Courseiva
Question 840 of 1,250

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

Match each security control type to its example.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Warning signs or security policies

Firewall rules blocking unauthorized access

Intrusion detection system alerts

Patching a vulnerability after discovery

Requiring strong passwords via policy

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Preventive: Firewall rules blocking unauthorized traffic

Security control types categorize how controls operate: preventive controls block incidents, detective controls identify them, and corrective controls fix issues. Common examples include firewall rules (preventive), IDS (detective), and backup/restore (corrective).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Preventive: Firewall rules blocking unauthorized traffic

    Why this is correct

    Firewall rules blocking unauthorized traffic are a classic example of a preventive security control. These rules are configured to inspect incoming and outgoing network packets, dropping any traffic that violates predefined security policies, such as specific IP addresses, ports, or protocols. By actively denying malicious or unauthorized connections before they can establish, firewalls effectively stop incidents from occurring in the first place, safeguarding network perimeters.

  • Detective: Intrusion detection system monitoring network traffic

    Why this is correct

    An Intrusion Detection System (IDS) monitoring network traffic exemplifies a detective security control. An IDS passively observes network activity or system logs, comparing patterns against known attack signatures or behavioral baselines to identify suspicious or malicious actions. Its primary function is to detect ongoing threats or anomalies after they have begun but before significant damage is inflicted, subsequently generating alerts for security personnel to investigate.

  • Corrective: Backup and restore procedures

    Why this is correct

    Backup and restore procedures are a fundamental corrective security control. In the event of data corruption, accidental deletion, system failure, or a successful cyberattack like ransomware, these procedures enable an organization to revert systems and data to a previous, uncompromised state. This capability is crucial for remediating the impact of an incident, minimizing downtime, and restoring operational continuity after a security breach.

  • Preventive: Intrusion detection system monitoring network traffic

    Why it's wrong here

    Categorizing an Intrusion Detection System (IDS) as a preventive control is incorrect because an IDS primarily functions by observing and alerting on suspicious activities *after* they have occurred or are in progress. While an IDS is vital for identifying threats, it does not actively block or stop an attack from happening in the first place. Its role is to detect and notify, rather than to prevent initial access or execution.

  • Detective: Backup and restore procedures

    Why it's wrong here

    Classifying backup and restore procedures as a detective control is incorrect because their purpose is not to identify or monitor for suspicious activities. Backup and restore mechanisms are implemented to recover from an incident *after* it has been detected and caused damage, such as data loss or system compromise. They serve as a post-incident remediation tool, rather than a real-time threat identification system.

  • Corrective: Firewall rules blocking unauthorized traffic

    Why it's wrong here

    Labeling firewall rules blocking unauthorized traffic as a corrective control is inaccurate because firewalls are designed to prevent incidents, not to remediate them. Firewall rules proactively inspect and block malicious or unauthorized traffic from entering or leaving a network *before* an attack can occur or cause harm. Their function is proactive defense and access control, not reactive recovery or damage repair after a security event.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.