dc dotCreds
Microsoft Security, Compliance, and Identity Fundamentals

SC-900 Practice Test

Start today’s free 10-question SC-900 set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 7, 2026, 10:05 AM CDT

Go Pro - One Time Unlock

Unlock the full SC-900 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$2.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 SC-900 questions

Use this SC-900 practice test to review Microsoft Security, Compliance, and Identity Fundamentals. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Define authentication Describe the concepts of security, compliance, and identity

A user successfully signs in to a payroll application but receives an access-denied message when opening payroll reports. Which statement best describes the two checks?

Concept tested:
Question 2 of 10
Objective Describe the benefits of Content explorer and Activity explorer Describe the capabilities of Microsoft compliance solutions

A compliance analyst knows where labeled files are stored but needs to review which users applied, changed, or removed labels and what other information-protection actions occurred. Which Purview tool should the analyst use?

Concept tested:
Question 3 of 10
Objective Describe the Zero Trust model Describe the concepts of security, compliance, and identity

A contractor needs two hours of access to a payment application. The contractor is on the corporate network, but the device risk can change during the session. Which design applies both verify explicitly and least privilege?

Concept tested:
Question 4 of 10
Objective Describe Microsoft Defender for Office 365 Describe the capabilities of Microsoft security solutions

Attackers are sending email that displays the chief executive's name and uses a lookalike sender identity to request urgent payments. Which Defender for Office 365 capability most directly addresses this threat?

Concept tested:
Question 5 of 10
Objective Describe authentication methods Describe the capabilities of Microsoft Entra

A new employee has no registered strong authentication method yet and cannot complete passwordless enrollment. The help desk needs a credential that expires and is used only to bootstrap that enrollment. What should it issue?

Concept tested:
Question 6 of 10
Objective Describe network segmentation with Azure virtual networks Describe the capabilities of Microsoft security solutions

Development and production resources must use separate private Azure network address spaces, but approved traffic must still flow between them through controlled connectivity. Which design creates the required isolation boundaries?

Concept tested:
Question 7 of 10
Objective Describe the privacy principles of Microsoft Describe the capabilities of Microsoft compliance solutions

During a privacy review, a customer asks Microsoft to explain how its data is collected, stored, processed, and protected. Which Microsoft privacy principle directly addresses that request?

Concept tested:
Question 8 of 10
Objective Describe Microsoft Entra Conditional Access Describe the capabilities of Microsoft Entra

A finance application must remain available to employees, but sign-ins assessed as high risk from unmanaged devices must satisfy both stronger authentication and device requirements. The organization does not want to block ordinary low-risk access. Which configuration meets the requirement?

Concept tested:
Question 9 of 10
Objective Describe Microsoft Defender XDR services Describe the capabilities of Microsoft security solutions

An attack begins with a phishing email, compromises an employee identity, and then executes on an endpoint. Analysts want the related signals correlated into one incident with cross-domain context. Which service provides that experience?

Concept tested:
Question 10 of 10
Objective Describe password protection and management capabilities Describe the capabilities of Microsoft Entra

The security team wants users to enroll security information once for both MFA and self-service password recovery. It also wants repeated malicious password guesses blocked while minimizing disruption to legitimate users. Which combination satisfies both requirements?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
SC-900 Pro $2.99 one-time

Best if you only need this one certification and want the lower fundamentals price.

50 Exam Practice Test $1.99 one-time

A 50-question SC-900 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Microsoft Access $6.99/month

Unlock Microsoft, Azure, Power Platform, Copilot, and AI practice exams.

Why it fitsUnlock Microsoft, Azure, Power Platform, Copilot, and AI practice exams, Includes current and future Microsoft practice banks on dotCreds, Best for learners taking more than one Microsoft exam, PDF downloads sold separately where available

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full SC-900 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily SC-900 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily SC-900 set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A user successfully signs in to a payroll application but receives an access-denied message when opening payroll reports. Which statement best describes the two checks?

Answer choices

  1. A. Authentication confirms what data the user may access, while authorization confirms the user’s identity.
  2. B. Authentication and authorization are the same check, so a successful sign-in should grant every permission.
  3. C. Authentication confirms the identity, while authorization determines whether that authenticated identity may access the payroll reports.
  4. D. Authorization verifies the user’s MFA factors, while authentication assigns access permissions.

Correct answer

Authentication confirms the identity, while authorization determines whether that authenticated identity may access the payroll reports.

Authentication establishes who or what the identity is. Authorization is the separate decision about which resources that authenticated identity may access, so a successful sign-in does not by itself grant access to the payroll reports.

Wrong-answer review

  • A. Authentication confirms what data the user may access, while authorization confirms the user’s identity.: The roles are reversed: authentication establishes identity, while authorization evaluates access to a resource.
  • B. Authentication and authorization are the same check, so a successful sign-in should grant every permission.: Authentication and authorization are related but distinct checks; signing in does not grant every permission.
  • D. Authorization verifies the user’s MFA factors, while authentication assigns access permissions.: MFA is an authentication method, while permissions are part of authorization; the choice reverses both concepts.

Extra learning features

Why this matters

A successful sign-in does not guarantee access to the payroll reports, highlighting the critical distinction between authentication and authorization, preventing unauthorized access to sensitive financial data. This separation is fundamental to secure access management. (34 words)

Objective/domain: Describe the concepts of security, compliance, and identity

Source: Identity and access management fundamental concepts

Question 2 A compliance analyst knows where labeled files are stored but needs to review which users applied, changed, or removed labels and what other information-protection actions occurred. Which Purview tool should the analyst use?

