office 365, Salesforce) and needs to detect shadow IT, control access, and prevent data leaks from these apps. They also require visibility into user activities and anomaly detection across cloud apps.

Why candidates pick the wrong answer

B

Candidates may confuse Sentinel's security monitoring capabilities with Defender for Cloud's posture management and workload protection, especially since both involve security dashboards and threat detection.

C

Candidates may confuse 'Defender for Endpoint' with 'Defender for Cloud' due to similar naming, or assume endpoint protection covers all security needs, overlooking the specific requirements for cloud workload protection and secure score.

D

Candidates may confuse 'Cloud Apps' with 'Cloud' and think it covers all cloud workloads, or they may assume it includes VM security features due to the 'Defender' branding.

584
MCQmedium

A compliance officer needs to investigate a potential data exfiltration incident. They must search the unified audit log for all activities where users accessed a specific sensitive SharePoint site in the last 7 days. Additionally, they need to create a custom alert that triggers when more than 10 file downloads occur from that site within an hour. Which Microsoft Purview solution should they use?

A.Microsoft Purview Audit (Standard)
B.Microsoft Purview Data Loss Prevention (DLP)
C.Microsoft Purview eDiscovery
D.Microsoft Purview Communications Compliance
AnswerA

Microsoft Purview Audit (Standard) provides access to the unified audit log, enabling organizations to search for user and administrator activities across various Microsoft 365 services, including SharePoint Online. This service allows compliance officers to investigate past events, such as unusual file downloads, and to create custom alert policies based on specific activity patterns or thresholds. Its capability to search historical audit data and configure alerts for suspicious behaviors directly addresses the need for both investigation and proactive monitoring.

Why this answer

Microsoft Purview Audit (Standard) logs all user activities, including file accesses and downloads from SharePoint sites, for 90 days. The compliance officer can search the unified audit log for the specific site's activities over the last 7 days and create custom alert policies (e.g., threshold-based alerts for >10 downloads per hour) using the Microsoft 365 Defender portal. This makes Audit (Standard) the correct solution for both investigation and alerting.

Exam trap

The trap here is that candidates confuse the investigative and alerting capabilities of Audit (Standard) with the preventive controls of DLP, assuming DLP can retroactively search logs or create threshold-based alerts, when in fact DLP only applies real-time policies to content in transit or at rest.

Why the other options are wrong

B

Microsoft Purview Data Loss Prevention (DLP) is designed to prevent data exfiltration by enforcing policies on sensitive data, not to investigate past incidents or create alerts based on activity thresholds from the unified audit log.

C

Microsoft Purview eDiscovery is designed for legal investigations and content searches across data sources, not for real-time monitoring of user activities or creating custom alerts based on download thresholds from the unified audit log.

D

Microsoft Purview Communications Compliance is designed to monitor and manage internal and external communications for regulatory compliance, not to investigate data exfiltration via audit logs or create alerts based on file download thresholds from SharePoint.

When would these options actually be correct?

B

A question asks: 'An organization needs to prevent users from sharing credit card numbers via email. Which Microsoft Purview solution should they use?' In that scenario, DLP would be correct because it can detect and block sensitive data in transit.

C

A legal team needs to identify and preserve all documents containing specific keywords from a SharePoint site as part of a litigation hold. They must search across mailboxes, sites, and Teams for relevant content and export it for review. In this case, Microsoft Purview eDiscovery would be the correct solution.

D

A question asking which solution monitors employee communications (e.g., email, Teams) for inappropriate language, sensitive information sharing, or regulatory compliance (e.g., FINRA, SEC rules) would make Communications Compliance the correct answer.

Why candidates pick the wrong answer

B

Candidates may confuse DLP's data protection capabilities with audit and alerting, assuming DLP can both monitor and alert on download activities, but DLP focuses on policy enforcement rather than historical investigation and custom alert rules.

C

Candidates may confuse eDiscovery's ability to search audit logs and content with the real-time alerting and investigation capabilities of Audit, especially when the question involves searching for user activities and setting thresholds.

D

Candidates may confuse 'compliance' with general compliance tasks like investigating incidents, or think Communications Compliance covers all compliance-related monitoring including data exfiltration.

585
MCQhard

Your company is deploying Microsoft Entra ID Governance. They want to automate the review of guest user access to Microsoft Teams and remove access when guests leave the partner organization. Which feature should they implement?

A.Access reviews and connected organizations
B.Entitlement management
C.Terms of use
D.Password policies
AnswerA

Access reviews are a core component of Microsoft Entra ID Governance, enabling organizations to periodically review access rights for users, including guests. When combined with connected organizations, which define external partners, access reviews can be configured to automatically remove guest accounts or their access to resources if their access is no longer justified or if reviewers fail to attest to their continued need. This directly addresses the requirement for automated removal of guest access.

