SC-900 — Microsoft Security, Compliance, and Identity Fundamentals
Microsoft

Microsoft Security, Compliance, and Identity Fundamentals (SC-900) Practice Questions

4.8 574 verified reviews
141 questions
June 11, 2026 updated
Online quiz simulator

Domain coverage

  • Describe the concepts of security, compliance, and identity (10–15%)
  • Describe the capabilities of Microsoft Entra (25–30%)
  • Describe the capabilities of Microsoft security solutions (35–40%)
  • Describe the capabilities of Microsoft compliance solutions (20–25%)

Sample Questions (15 of 141 shown)

Q1 Describe the capabilities of Microsoft compliance solutions
Which Microsoft portal provides information about how Microsoft manages privacy, compliance, and security?
  1. Microsoft Service Trust Portal
  2. Compliance Manager
  3. Microsoft Purview compliance portal
  4. Microsoft Support
✓ Correct Answer: A
The Microsoft Service Trust Portal provides detailed information about Microsoft's security, privacy, and compliance practices, including audit reports and compliance guides.
Q2 Describe the capabilities of Microsoft compliance solutions
Your compliance officer needs access to audit reports, compliance guides, and security assessments for Microsoft cloud services. Where should they look?
  1. Microsoft Compliance Manager
  2. Service Trust Portal
  3. Microsoft Purview
  4. Azure portal
✓ Correct Answer: B
The Service Trust Portal (STP) provides access to audit reports, compliance documentation, and security assessments for Microsoft cloud services including Azure, Microsoft 365, and Dynamics 365.
Q3 Describe the capabilities of Microsoft compliance solutions
Which Microsoft portal provides information about how Microsoft cloud services comply with regulatory standards such as ISO?
  1. Microsoft Endpoint Manager admin center
  2. Azure Cost Management + Billing
  3. Microsoft Service Trust Portal
  4. Microsoft Entra admin center
✓ Correct Answer: C
The Service Trust Portal provides audit reports, compliance documentation, and security assessments for Microsoft cloud services against standards like ISO, SOC, and GDPR.
Q4 Describe the capabilities of Microsoft compliance solutions
Which statement represents a Microsoft privacy principle?
  1. Microsoft does not collect any customer data
  2. Microsoft uses hosted customer email and chat data for targeted advertising
  3. Microsoft manages privacy settings for its customers
  4. Microsoft respects the local privacy laws that are applicable to its customers
✓ Correct Answer: D
Microsoft's privacy principles include: control, transparency, security, strong legal protections, no content-based targeted advertising, and respecting local privacy laws.
Q5 Describe the capabilities of Microsoft compliance solutions
An organization needs to assess its compliance posture against regulatory standards such as GDPR and ISO 27001, and wants to track improvement actions with a risk-based compliance score. Which Microsoft tool should they use?
  1. Microsoft Defender for Cloud
  2. Microsoft Purview Information Protection
  3. Microsoft Purview Compliance Manager
  4. Azure Policy
✓ Correct Answer: C
Microsoft Purview Compliance Manager provides pre-built assessments for regulations like GDPR, HIPAA, and ISO 27001, along with a risk-based compliance score and step-by-step improvement actions.
Q6 Describe the capabilities of Microsoft compliance solutions
The compliance team wants to assess their organization's compliance posture, get improvement recommendations, and track progress against regulatory requirements like GDPR and ISO 27001. Which tool should they use?
  1. Service Trust Portal
  2. Microsoft Purview Compliance Manager
  3. Azure Policy
  4. Microsoft Purview Audit
✓ Correct Answer: B
Compliance Manager assesses compliance posture, provides improvement actions, and tracks progress against regulatory standards including GDPR and ISO 27001 with a percentage-based compliance score.
Q7 Describe the capabilities of Microsoft compliance solutions
A company wants to measure its overall compliance posture using a percentage-based score that reflects the completion of improvement actions mapped to data protection regulations. Which feature provides this capability?
  1. Microsoft Secure Score
  2. Azure Policy compliance dashboard