Answer choices

  1. A. Content explorer only
  2. B. Microsoft Defender XDR advanced hunting
  3. C. Activity explorer
  4. D. Microsoft Entra sign-in logs

Correct answer

Activity explorer

Objective/domain: Describe the capabilities of Microsoft compliance solutions

Source: Microsoft Purview Information Protection

Question 3 A contractor needs two hours of access to a payment application. The contractor is on the corporate network, but the device risk can change during the session. Which design applies both verify explicitly and least privilege?

Answer choices

  1. A. Trust the session for the rest of the day because it began on the corporate network
  2. B. Approve permanent access after checking only the contractor's password at first sign-in
  3. C. Evaluate identity, device, and risk signals continuously and grant time-limited access only to the required application
  4. D. Allow access from any managed device and review the contractor's activity at the end of the month

Correct answer

Evaluate identity, device, and risk signals continuously and grant time-limited access only to the required application

Objective/domain: Describe the concepts of security, compliance, and identity

Source: Zero Trust as a security foundation

Question 4 Attackers are sending email that displays the chief executive's name and uses a lookalike sender identity to request urgent payments. Which Defender for Office 365 capability most directly addresses this threat?

Answer choices

  1. A. Anti-phishing policies with impersonation protection
  2. B. Safe Attachments detonation
  3. C. Defender for Endpoint EDR
  4. D. Azure DDoS Protection

Correct answer

Anti-phishing policies with impersonation protection

Objective/domain: Describe the capabilities of Microsoft security solutions

Source: Microsoft Defender for Office 365 features

Question 5 A new employee has no registered strong authentication method yet and cannot complete passwordless enrollment. The help desk needs a credential that expires and is used only to bootstrap that enrollment. What should it issue?

Answer choices

  1. A. A Temporary Access Pass
  2. B. A permanent shared password
  3. C. An access-review decision
  4. D. A device-compliance exception

Correct answer

A Temporary Access Pass

Objective/domain: Describe the capabilities of Microsoft Entra

Source: Authentication methods and features

Question 6 Development and production resources must use separate private Azure network address spaces, but approved traffic must still flow between them through controlled connectivity. Which design creates the required isolation boundaries?

Answer choices

  1. A. Place every resource on the public internet and distinguish environments by DNS name.
  2. B. Put both environments in one subnet with no routing or traffic controls.
  3. C. Create one network interface for all resources and separate access only by user account.
  4. D. Place each environment in its own virtual network and connect them with controlled peering and traffic rules.

Correct answer

Place each environment in its own virtual network and connect them with controlled peering and traffic rules.

Objective/domain: Describe the capabilities of Microsoft security solutions

Source: Azure virtual network overview

Question 7 During a privacy review, a customer asks Microsoft to explain how its data is collected, stored, processed, and protected. Which Microsoft privacy principle directly addresses that request?

Answer choices

  1. A. Purpose limitation, because it states the service purpose instead of explaining processing
  2. B. Transparency
  3. C. Customer control, because the customer can modify data without processing information
  4. D. Legal protection, because every processing detail is a government request

Correct answer

Transparency

Objective/domain: Describe the capabilities of Microsoft compliance solutions

Source: Microsoft Privacy Principles

Question 8 A finance application must remain available to employees, but sign-ins assessed as high risk from unmanaged devices must satisfy both stronger authentication and device requirements. The organization does not want to block ordinary low-risk access. Which configuration meets the requirement?

Answer choices

  1. A. Block the finance application for every user and device regardless of sign-in context.
  2. B. Require multifactor authentication for every cloud application but ignore device state and sign-in risk.
  3. C. Mark the corporate network as trusted and grant all requests originating there without further evaluation.
  4. D. Create a Conditional Access policy using application, risk, and device signals that requires MFA and a compliant device.

Correct answer

Create a Conditional Access policy using application, risk, and device signals that requires MFA and a compliant device.

Objective/domain: Describe the capabilities of Microsoft Entra

Source: Microsoft Entra Conditional Access: Zero Trust policy engine

Question 9 An attack begins with a phishing email, compromises an employee identity, and then executes on an endpoint. Analysts want the related signals correlated into one incident with cross-domain context. Which service provides that experience?

Answer choices

  1. A. Azure DDoS Protection
  2. B. Microsoft Defender XDR
  3. C. Azure Key Vault
  4. D. Microsoft Purview Records Management

Correct answer

Microsoft Defender XDR

Objective/domain: Describe the capabilities of Microsoft security solutions

Source: Microsoft Defender XDR overview

Question 10 The security team wants users to enroll security information once for both MFA and self-service password recovery. It also wants repeated malicious password guesses blocked while minimizing disruption to legitimate users. Which combination satisfies both requirements?

Answer choices

  1. A. Password Protection for registration and access reviews for password guessing
  2. B. Separate MFA and SSPR enrollment portals plus permanent account lockout after one failure
  3. C. Combined MFA and SSPR registration together with smart lockout
  4. D. Conditional Access registration together with entitlement management for password guessing

Correct answer

Combined MFA and SSPR registration together with smart lockout

Objective/domain: Describe the capabilities of Microsoft Entra

Source: Combined registration for SSPR and Microsoft Entra multifactor authentication

Where to go after the daily web set

How are SC-900 questions generated?

dotCreds builds SC-900 practice questions from public exam objectives and Microsoft Learn and exam-objective references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start SC-900 practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.