Courseiva
← Back to Microsoft Security, Compliance, and Identity Fundamentals SC-900 questions

Scenario-based practice

Troubleshooting Scenario Questions

Practise Microsoft Security, Compliance, and Identity Fundamentals SC-900 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

15
scenario questions
SC-900
exam code
Microsoft
vendor

Scenario guide

How to approach troubleshooting scenario questions

These questions describe a network symptom and ask you to identify the root cause or the correct fix. They appear across all certification exams and reward systematic thinking over memorisation. The best candidates follow a consistent troubleshooting framework even under time pressure.

Quick answer

Troubleshooting Scenario Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related SC-900 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

Refer to the exhibit. You run a KQL query in Microsoft Sentinel to investigate ransomware alerts. The query returns: AlertSeverity High: 5, Medium: 3, Low: 2. The security team wants to automate a response for all high-severity ransomware alerts. What should you configure?

Exhibit

Refer to the exhibit.

```kql
SecurityAlerts
| where Timestamp > ago(7d)
| where AlertName has "ransomware"
| summarize Count=count() by AlertSeverity
| order by Count desc
```
Question 2easymultiple choice
Full question →

A user is unable to access a cloud app and receives a message that their sign-in was blocked by a Conditional Access policy. The admin wants to allow the user to self-remediate by meeting policy requirements. What should the admin enable?

Question 3easymultiple choice
Full question →

A user reports that they are unable to sign in to a SaaS application that is configured for single sign-on (SSO) with Microsoft Entra ID. The user can sign in to other applications. What should you check first?

Question 4mediummultiple choice
Full question →

A compliance officer needs to investigate a potential data exfiltration incident. They must search the unified audit log for all activities where users accessed a specific sensitive SharePoint site in the last 7 days. Additionally, they need to create a custom alert that triggers when more than 10 file downloads occur from that site within an hour. Which Microsoft Purview solution should they use?

Question 5mediummultiple choice
Full question →

A security team needs to investigate a potential data leak where an employee may have emailed sensitive customer information to a competitor. They want to search the unified audit log for specific email activities, such as 'Send' or 'Forward', and generate a detailed report. Which Microsoft Purview solution should they use?

Question 6hardmultiple choice
Full question →

A security analyst is using Microsoft 365 Defender to investigate a sophisticated multi-stage attack. The analyst needs to query data across endpoints, email, and identity logs to identify the attacker's behavior patterns and correlate events. Which Microsoft 365 Defender capability should the analyst use?

Question 7hardmultiple choice
Full question →

Refer to the exhibit. A security analyst is reviewing an alert from Microsoft 365 Defender. The alert is associated with an incident. What is the best first step to investigate this alert?

Exhibit

{
  "alerts": [
    {
      "id": "alert-123",
      "title": "Suspicious inbound email with malware",
      "category": "Malware",
      "severity": "High",
      "incidentId": "inc-456"
    }
  ]
}
Question 8easymultiple choice
Full question →

You are the security administrator for a company using Microsoft Defender XDR. A user reports receiving a suspicious email with a link. What Microsoft Defender XDR feature should you use to investigate the email's threat level?

Question 9hardmultiple choice
Full question →

Your organization uses Microsoft Defender XDR (formerly Microsoft 365 Defender). A user reports receiving a suspicious email with a link. The email was not blocked by Exchange Online Protection (EOP). Which feature should you use to investigate the link's reputation in real time?

Question 10hardmultiple choice
Full question →

During a security incident, a SOC analyst needs to investigate a compromised user account that accessed multiple cloud apps. Which Microsoft Defender XDR feature provides a unified view of the attack timeline across endpoints, identities, and cloud apps?

Question 11easymultiple choice
Full question →

Your organization wants to automatically investigate and remediate email-based threats in Microsoft 365. Which security solution should you use?

Question 12hardmultiple choice
Full question →

A security analyst needs to investigate a potential ransomware attack affecting multiple endpoints. They want to centralize detection and response across devices, email, and applications. Which Microsoft solution should they use?

Question 13mediummultiple choice
Full question →

Your company uses Microsoft Defender for Endpoint. You need to investigate a potential malware outbreak on a specific device. Which feature should you use to get real-time visibility into running processes and network connections?

Question 14mediummultiple choice
Full question →

Your company uses Microsoft Defender for Identity to monitor on-premises Active Directory. You receive an alert about a potential lateral movement attack involving a service account. The alert indicates that the account was used to log in to multiple servers from a non-domain-joined machine. You need to investigate the alert and determine if the account is compromised. What should you do first?

Question 15hardmultiple choice
Full question →

Your organization uses Microsoft Purview Audit (Standard) and needs to investigate a data breach that occurred 120 days ago. You discover that the required audit logs are not available. What is the most likely reason?

These SC-900 practice questions are part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style SC-900 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.