SC-900 — Microsoft Security, Compliance, and Identity Fundamentals
Microsoft

Microsoft Security, Compliance, and Identity Fundamentals (SC-900) Practice Questions

★★★★★ 5.0 579 verified reviews
141 questions
June 11, 2026 updated
✓ Online quiz simulator

Domain coverage

  • Describe the concepts of security, compliance, and identity (10–15%)
  • Describe the capabilities of Microsoft Entra (25–30%)
  • Describe the capabilities of Microsoft security solutions (35–40%)
  • Describe the capabilities of Microsoft compliance solutions (20–25%)

Sample Questions (15 of 141 shown)

Q1 Describe the concepts of security, compliance, and identity
Which statement best describes the cloud shared responsibility model?
  1. The cloud provider is responsible for all security regardless of service model
  2. Security responsibilities are divided between the cloud provider and the customer based on the service model
  3. The customer is always responsible for the physical datacenter
  4. Responsibility shifts entirely to the customer once data is uploaded
✓ Correct Answer: B
The shared responsibility model divides security responsibilities between the cloud provider and customer. The provider handles physical hosts, network, and datacenter. The customer always owns information and data, devices, and accounts/identities. Other responsibilities shift depending on whether the service is IaaS, PaaS, or SaaS.
Q2 Describe the concepts of security, compliance, and identity
Under the shared responsibility model, who is ALWAYS responsible for information and data, devices, and accounts/identities?
  1. The cloud provider
  2. The customer
  3. It depends on the service model
  4. A neutral third party
✓ Correct Answer: B
Across IaaS, PaaS, and SaaS, the customer always retains responsibility for information and data, devices (mobile and PCs), and accounts/identities. The cloud provider is always responsible for physical hosts, network, and datacenter.
Q3 Describe the concepts of security, compliance, and identity
In the shared responsibility model for an Azure deployment, what is Microsoft solely responsible for managing?
  1. The management of mobile devices
  2. The permissions for the user data stored in Azure
  3. The creation and management of user accounts
  4. The management of the physical hardware
✓ Correct Answer: D
Microsoft is always responsible for physical hosts, network, and datacenter in the shared responsibility model, regardless of service type.
Q4 Describe the concepts of security, compliance, and identity
In the shared responsibility model for cloud security, which of the following is ALWAYS the responsibility of the customer, regardless of the cloud service model?
  1. Physical host security
  2. Network controls
  3. Operating system patching
  4. Data classification and accountability
✓ Correct Answer: D
Data classification and accountability is always the customer's responsibility. Physical hosts are always the provider's responsibility. OS patching and network controls shift by service model.
Q5 Describe the concepts of security, compliance, and identity
In infrastructure as a service (IaaS), managing the physical network is the responsibility of the cloud provider.
  1. Yes
  2. No
✓ Correct Answer: A
The cloud provider is always responsible for the physical datacenter, physical network, and physical hosts regardless of service model.
Q6 Describe the concepts of security, compliance, and identity
In all Azure cloud deployment types, managing the security of information and data is the responsibility of the organization.
  1. Yes
  2. No
✓ Correct Answer: A
The customer is always responsible for their information and data, endpoints, and accounts/identities, regardless of deployment model (IaaS, PaaS, or SaaS).
Q7 Describe the concepts of security, compliance, and identity
Your organization is migrating workloads to Azure using Platform as a Service (PaaS). Who is responsible for operating system security in a PaaS model?
  1. The customer is always responsible
  2. Microsoft is responsible for the operating system
  3. Responsibility is shared equally
  4. Neither party is responsible
✓ Correct Answer: B
In PaaS, Microsoft manages the operating system, runtime, and middleware. The customer is responsible for applications and data.