Why this answer

Access reviews in Microsoft Entra ID Governance allow you to create recurring reviews of guest user access to resources like Microsoft Teams. By configuring the review to include connected organizations, you can automatically remove guest access when the guest's identity is no longer associated with a partner organization, such as when they leave the partner company. This automation is achieved through the integration of access reviews with the connected organization's lifecycle, ensuring that guest access is revoked without manual intervention.

Exam trap

The trap here is that candidates often confuse entitlement management (which handles access requests and provisioning) with access reviews (which handle periodic attestation and automated removal), leading them to choose entitlement management instead of the correct feature for automated removal based on partner organization changes.

How to eliminate wrong answers

Option B is wrong because entitlement management is used to manage access packages and automate the request and approval process for resources, but it does not directly automate the removal of guest access based on the guest leaving a partner organization; that is the function of access reviews with connected organizations. Option C is wrong because terms of use are used to present and require acceptance of legal or policy documents before accessing resources, not to automate access removal based on organizational membership changes. Option D is wrong because password policies control password complexity, expiration, and lockout settings, and have no role in automating the review or removal of guest access based on partner organization membership.

586
MCQeasy

Your company uses Microsoft Purview to manage records. You need to ensure that financial records are retained for 7 years and then permanently deleted. Which type of policy should you create?

A.A retention policy with a retention period of 7 years and then delete
B.A sensitivity label set to 'Financial' with auto-labeling
C.A retention label that triggers a disposition review after 7 years
D.A DLP policy that blocks sharing of financial records
AnswerA

A retention policy with a retention period of 7 years and then delete is the correct solution because retention policies are designed to automatically apply retention and deletion actions across entire locations, such as SharePoint sites or Exchange mailboxes. This policy ensures that content is retained for the specified 7 years and then permanently deleted without requiring any manual intervention, directly fulfilling the requirement for automatic disposition.

Why this answer

A retention policy with a retention period of 7 years and then delete is correct because it applies a time-based retention rule to financial records at the container or folder level, ensuring they are kept for exactly 7 years and then permanently removed without human intervention. This meets the requirement for automatic deletion after the retention period, as opposed to a disposition review which requires manual approval.

Exam trap

The trap here is that candidates confuse a retention label with a retention policy, thinking a label is required for deletion, but a retention policy can enforce deletion at the container level without needing a label or human review.

How to eliminate wrong answers

Option B is wrong because a sensitivity label set to 'Financial' with auto-labeling classifies data based on sensitivity but does not enforce a retention or deletion schedule; it only applies protection actions like encryption or headers. Option C is wrong because a retention label that triggers a disposition review after 7 years requires a human to approve deletion, which contradicts the requirement for permanent deletion without manual steps. Option D is wrong because a DLP policy blocks sharing of financial records to prevent data loss but does not manage retention or deletion timelines.

587
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID) to manage user access to cloud applications. The security team wants to enforce that users must provide a second form of authentication, such as a phone call or mobile app notification, in addition to their password. Which Microsoft Entra capability should they enable?

A.Conditional Access
B.Identity Protection
C.Multi-Factor Authentication
D.Privileged Identity Management
AnswerC

Multi-Factor Authentication (MFA) is the security feature specifically designed to enhance account security by requiring users to provide two or more distinct verification factors to prove their identity. These factors typically come from different categories, such as something you know (password), something you have (phone, authenticator app), or something you are (biometrics). MFA directly implements and provides the additional authentication factor beyond the primary password, making it the correct choice for adding a second verification method.

Why this answer

Multi-Factor Authentication (MFA) is the correct capability because it requires users to provide a second form of authentication (e.g., phone call, mobile app notification) in addition to their password. This directly addresses the security team's requirement for a second authentication factor, which is the core function of MFA in Microsoft Entra ID.

Exam trap

The trap here is that candidates may confuse Conditional Access (which can *require* MFA) with the actual MFA capability itself, but the question asks for the capability that *provides* the second form of authentication, not the policy that enforces it.

How to eliminate wrong answers

Option A is wrong because Conditional Access is a policy engine that enforces conditions (e.g., location, device state) to grant access, but it does not itself provide a second authentication factor; it can require MFA as a control, but the capability to provide the second factor is MFA. Option B is wrong because Identity Protection uses risk signals (e.g., leaked credentials, anonymous IP addresses) to detect and respond to potential identity threats, but it does not enforce a second authentication factor; it can trigger MFA via Conditional Access, but the second factor itself is MFA. Option D is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and approval workflows, not the enforcement of a second authentication factor for all users.

