Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Match each Microsoft identity service to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Cloud-based identity and access management

Directory service for Windows domain networks

Collaboration with external partners

Customer identity and access management for apps

Integration of on-premises AD with Azure AD

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Azure AD: Cloud-based identity and access management service

Microsoft identity services include Azure AD (cloud IAM), Azure AD DS (managed domain services), and Azure AD B2C (customer IAM). Common confusions involve swapping descriptions of Azure AD with on-premises AD and Azure AD DS with Azure AD B2B.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Azure AD: Cloud-based identity and access management service

    Why this is correct

    Azure Active Directory (Azure AD) is Microsoft's foundational cloud-based identity and access management (IAM) service, providing secure authentication and authorization for users, groups, and applications. It enables single sign-on (SSO) to thousands of SaaS applications, Microsoft 365, and custom cloud applications, securing access to resources both within and outside an organization's network perimeter. Azure AD is fundamental for modern cloud-first identity strategies.

  • Azure AD DS: Provides managed domain services including domain join, group policy, and LDAP

    Why this is correct

    Azure Active Directory Domain Services (Azure AD DS) delivers managed domain services, such as domain join, Lightweight Directory Access Protocol (LDAP), and Kerberos/NTLM authentication, directly within Azure. This service allows organizations to lift-and-shift legacy applications that require traditional Active Directory features to the cloud without deploying, managing, and patching domain controllers. It seamlessly synchronizes identities from Azure AD to support these traditional workloads.

  • Azure AD B2C: Customer identity and access management solution for consumer-facing applications

    Why this is correct

    Azure Active Directory B2C (Business-to-Consumer) is a highly scalable customer identity and access management (CIAM) solution specifically designed for consumer-facing web and mobile applications. It allows businesses to customize and control how customers sign up, sign in, and manage their profiles using various identity providers, including social accounts and local accounts. B2C focuses on securely managing millions of consumer identities for public applications.

  • Azure AD B2B: Managed domain services such as domain join and LDAP

    Why it's wrong here

    This description is incorrect for Azure AD B2B. Azure AD B2B (Business-to-Business) is a feature within Azure AD that facilitates secure collaboration with external users and partners by allowing them to use their own identities to access an organization's applications and resources. It does not provide managed domain services like domain join or LDAP, which are functionalities of Azure AD Domain Services.

  • Active Directory (on-premises): Cloud-based identity and access management

    Why it's wrong here

    This statement incorrectly describes Active Directory (on-premises). Active Directory is a traditional, server-based directory service primarily used for managing identities, resources, and security within a private, on-premises Windows Server network. It is not a cloud-based service; cloud-based identity and access management is the domain of Azure Active Directory, which operates entirely in the cloud.

  • Azure AD: On-premises directory service for Windows networks

    Why it's wrong here

    This description is inaccurate for Azure AD. Azure Active Directory is fundamentally a cloud-based identity and access management service, designed to manage identities and access for cloud applications and services. An on-premises directory service for Windows networks is traditionally provided by Windows Server Active Directory, which requires local server infrastructure and is distinct from Azure AD.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.