Courseiva
← Back to Microsoft Security, Compliance, and Identity Fundamentals SC-900 questions

Scenario-based practice

Hard Difficulty Questions

Practise Microsoft Security, Compliance, and Identity Fundamentals SC-900 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
SC-900
exam code
Microsoft
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related SC-900 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

A financial company needs to prevent any communication between their mergers and acquisitions (M&A) team and the trading desk across all Microsoft 365 channels, including email, Microsoft Teams, and SharePoint. They must ensure that no user in one group can send emails to or chat with users in the other group. Which Microsoft Purview solution should they implement?

Question 2hardmultiple choice
Full question →

Your organization uses Microsoft Purview Communication Compliance to detect harassing messages. You receive an alert for a message that appears to be a joke between colleagues. What should you do to prevent similar false positives?

Question 3hardmultiple choice
Full question →

A multinational corporation must comply with regulations that require them to keep financial records for 7 years and then permanently delete them. However, they are currently involved in litigation that requires preservation of all documents related to a specific project. They use Microsoft Purview. Which combination of features should they use to meet both requirements?

Question 4hardmultiple choice
Full question →

You are reviewing a Conditional Access policy configuration in Microsoft Entra ID. Based on the exhibit, what is the effect of this policy?

Exhibit

Refer to the exhibit.
```json
{
  "properties": {
    "displayName": "Block high-risk sign-ins",
    "state": "enabled",
    "conditions": {
      "userRiskLevels": [],
      "signInRiskLevels": ["high"]
    },
    "grantControls": {
      "builtInControls": ["block"]
    }
  }
}
```
Question 5hardmultiple choice
Full question →

Refer to the exhibit. You run a Kusto query in Microsoft Defender XDR Advanced Hunting. What does this query return?

Exhibit

Refer to the exhibit.

```kusto
DeviceAlertEvents
| where Timestamp > ago(7d)
| where AlertSeverity == "High"
| summarize Count = dcount(DeviceName) by AlertTitle
| top 10 by Count
```
Question 6hardmulti select
Full question →

Which THREE Microsoft Purview solutions help protect sensitive data in Microsoft 365? (Choose three.)

Question 7hardmultiple choice
Full question →

Refer to the exhibit. An administrator runs the Azure CLI commands shown. What is the purpose of these commands?

Network Topology
service-principal -u $ARM_CLIENT_ID -p $ARM_CLIENT_SECRETaz logintenant $ARM_TENANT_IDRefer to the exhibit.```azurecliecho $ARM_CLIENT_IDecho $ARM_TENANT_ID```
Question 8hardmultiple choice
Full question →

Refer to the exhibit. You are a compliance administrator running PowerShell to update a sensitivity label in Microsoft Purview. The command fails with an error that the label is not found. What is the most likely cause?

Exhibit

Refer to the exhibit.
```powershell
$config = Get-MgInformationProtectionPolicy
$config.Labels | Where-Object {$_.DisplayName -eq "Confidential"} | Set-MgInformationProtectionPolicyLabel -Settings @{ "Color" = "Red" }
```
Question 9hardmulti select
Full question →

Which TWO of the following are capabilities of Microsoft Purview Insider Risk Management? (Select TWO.)

Question 10hardmulti select
Full question →

Your organization uses Microsoft Entra ID. Which THREE authentication methods can be used for passwordless sign-in?

Question 11hardmultiple choice
Full question →

A company is planning to use Copilot for Microsoft 365. To ensure that Copilot responses are based only on data accessible to the user, which principle must be enforced?

Question 12hardmultiple choice
Full question →

A company runs Windows Server virtual machines (VMs) on-premises and in Azure. The security team wants a unified view of missing security updates and known vulnerabilities (CVEs) across all VMs. They want to enable agentless scanning for Azure VMs and deploy a lightweight agent for on-premises machines. The results should be consolidated in a single dashboard with prioritized remediation recommendations. Which Microsoft security solution should they use?

Question 13hardmultiple choice
Full question →

Your organization uses Microsoft Sentinel as its SIEM. You need to create an analytics rule that detects when a user account is created in Azure AD and then, within 10 minutes, that same account is used to grant admin consent to an application. You have a KQL query that joins AuditLogs and SigninLogs. However, the rule is generating too many false positives. You need to refine the query to reduce false positives. What should you do?

Question 14hardmultiple choice
Full question →

A company has a Microsoft Entra ID tenant with thousands of users. They need to ensure that only users with a 'Manager' attribute populated can access a sensitive app. Which approach should they use?

Question 15hardmultiple choice
Full question →

Refer to the exhibit. You are creating a custom analytics rule in Microsoft Sentinel. What does this rule detect?

Exhibit

Refer to the exhibit.

```json
{
  "alertRule": {
    "displayName": "Unusual sign-in from unfamiliar location",
    "query": "SigninLogs | where RiskLevelDuringSignIn == 'medium' or RiskLevelDuringSignIn == 'high' | where Location != 'US'",
    "frequency": "PT1H",
    "severity": 2
  }
}
```
Question 16hardmulti select
Full question →

Which THREE are features of Microsoft Purview Data Lifecycle Management (formerly Records Management)? (Choose three.)

Question 17hardmultiple choice
Full question →

The exhibit shows a Conditional Access policy named 'Block Legacy Auth'. The admin notices that the policy is not blocking legacy authentication as intended. Based on the output, what is the most likely reason?

Exhibit

Refer to the exhibit. The exhibit shows a PowerShell command and its output:

```powershell
Get-MgPolicyConditionalAccessPolicy -Filter "DisplayName eq 'Block Legacy Auth'" | Format-List Id, DisplayName, Conditions

Id            : 12345678-1234-1234-1234-123456789abc
DisplayName   : Block Legacy Auth
Conditions    : @{ClientAppTypes=System.Object[]; Applications=; Users=; Locations=; Platforms=; SignInRiskLevels=; UserRiskLevels=;}
```
Question 18hardmultiple choice
Full question →

Refer to the exhibit. A Microsoft Graph PowerShell script is shown. What is the purpose of this script?

Exhibit

Refer to the exhibit.
$users = Get-MgUser -Filter "startsWith(userPrincipalName, 'john') and userType eq 'Member'"
foreach ($user in $users) {
    New-MgUserAuthenticationMethod -UserId $user.Id -PhoneAuthenticationMethod -PhoneNumber "+1234567890" -PhoneType "mobile"
}
Question 19hardmultiple choice
Full question →

Your organization has multiple on-premises directories and wants to synchronize them to Microsoft Entra ID. However, you must avoid duplicate user objects. Which feature should you configure?

Question 20hardmulti select
Full question →

Which THREE Microsoft Defender XDR components are included in the unified security operations platform? (Select three.)

These SC-900 practice questions are part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style SC-900 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.