dc dotCreds
Microsoft Security, Compliance, and Identity Fundamentals

SC-900 Practice Test

Start today’s free 10-question SC-900 set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 7, 2026, 2:36 PM CDT

Go Pro - One Time Unlock

Unlock the full SC-900 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$2.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 SC-900 questions

Use this SC-900 practice test to review Microsoft Security, Compliance, and Identity Fundamentals. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Describe how security policies, standards, and recommendations improve cloud security posture Describe the capabilities of Microsoft security solutions

A storage resource passed an enabled Defender for Cloud security standard when deployed. Its configuration is later changed so that it no longer satisfies a control. Which behavior allows Defender for Cloud to identify the new failure and produce remediation guidance?

Concept tested:
Question 2 of 10
Objective Describe Microsoft Entra ID Governance Describe the capabilities of Microsoft Entra

A company manually creates identities when people join, adds new access through tickets when they change jobs, and often leaves accounts and entitlements active after departure. It wants automated lifecycle changes plus evidence that access was approved and removed. What should it implement?

Concept tested:
Question 3 of 10
Objective Describe federation Describe the concepts of security, compliance, and identity

After an acquisition, the parent company and subsidiary must keep their identity systems separate for six months. The parent company's application must nevertheless trust sign-ins that the subsidiary already performs, without copying the subsidiary's directory objects. What should the identity team configure?

Concept tested:
Question 4 of 10
Objective Describe data loss prevention Describe the capabilities of Microsoft compliance solutions

An organization wants one Purview DLP strategy to monitor or restrict sensitive-data use in supported Microsoft 365 workloads and on managed endpoints. Which statement about DLP scope is correct?

Concept tested:
Question 5 of 10
Objective Describe authentication methods Describe the capabilities of Microsoft Entra

Employees must stop entering passwords during routine workstation sign-in. A Temporary Access Pass may be used only to enroll or recover the strong method, not as the permanent daily method. Which method should the company deploy?

Concept tested:
Question 6 of 10
Objective Describe directory services and Active Directory Describe the concepts of security, compliance, and identity

During a hybrid-cloud migration, administrators need one organized inventory where user, group, and device objects can be found and managed for authentication and access policy. Which directory capability meets that requirement?

Concept tested:
Question 7 of 10
Objective Describe Microsoft Defender Threat Intelligence Describe the capabilities of Microsoft security solutions

A threat-research team wants curated information organized around a particular threat actor, including associated tools and known vulnerabilities. Which Microsoft Defender Threat Intelligence resource should the team review?

Concept tested:
Question 8 of 10
Objective Describe Compliance Manager Describe the capabilities of Microsoft compliance solutions

While reviewing an assessment, a team needs to determine whether each control is implemented by the customer, implemented by Microsoft, or divided between both parties. Which Compliance Manager information should it review?

Concept tested:
Question 9 of 10
Objective Describe identity providers Describe the concepts of security, compliance, and identity

A development team is building a claims application but does not want the application to maintain user passwords. It needs a trusted service to maintain identity information, authenticate users, issue identity tokens, and record sign-in activity. What should the identity engineer implement?

Concept tested:
Question 10 of 10
Objective Describe network segmentation with Azure virtual networks Describe the capabilities of Microsoft security solutions

Development and production resources must use separate private Azure network address spaces, but approved traffic must still flow between them through controlled connectivity. Which design creates the required isolation boundaries?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
SC-900 Pro $2.99 one-time

Best if you only need this one certification.

50 Exam Practice Test $1.99 one-time

A 50-question SC-900 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Microsoft Security Bundle $9.99 one-time

Unlock all 6 active Microsoft Security Bundle practice banks in one permanent purchase.

What’s includedSC-900, SC-200, SC-300, SC-401, SC-500, SC-100
All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full SC-900 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily SC-900 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily SC-900 set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A storage resource passed an enabled Defender for Cloud security standard when deployed. Its configuration is later changed so that it no longer satisfies a control. Which behavior allows Defender for Cloud to identify the new failure and produce remediation guidance?

Answer choices

  1. A. The original deployment result remains final until an analyst creates an incident
  2. B. A Sentinel playbook changes the standard whenever a resource drifts
  3. C. An annual manual review replaces policy evaluation for existing resources
  4. D. Defender for Cloud continuously reevaluates resources against enabled standards

Correct answer

Defender for Cloud continuously reevaluates resources against enabled standards

Defender for Cloud continuously evaluates resources against enabled standards, so later configuration drift can cause a control to fail and generate a recommendation with affected resources and remediation guidance. A successful deployment-time result is not treated as permanent compliance.

Wrong-answer review

  • A. The original deployment result remains final until an analyst creates an incident: Posture is reevaluated continuously and is not frozen by the initial deployment result.
  • B. A Sentinel playbook changes the standard whenever a resource drifts: Sentinel playbooks automate incident response rather than redefining Defender for Cloud standards on drift.
  • C. An annual manual review replaces policy evaluation for existing resources: Annual manual review does not meet the documented continuous evaluation behavior.

Extra learning features

Why this matters

If Defender for Cloud fails to identify configuration drift, the organization faces the risk of a compromised resource being exposed to attack, potentially leading to data breaches and significant financial losses. Continuous evaluation is crucial for proactive protection.

Objective/domain: Describe the capabilities of Microsoft security solutions

Source: Security policies in Microsoft Defender for Cloud

Question 2 A company manually creates identities when people join, adds new access through tickets when they change jobs, and often leaves accounts and entitlements active after departure. It wants automated lifecycle changes plus evidence that access was approved and removed. What should it implement?

