Microsoft SC-900 Exam Questions
Microsoft Security, Compliance, and Identity Fundamentals (Page 3 )

Updated On: 24-Feb-2026

HOTSPOT (Drag and Drop is not supported)
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:




Box 1: Yes
System updates reduces security vulnerabilities, and provide a more stable environment for end users. Not applying updates leaves unpatched vulnerabilities and results in environments that are susceptible to attacks.
Box 2: Yes
Box 3: Yes
If you only use a password to authenticate a user, it leaves an attack vector open. With MFA enabled, your accounts are more secure.


Reference:

https://docs.microsoft.com/en-us/azure/security-center/secure-score-security-controls



Which score measures an organization's progress in completing actions that help reduce risks associated to data protection and regulatory standards?

  1. Microsoft Secure Score
  2. Productivity Score
  3. Secure score in Microsoft Defender for Cloud
  4. Compliance score

Answer(s): D

Explanation:

The Compliance Manager dashboard displays your overall compliance score. This score measures your progress in completing recommended improvement actions within controls. Your score can help you understand your current compliance posture. It can also help you prioritize actions based on their potential to reduce risk.
A score value is assigned at these levels:
Improvement action: Each action has a different impact on your score depending on the potential risk involved. See Action types and points below for details.
* Assessment: This score is calculated using improvement action scores. Each Microsoft action and each improvement action managed by your organization is counted once, regardless of how often it's referenced in a control.


Reference:

https://docs.microsoft.com/en-us/microsoft-365/compliance/compliance-manager?view=o365-worldwide
https://docs.microsoft.com/en-us/microsoft-365/compliance/compliance-score-calculation?view=o365- worldwide



What do you use to provide real-time integration between Microsoft Sentinel and another security source?

  1. Microsoft Entra Connect sync
  2. a Log Analytics workspace
  3. Azure Information Protection
  4. a data connector

Answer(s): D

Explanation:

To on-board Azure Sentinel, you first need to connect to your security sources. Azure Sentinel comes with a number of connectors for Microsoft solutions, including Microsoft 365 Defender solutions, and Microsoft 365 sources, including Office 365, Microsoft Entra ID, Microsoft Defender for Identity, and Microsoft Cloud App Security, etc.


Reference:

https://docs.microsoft.com/en-us/azure/sentinel/overview



Which Microsoft portal provides information about how Microsoft cloud services comply with regulatory standard, such as International Organization for Standardization (ISO)?

  1. the Microsoft Endpoint Manager admin center
  2. Azure Cost Management + Billing
  3. Microsoft Service Trust Portal
  4. the Microsoft Entra admin center

Answer(s): C

Explanation:

The Microsoft Service Trust Portal contains details about Microsoft's implementation of controls and processes that protect our cloud services and the customer data therein.


Reference:

https://docs.microsoft.com/en-us/microsoft-365/compliance/get-started-with-service-trust-portal?view=o365- worldwide



In the shared responsibility model for an Azure deployment, what is Microsoft solely responsible for managing?

  1. the management of mobile devices
  2. the permissions for the user data stored in Azure
  3. the creation and management of user accounts
  4. the management of the physical hardware

Answer(s): D






Post your Comments and Discuss Microsoft SC-900 exam dumps with other Community members:

Join the SC-900 Discussion