Q8 Describe the concepts of security, compliance, and identity
What is the core idea behind a defense in depth strategy?
  1. Rely on a single strong perimeter firewall
  2. Use multiple layers of security controls so no single failure exposes the asset
  3. Encrypt data only when it leaves the network
  4. Replace all on-premises controls with cloud-native ones
✓ Correct Answer: B
Defense in depth uses a layered approach (physical, identity, perimeter, network, compute, application, data) so that if one control fails another still protects the asset.
Q9 Describe the concepts of security, compliance, and identity
You plan to implement a security strategy and place multiple layers of defense throughout a network infrastructure. Which security methodology does this represent?
  1. Threat modeling
  2. Identity as the security perimeter
  3. Defense in depth
  4. The shared responsibility model
✓ Correct Answer: C
Defense in depth places multiple layers of security controls throughout an IT infrastructure to protect assets from various attack vectors.
Q10 Describe the concepts of security, compliance, and identity
Which three principles form the foundation of the Zero Trust model?
  1. Trust but verify, encrypt everything, audit annually
  2. Verify explicitly, use least privilege access, assume breach
  3. Build perimeter, monitor logs, patch systems
  4. Block by default, allow by exception, log everything
✓ Correct Answer: B
The three Zero Trust guiding principles are: Verify Explicitly (always authenticate and authorize based on all available signals), Use Least Privilege Access (just-in-time and just-enough access), and Assume Breach (segment, encrypt, and use analytics).
Q11 Describe the concepts of security, compliance, and identity
Which Zero Trust principle is best illustrated by network microsegmentation and end-to-end encryption?
  1. Verify explicitly
  2. Use least privilege access
  3. Assume breach
  4. Trust internal traffic
✓ Correct Answer: C
Assume Breach drives the use of microsegmentation, end-to-end encryption, and continuous analytics. The premise is that an attacker may already be inside, so you limit blast radius.
Q12 Describe the concepts of security, compliance, and identity
Which Zero Trust principle addresses limiting the impact of a breach?
  1. Verify explicitly
  2. Use least privilege access
  3. Assume breach
  4. Enable multi-factor authentication
✓ Correct Answer: C
Assume Breach means designing security as if attackers are already in your environment, minimizing blast radius through segmentation, encryption, and analytics.
Q13 Describe the concepts of security, compliance, and identity
Which three statements accurately describe the guiding principles of Zero Trust?
  1. Define the perimeter by physical locations
  2. Use identity as the primary security boundary
  3. Always verify the permissions of a user explicitly
  4. Always assume that the user system can be breached
  5. Use the network as the primary security boundary
✓ Correct Answer: B, C, D
Zero Trust principles: identity is the primary security boundary (not the network perimeter), always verify explicitly, and assume breach.
Q14 Describe the concepts of security, compliance, and identity
Which security model operates on the principle of 'never trust, always verify' and assumes that every request must be authenticated, authorized, and continuously validated?
  1. Defense in depth
  2. Zero Trust
  3. Least privilege access
  4. Perimeter-based security
✓ Correct Answer: B
Zero Trust operates on 'never trust, always verify.' Every access request is authenticated, authorized, and continuously validated regardless of origin.
Q15 Describe the concepts of security, compliance, and identity
What does the C in the CIA triad stand for?
  1. Compliance
  2. Confidentiality
  3. Continuity
  4. Cryptography
✓ Correct Answer: B
The CIA triad consists of Confidentiality (protecting data from unauthorized disclosure), Integrity (preventing unauthorized modification), and Availability (ensuring authorized access when needed).

You've viewed 3 of 141 questions. Start the free practice exam to answer all questions with instant feedback.

