Courseiva

SC-900 Password Hash Synchronization Practice Question

Your company is implementing a hybrid identity solution with Microsoft Entra ID. You need to ensure that password changes on-premises are synchronized to the cloud within minutes. Which feature should you enable?

⚠ Common exam trap

The trap is that candidates often think Password Writeback is for on-premises-to-cloud sync when it actually does the opposite (cloud-to-on-premises). Password Hash Synchronization is the correct feature for synchronizing on-premises password changes to the cloud.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Password Hash Synchronization

Password Hash Synchronization (A) synchronizes password hashes from on-premises Active Directory to Microsoft Entra ID in near real-time, ensuring that password changes made on-premises are reflected in the cloud within minutes. Password Writeback (D) performs the reverse: it writes password changes from the cloud back to on-premises, not from on-premises to the cloud. Pass-through Authentication (B) validates passwords against on-premises AD directly without syncing hashes, and Seamless SSO (C) provides automatic sign-in but does not handle password synchronization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Password Hash Synchronization

    Why this is correct

    Password Hash Synchronization continuously replicates on-premises password hashes to Microsoft Entra ID, so any password change made in Active Directory is reflected in the cloud within minutes. This directly satisfies the stem's requirement for near-immediate synchronisation of on-premises password changes, without requiring users to authenticate against on-premises infrastructure.

  • ✗

    Pass-through Authentication

    Why it's wrong here

    Pass-through Authentication validates credentials against on-premises Active Directory at sign-in; it never copies password hashes to Microsoft Entra ID, so no cloud-side password change propagation occurs. It would be correct where you must avoid storing password hashes in the cloud.

  • ✗

    Seamless Single Sign-On

    Why it's wrong here

    Seamless SSO authenticates domain-joined users via Kerberos without re-entering credentials; it does not transfer password hashes or changes. It is tempting because it is a hybrid identity feature, and would be correct for removing sign-in prompts on corporate desktops, whereas password hash synchronisation handles the cloud password update requirement.

  • ✗

    Password Writeback

    Why it's wrong here

    Password Writeback pushes cloud-initiated password resets back to on-premises directories, the reverse direction of the requirement. It would be correct for self-service password reset in Microsoft Entra ID writing changes to on-premises Active Directory, not for on-premises changes reaching the cloud.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.