SC-900 sample questions with answers

10 free practice questions for the Microsoft Security, Compliance, and Identity Fundamentals exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Describe the concepts of security, compliance, and identity

Employees at Munson's Pickles now use personal laptops and phones on home networks to reach SaaS applications that no longer sit behind the corporate firewall. The leadership team asks why the security strategy has moved its centre of gravity from the network edge to identity. Which explanation is the most accurate?

  1. A.

    SaaS providers assume full responsibility for access control, so the customer only needs to manage identities

  2. B.

    Network firewalls can no longer inspect encrypted traffic, so network controls provide no security value

  3. C.

    Identity is the one consistent control plane across every user, device, application, and network, so it becomes the primary security perimeter

  4. D.

    Identity controls replace the need for device management and data protection, simplifying the control set

Show answer

Answer: C

Identity is the only control plane present in every access request regardless of device, network, or hosting location, which is why it becomes the primary perimeter.

  • A. Shared responsibility keeps accounts, identities, data, and devices with the customer even in SaaS, so the provider does not own access control.
  • B. Network controls retain value in defense in depth and form one of the seven Zero Trust pillars; the claim that they provide none is false.
  • C. Identity is present in every access request regardless of network or hosting model, making it the consistent control plane and the primary perimeter.
  • D. Identity controls complement rather than replace device management and data protection, which remain separate Zero Trust pillars.
Question 2Describe the concepts of security, compliance, and identity

An identity architect at Adventure Works is reviewing five sign-in arrangements in use across the business and must mark the ones in which another organization's identity provider performed the authentication. Which two of them are federated sign-ins? (Choose TWO.)

Choose 2.

  1. A.

    A partner's employees open a shared portal using credentials issued by their own employer

  2. B.

    A customer signs in to the support site with an existing Microsoft consumer account

  3. C.

    A contractor is given a new account created directly in the Adventure Works directory

  4. D.

    An employee reuses the same password on two unrelated internal systems

  5. E.

    A user resets a forgotten password through a self-service page

Show answer

Answer: A, B

Federation means another organization's identity provider performed the authentication — partner credentials and a consumer account sign-in both qualify.

  • A. Partner staff authenticating with their employer's credentials on the strength of a configured trust is federated B2B access.
  • B. A customer signing in with an existing Microsoft consumer account is federation with a consumer identity provider.
  • C. Creating a local account is exactly what federation avoids, so it is not a federated sign-in.
  • D. Reusing a password on two systems involves no trust relationship; each system authenticates the user independently.
  • E. Self-service password reset is credential management inside one identity provider, with no external authentication.
Question 3Describe the concepts of security, compliance, and identity

Under the shared responsibility model, which responsibility stays with the customer no matter whether the workload runs as IaaS, PaaS, or SaaS?

  1. A.

    Classifying and protecting the organization's own data

  2. B.

    Patching the host hypervisor that runs the virtual machines

  3. C.

    Maintaining the runtime and middleware under a managed service

  4. D.

    Securing the physical datacenter and its network hardware

Show answer

Answer: A

Data is one of the responsibilities the customer never delegates, because only the customer knows what the data is and how sensitive it is.

  • A. Data classification, access decisions and retention remain with the customer in on-premises, IaaS, PaaS and SaaS alike.
  • B. The host hypervisor sits below the customer boundary and is patched by the provider from IaaS upwards.
  • C. In PaaS the provider takes over the operating system and runtime, so this responsibility is explicitly one that transfers.
  • D. Physical datacenter and network hardware security belongs to the provider in every cloud model, so it is never the customer's.
Question 4Describe the concepts of security, compliance, and identity

A developer at Litware inspects a security token returned by the identity provider and finds the user's unique identifier, their display name, the groups they belong to, and the time at which the token expires. What are these individual pieces of information called?

  1. A.

    Credentials

  2. B.

    Authentication factors

  3. C.

    Claims

  4. D.

    Attributes of the directory schema

Show answer

Answer: C

The individual pieces of data an identity provider places inside a security token are called claims.

  • A. Credentials are the evidence presented to the identity provider before any token is issued.
  • B. Authentication factors are the categories of proof used during verification, not data inside the resulting token.
  • C. Claims are the individual pieces of data about an authenticated identity carried inside a security token.
  • D. Directory attributes are stored properties of an account; only some are emitted as claims, and they are not the same thing.
Question 5Describe the concepts of security, compliance, and identity

An application at Proseware must decide, for each request, whether the signed-in user may open a particular record. On what are authorization decisions typically based?

  1. A.

    Roles, permissions, and attributes assigned to the identity

  2. B.

    The number of previous sign-ins recorded for the account

  3. C.

    The order in which accounts were created in the directory

  4. D.

    The strength of the credential the user presented

Show answer

Answer: A

Authorization evaluates roles, permissions, and attributes to decide what an authenticated identity may do.

  • A. Roles, permissions and attributes are the three bases on which authorization decisions are evaluated.
  • B. Sign-in history may inform risk detection, but it is not a basis for deciding what an identity is allowed to do.
  • C. The order accounts were created is an administrative detail with no bearing on permissions.
  • D. Credential strength is an authentication concern; it establishes who the subject is, not what they may do.
Question 6Describe the concepts of security, compliance, and identity

An internal review at Litware finds that accounts belonging to people who left the organization several months ago are still enabled, still hold the permissions they had on their last working day, and were never picked up by any process. Which pillar of the identity infrastructure has failed?

