Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

Which THREE of the following are key concepts of identity management in Microsoft Entra ID?

⚠ Common exam trap

SC-900 often tests the boundary between authentication and authorization — candidates confuse 'who you are' with 'what you can do,' and may also incorrectly include encryption or least privilege as core identity concepts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Federation

Authentication (E) is a core identity-management concept in Microsoft Entra ID because it verifies a user's or service principal's identity through credentials such as passwords, certificate-based authentication, Windows Hello for Business, or FIDO2 security keys, and it underpins tokens issued by the Microsoft identity platform. Authorization (D) is equally fundamental: once Entra ID authenticates an identity, it determines what that identity may access through mechanisms like role-based access control (RBAC), OAuth 2.0 scopes, app roles, and conditional access policies. Federation (B) is also a key concept because Entra ID can trust external identity providers via protocols such as SAML 2.0, WS-Federation, and OpenID Connect, enabling single sign-on and delegated authentication for partner or on-premises identities. Encryption (A) is a security control used to protect data in transit and at rest, but it is not itself an identity-management concept. Least privilege (C) is an important security principle applied within authorization and access reviews, yet it is a guiding principle rather than one of the core identity-management concepts tested here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Encryption

    Why it's wrong here

    Encryption is primarily a cryptographic technique used to protect data confidentiality and integrity, whether data is at rest or in transit. While it's crucial for securing communication channels and protecting sensitive identity data within an identity system, it is not one of the fundamental processes or concepts that define how identities are managed, verified, or authorized access to resources. Its role is data protection, not identity lifecycle or access control.

  • ✓

    Federation

    Why this is correct

    Federation is a key concept in modern identity management that establishes a trust relationship between multiple independent identity providers and service providers. It enables users to authenticate once with their home identity provider and then gain access to various applications and services across different organizational boundaries without re-authenticating. This facilitates single sign-on (SSO) and streamlines user experience by leveraging external identity sources.

  • ✗

    Least privilege

    Why it's wrong here

    Least privilege is a fundamental security principle dictating that users, programs, or processes should be granted only the minimum necessary permissions to perform their intended function. While identity management systems are designed to enforce least privilege through granular access controls, the principle itself describes a desired state of access rather than a core operational concept of identity verification, authorization, or trust establishment. It guides policy, but isn't a mechanism.

  • ✓

    Authorization

    Why this is correct

    Authorization is the process of determining whether an authenticated user or service principal is permitted to access a specific resource or perform a particular action. This decision is made based on predefined policies, roles, attributes, and permissions associated with the identity and the resource. It ensures that even after identity verification, access is strictly controlled according to established security rules and business requirements.

  • ✓

    Authentication

    Why this is correct

    Authentication is the crucial first step in identity management, involving the verification of a user's or system's claimed identity. This process typically relies on presenting credentials, such as passwords, multi-factor authentication (MFA) tokens, biometrics, or digital certificates, which are then validated against an authoritative identity store. Successful authentication confirms "who you are" before any access decisions can be made.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.