588
MCQmedium

A company uses Microsoft Entra ID. The security team wants to automatically detect user behaviors that indicate possible compromise, such as leaked credentials, impossible travel, or anomalous login patterns. When a user is determined to be at high risk, the system should automatically require the user to reset their password the next time they sign in. Which Microsoft Entra capability should they use?

A.Conditional Access
B.Identity Protection
C.Privileged Identity Management (PIM)
D.Identity Governance
AnswerB

Microsoft Entra ID Protection is specifically designed to detect and remediate identity-based risks. It analyzes sign-in and user behavior to identify threats like impossible travel, leaked credentials, or unfamiliar sign-in properties. Crucially, it allows administrators to configure user risk policies that can automatically enforce actions such as requiring a password reset or blocking access when a user's risk level is deemed high, directly addressing the need for automated remediation.

Why this answer

Identity Protection is the correct Microsoft Entra capability because it is specifically designed to automatically detect risky user behaviors such as leaked credentials, impossible travel, and anomalous sign-in patterns. It assigns a risk level to users and sign-ins, and can be configured with a Conditional Access policy to enforce actions like requiring a password reset at next sign-in when a user is deemed high risk. This directly matches the security team's requirement for automated detection and remediation.

Exam trap

Microsoft often tests the distinction between detection and enforcement: candidates mistakenly choose Conditional Access because it enforces the password reset, but the question asks for the capability that automatically detects the risky behaviors, which is Identity Protection—Conditional Access is the enforcement mechanism, not the detection engine.

How to eliminate wrong answers

Option A is wrong because Conditional Access is a policy engine that enforces access controls based on conditions (e.g., location, device state), but it does not itself detect risky behaviors like leaked credentials or impossible travel; it relies on Identity Protection to provide the risk signals. Option C is wrong because Privileged Identity Management (PIM) focuses on just-in-time privileged role activation, approval workflows, and access reviews for administrative roles, not on detecting user compromise behaviors or enforcing password resets for risky users. Option D is wrong because Identity Governance manages user lifecycle, access certifications, and entitlement management (e.g., access reviews, group membership), but it does not include risk detection or automatic remediation for compromised accounts.

589
MCQeasy

A company uses Microsoft Entra ID. A new IT support technician is hired and needs to be able to reset passwords for users but must not be allowed to delete user accounts or modify group memberships. Which built-in Microsoft Entra ID role should be assigned to this technician?

A.User Administrator
B.Password Administrator
C.Helpdesk Administrator
D.Global Administrator
AnswerB

The Password Administrator role in Microsoft Entra ID is specifically designed for helpdesk personnel who need to reset passwords for users and manage service requests related to identity issues. This role grants the necessary permissions to perform password resets without conferring broader administrative rights, such as the ability to create or delete user accounts, modify group memberships, or manage other user properties. It perfectly adheres to the principle of least privilege by providing only the capabilities essential for password management tasks.

Why this answer

The Password Administrator role is the correct choice because it grants the specific permissions required to reset passwords for all users, including administrators, while explicitly excluding permissions to delete user accounts or modify group memberships. This role is designed for scenarios where a technician needs to perform password-related tasks without broader user management capabilities.

Exam trap

The trap here is that candidates often confuse the Password Administrator role with the Helpdesk Administrator role, mistakenly thinking the latter is more restrictive, when in fact the Helpdesk Administrator has broader user management capabilities including modifying user properties and managing support tickets.

Why the other options are wrong

A

The User Administrator role can reset passwords but also allows deleting user accounts and modifying group memberships, which exceeds the required permissions.

C

The Helpdesk Administrator role can reset passwords, but it also allows managing support tickets and other helpdesk functions, which is broader than the requirement. However, the key issue is that the Password Administrator role is more restrictive and specifically designed for password resets, making it the correct choice.

D

The Global Administrator role has full access to all Microsoft Entra ID features, including deleting user accounts and modifying group memberships, which exceeds the technician's required permissions.

When would these options actually be correct?

A

A question where the technician needs to manage all user and group objects, including creating users, resetting passwords, and managing group memberships, but not have full administrative access.

C

A company needs a technician who can reset passwords AND manage service requests (support tickets) in the Microsoft 365 admin center, but not delete users or modify groups. In that scenario, Helpdesk Administrator would be the correct role.

D

This role would be correct if the question asked for a role that can manage all aspects of Microsoft Entra ID, including security settings, user administration, and access to all administrative features, with no restrictions.

Why candidates pick the wrong answer

A

Candidates may think 'User Administrator' is the standard role for user management tasks like password resets, overlooking its broader permissions.

C

Candidates may think 'Helpdesk' implies password reset duties, and they might not be aware of the Password Administrator role's existence or its narrower scope.

