SC-900: Microsoft Security, Compliance, and Identity Fundamentals
This exam measures foundational knowledge of security, compliance, and identity concepts across cloud-based and related Microsoft services. It is intended for business stakeholders, students, and new or existing IT professionals who want to understand Microsoft security, compliance, and identity solutions. Candidates should be familiar with Microsoft Azure and Microsoft 365 and understand how these solutions provide a holistic end-to-end approach.
What you get with membership
- The full SC-900 question bank with detailed explanations
- Readiness tracking by objective so you know when you're ready
- Access to every other exam in the Certavo library
- Content kept in step with the latest exam objectives
SC-900 exam objectives and study guide
The skills measured on the SC-900 exam, by objective domain. Percentages are the share of the exam each domain carries.
Describe the capabilities of Microsoft security solutions
37.5% of the exam- Describe core infrastructure security services in Azure
- Describe Azure DDoS Protection
- Describe Azure Firewall
- Describe Azure Web Application Firewall (WAF)
- Describe network segmentation with Azure virtual networks
- Describe network security groups (NSGs)
- Describe Azure Bastion
- Describe Azure Key Vault
- Describe security management capabilities of Azure
- Describe Microsoft Defender for Cloud
- Describe Cloud Security Posture Management (CSPM)
- Describe how security policies, standards, and recommendations improve the cloud security posture
- Describe enhanced security features provided by cloud workload protection
- Describe capabilities of Microsoft Sentinel
- Define the concepts of security information and event management (SIEM) and security orchestration automated response (SOAR)
- Describe threat detection and mitigation capabilities in Microsoft Sentinel
- Describe threat protection with Microsoft Defender XDR
- Describe Microsoft Defender XDR services
- Describe Microsoft Defender for Office 365
- Describe Microsoft Defender for Endpoint
- Describe Microsoft Defender for Cloud Apps
- Describe Microsoft Defender for Identity
- Describe Microsoft Defender Vulnerability Management
- Describe Microsoft Defender Threat Intelligence (Defender TI)
- Describe the Microsoft Defender portal
Describe the capabilities of Microsoft Entra
27.5% of the exam- Describe function and identity types of Microsoft Entra ID
- Describe Microsoft Entra ID
- Describe types of identities, including agent ID
- Describe hybrid identity
- Describe authentication capabilities of Microsoft Entra ID
- Describe the authentication methods
- Describe multifactor authentication (MFA)
- Describe password protection and management capabilities
- Describe access management capabilities of Microsoft Entra ID
- Describe Microsoft Entra Conditional Access
- Describe Microsoft Entra roles and role-based access control (RBAC)
- Describe identity protection and governance capabilities of Microsoft Entra
- Describe Microsoft Entra ID Governance
- Describe access reviews
- Describe the capabilities of Microsoft Entra Privileged Identity Management
- Describe Microsoft Entra ID Protection
Describe the capabilities of Microsoft compliance solutions
22.5% of the exam- Describe Microsoft Service Trust Portal and privacy principles
- Describe the Service Trust Portal offerings
- Describe the privacy principles of Microsoft
- Describe compliance management capabilities of Microsoft Purview
- Describe the Microsoft Purview portal
- Describe Compliance Manager
- Describe the uses and benefits of compliance score
- Describe information protection, data lifecycle management, and data governance capabilities of Microsoft Purview
- Describe the data classification capabilities
- Describe the benefits of Content explorer and Activity explorer
- Describe sensitivity labels and sensitivity label policies
- Describe data loss prevention (DLP)
- Describe records management
- Describe retention policies, retention labels, and retention label policies
- Describe insider risk, eDiscovery, and audit capabilities in Microsoft Purview
- Describe insider risk management
- Describe eDiscovery solutions in Microsoft Purview
- Describe audit solutions in Microsoft Purview
Describe the concepts of security, compliance, and identity
12.5% of the exam- Describe security and compliance concepts
- Describe the shared responsibility model
- Describe defense-in-depth
- Describe the Zero Trust model
- Describe encryption and hashing
- Describe Governance, Risk, and Compliance (GRC) concepts
- Define identity concepts
- Define identity as the primary security perimeter
- Define authentication
- Define authorization
- Describe identity providers
- Describe the concept of directory services and Active Directory
- Describe the concept of federation
SC-900 practice questions and answers
12 free sample questions from the SC-900 bank, with the correct answer and a full explanation for each. These are original questions written to the Microsoft objective domains — not real exam content.