  3. Compliance Manager compliance score
  4. Defender for Cloud Secure Score
✓ Correct Answer: C
The Compliance Manager compliance score measures progress on improvement actions mapped to regulatory controls. Microsoft Secure Score measures security posture — they serve different purposes.
Q8 Describe the capabilities of Microsoft compliance solutions
Which score measures an organization's progress in completing actions that help reduce risks associated with data protection and regulatory standards?
  1. Microsoft Secure Score
  2. Productivity Score
  3. Secure score in Microsoft Defender for Cloud
  4. Compliance score
✓ Correct Answer: D
Compliance score specifically measures progress on improvement actions mapped to data protection regulations and standards, distinct from security posture scores.
Q9 Describe the capabilities of Microsoft compliance solutions
What is an assessment in Compliance Manager?
  1. Grouping of controls from a specific regulation, standard, or policy
  2. Recommended guidance for corporate standards
  3. Dictionary of banned words
  4. Policy initiative with multiple policies
✓ Correct Answer: A
An assessment in Compliance Manager is a grouping of controls from a specific regulation, standard, or policy (like GDPR or ISO 27001) that the organization needs to comply with.
Q10 Describe the capabilities of Microsoft compliance solutions
Compliance Manager assesses compliance data for an organization how often?
  1. Continually
  2. Monthly
  3. On-demand
  4. Quarterly
✓ Correct Answer: A
Compliance Manager continuously assesses compliance data and automatically updates the compliance score as configurations and improvement actions change.
Q11 Describe the capabilities of Microsoft compliance solutions
Compliance Manager can be directly accessed from which portal?
  1. Microsoft 365 admin center
  2. Microsoft 365 Defender portal
  3. Microsoft Purview compliance portal
  4. Microsoft Support portal
✓ Correct Answer: C
Compliance Manager is accessed through the Microsoft Purview compliance portal as part of the compliance solutions catalog.
Q12 Describe the capabilities of Microsoft compliance solutions
Which portal contains the Solution catalog?
  1. Microsoft 365 Apps admin center
  2. Microsoft 365 Defender portal
  3. Microsoft 365 admin center
  4. Microsoft Purview compliance portal
✓ Correct Answer: D
The Microsoft Purview compliance portal contains the solution catalog, providing a single location to discover, learn about, and set up Microsoft Purview solutions.
Q13 Describe the capabilities of Microsoft compliance solutions
Your organization needs to discover, classify, and protect sensitive data in Microsoft 365, including emails, documents, and Teams conversations. Which solution provides these data governance capabilities?
  1. Microsoft Defender for Cloud Apps
  2. Microsoft Purview
  3. Azure Information Protection
  4. Microsoft Sentinel
✓ Correct Answer: B
Microsoft Purview provides unified data governance including data discovery, classification, and protection across Microsoft 365 services, on-premises, and multi-cloud environments.
Q14 Describe the capabilities of Microsoft compliance solutions
What can you protect by using the information protection solution in Microsoft Purview?
  1. Computers from zero-day exploits
  2. Users from phishing attempts
  3. Files from malware and viruses
  4. Sensitive data from being exposed to unauthorized users
✓ Correct Answer: D
Microsoft Purview Information Protection protects sensitive data from unauthorized exposure through classification, labeling, and encryption that persists with the data.
Q15 Describe the capabilities of Microsoft compliance solutions
Your organization wants to classify and protect documents and emails by applying labels such as 'Confidential' or 'Public.' These labels should persist with the data and apply encryption. Which Microsoft feature provides this?
  1. Retention labels
  2. Sensitivity labels
  3. Data loss prevention (DLP) policies
  4. Conditional Access policies
✓ Correct Answer: B
Sensitivity labels classify and protect data with persistent labels that can apply encryption, content marking (headers, footers, watermarks), and access restrictions.

You've viewed 3 of 141 questions. Start the free practice exam to answer all questions with instant feedback.