D

Candidates may choose this option because they think the technician needs broad administrative powers to reset passwords, overlooking the specific restrictions mentioned in the question.

590
MCQhard

Refer to the exhibit. You are creating a Microsoft Purview sensitivity label for HR data. The JSON shows a label configuration. What is the likely effect of setting the sensitivity value to 90?

A.The label automatically encrypts the document
B.The label triggers auditing for 90 days
C.The label sets a 90-day retention period
D.The label will be applied with higher priority than labels with lower sensitivity values
AnswerD

In Microsoft Purview, sensitivity labels are assigned a priority order, typically based on their sensitivity value. When multiple auto-labeling policies might apply different labels to the same content, the label with the higher sensitivity value (and thus higher priority) will be applied. This ensures that the most restrictive or appropriate classification and protection settings are consistently enforced.

Why this answer

In Microsoft Purview, sensitivity labels are assigned an integer priority value (typically 0 to 100). A higher sensitivity value indicates a higher priority. When multiple labels are available, the label with the highest sensitivity value is applied by default or takes precedence in auto-labeling and policy conflicts.

Setting the value to 90 ensures this HR label is prioritized over labels with lower values, such as 75 or 50.

Exam trap

The SC-900 exam often tests the misconception that the sensitivity value directly controls encryption, retention, or auditing, when in fact it only determines label priority in a hierarchical classification scheme.

How to eliminate wrong answers

Option A is wrong because sensitivity labels do not automatically encrypt documents unless an encryption action (e.g., 'Protect' with user-defined permissions) is explicitly configured in the label settings; the JSON snippet only shows a sensitivity value, not an encryption action. Option B is wrong because auditing is controlled by audit policies in Microsoft 365, not by the sensitivity value; a value of 90 does not trigger or set an audit duration. Option C is wrong because retention periods are configured separately via retention labels or retention policies in Microsoft Purview, not by the sensitivity value of a sensitivity label.

591
MCQmedium

A company has several custom-developed web applications hosted on-premises. The company wants to provide employees with secure remote access to these applications without deploying a traditional VPN. Employees should be able to sign in using their existing Microsoft Entra ID credentials, and the solution should pass through multi-factor authentication policies. Which Microsoft Entra ID feature should they implement?

A.Microsoft Entra Application Proxy
B.Microsoft Entra Domain Services
C.Microsoft Entra Privileged Identity Management
D.Microsoft Entra Identity Protection
AnswerA

Microsoft Entra Application Proxy is the correct solution because it provides secure remote access to on-premises web applications by acting as a reverse proxy. It integrates these applications with Microsoft Entra ID, allowing users to authenticate using their Entra ID credentials, including multi-factor authentication and Conditional Access policies. The Application Proxy connector, installed on the on-premises network, establishes an outbound-only connection to the Entra ID cloud service, eliminating the need for inbound firewall rules or a VPN.

Why this answer

Microsoft Entra Application Proxy provides secure remote access to on-premises web applications by acting as a reverse proxy. It allows employees to sign in with their existing Microsoft Entra ID credentials and enforces conditional access policies, including multi-factor authentication, without requiring a traditional VPN.

Exam trap

The trap here is that candidates often confuse Microsoft Entra Application Proxy with a traditional VPN or assume that Microsoft Entra Domain Services is needed for authentication, but the key requirement is secure remote access without VPN, which only Application Proxy fulfills by acting as a reverse proxy with Entra ID integration.

Why the other options are wrong

B

Microsoft Entra Domain Services provides managed domain services like domain join and LDAP, not secure remote access to on-premises web applications with Microsoft Entra ID authentication and MFA.

C

Privileged Identity Management (PIM) manages, controls, and monitors access to privileged roles in Microsoft Entra ID, but it does not provide secure remote access to on-premises web applications. The question requires a solution for remote application access, not identity governance.

D

Microsoft Entra Identity Protection is a risk-based detection and remediation tool, not a remote access solution. It does not provide secure access to on-premises web applications or pass through authentication to them.

When would these options actually be correct?

B

A company needs to migrate legacy on-premises applications that require LDAP or NTLM authentication to the cloud without rewriting them. They want to use Microsoft Entra ID for authentication but the apps don't support modern protocols. In this case, Entra Domain Services would provide the necessary domain services.

C

A company needs to implement just-in-time privileged access for administrators managing critical Azure resources, requiring time-bound role assignments and approval workflows. PIM would be the correct answer for managing and auditing privileged roles.

D

An exam question asks: 'A company wants to automatically detect and respond to suspicious sign-in behaviors, such as impossible travel or leaked credentials, and enforce conditional access policies based on user risk. Which Microsoft Entra feature should they implement?'