- Question 1Describe the capabilities of Microsoft compliance solutions
During an audit readiness workshop, Woodgrove Bank's governance team is already signed in to the Microsoft Purview portal. The team needs to open the Microsoft trust documentation experience from Purview. Which navigation path should they use?
- ASolutions > Related portals > Microsoft Service Trust
- BSettings > Roles and scopes > Microsoft Service Trust
- CUnified Catalog > Discovery > Data assets
- DRisk & Compliance > eDiscovery > Content Search
Show answer and explanation
Correct answer
- Solutions > Related portals > Microsoft Service Trust
Explanation
The correct answer is Solutions > Related portals > Microsoft Service Trust. The Microsoft Purview portal lists Microsoft Service Trust as a related portal that can be accessed from Solutions > Related portals.
- Settings > Roles and scopes > Microsoft Service Trust is incorrect because roles and scopes are for Purview permissions management, not for opening related portals.
- Unified Catalog > Discovery > Data assets is used for catalog data asset search and browse, not Service Trust Portal access.
- Risk & Compliance > eDiscovery > Content Search is for eDiscovery content search workflows, not Microsoft trust documents.
References:
- Question 2Describe the capabilities of Microsoft compliance solutions
A help desk intake form routes requests for Microsoft cloud compliance evidence. Complete the configuration so requests for Microsoft-published audit evidence are sent to the correct Microsoft portal and document category.
json { "evidenceRequest": { "requestType": "Microsoft cloud compliance evidence", "destinationPortal": "1", "documentSet": "2" } }Blank 1
- AMicrosoft Service Trust
- BMicrosoft Priva
- CMicrosoft Defender
- DMicrosoft Entra
Blank 2
- AAudit reports
- BInsider Risk Management cases
- CConditional Access policies
- DData Loss Prevention alerts
Show answer and explanation
Correct answers
- Blank 1: Microsoft Service Trust
- Blank 2: Audit reports
Explanation
The correct configuration sends the request to Microsoft Service Trust and selects Audit reports.
- Microsoft Service Trust Portal provides Microsoft cloud compliance resources such as audit reports, data protection resources, and trust documentation.
- Microsoft Priva is used for privacy management capabilities, not for downloading Microsoft cloud audit reports.
- Microsoft Defender is for security operations and threat protection experiences.
- Microsoft Entra is for identity and access management.
- Insider Risk Management cases, Conditional Access policies, and Data Loss Prevention alerts are tenant-specific controls or events, not the Service Trust Portal audit report document set.
References:
- Question 3Describe the capabilities of Microsoft compliance solutions
A data protection workshop is introducing Microsoft privacy commitments to new project managers. Which two statements align with Microsoft privacy principles?
- AGive customers control over their data and privacy choices.
- BBe transparent about what data is collected and how it is used.
- CUse customer email, chat, files, or other content in Microsoft Advertising targeting when personalization is enabled.
- DRely on privacy notices instead of security protections for customer data.
Show answer and explanation
Correct answers
- Give customers control over their data and privacy choices.
- Be transparent about what data is collected and how it is used.
Explanation
Microsoft privacy principles include control and transparency. Customers should have meaningful choices over their data, and Microsoft should be clear about what data is collected and how it is used.
- Using customer email, chat, files, or other content for Microsoft Advertising targeting contradicts the principle of no content-based targeting.
- Privacy commitments do not replace security safeguards; security is also a Microsoft privacy principle.
References:
- Question 4Describe the capabilities of Microsoft compliance solutions
Fourth Coffee’s risk team is creating an evidence packet for a customer that asks what can be obtained from Microsoft’s compliance evidence portal. Which two artifact types should the team expect to retrieve there?
- AMicrosoft cloud services audit reports
- BData protection resources for Microsoft online services
- CMicrosoft Entra sign-in logs for tenant users
- DMicrosoft Purview eDiscovery exports from mailbox content
Show answer and explanation
Correct answers
- Microsoft cloud services audit reports
- Data protection resources for Microsoft online services
Explanation
The Microsoft Service Trust Portal provides Microsoft cloud compliance materials such as audit reports and data protection resources.
- Microsoft Entra sign-in logs are tenant identity monitoring records, not Microsoft-published compliance evidence documents.
- Microsoft Purview eDiscovery exports contain tenant content collected for legal or investigation workflows, not Microsoft audit and trust documentation.
