Limited-Time Offer: Enjoy 50% Savings! - Ends In 0d 00h 00m 00s Coupon code: 50OFF
Free Exam Questions

SC-900 Exam Questions & Answers

Microsoft Security, Compliance, and Identity Fundamentals  •  Microsoft

215 Questions 45 min Updated Sep 2026 99% Pass Rate
Get Full Access

100% money-back guarantee

Sample SC-900 Questions

Practice with real exam-style questions, each with the verified correct answer and explanation.

Q1 MultipleChoice

You have an Azure subscription.

You need to implement approval-based, tiProme-bound role activation.

What should you use?

Correct Answer: D
Explanation:

In Microsoft's Security, Compliance, and Identity guidance, Azure AD Privileged Identity Management (PIM) is the service used to manage, control, and monitor access to important resources in Azure and Microsoft 365. The documentation explains that PIM enables ''just-in-time'' and ''time-bound'' activation of privileged roles, requiring users to elevate only when needed and for a limited duration. PIM policies can require approval before a role is activated, enforce multifactor authentication, capture business justification, send notifications, and maintain detailed auditing and access review records. These controls are designed to reduce the risk associated with standing administrative privileges by ensuring that elevation is temporary, approved, and tracked.

By contrast, Windows Hello for Business provides strong, device-bound authentication; Azure AD Identity Protection focuses on detecting and remediating risky sign-ins and users; and Azure AD Access Reviews periodically reattest existing assignments but do not provide the on-demand, approval-based, time-limited activation of roles. Therefore, when the requirement is approval-based, time-bound role activation, Microsoft's prescribed capability is Azure AD PIM, which delivers just-in-time elevation with approvers, duration limits, and audit/logging to support least privilege and Zero Trust operational practices.

Q2 MultipleChoice

What can you use to scan email attachments and forward the attachments to recipients only if the attachments are free from malware?

Correct Answer: A
Explanation:

Microsoft Defender for Office 365 includes Safe Attachments, a protection that ''checks attachments in a secure, virtual environment to detect malicious behavior.'' In Microsoft's guidance, Safe Attachments is described as part of the anti-malware pipeline that ''routes messages with attachments to a detonation chamber; if no suspicious activity is detected, the message is released to the recipient, and if malicious behavior is found, the attachment is blocked or removed.'' Administrators can choose Block, Replace, Dynamic Delivery, or Monitor actions. The Dynamic Delivery option specifically supports the use case in the question: the email body is delivered while the attachment is scanned, and ''the attachment is automatically reattached and forwarded to the recipient only when it is determined to be safe.'' This capability is unique to Defender for Office 365's Safe Attachments, not to be confused with endpoint antivirus or identity tools. Defender Antivirus protects Windows devices, Defender for Identity secures on-premises identities, and Defender for Endpoint focuses on endpoint detection and response. Therefore, the Microsoft service you use to scan email attachments and forward them only when clean is Microsoft Defender for Office 365 (Safe Attachments).

Q3 MultipleChoice

Which three tasks can be performed by using Azure Active Directory (Azure AD) Identity Protection? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

Correct Answer: B, C, D
Explanation:

Microsoft Entra ID Identity Protection is a risk-based conditional access capability that ''automates the detection and remediation of identity-based risks'' and enables admins to investigate risky users and sign-ins. SCI guidance explains that Identity Protection evaluates signals such as user risk and sign-in risk, raises risk detections, and can automatically remediate by enforcing actions like password reset or blocking access via risk-based policies. The portal provides rich investigation experiences for risky users, risky sign-ins, and risk detections, allowing security teams to review evidence and confirm/dismiss risks. In addition, identity risk data can be exported through Azure Monitor/diagnostic settings and integrated with SIEM/SOAR tools, enabling ''export of risk detections and security alerts to third-party solutions'' for correlation and response. Tasks such as configuring external access for partner organizations are handled by B2B collaboration features, and creating/assigning sensitivity labels belongs to Microsoft Purview Information Protection---not Identity Protection. Therefore, the tasks Identity Protection supports are: export risk detection (B), automate detection and remediation of identity-based risks (C), and investigate risks related to user authentication (D).

Q4 MultipleChoice

Which Microsoft portal provides information about how Microsoft manages privacy, compliance, and security?

Correct Answer: A
Explanation:

The Service Trust Portal is Microsoft's public-facing portal that centralizes how Microsoft manages privacy, compliance, and security for its cloud services. It provides independent audit reports, compliance guides, data protection resources, and details on Microsoft's internal controls and practices. It's the authoritative place to learn how Microsoft meets global, regional, and industry standards.

Q5 MultipleChoice

You have an Azure subscription that contains a Log Analytics workspace.

You need to onboard Microsoft Sentinel.

What should you do first?

Correct Answer: C
Explanation:

Onboarding Microsoft Sentinel starts by enabling Sentinel on an existing Log Analytics workspace and then connecting data sources so analytics can operate on ingested security data. Microsoft's Sentinel onboarding guidance emphasizes that after you add Sentinel to a workspace, you must ''connect Microsoft services, non-Microsoft solutions, and custom sources'' using built-in data connectors. Microsoft also states that ''you need data in your workspace before you can use Microsoft Sentinel's analytics, hunting, and investigation capabilities.'' Features such as custom analytics rules, hunting queries, and incident correlation depend on ingested telemetry from sources like Microsoft Entra ID sign-in logs, Microsoft 365, Defender products, firewalls, and other appliances. Because the question already gives you a Log Analytics workspace (the prerequisite for enabling Sentinel), the first action in the onboarding workflow that unlocks Sentinel's value is to connect your security sources. Only after data is flowing should you proceed to create analytics rules, hunting queries, and incident processes. Therefore, the correct first step to onboard Microsoft Sentinel is connect to your security sources.

Get access to all 215 verified questions with detailed answers.

Unlock All SC-900 Questions

Frequently Asked Questions

The SC-900 is Microsoft's Security, Compliance, and Identity Fundamentals certification that validates foundational knowledge of security, compliance, and identity concepts. It's an entry-level exam designed for those beginning their journey in cybersecurity and is a prerequisite for more advanced Microsoft security certifications.

The SC-900 exam typically costs $99 USD, though prices may vary by region and country. Microsoft occasionally offers discounts and free exam vouchers through various promotional programs and learning platforms.

The exam covers four main domains: Security and Compliance Concepts (25-30%), Identity and Access Management (20-25%), Security Operations (35-40%), and Governance, Risk, and Compliance (15-20%). Topics include cloud security, Azure services, identity solutions, threat protection, and compliance frameworks.

The SC-900 exam is 60 minutes long and contains approximately 40-60 questions in various formats including multiple choice and multiple select. The passing score is typically 700 out of 1000, though the exact passing score may vary.

No prior experience is required for the SC-900 as it's an entry-level certification designed for beginners in security and compliance. However, basic IT knowledge and familiarity with cloud concepts can be helpful for understanding the material.
Exam Details
  • Exam CodeSC-900
  • VendorMicrosoft
  • Total Questions215
  • Duration45 min
  • LanguageEnglish
  • Last UpdatedSep 1, 2026
4.9/5

Pass SC-900 First Time

Get all 215 exam questions with verified answers and 90-day free updates.

Buy Now & Pass
  • PDF + Practice Test Bundle
  • 90-Day Free Updates
  • 100% Money-Back Guarantee
  • Instant Download
  • 24/7 Customer Support
99% Pass Rate Trusted by 50,000+ IT professionals