Why candidates pick the wrong answer

B

Candidates may confuse 'Domain Services' with providing access to on-premises resources, or think that domain services are needed for authentication and MFA pass-through.

C

Candidates may confuse PIM with a security feature that controls access, but they overlook that PIM focuses on role-based access control for privileged identities, not on proxying application traffic.

D

Candidates may confuse Identity Protection's security monitoring capabilities with the secure access requirements of the question, thinking that identity protection includes remote access features.

592
Multi-Selectmedium

Which THREE of the following are features of Microsoft Entra ID Governance? (Select three.)

Select 3 answers
A.Access reviews
B.Privileged Identity Management (PIM)
C.Entitlement management
D.Self-service password reset
E.Multifactor authentication
AnswersA, B, C

Microsoft Entra Access Reviews enable organizations to efficiently manage group memberships, access to enterprise applications, and roles. They help ensure that users only have the access they need, reducing the risk of excessive or stale permissions. These reviews can be scheduled periodically or triggered on demand, requiring reviewers (e.g., group owners, managers) to attest to continued access necessity.

Why this answer

Access reviews (A) are a core Microsoft Entra ID Governance capability that lets organizations periodically recertify users' group memberships, application access, and role assignments to ensure least privilege. Privileged Identity Management (B) is included in Entra ID Governance and provides just-in-time privileged role activation, approval workflows, access reviews, and audit history for privileged access. Entitlement management (C) is also a governance feature that automates access request workflows, access packages, and lifecycle policies for internal and external users.

Self-service password reset (D) is an authentication/credential-management feature, not a governance capability, and multifactor authentication (E) is an authentication method for strengthening sign-in security, so neither belongs to Entra ID Governance.

Exam trap

The trap here is that candidates confuse security features like MFA and SSPR (which are part of Microsoft Entra ID's core authentication and protection capabilities) with governance features, which specifically focus on access lifecycle, attestation, and privileged role management.

593
Multi-Selecthard

Which THREE capabilities are provided by Microsoft Defender XDR (formerly Microsoft 365 Defender)? (Choose three.)

Select 3 answers
A.Identity threat detection
B.Data classification and labeling
C.Endpoint detection and response (EDR)
D.Mobile device management (MDM)
E.Email and collaboration protection
AnswersA, C, E

Microsoft Defender for Identity provides robust identity threat detection by continuously monitoring on-premises Active Directory signals and cloud identities for suspicious activities and anomalous behaviors. It leverages behavioral analytics and machine learning to identify advanced attacks such as pass-the-hash, golden ticket, and brute-force attempts, offering real-time insights into potential compromises across hybrid environments. This capability is a core component of Microsoft Defender XDR, integrating with other Defender services to provide a comprehensive view of identity-related risks and incidents.

Why this answer

Microsoft Defender XDR is a unified extended detection and response suite that correlates signals across identities, endpoints, email, and collaboration tools. Option A (Identity threat detection) is correct because Microsoft Defender for Identity is a core component of Defender XDR, detecting advanced identity-based attacks such as pass-the-hash, Kerberoasting, and reconnaissance against Active Directory. Option C (Endpoint detection and response (EDR)) is correct because Microsoft Defender for Endpoint provides EDR capabilities—behavioral monitoring, attack timeline, and automated investigation and response—within the Defender XDR portal.

Option E (Email and collaboration protection) is correct because Microsoft Defender for Office 365 delivers protection against phishing, malware, and business email compromise across Exchange Online, Teams, SharePoint, and OneDrive. Option B (Data classification and labeling) is not part of Defender XDR; that capability belongs to Microsoft Purview Information Protection (sensitivity labels and data classification). Option D (Mobile device management (MDM)) is not provided by Defender XDR; MDM is delivered by Microsoft Intune, although Defender for Endpoint can integrate with Intune for onboarding and compliance signals.

Exam trap

The trap here is that candidates confuse Microsoft Defender XDR's unified threat protection capabilities with broader Microsoft 365 security features like compliance (Purview) or device management (Intune), leading them to select data classification or MDM as valid options.

594
MCQmedium

Your company uses Microsoft Defender for Cloud to assess security posture. A recommendation states that virtual machines should have just-in-time (JIT) network access enabled. What is the primary security benefit of enabling JIT?

A.It reduces the attack surface by opening ports only when necessary
B.It replaces the need for network security groups
C.It encrypts all network traffic between the VM and clients
D.It permanently blocks all inbound traffic to the VM
AnswerA

Just-in-Time (JIT) VM access significantly reduces the attack surface by ensuring that management ports, such as RDP and SSH, remain closed by default. It dynamically opens these ports only for a limited time and from specified source IP addresses when an authorized request is made. This temporary, conditional access minimizes the window of opportunity for malicious actors to exploit open ports, thereby enhancing the security posture of virtual machines.