What Our Customers Say 574 verified reviews

4.8 Based on 574 reviews
I was skeptical about paying for exam prep, but the SC-900 bank saved me. Covered everything I needed.
— Nathan R.
Straightforward and effective. No fluff in the SC-900 practice set, just relevant questions with solid answer keys.
— Owen P.
Bought lifetime access for the SC-900 bank and it’s been great. Still use it to brush up even after passing the cert.
— Sophie L.
Straight to the point. No filler, just good SC-900 practice questions with clear explanations. Exactly what I needed.
— Paisley K.
I scored 890 on the SC-900 exam. Went through about 80% of this question bank and it was more than enough to pass.
— Levi C.
Detailed, organized, and accurate. Exactly what you want in SC-900 prep material. The explanations deserve special mention.
— Gabriel L.

Log in to rate this exam and leave a review.

Submitted for moderation before publishing. Keep it helpful and respectful.

Frequently Asked Questions

The most common stumbling block is branding confusion—candidates frequently mix up the specific target environments of the Microsoft Defender XDR suite (for example, confusing Defender for Identity with Defender for Cloud Apps). Another frequent area of confusion is where Microsoft Entra ID identity handling ends and Microsoft Purview compliance governance begins. Our practice questions are designed to reinforce these service boundaries through targeted scenario comparisons, helping you keep each product's role clear in your mind on exam day.

Start with the free, self-paced interactive modules under the official SC-900 learning path on Microsoft Learn. Then use the free Microsoft Learn Practice Assessment, which offers unlimited simulated test runs built by the same internal team that designs the live certification exam—it is the single most accurate readiness tool available at zero cost. Our practice question bank supplements these official resources with additional explanations that break down the specific distractor logic Microsoft uses to test service differentiation.

No. Unlike Associate, Expert, and Specialty certifications—which are valid for exactly one year and require a free annual renewal assessment—all Microsoft Fundamentals certifications, including SC-900, never expire. Once you pass the exam, the credential remains active on your transcript indefinitely with no maintenance fees or renewal tests required. Our study materials are designed to help you pass on your first attempt, making the $99 exam fee a one-time investment in a permanent credential.

After a failed first attempt, you must wait 24 hours before rescheduling. A third or subsequent attempt requires a 14-day waiting period between sittings, and you are capped at five attempts within any rolling 12-month period. Each attempt requires a separate registration fee unless your initial booking included an Exam Replay voucher bundle. Our mock exam mode helps you identify domain-level gaps—especially in the heavyweight Domain 3 (security solutions) and Domain 4 (compliance solutions)—so you can avoid needing a retake.

The real SC-900 exam gives you 45 to 60 minutes for 40 to 50 questions—significantly shorter than role-based Microsoft exams—and explicitly excludes Case Studies and interactive code scripts. Our mock exam mode enforces the same shorter time window and question mix, including drag-and-drop matching lists, hot-spot diagrams, and drop-down "Yes/No" evaluation matrices that test your ability to distinguish between Defender XDR components and Entra ID versus Purview responsibilities. Practicing under this compressed timeline is essential because the shorter format leaves less room for pacing recovery.

Yes—the downloadable PDF packages the full question bank in a print-friendly format that you can use on flights, commutes, or anywhere without reliable internet. The PDF includes the same detailed answer explanations as the online version, with references to the specific Microsoft Learn documentation paths for Sensitivity Labels, DLP rules, Defender XDR component boundaries, and Entra ID Conditional Access signal evaluation. Many candidates use the PDF for a final review of Zero Trust tenets and the Shared Responsibility Model the morning of their exam sitting.

The three Zero Trust tenets—Verify explicitly (always authenticate and authorize based on all available signals), Use least privileged access (limit user access with JIT/JEA policies and risk-based adaptive policies), and Assume breach (minimize blast radius and segment access)—are foundational to understanding all Microsoft security solutions. SC-900 tests these principles across every domain because they underpin how Entra ID Conditional Access, Defender XDR detection, and Purview compliance policies all function. Our practice materials integrate Zero Trust logic into scenario questions across all four domains so you see how the same principle applies differently in each context.

Free Study Resources

Community-verified analysis of 24 topics from real test-taker discussions — 2 deep analyses and 0 FAQs.