Answer choices

  1. A. Password Protection and smart lockout for every employee account
  2. B. Microsoft Entra ID Governance for identity and access lifecycle management
  3. C. Conditional Access rules based only on office network locations
  4. D. Microsoft Sentinel analytics without any identity-lifecycle integration

Correct answer

Microsoft Entra ID Governance for identity and access lifecycle management

Objective/domain: Describe the capabilities of Microsoft Entra

Source: What is Microsoft Entra ID Governance?

Question 3 After an acquisition, the parent company and subsidiary must keep their identity systems separate for six months. The parent company's application must nevertheless trust sign-ins that the subsidiary already performs, without copying the subsidiary's directory objects. What should the identity team configure?

Answer choices

  1. A. Merge both directories immediately and retire the subsidiary's authentication system.
  2. B. Synchronize the subsidiary's directory objects into the parent directory each hour.
  3. C. Establish federation so the application trusts authentication performed by the subsidiary's identity provider.
  4. D. Create local parent-company accounts for every subsidiary user until the directories can be merged.

Correct answer

Establish federation so the application trusts authentication performed by the subsidiary's identity provider.

Objective/domain: Describe the concepts of security, compliance, and identity

Source: Identity and access management fundamental concepts

Question 4 An organization wants one Purview DLP strategy to monitor or restrict sensitive-data use in supported Microsoft 365 workloads and on managed endpoints. Which statement about DLP scope is correct?

Answer choices

  1. A. DLP can protect only Exchange email and no other supported location
  2. B. DLP applies only after content is declared a regulatory record
  3. C. DLP can cover supported Microsoft 365 workloads, endpoints, and other integrated locations
  4. D. DLP is a network firewall that inspects only layer 3 and layer 4 traffic

Correct answer

DLP can cover supported Microsoft 365 workloads, endpoints, and other integrated locations

Objective/domain: Describe the capabilities of Microsoft compliance solutions

Source: Learn about data loss prevention

Question 5 Employees must stop entering passwords during routine workstation sign-in. A Temporary Access Pass may be used only to enroll or recover the strong method, not as the permanent daily method. Which method should the company deploy?

Answer choices

  1. A. Windows Hello for Business
  2. B. A permanent Temporary Access Pass
  3. C. A longer memorized password
  4. D. Two security questions

Correct answer

Windows Hello for Business

Objective/domain: Describe the capabilities of Microsoft Entra

Source: Authentication methods and features

Question 6 During a hybrid-cloud migration, administrators need one organized inventory where user, group, and device objects can be found and managed for authentication and access policy. Which directory capability meets that requirement?

Answer choices

  1. A. Encrypt all traffic exchanged between on-premises and cloud networks.
  2. B. Store and organize identity, group, and device objects for centralized management.
  3. C. Detect and automatically remediate vulnerabilities on every managed device.
  4. D. Translate each industry's regulations into mandatory technical controls.

Correct answer

Store and organize identity, group, and device objects for centralized management.

Objective/domain: Describe the concepts of security, compliance, and identity

Source: Microsoft Entra ID documentation

Question 7 A threat-research team wants curated information organized around a particular threat actor, including associated tools and known vulnerabilities. Which Microsoft Defender Threat Intelligence resource should the team review?

Answer choices

  1. A. A vulnerability asset inventory
  2. B. An intel profile
  3. C. A Defender for Cloud regulatory standard
  4. D. A Microsoft Sentinel automation rule

Correct answer

An intel profile

Objective/domain: Describe the capabilities of Microsoft security solutions

Source: Microsoft Threat Intelligence in Microsoft Defender XDR

Question 8 While reviewing an assessment, a team needs to determine whether each control is implemented by the customer, implemented by Microsoft, or divided between both parties. Which Compliance Manager information should it review?

Answer choices

  1. A. The initial compliance-score baseline only
  2. B. Control ownership
  3. C. Microsoft Sentinel automation rules
  4. D. Purview Activity explorer labels

Correct answer

Control ownership

Objective/domain: Describe the capabilities of Microsoft compliance solutions

Source: Microsoft Purview Compliance Manager

Question 9 A development team is building a claims application but does not want the application to maintain user passwords. It needs a trusted service to maintain identity information, authenticate users, issue identity tokens, and record sign-in activity. What should the identity engineer implement?

Answer choices

  1. A. Use an identity provider to manage the identities, authenticate users, issue trusted tokens, and audit sign-ins.
  2. B. Store password hashes in the claims database and let the application authenticate every user locally.
  3. C. Use a network firewall to authenticate users before forwarding traffic to the claims application.
  4. D. Send application events to a log workspace but keep identity creation and authentication inside the application.

Correct answer

Use an identity provider to manage the identities, authenticate users, issue trusted tokens, and audit sign-ins.

Objective/domain: Describe the concepts of security, compliance, and identity

Source: Identity and access management fundamental concepts

Question 10 Development and production resources must use separate private Azure network address spaces, but approved traffic must still flow between them through controlled connectivity. Which design creates the required isolation boundaries?

Answer choices

  1. A. Place every resource on the public internet and distinguish environments by DNS name.
  2. B. Put both environments in one subnet with no routing or traffic controls.
  3. C. Create one network interface for all resources and separate access only by user account.
  4. D. Place each environment in its own virtual network and connect them with controlled peering and traffic rules.

Correct answer

Place each environment in its own virtual network and connect them with controlled peering and traffic rules.

Objective/domain: Describe the capabilities of Microsoft security solutions

Source: Azure virtual network overview

Where to go after the daily web set

How are SC-900 questions generated?

dotCreds builds SC-900 practice questions from public exam objectives and Microsoft Learn and exam-objective references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start SC-900 practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.