SC-900 — Frequently Asked Questions

Community-vetted answers to 22 common questions about this exam.

Questions from real practice questions

Each Q&A comes from a specific community question — follow the link for its full analysis.

How Many Factors Does Azure AD Multi-Factor Authentication Require?

Because MFA is often described using three factor categories (know, have, are). Azure AD MFA still enforces only two factors at sign-in, so 3 is not the required count.

Not as the baseline definition. Extra verification comes from step-up or Conditional Access risk policies, which are separate from the standard two-factor MFA requirement.

Which Microsoft Purview Solution Identifies Data Leakage?

eDiscovery collects, holds, and exports content for legal or regulatory cases on demand; it does not proactively surface the insider risk signals that indicate data leakage.

No. Compliance Manager scores your compliance posture against regulations and proposes improvement actions, but it does not monitor user activity for leakage.

CSPM vs SIEM for Vulnerability Assessment

No. SIEM aggregates logs to detect incidents but does not actively scan for or assess vulnerabilities/misconfigurations like CSPM does.

CSPM secures the overall cloud configuration and posture, while CWPP protects specific workloads (servers/containers) from runtime threats.

Which Defender Protects Against Malicious Links in Email, Chat, and Channels?

Defender for Cloud Apps is a CASB that discovers SaaS usage and applies session or anomaly policies; it does not rewrite or detonate URLs inside email and Teams messages the way Safe Links does.

Yes. Safe Links covers email plus Microsoft Teams messages, channels, and supported Office apps, applying time-of-click verification so a link weaponized after delivery is still blocked.

Which Defender Service Includes Microsoft Secure Score for Devices?

Defender for Identity monitors Active Directory and identity signals, so it has no device onboarding or vulnerability data to compute a device hardening score.

No. The overall Microsoft Secure Score aggregates tenant-wide recommendations across services, while Secure Score for Devices is scoped to device configuration and lives in Defender for Endpoint.

Which Microsoft Portal Documents ISO Compliance for Microsoft Cloud Services?

Purview is where your own organization manages compliance settings like DLP, eDiscovery, and Compliance Manager; Microsoft's ISO certifications for its cloud services are published on the Service Trust Portal instead.

Independent audit reports, ISO/IEC 27001 and 27018 certificates, SOC 1/2/3 reports, FedRAMP packages, and regulatory compliance guides covering Microsoft cloud services.

Onboarding Microsoft Sentinel First Step

Detection rules need data to analyze. You must connect data sources so telemetry flows into the workspace before rules can trigger.

No. While the workspace is the storage component, Sentinel requires active data connections via connectors to become operational.

Azure Key Vault Purpose and Function

Key Vault stores software-managed keys and secrets, while Managed HSM provides dedicated hardware modules for FIPS 140-2 Level 3 compliance.

No, it protects secrets and keys. General cyber threat protection is handled by services like Microsoft Defender for Cloud.

Azure Key Vault Functions for SC-900

No. ARM templates should be stored in version control systems like GitHub or Azure DevOps. Key Vault is for sensitive data, not infrastructure code.

No. DDoS protection is handled by Azure DDoS Protection Standard, a networking service. Key Vault focuses on secret and key management.

Creating a Case for eDiscovery Search and Export

No. A case is required to define the scope, manage permissions, and track the export process within the eDiscovery framework.

A hold preserves data to prevent deletion, while a case is the workspace used to search, review, and export that preserved data.

Which Two Device Types Can Be Managed by Endpoint DLP?

Endpoint DLP enforcement requires the Purview onboarding agent, which Microsoft documents only for Windows 10/11 and macOS, so Linux devices cannot receive Endpoint DLP policies.

No. Mobile platforms are handled by Intune app protection and Purview data protection policies, not by the Endpoint DLP device agent used for Windows and macOS.

Ready to practice?

Access 141 SC-900 questions with instant feedback and detailed explanations.

View SC-900 Practice Questions →

← Back to SC-900 Microsoft Security, Compliance, and Identity Study Guide