Skip to content

SC-900 Practice Questions

Prepare for SC-900 with more than an answer.

203 questions in the full set17 sample questionsUpdated Jan 25, 2026

Unlock the full exam and previous versions

  • v1Version 1 203 questions Current
  • 98-367Legacy Security Fundamentals 49 questions Locked
Exam fee
$99 USD
Level
Fundamentals
Valid for
Does not expire
Domains covered on the exam 4
  1. Describe the concepts of security, compliance, and identity12.5%
  2. Describe the capabilities of Microsoft Entra27.5%
  3. Describe the capabilities of Microsoft security solutions37.5%
  4. Describe the capabilities of Microsoft compliance solutions22.5%
  1. 1

    A system administrator needs to grant a consultant temporary administrator access to a specific Azure subscription. The access should require approval and automatically expire after 4 hours. Which Microsoft Entra service should be used?

    Show answer details

    Correct answer: A

    PIM provides Just-In-Time (JIT) access to Azure AD and Azure resources. It supports workflow approvals, time-bound access, and audit trails for privileged roles.

  2. 2

    An organization wants to collaborate with partners from another company. The partners should use their existing corporate credentials to access shared resources in your tenant. Which feature of Microsoft Entra External ID should you utilize?

    Show answer details

    Correct answer: D

    B2B (Business-to-Business) collaboration allows you to invite guest users from other organizations to your tenant. They authenticate using their home organization's credentials.

  3. 3

    Which of the following are valid passwordless authentication methods supported by Microsoft Entra ID? (Select TWO)

    Show answer details

    Correct answer: A, C

    FIDO2 security keys are a supported passwordless method that allows users to sign in using a hardware key and a PIN or biometric.

    The Microsoft Authenticator app supports passwordless phone sign-in, where a user matches a number displayed on the screen.

  4. 4

    A security engineer is configuring Microsoft Entra Identity Protection. They want to create a policy that blocks access when a user's credentials have likely been leaked to the dark web. Which type of risk should they target in the policy?

    Show answer details

    Correct answer: A

    Leaked credentials are a 'User Risk' event because they compromise the user's identity integrity, not just a specific sign-in attempt. Sign-in risk relates to the specific authentication attempt (e.g., unfamiliar location).

  5. 5

    You are managing a project that involves external contractors. You need to ensure these contractors only have access to specific resources for the duration of the project (90 days). You want to automate the process of adding them to the correct groups and removing their access when the project ends. Which feature should you use?

    Show answer details

    Correct answer: D

    Entitlement Management allows you to create access packages that bundle resources (groups, apps, sites). It supports expiration dates and automated removal of access, ideal for temporary project work.

  6. 6

    Which score measures an organization's progress in completing actions that help reduce risks associated to data protection and regulatory standards?

    Show answer details

    Correct answer: B

  7. 7

    What do you use to provide real-time integration between Azure Sentinel and another security source?

    Show answer details

    Correct answer: B

  8. 8

    Which Microsoft portal provides information about how Microsoft cloud services comply with regulatory standard, such as International Organization forStandardization (ISO)?

    Show answer details

    Correct answer: D

Create an account to continue.