What Our Customers Say 579 verified reviews

5.0 ★★★★★ Based on 579 reviews
★★★★★★
The SC-900 questions were tougher than the actual exam, which honestly made me more confident. Great prep tool.
— Brandon L.
★★★★★★
I travel a lot for work, so the mobile-friendly SC-900 practice was a lifesaver. Did questions on flights and during commute.
— Lily B.
★★★★★★
Solid SC-900 prep. No complaints. Questions are relevant and the platform works well on both desktop and phone.
— Scarlett W.
★★★★★★
Had to renew my SC-900 certification and used this to refresh. Way more efficient than re-reading the official study guide.
— Leo D.
★★★★★
I bought the SC-900 question bank a week before my exam and passed with 90%+. The questions are that good.
— Maria V.
★★★★★★
The SC-900 bank has a good mix of easy, medium, and hard questions. Kept me engaged and prevented me from getting complacent.
— Skylar M.

Log in to rate this exam and leave a review.

Submitted for moderation before publishing. Keep it helpful and respectful.

Frequently Asked Questions

The most common stumbling block is branding confusion—candidates frequently mix up the specific target environments of the Microsoft Defender XDR suite (for example, confusing Defender for Identity with Defender for Cloud Apps). Another frequent area of confusion is where Microsoft Entra ID identity handling ends and Microsoft Purview compliance governance begins. Our practice questions are designed to reinforce these service boundaries through targeted scenario comparisons, helping you keep each product's role clear in your mind on exam day.

Start with the free, self-paced interactive modules under the official SC-900 learning path on Microsoft Learn. Then use the free Microsoft Learn Practice Assessment, which offers unlimited simulated test runs built by the same internal team that designs the live certification exam—it is the single most accurate readiness tool available at zero cost. Our practice question bank supplements these official resources with additional explanations that break down the specific distractor logic Microsoft uses to test service differentiation.

No. Unlike Associate, Expert, and Specialty certifications—which are valid for exactly one year and require a free annual renewal assessment—all Microsoft Fundamentals certifications, including SC-900, never expire. Once you pass the exam, the credential remains active on your transcript indefinitely with no maintenance fees or renewal tests required. Our study materials are designed to help you pass on your first attempt, making the $99 exam fee a one-time investment in a permanent credential.

After a failed first attempt, you must wait 24 hours before rescheduling. A third or subsequent attempt requires a 14-day waiting period between sittings, and you are capped at five attempts within any rolling 12-month period. Each attempt requires a separate registration fee unless your initial booking included an Exam Replay voucher bundle. Our mock exam mode helps you identify domain-level gaps—especially in the heavyweight Domain 3 (security solutions) and Domain 4 (compliance solutions)—so you can avoid needing a retake.

The real SC-900 exam gives you 45 to 60 minutes for 40 to 50 questions—significantly shorter than role-based Microsoft exams—and explicitly excludes Case Studies and interactive code scripts. Our mock exam mode enforces the same shorter time window and question mix, including drag-and-drop matching lists, hot-spot diagrams, and drop-down "Yes/No" evaluation matrices that test your ability to distinguish between Defender XDR components and Entra ID versus Purview responsibilities. Practicing under this compressed timeline is essential because the shorter format leaves less room for pacing recovery.

Yes—the downloadable PDF packages the full question bank in a print-friendly format that you can use on flights, commutes, or anywhere without reliable internet. The PDF includes the same detailed answer explanations as the online version, with references to the specific Microsoft Learn documentation paths for Sensitivity Labels, DLP rules, Defender XDR component boundaries, and Entra ID Conditional Access signal evaluation. Many candidates use the PDF for a final review of Zero Trust tenets and the Shared Responsibility Model the morning of their exam sitting.

The three Zero Trust tenets—Verify explicitly (always authenticate and authorize based on all available signals), Use least privileged access (limit user access with JIT/JEA policies and risk-based adaptive policies), and Assume breach (minimize blast radius and segment access)—are foundational to understanding all Microsoft security solutions. SC-900 tests these principles across every domain because they underpin how Entra ID Conditional Access, Defender XDR detection, and Purview compliance policies all function. Our practice materials integrate Zero Trust logic into scenario questions across all four domains so you see how the same principle applies differently in each context.

Free Study Resources

Community-verified analysis of 24 topics from real test-taker discussions — 2 deep analyses and 0 FAQs.