Courseiva

SC-900 · topic practice

Describe the capabilities of Microsoft security solutions practice questions

This domain covers Microsoft's security stack: Entra ID protection features, Conditional Access, Defender XDR and its workloads, Microsoft Purview information protection and data loss prevention, and Microsoft Sentinel. Questions present exhibits, Kusto queries, or policy configurations and ask you to identify the resulting behavior or select the correct service for a stated requirement.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Describe the capabilities of Microsoft security solutions

What the exam tests

What to know about Describe the capabilities of Microsoft security solutions

Be able to read a Conditional Access exhibit and state which users, apps, and conditions trigger it, and which grant or session control applies. Also match a stated data-protection requirement to the correct Microsoft Purview solution: sensitivity labels, DLP, or Insider Risk Management.

Conditional Access policy evaluation: assignments, conditions, grant controls, and session controls in Microsoft Entra ID

Microsoft Defender XDR Advanced Hunting Kusto Query Language (KQL) queries across device, email, identity, and app tables

Microsoft Purview sensitivity labels, auto-labeling, and Data Loss Prevention policies for emails and documents

Microsoft Sentinel SIEM/SOAR capabilities: data connectors, analytics rules, workbooks, and automation playbooks

Watch out for

Common Describe the capabilities of Microsoft security solutions exam traps

  • ▸Confusing Microsoft Defender for Cloud (cloud workload protection) with Microsoft Defender XDR (correlated signals across endpoints, email, identity, and apps).
  • ▸Assuming sensitivity labels encrypt content by default; encryption requires configuring encryption settings, and labels alone may only mark content.
  • ▸Mixing up Microsoft Purview Data Loss Prevention with Insider Risk Management; DLP enforces on sensitive content flows, while Insider Risk detects risky user behavior.

Practice set

Describe the capabilities of Microsoft security solutions questions

20 questions · select your answer, then reveal the explanation

A security administrator wants to use Microsoft Defender for Cloud to protect Azure VMs. Which two of the following should be enabled to meet the requirements? (Choose two.)

A security team manages a hybrid environment with Azure VMs and on-premises Windows servers. They want a single dashboard that provides continuous assessment of security posture, actionable recommendations to harden configurations, and integration with Microsoft Defender for Cloud to detect threats. Which Microsoft security solution should they use?

A company uses Azure resources, on-premises servers, and third-party cloud apps. The security team wants a single solution to collect security logs from all these sources, detect threats using advanced analytics, and automate responses to incidents. Which Microsoft security solution should they use?

Sequence the steps to enable Microsoft Defender for Cloud Apps for an organization.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Arrange the steps to configure multi-factor authentication (MFA) for a user in Azure AD.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Match each authentication method to its description. Select all that apply.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Sign in without a password using biometrics or FIDO2

Require two or more verification methods

One credential for multiple applications

Policy-based access controls based on signals

Biometric or PIN-based sign-in for Windows

Your company wants to use Microsoft Security Copilot to help analysts investigate security incidents. Which data source can Security Copilot ingest to provide contextual insights?

Your organization uses Microsoft Purview eDiscovery to manage legal cases. You need to place a hold on a user's mailbox to preserve data for an ongoing litigation. Which role do you need to assign to the eDiscovery manager?

You are reviewing a Microsoft Purview sensitivity label configuration. Based on the exhibit, what will happen when this label is applied to a document?

Exhibit

Refer to the exhibit.

{
  "LabelId": "12345678-1234-1234-1234-123456789012",
  "DisplayName": "Confidential",
  "Description": "Sensitive business data",
  "Actions": [
    {
      "Type": "encrypt",
      "EncryptionType": "AES256"
    },
    {
      "Type": "marking",
      "MarkingType": "watermark",
      "WatermarkText": "CONFIDENTIAL"
    },
    {
      "Type": "protection",
      "ProtectionType": "block",
      "BlockAction": "share"
    }
  ]
}

Refer to the exhibit. An analyst runs a KQL query in Microsoft Sentinel. What is the primary purpose of this query?