Why this answer

JIT VM access in Microsoft Defender for Cloud works by keeping management ports (RDP 3389, SSH 22) closed by default and only opening them on demand when an authorized user requests access, for a limited time and from a specific source IP. This dramatically reduces the attack surface exposed to internet-based brute-force and scanning attacks, since the ports are not persistently listening. Once the approved time window expires, Defender for Cloud automatically closes the port via NSG rules.

Exam trap

SC-900 often tests the misconception that JIT is an encryption or permanent-blocking feature, when it is actually a time-bound, on-demand port-opening mechanism layered on top of NSGs.

How to eliminate wrong answers

Option B is wrong because JIT does not replace network security groups — it actually works by dynamically modifying NSG rules, so NSGs remain a required underlying control. Option C is wrong because JIT has nothing to do with encryption; encryption of traffic is handled by TLS/IPsec, not by port-access control. Option D is wrong because JIT does not permanently block inbound traffic — it temporarily opens specific ports on request and closes them after the approved window, which is the opposite of a permanent block.

595
MCQeasy

A company wants to allow users to reset their own passwords from the login screen without contacting IT. Which Microsoft Entra ID feature enables this?

A.Conditional Access
B.Multifactor authentication
C.Self-Service Password Reset
D.Identity Protection
AnswerC

Self-Service Password Reset lets users reset or unlock their accounts from the sign-in page after proving identity via authentication methods, removing IT involvement. This directly satisfies the stem's requirement for login-screen resets without contacting the service desk.

Why this answer

Self-Service Password Reset (SSPR) is the Microsoft Entra ID feature that allows users to reset their own passwords from the login screen without contacting IT. It is specifically designed to reduce helpdesk workload by enabling password changes or unlocks through a verified authentication method, such as a phone call, text message, or the Microsoft Authenticator app.

Exam trap

The trap here is that candidates often confuse Conditional Access with SSPR because both appear in the login flow, but Conditional Access enforces policies after authentication, whereas SSPR is a separate feature for password recovery before authentication completes.

How to eliminate wrong answers

Option A is wrong because Conditional Access is a policy engine that enforces access controls (e.g., requiring MFA or blocking sign-ins from specific locations) based on signals like user, device, or location, but it does not provide password reset functionality. Option B is wrong because Multifactor Authentication (MFA) adds an extra layer of security by requiring a second verification factor during sign-in, but it does not enable users to reset their own passwords. Option D is wrong because Identity Protection uses machine learning to detect and respond to identity-based risks (e.g., leaked credentials or anomalous sign-ins), but it does not include a self-service password reset capability.

596
MCQeasy

A company wants to automatically detect and remediate compliance issues such as sharing sensitive data externally. Which Microsoft Purview solution should they use?

A.Microsoft Purview Records Management
B.Microsoft Purview Data Loss Prevention
C.Microsoft Purview eDiscovery
D.Microsoft Purview Audit
AnswerB

Microsoft Purview Data Loss Prevention (DLP) is precisely designed to identify, monitor, and protect sensitive information across various locations, including cloud services, endpoints, and on-premises. DLP policies use sophisticated rules to detect sensitive data and automatically apply remediation actions, such as blocking sharing, encrypting content, or notifying administrators, effectively preventing unauthorized disclosure and ensuring compliance.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect, alert, and automatically remediate when sensitive data (e.g., credit card numbers, personally identifiable information) is shared externally via email, Teams, or cloud apps. DLP policies can enforce actions like blocking the transmission or applying encryption, directly addressing the requirement to prevent unauthorized external sharing of sensitive data.

Exam trap

The trap here is that candidates often confuse the proactive, blocking capability of DLP with the reactive, investigative tools like eDiscovery or Audit, mistakenly thinking that logging or searching for past incidents fulfills the requirement to 'automatically detect and remediate' in real time.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Records Management focuses on managing the lifecycle of records (retention, deletion, and disposition) for compliance with regulatory requirements, not on detecting or preventing real-time data sharing violations. Option C is wrong because Microsoft Purview eDiscovery is used for searching, preserving, and exporting content for legal investigations or litigation, not for proactive detection and remediation of data sharing compliance issues. Option D is wrong because Microsoft Purview Audit provides logging and forensic visibility into user and admin activities (e.g., who accessed what and when), but it does not have the capability to automatically detect and block sensitive data sharing in transit.

597
MCQhard

A multinational corporation stores highly sensitive intellectual property in SharePoint Online. To meet regulatory requirements, they need an additional layer of encryption beyond Microsoft's baseline encryption. The company wants to manage their own encryption keys using Azure Key Vault, so that if they remove the key from the service, the data becomes unreadable. Which Microsoft Purview solution should they implement?