  1. A.

    Auditing

  2. B.

    Administration

  3. C.

    Authentication

  4. D.

    Authorization

Show answer

Answer: B

Deprovisioning is part of administration, so accounts left active after a leaver departs is an administration failure.

  • A. Auditing is how such accounts are usually found, but recording activity is not the control that should have removed them.
  • B. Deprovisioning when a user leaves is an administration responsibility, so leaving accounts active is an administration failure.
  • C. Authentication is functioning correctly; it verifies whoever presents valid credentials, which is why the stale account is dangerous.
  • D. Authorization is evaluating the permissions as configured; nothing in the scenario says the permissions were wrong for the role.
Question 7Describe the concepts of security, compliance, and identity

Lamna Healthcare is retiring an on-premises payroll server and moving the workload to a software as a service (SaaS) payroll product. The security team is rewriting its responsibility matrix for the new deployment model. In the shared responsibility model, which responsibility stays with Lamna Healthcare no matter which deployment model is used?

  1. A.

    Configuration of the virtual network and the host firewall used by the service

  2. B.

    Physical security of the datacenter racks that host the payroll service

  3. C.

    Information and data, devices, and accounts and identities

  4. D.

    Guest operating system patching on the servers that run the payroll service

Show answer

Answer: C

Information and data, devices, and accounts and identities are always the customer's responsibility in every deployment model, including SaaS.

  • A. Network controls vary by model: the provider owns them in SaaS, while the customer configures them in IaaS.
  • B. Physical datacenter security is one of the responsibilities that always belongs to Microsoft, never to the customer.
  • C. Data, devices, and accounts and identities are retained by the customer in on-premises, IaaS, PaaS, and SaaS deployments alike.
  • D. Operating system patching is the provider's job in SaaS and PaaS; it only returns to the customer in IaaS, so it is not constant.
Question 8Describe the concepts of security, compliance, and identity

Contoso has configured its identity provider to trust Fabrikam's, and Fabrikam staff can now open a Contoso application with their own credentials. Contoso staff then try to open a Fabrikam application and are refused. What explains this?

  1. A.

    Trust relationships are not automatically bidirectional, so a second trust must be configured explicitly

  2. B.

    A federated trust expires as soon as it has been used by the first partner organization

  3. C.

    Federation grants access to web applications only, so Contoso staff must use a desktop client

  4. D.

    Federation only works when both organizations use identity products from the same vendor

Show answer

Answer: A

Federation trust is directional; Contoso trusting Fabrikam does not make Fabrikam trust Contoso, so a second trust is required.

  • A. Trust relationships are directional; a two-way arrangement must be configured explicitly on both sides.
  • B. A federated trust is a standing configuration; it is not consumed or invalidated by being used.
  • C. Federated access is not limited to web applications, and changing client type would not create the missing trust.
  • D. Federation works across vendors and platforms because providers exchange tokens using industry-standard protocols.
Question 9Describe the concepts of security, compliance, and identity

A trainer at Adventure Works is checking that students can name the rings of a layered security strategy before moving on to the controls that sit in each one. Which two of the following are layers named in defense in depth? (Choose TWO.)

Choose 2.

  1. A.

    Attestation

  2. B.

    Perimeter

  3. C.

    Governance

  4. D.

    Compute

  5. E.

    Procurement

Show answer

Answer: B, D

Perimeter and compute are two of the seven defense-in-depth layers; procurement, governance and attestation are not layers at all.

  • A. Attestation is a mechanism used in device health and confidential computing, not a defense-in-depth layer.
  • B. Perimeter is a named layer covering DDoS protection and perimeter firewalls at the boundary of the network.
  • C. Governance is a GRC pillar describing rules and accountability, not one of the technical rings of defense in depth.
  • D. Compute is a named layer covering patching, port reduction, administrative restriction and monitoring on workloads.
  • E. Procurement is a business process and appears nowhere in the list of defense-in-depth layers.
Question 10Describe the concepts of security, compliance, and identity

Fabrikam publishes an installer for its desktop client and signs the file with its private key before uploading it. A customer downloads the installer and verifies the signature with Fabrikam's published public key before running it. What two assurances does that verification give the customer?

  1. A.

    That the file is encrypted and unreadable to anyone without the key

  2. B.

    That the file will remain available for download for a guaranteed period

  3. C.

    That the file is free of malware because Fabrikam scanned it

  4. D.

    That the file came from Fabrikam and has not been altered since signing

Show answer

Answer: D

A digital signature verifies authenticity and integrity — who produced the data and that it has not changed since it was signed.

  • A. Signing does not encrypt; a signed file remains fully readable to anyone who obtains it.
  • B. Availability guarantees come from hosting and service commitments, not from a cryptographic signature.
  • C. A valid signature says nothing about the safety of the content, only about its origin and integrity.
  • D. Signature verification proves the data came from the expected sender and was not modified after signing.

Keep going with 520 more SC-900 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

SC-900 sample questions with answers (10 free) · CertifyCloudx