References:
- Question 5Describe the capabilities of Microsoft compliance solutions
You need a Microsoft Purview configuration that applies the same retain-or-delete settings automatically to all content in selected Exchange mailboxes and SharePoint sites. Users should not choose a classification for individual items. Which capability should you use?
- ARetention policy
- BRetention label
- CSensitivity label
- DData Loss Prevention policy
Show answer and explanation
Correct answer
- Retention policy
Explanation
The correct answer is retention policy.
- A retention policy applies retention settings at the container level, such as Exchange mailboxes and SharePoint sites, and the content in those containers inherits the settings.
- A retention label is applied at the item level, such as to a specific document or email.
- A sensitivity label is used for information protection and classification, not for a retain-or-delete schedule.
- A Data Loss Prevention policy detects and helps protect sensitive information; it does not apply retention settings to containers.
References:
- Question 6Describe the capabilities of Microsoft compliance solutions
Users report that they can delete a retained file from a SharePoint library, but compliance reviewers can still recover a preserved copy of the file. Which SharePoint location is used for that preserved content?
- APreservation Hold library
- BFirst-stage Recycle Bin
- CSite Assets library
- DeDiscovery review set
Show answer and explanation
Correct answer
- Preservation Hold library
Explanation
The correct answer is the Preservation Hold library.
- For SharePoint and OneDrive content that is subject to retention, Microsoft 365 creates a hidden Preservation Hold library when needed and stores preserved copies there.
- The Recycle Bin is a user recovery feature, not the compliance storage location used by Purview retention.
- The Site Assets library stores site assets such as images and pages; it is not the hidden compliance preservation location.
- An eDiscovery review set is used to review collected content in eDiscovery workflows; it is not where SharePoint automatically stores retained copies.
References:
- Question 7Describe the capabilities of Microsoft compliance solutions
Lamna Healthcare is piloting automatic item classification for contracts. The compliance team wants to run a simulation before turning on the policy and then review matching samples. Which two condition types support simulation mode for auto-applying a retention label?
- ASpecific types of sensitive information
- BSpecific keywords or searchable properties in a query
- CTrainable classifiers selected in the policy
- DA default label for a SharePoint document library or Exchange folder
Show answer and explanation
Correct answers
- Specific types of sensitive information
- Specific keywords or searchable properties in a query
Explanation
The correct answers are specific types of sensitive information and specific keywords or searchable properties.
- Simulation mode for auto-applying retention labels is supported when the policy is configured for specific sensitive information types.
- Simulation mode is also supported when the policy uses keywords or searchable properties that match a query.
- Trainable classifiers can be used to auto-apply retention labels, but the documented simulation mode conditions are sensitive information types and keyword/searchable-property queries.
- A default label for an organizing structure such as a SharePoint library or an Exchange folder is not configured by an auto-apply simulation; Microsoft documents that these scenarios require a published retention label policy.
References:
- Question 8Describe the capabilities of Microsoft compliance solutions
SharePoint Online sites and Exchange Online mailboxes already hold project documents and email. The legal team now requires a visible classification marking on highly confidential content and access restrictions that remain with the content when it is shared. Which Microsoft Purview capability should you implement?
- AA sensitivity label configured with content markings and encryption
- BA data loss prevention policy configured to block external sharing
- CA retention label configured to declare content as a record
- DAn eDiscovery hold configured for the project mailboxes and sites
Show answer and explanation
Correct answer
- A sensitivity label configured with content markings and encryption
Explanation
The correct answer is a sensitivity label configured with content markings and encryption.
- Sensitivity labels in Microsoft Purview Information Protection can classify content, add markings such as headers or footers, and apply encryption to restrict access.
- A DLP policy can detect sensitive information and block or audit risky sharing, but it does not provide the visible classification label and persistent encryption requirement by itself.
- A retention label manages how long content is retained or deleted; it is not used to display classification markings or encrypt content.
- An eDiscovery hold preserves content for legal or investigative purposes; it does not classify or protect content for normal collaboration.
References:
- Question 9Describe the capabilities of Microsoft compliance solutions
Employees report that obsolete Teams channel files and Exchange messages remain available long after business value has ended. Compliance requires the content to be kept for five years and then removed automatically, without declaring the items as formal records. Which Microsoft Purview solution best addresses the requirement?
- AMicrosoft Purview Data Lifecycle Management
- BMicrosoft Purview Records Management
- CMicrosoft Purview Data Loss Prevention
- DMicrosoft Purview Compliance Manager
Show answer and explanation
Correct answer
- Microsoft Purview Data Lifecycle Management
Explanation
The correct answer is Microsoft Purview Data Lifecycle Management.