A.Double Key Encryption
B.Customer Key
C.Information Rights Management
D.Customer Lockbox
AnswerB

Correct. Microsoft Purview Customer Key allows customers to provide and manage their own encryption keys using Azure Key Vault, providing an additional layer of encryption on top of the baseline. Data is encrypted using these keys, and the customer can control key access.

Why this answer

Customer Key (Option B) is the correct solution because it provides the ability to control and manage the encryption keys used to encrypt data at rest in Microsoft 365, including SharePoint Online. By using Azure Key Vault to store the keys, the organization can revoke access at any time, rendering the data unreadable—a key requirement for meeting regulatory obligations. This goes beyond Microsoft's baseline encryption by adding a customer-controlled layer of encryption.

Exam trap

The trap here is that candidates often confuse Customer Key with Double Key Encryption, mistakenly thinking DKE is required for customer-managed keys in Azure Key Vault, when in fact Customer Key is the correct solution for managing encryption keys at rest across Microsoft 365 workloads.

Why the other options are wrong

A

Double Key Encryption (DKE) requires two keys: one managed by Microsoft and one managed by the customer. The question specifies that the company wants to manage their own encryption keys using Azure Key Vault and that removing the key makes data unreadable, which aligns with Customer Key, not DKE. DKE is designed for scenarios where data must be encrypted with a key held outside Microsoft's control, but it does not use Azure Key Vault for the customer key.

D

Customer Lockbox provides controlled access for Microsoft engineers to your data during support requests, not an additional layer of encryption where you manage your own keys. It does not make data unreadable if you remove a key.

When would these options actually be correct?

A

A company needs to ensure that only they can decrypt sensitive data, even if Microsoft's systems are compromised, and they want to hold one of the two encryption keys themselves (not in Azure Key Vault). For example: 'A law firm stores highly confidential client documents in SharePoint Online and requires that no one, including Microsoft, can access the data without the firm's explicit key, which is stored on-premises.'

D

A company needs to ensure that Microsoft support engineers cannot access their data without explicit approval, often for compliance or audit purposes. The question would specify a need for access control during support sessions, not encryption key management.

Why candidates pick the wrong answer

A

Candidates may confuse Double Key Encryption with Customer Key because both involve customer-managed keys. The term 'double' might suggest an extra layer of encryption, which matches the question's requirement for an additional layer beyond baseline encryption.

D

Candidates may confuse 'Customer Lockbox' with a customer-managed encryption solution because both involve customer control, but Lockbox controls access, not encryption keys.

598
MCQeasy

A company implements multiple layers of security controls: firewalls at the perimeter, intrusion detection systems on internal segments, antivirus software on all workstations, and encryption for sensitive data at rest and in transit. This strategy is intended to ensure that if one control fails, others still provide protection. Which security concept does this approach represent?

A.Least privilege
B.Defense in depth
C.Separation of duties
D.Zero trust
AnswerB

Defense in depth is a comprehensive cybersecurity strategy that employs a series of diverse and overlapping security mechanisms and controls to protect valuable assets. By implementing multiple layers—such as physical security, network segmentation, firewalls, intrusion detection systems, endpoint protection, and data encryption—organizations create a robust and resilient defense. This multi-layered approach ensures that if one security control fails or is bypassed, subsequent layers are still in place to detect and prevent a breach, significantly increasing the effort and time required for an attacker to succeed.

Why this answer

Defense in depth is the correct concept because it involves implementing multiple layers of security controls (e.g., firewalls, IDS, antivirus, encryption) so that if one layer fails, subsequent layers continue to provide protection. This layered approach ensures redundancy and mitigates the risk of a single point of failure, aligning with the scenario described.

Exam trap

The trap here is that candidates often confuse defense in depth with zero trust, mistakenly thinking that multiple layers automatically imply a zero-trust architecture, but zero trust specifically requires explicit verification per request rather than just layered controls.

Why the other options are wrong

A

The question describes multiple layers of security controls (firewalls, IDS, antivirus, encryption) working together to provide protection even if one fails. This is the definition of defense in depth, not least privilege, which focuses on granting only necessary permissions.

C

Separation of duties prevents fraud or error by dividing critical tasks among multiple people, not by layering security controls. The question describes multiple overlapping security layers, which is defense in depth, not separation of duties.

D

Zero trust is a security model that assumes no implicit trust and requires continuous verification of every access request, not a layered defense strategy. The question describes multiple overlapping controls, which is defense in depth, not zero trust.

When would these options actually be correct?

