Microsoft SC-900 Security, Compliance, and Identity Fundamentals 1-10

表示モード
画像位置
文字位置
理解度の自動記録
STATUS FILTER

Choose confidence levels to display

Loading...
Q1SC-900
Show answer
Correct answer: A. Microsoft Purview compliance portal

A data loss prevention (DLP) policy detects and controls sensitive information across all of Microsoft 365, including email, SharePoint, OneDrive, and Teams.
The official administrative console for creating and managing these DLP policies is the Microsoft Purview compliance portal.
From here you centrally manage DLP policies, sensitivity labels, information protection, and more.
The Microsoft 365 admin center is for user and license management, the Intune admin center is for endpoint management, and the Microsoft 365 Defender portal focuses on threat detection and response (XDR); none of these is where DLP is created.
Microsoft Purview Data Loss Prevention
Overview of the Microsoft 365 admin center

Q2SC-900
Show answer
Correct answer: A. Microsoft Defender for Cloud

Microsoft Defender for Cloud is a security service that provides cloud workload protection (CWPP) for Azure and hybrid environments (on-premises and other clouds).
It provides vulnerability assessment, threat detection, and security recommendations for resources such as virtual machines, containers, SQL, and storage.
Azure Monitor is intended for monitoring and log collection and has no protection capability.
The Microsoft cloud security benchmark is a set of security guidelines and does not perform actual protection.
Microsoft Secure Score is a metric that quantifies and visualizes your security posture.
What is Microsoft Defender for Cloud?
What is CWPP?

Q3SC-900
Statement Yes No
In Security Center’s Secure Score, you can review recommendations related to Defender for Cloud Apps
From Security Center, you can display your organization’s score compared with other organizations’ scores
Even when you address an improvement action using a third-party app, you are awarded score points
Show answer
Correct answer: Statement 1 “Yes” / Statement 2 “Yes” / Statement 3 “No”

Microsoft Secure Score can be viewed from the Microsoft 365 Defender portal, where it aggregates and displays recommendations from each security product, including Defender for Cloud Apps.
Therefore, improvement actions related to Defender for Cloud Apps are also included in the score.
In addition, you can display your organization’s score compared with the industry average or with other organizations (anonymized, aggregated data).
On the other hand, points are awarded only for improvement actions that Microsoft can detect and evaluate, so measures taken with third-party apps cannot be verified and are not added to the score.
Microsoft Secure Score

Q4SC-900
Statement Yes No
You can export the search results of Microsoft Purview eDiscovery (Standard)
You can integrate Microsoft Purview eDiscovery (Standard) with insider risk management
You can use Microsoft Purview eDiscovery (Standard) to search Exchange Online public folders
Show answer
Correct answer: Statement 1 “Yes” / Statement 2 “No” / Statement 3 “Yes”

Microsoft Purview eDiscovery (Standard) is a basic electronic discovery capability that provides search, hold, and export for Microsoft 365 data, and search results can be exported for review or evidence submission.
On the other hand, integration with insider risk management is a feature of eDiscovery (Premium) and is not supported in Standard, so that statement is incorrect.
In addition, even in Standard you can include Exchange Online public folders in the search scope, along with mailboxes.
Get started with eDiscovery (Standard)
Overview of Microsoft Purview eDiscovery (Premium)

Q5SC-900
Show answer
Correct answer: B. Managing physical hardware

In the shared responsibility model, security and management responsibilities in a cloud environment are divided between Microsoft (the cloud provider) and the customer.
What Microsoft is solely responsible for is managing physical hardware such as datacenter facilities, servers, and network equipment.
On the other hand, managing user accounts, access permissions to user data, and mobile devices are among the responsibilities of the customer using the cloud.
Because security for these depends on identity management, access control, and device management settings, Microsoft does not manage them automatically.
Shared responsibility in the cloud

Q6SC-900
Show answer
Correct answer: A. A retention policy

When you want to retain a copy of all files on a SharePoint site for a set period (one year), what you should apply is a Microsoft Purview retention policy.
A retention policy can be applied at the SharePoint site level and reliably preserves a retained copy (a hold copy) even if a file is deleted or modified during the specified period.
Sensitivity labels are intended for classification and encryption and are not suited to enforcing retention periods.
An insider risk policy is for detecting internal wrongdoing, and a DLP policy is for preventing data exfiltration.
Learn about retention policies and retention labels
Learn about retention for SharePoint and OneDrive

Q7SC-900
Show answer
Correct answer: F. Defender for Cloud (formerly: Security Center)

The Azure Secure Score is a metric that visualizes the security posture of your Azure environment and indicates areas for improvement numerically.
The service that displays and manages this score is Microsoft Defender for Cloud (formerly Azure Security Center).
In Defender for Cloud, the Secure Score is displayed together with security recommendations across your subscriptions and resources.
Azure Monitor and Application Insights are intended for monitoring and observability and do not provide Secure Score; Advisor offers optimization suggestions, Policy enforces rules, and Subscriptions are a management unit.
What is Microsoft Defender for Cloud?
Secure score in Defender for Cloud

Q8SC-900
Statement Yes No
Conditional Access is implemented using Microsoft Entra ID policies
You can block or allow connections based on the specific platform of the user’s device
You can apply a Conditional Access policy to a Microsoft 365 group
Show answer
Correct answer: Statement 1 “Yes” / Statement 2 “Yes” / Statement 3 “No”

Conditional Access is an identity-based access control capability provided by Microsoft Entra ID and is implemented using policies.
Based on users and sign-in conditions (such as location, risk, and device state), it can grant, block, or require additional authentication for access.
Because you can specify the device platform (iOS, Android, Windows, and so on) as a condition, controlling connections from specific operating systems is possible.
On the other hand, the assignment targets are users, security groups, and apps; you cannot directly specify a Microsoft 365 group.
What is Conditional Access?
Conditional Access: Users, groups, agents, and workload identities

Q9SC-900
Show answer
Correct answer: C. Integration with Microsoft 365 Defender

Microsoft Sentinel (formerly Azure Sentinel) is a SIEM/SOAR service, but its XDR capabilities are realized through integration with Microsoft 365 Defender.
This integration correlates threat signals from multiple domains, such as endpoints, identities, email, and cloud apps, and lets you visualize and respond to them centrally as incidents.
Support for Azure Monitor workbooks and threat hunting are Sentinel features, but they are not XDR-specific capabilities.
Also, the compliance center (Purview) is intended for data protection and governance and is not directly related to XDR.
Integrate Microsoft Defender XDR with Microsoft Sentinel
What is Microsoft Defender XDR?

Q10SC-900
Show answer
Correct answer: B. The Azure portal

Azure Bastion is a managed service that provides RDP or SSH connectivity directly from the Azure portal without exposing the VM’s public IP to the internet.
Because the connection is made through the browser from within the Azure portal, there is no need to install an RDP client or SSH client on the client device.
PowerShell remoting is also not a prerequisite for a Bastion connection.
From the standpoint of “where do you connect from,” the Azure portal is the correct answer.
What is Azure Bastion?
Create an RDP connection to a Windows VM using Azure Bastion