The Microsoft SC-900 - Microsoft Security, Compliance, and Identity Fundamentals exam is part of the Microsoft Azure certification track. It is designed for learners who want to build a strong foundation in security, compliance, and identity concepts within the Microsoft ecosystem. This exam is a great starting point for beginners, business users, and technical professionals who need to understand core Microsoft security solutions. Earning this certification helps validate your knowledge of essential cloud security and compliance principles.
| # | Exam Topics | Sub-Topics | Approximate Weightage (%) |
|---|---|---|---|
| 1 | Describe the Concepts of Security, Compliance, and Identity | Security principles and shared responsibility, compliance concepts, identity fundamentals, zero trust basics | 25% |
| 2 | Describe the capabilities of Microsoft Entra | Authentication and access management, conditional access, identity protection, role-based access control | 25% |
| 3 | Describe the capabilities of Microsoft Security Solutions | Threat protection, endpoint security, cloud security, security monitoring and response | 25% |
| 4 | Describe the Capabilities of Microsoft Compliance Solutions | Data governance, compliance management, information protection, regulatory and risk controls | 25% |
The SC-900 exam tests foundational understanding rather than deep technical implementation. Candidates should be able to recognize Microsoft security, compliance, and identity capabilities, explain key concepts, and understand how the solutions work together. The focus is on practical awareness, terminology, and basic decision-making knowledge needed for real-world cloud and security discussions.
QA4Exam.com offers Exam PDF materials with actual questions and answers, along with an Online Practice Test for the Microsoft SC-900 exam. These resources help you study with up-to-date questions that match the exam style and key topic areas. The online test gives you a real exam simulation so you can practice under timed conditions and improve your time management. Verified answers help you check your understanding quickly and focus on the areas that need more review. Using both formats together can make your preparation more efficient and increase your confidence for first-attempt success.
It is the Microsoft Security, Compliance, and Identity Fundamentals exam in the Microsoft Azure certification path. It validates basic knowledge of security, compliance, and identity concepts and Microsoft solution capabilities.
It is suitable for beginners, students, business users, and IT professionals who want a foundation in Microsoft security, compliance, and identity topics. It is also useful for anyone starting a cloud security learning path.
The exam is considered fundamental, so it is less difficult than advanced Microsoft security exams. However, candidates still need to understand the concepts clearly and recognize how Microsoft solutions are used.
Braindumps alone are not the best approach. A better result comes from using QA4Exam.com dumps together with practice testing and concept review so you understand the answers, not just memorize them.
Hands-on experience is helpful but not mandatory for this fundamentals exam. Basic familiarity with Microsoft security and identity services can improve understanding, but strong study materials can also prepare you well.
The PDF gives you convenient study access to actual questions and answers, while the online practice test simulates the real exam environment. Together they help you review faster, verify answers, and practice time management before exam day.
The materials are presented as up-to-date exam preparation resources, which helps you stay aligned with current exam coverage. This is important for studying the latest Microsoft topics and answer patterns.
Which Microsoft 365 feature can you use to restrict users from sending email messages that contain lists of customers and their associated credit card numbers?
In Microsoft 365, Data Loss Prevention (DLP) policies are designed to ''help you identify, monitor, and automatically protect sensitive information'' across services such as Exchange Online, SharePoint Online, OneDrive, and Microsoft Teams. Microsoft's guidance explains that DLP uses sensitive information types---including built-in classifiers like Credit Card Number---to detect when content matches a defined pattern and then enforce protective actions. With DLP, you can create rules that trigger when email messages contain customer lists with credit card numbers, and choose actions to block the message, restrict access, or notify and educate users via policy tips and incident reports. Microsoft further notes that DLP ''prevents the accidental sharing of sensitive information,'' can require user justification to override, and supports granular conditions (e.g., number of matches, recipients internal vs. external) to ensure that only risky transmissions are stopped. By applying a DLP policy to Exchange with the Credit Card Number sensitive info type, an organization can block or quarantine outbound mail that includes those numbers, thereby reducing regulatory and data-exposure risk. Other options listed---retention policies, conditional access, and information barriers---serve different purposes (data lifecycle, access/authentication conditions, and restricting communication between groups) and do not inspect message contents for sensitive data. Hence, DLP policies are the correct control to restrict sending emails that contain customer lists and associated credit card numbers.
Which two cards are available in the Microsoft 365 Defender portal? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
Microsoft's SCI learning content describes the Microsoft 365 Defender portal as a unified security operations experience that surfaces security posture and active threats on a card-based dashboard. In the overview of the portal, Microsoft explains that the home page ''presents key security information in dashboard cards,'' and that among these cards are summaries that highlight risky entities such as ''Users at risk'' and ''Devices at risk.'' These cards provide quick, actionable visibility for analysts by aggregating detections and exposure data across Microsoft Defender services (for identities and endpoints). The guidance emphasizes that the portal ''correlates signals across identities, endpoints, email, and applications'' and that security teams can use the dashboard cards to pivot directly into incidents and investigations from ''Users at risk'' or ''Devices at risk'' to take containment or remediation actions.
By contrast, Compliance Score is part of Microsoft Purview Compliance Manager, not the Microsoft 365 Defender portal; Service Health and User Management are functions of the Microsoft 365 admin center. Therefore, the cards you'll find on the Microsoft 365 Defender portal that match the choices provided are Users at risk and Devices at risk.
What are three uses of Microsoft Cloud App Security? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
Microsoft Cloud App Security (now Microsoft Defender for Cloud Apps) is Microsoft's CASB that ''discovers and controls shadow IT,'' integrates with identity and endpoint signals, and enforces data protection in SaaS and custom apps. SCI materials describe three core use cases relevant here: (1) Discovery and control of shadow IT by analyzing network logs and app usage, rating risk, and applying governance---matching A. (2) Protect sensitive information hosted anywhere in the cloud via policies such as DLP, information protection label awareness, and integration with apps through API connectors---matching C. (3) Prevent data leaks to noncompliant apps and limit access to regulated data using Conditional Access App Control and session controls that can block download, apply protections, or monitor in real time---matching E. In contrast, secure connections to Azure virtual machines are provided by Azure Bastion, not the CASB (eliminating B), and pass-through authentication to on-premises apps is delivered by Azure AD features such as Azure AD Application Proxy or PTA (not Cloud App Security), eliminating D.
Which security feature is available in the free mode of Microsoft Defender for Cloud?
In Microsoft Defender for Cloud, the Free plan provides continuous security assessment and visibility into your posture via Secure Score and security recommendations. Microsoft explains that the free tier offers ''foundational CSPM capabilities,'' including recommendations and a security score (Secure score) to help you prioritize hardening tasks. Advanced features---such as vulnerability scanning for VMs (Qualys-based), Just-In-Time (JIT) VM access, and threat protection alerts---require the enhanced/paid Defender plans (for example, Defender for Servers). Consequently, among the listed options, only Secure score is available in the free mode. This score aggregates the effect of recommendations across subscriptions and resources so you can track and improve security posture without enabling any of the paid Defender plans.
What should you use to ensure that the members of an Azure Active Directory group use multi-factor authentication (MFA) when they sign in?
The recommended way to enable and use Azure AD Multi-Factor Authentication is with Conditional Access policies. Conditional Access lets you create and define policies that react to sign-in events and that request additional actions before a user is granted access to an application or service.
Full Exam Access, Actual Exam Questions, Validated Answers, Anytime Anywhere, No Download Limits, No Practice Limits
Get All 215 Questions & Answers