Exhibit

SecurityAlert | where AlertName == "Malware detected" | project TimeGenerated, ComputerName, AlertSeverity | order by TimeGenerated desc | take 10

Your company uses Microsoft Purview Information Protection to classify and protect sensitive data. You need to ensure that when a user sends an email containing a credit card number, the email is automatically encrypted and a custom footer is added. Which two components should you configure?

A company uses Microsoft Defender for Cloud to secure its hybrid cloud workload. The security team needs to ensure that all virtual machines (VMs) have Just-In-Time (JIT) VM access enabled. What should they use to enforce this across subscriptions?

A SOC analyst is investigating a potential security incident in Microsoft Sentinel. Which three are valid methods to gather additional context about a user entity? (Choose three.)

Which TWO Microsoft security solutions can be used to detect and respond to identity-based threats? (Choose two.)

You are reviewing a Microsoft Purview auto-labeling policy configuration. Based on the exhibit, what happens when a document contains a credit card number and is labeled 'Confidential'?

Exhibit

Refer to the exhibit.
```json
{
  "policy": {
    "name": "GDPR Policy",
    "labels": [
      {
        "name": "Confidential",
        "settings": {
          "encryption": {
            "enabled": true,
            "templateId": "dummy-encryption-template"
          }
        }
      }
    ],
    "rules": [
      {
        "condition": {
          "sensitivityLabel": "Confidential",
          "contains": "Credit Card Number"
        },
        "action": "blockAccess"
      }
    ]
  }
}
```

Your organization uses Microsoft Intune to manage mobile devices. You need to ensure that devices with a jailbroken or rooted OS cannot access corporate resources. What should you configure?

You are troubleshooting a Conditional Access policy in Microsoft Entra ID. The policy in the exhibit is not blocking some sign-ins that you expected to block. What is the most likely reason?

Exhibit

Refer to the exhibit.
```json
{
  "displayName": "Block high-risk sign-ins",
  "conditions": {
    "userRiskLevels": ["high"],
    "signInRiskLevels": []
  },
  "grantControls": {
    "builtInControls": ["block"]
  }
}
```

Refer to the exhibit. You run the PowerShell command to retrieve a conditional access policy's conditions. The output shows Applications: All, Users: All, and Locations: All trusted. You need to ensure that only trusted locations are used when accessing Microsoft 365. What change should you make?

Exhibit

Refer to the exhibit.

```powershell
Get-MgPolicyConditionalAccessPolicy -Filter "id eq '12345678-1234-1234-1234-123456789abc'" | Select-Object -ExpandProperty Conditions
```

Your organization uses Microsoft Defender for Cloud to protect hybrid workloads. A security administrator needs to ensure that all Azure subscriptions are automatically covered by Defender for Cloud's security policies. What should the administrator configure?

An organization is deploying Microsoft Intune for mobile device management. They need to ensure that all iOS devices must have a passcode of at least 6 characters and the device must be encrypted. What should they configure?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Describe the capabilities of Microsoft security solutions sessions

Start a Describe the capabilities of Microsoft security solutions only practice session

Every question in these sessions is drawn from the Describe the capabilities of Microsoft security solutions domain — nothing else.

Related practice questions

Related SC-900 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SC-900 exam test about Describe the capabilities of Microsoft security solutions?
Be able to read a Conditional Access exhibit and state which users, apps, and conditions trigger it, and which grant or session control applies. Also match a stated data-protection requirement to the correct Microsoft Purview solution: sensitivity labels, DLP, or Insider Risk Management.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Describe the capabilities of Microsoft security solutions questions in a focused session?
Yes — the session launcher on this page draws every question from the Describe the capabilities of Microsoft security solutions domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SC-900 topics?
Use the topic links above to move to related areas, or go back to the SC-900 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SC-900 exam covers. They are not copied from any real exam or dump site.