A

A scenario where a company restricts user access rights so that employees can only access the data and systems required for their job roles, with no unnecessary permissions. The question would ask about minimizing exposure to sensitive data.

C

A company requires that no single employee can approve a purchase order and also process the payment. This ensures that two people must collaborate to complete a financial transaction, reducing the risk of embezzlement. This scenario tests separation of duties.

D

A question describing a network architecture where no device or user is trusted by default, even if inside the corporate perimeter, and every access request must be authenticated and authorized regardless of location. For example: 'A company implements micro-segmentation, requires multi-factor authentication for all internal resource access, and continuously validates device health before granting access.'

Why candidates pick the wrong answer

A

Candidates may confuse 'least privilege' with the layered approach because both involve security controls, but least privilege is about access rights, not overlapping defenses.

C

Candidates may confuse 'separation of duties' with 'multiple layers of defense' because both involve multiple components, but separation of duties is about dividing responsibilities among people, not layering technical controls.

D

Candidates may confuse zero trust with defense in depth because both involve multiple security controls, but zero trust specifically focuses on eliminating implicit trust and verifying every access, not on layered protection against failure of a single control.

599
MCQhard

Refer to the exhibit. You run a KQL query in Microsoft Sentinel to investigate ransomware alerts. The query returns: AlertSeverity High: 5, Medium: 3, Low: 2. The security team wants to automate a response for all high-severity ransomware alerts. What should you configure?

A.Create an analytics rule for ransomware
B.Create a hunting query for ransomware
C.Create a workbook to display ransomware alerts
D.Create an automation rule that triggers a playbook for high-severity ransomware incidents
AnswerD

Automation rules in Microsoft Sentinel are specifically engineered to manage and respond to incidents automatically, serving as the orchestrator for automated actions. By configuring an automation rule to trigger a specific playbook (an Azure Logic App) when a high-severity ransomware incident is created, organizations can execute predefined, automated response steps. This capability is central to Security Orchestration, Automation, and Response (SOAR), ensuring rapid and consistent handling of critical threats.

Why this answer

Microsoft Sentinel automation rules allow you to define automated responses triggered when incidents are created or updated. By configuring an automation rule with a condition that checks for 'AlertSeverity' equal to 'High' and 'Ransomware' as the related alert, you can invoke a playbook to automatically respond to high-severity ransomware incidents, such as isolating affected machines or blocking indicators of compromise.

Exam trap

Microsoft Sentinel components are often tested: analytics rules for detection, hunting queries for investigation, workbooks for visualization, and automation rules for automated response. Candidates commonly confuse the purpose of each, especially automation rules versus analytics rules.

How to eliminate wrong answers

Option A is wrong because an analytics rule is used to generate alerts from raw data based on detection logic, not to automate responses to already-created incidents. Option B is wrong because a hunting query is a proactive search for threats in historical data, not an automated response mechanism. Option C is wrong because a workbook provides visualizations and dashboards of data, but does not execute any automated actions or responses.

600
MCQmedium

You are reviewing a Microsoft Purview DLP policy configuration as shown in the exhibit. What is the expected behavior when a user sends an email containing a credit card number to an external recipient?

A.The email is delivered, but the user receives a warning.
B.The email is delivered, and the user is asked to provide a business justification.
C.The email is blocked, but only if the recipient is external and internal recipients are allowed.
D.The email is blocked, and the user receives a policy tip notification.
AnswerD

When a Microsoft Purview DLP policy is configured to block the sharing of sensitive information, the system actively prevents the email from being sent or delivered. Simultaneously, a policy tip notification is displayed to the sender within their email client or application. This notification informs the user about the policy violation, explains why the action was taken, and often provides guidance on how to resolve the issue, ensuring immediate feedback and education.

Why this answer

A DLP policy configured to block external sharing of credit card data will prevent the email from being sent and surface a policy tip to the user explaining the violation. The policy tip is the standard user-facing notification that accompanies a block action in Microsoft Purview DLP. Because the recipient is external and the content matches the sensitive information type, the block-and-notify behavior is triggered.

Exam trap

SC-900 often tests the confusion between 'warn' and 'block' DLP actions, causing candidates to pick a delivered-with-warning answer when the policy is actually configured to block and notify.

How to eliminate wrong answers

Option A is wrong because a warning-only policy would deliver the email; the exhibit shows a blocking configuration, not a warn-only override. Option B is wrong because business justification prompts occur with 'override' or 'block with override' actions, not with a straight block. Option C is wrong because it mischaracterizes the policy as recipient-scoped in a way that isn't supported — DLP blocks based on the rule conditions (external recipient + sensitive data), not on a separate 'internal allowed' toggle that would let the same email through to internal users while blocking external.

Page 7

Page 8 of 18

Page 9