- Data Lifecycle Management uses retention policies and retention labels to retain Microsoft 365 content for a configured period and delete it afterward.
- Records Management is used for more formal records scenarios, such as declaring items as records or regulatory records; the scenario specifically says formal record declaration is not required.
- Data Loss Prevention helps prevent accidental sharing or leakage of sensitive information; it does not implement a five-year retain-then-delete lifecycle.
- Compliance Manager tracks regulatory control implementation and compliance posture; it does not apply retention to content.
References:
- Question 10Describe the capabilities of Microsoft compliance solutions
Relecloud is enabling Microsoft 365 Copilot for users who already work with files protected by encrypted sensitivity labels. The security team wants to understand how Microsoft Purview protection affects what Copilot can return to a user. Which statement is accurate?
- ASupported AI apps can return encrypted labeled content only when the user has the required usage rights, including VIEW and EXTRACT.
- BSupported AI apps can return encrypted labeled content whenever the user can see a link to the file in search results.
- CRetention labels prevent supported AI apps from returning content until the retention period has expired.
- DUnified Catalog glossary terms determine whether supported AI apps can summarize protected files.
Show answer and explanation
Correct answer
- Supported AI apps can return encrypted labeled content only when the user has the required usage rights, including VIEW and EXTRACT.
Explanation
The correct answer is that supported AI apps check the user's VIEW and EXTRACT usage rights when sensitivity label encryption protects the content.
- Microsoft Purview protections for supported AI apps use existing access controls, and when a sensitivity label applies encryption, the user must have the required usage rights, including VIEW and EXTRACT, for the AI app to return the data.
- File access alone is not sufficient when label encryption requires specific usage rights.
- Retention labels manage lifecycle behavior and do not determine whether Copilot can return encrypted content.
- Unified Catalog glossary terms provide business context for governed data assets; they are not the access-control mechanism for Copilot responses.
References:
- Question 11Describe the capabilities of Microsoft security solutions
Fourth Coffee keeps Azure, endpoint, and email security alerts in different analyst views. The SOC wants to operate its cloud SIEM without requiring Microsoft Defender XDR licensing, but also wants a unified portal experience for incidents and hunting. Which experience should the SOC use?
- AUse Microsoft Sentinel in the Microsoft Defender portal.
- BUse Microsoft Sentinel only in the Azure portal because the Defender portal requires Microsoft Defender XDR or E5.
- CUse Azure Monitor Logs without enabling Microsoft Sentinel because workbooks provide the unified incident queue.
- DUse Microsoft Defender for Cloud only because it replaces Microsoft Sentinel for multi-source SIEM analytics.
Show answer and explanation
Correct answer
- Use Microsoft Sentinel in the Microsoft Defender portal.
Explanation
Microsoft Sentinel is generally available in the Microsoft Defender portal, including for customers that do not use Microsoft Defender XDR or an E5 license. In that portal, Sentinel provides full SIEM functionality and a unified SIEM and Defender operating experience.
Using Sentinel only in the Azure portal does not meet the unified portal requirement and the Azure portal experience is no longer the long-term direction. Azure Monitor Logs and workbooks can query and visualize logs, but they do not provide the unified Sentinel incident queue. Microsoft Defender for Cloud provides cloud security posture management and workload protection capabilities; it does not replace Sentinel for multi-source SIEM operations.
References:
- Question 12Describe the capabilities of Microsoft security solutions
Aarav, an IT auditor, must identify the Microsoft service for a security operations review covering 20 Azure subscriptions and Microsoft 365. The service must provide cloud-native SIEM and SOAR capabilities for collecting security data, detecting threats, investigating incidents, and orchestrating response. Which service should Aarav identify?
- AMicrosoft Sentinel
- BMicrosoft Purview Insider Risk Management
- CMicrosoft Entra ID Protection
- DAzure Key Vault
Show answer and explanation
Correct answer
- Microsoft Sentinel
Explanation
Microsoft Sentinel is the Microsoft cloud-native SIEM and SOAR solution. It collects security data, uses analytics for detection, supports investigation and hunting, and can automate response through Sentinel automation and playbooks.
Microsoft Purview Insider Risk Management is a compliance solution for insider risk workflows. Microsoft Entra ID Protection focuses on identity risk detection and remediation. Azure Key Vault protects secrets, keys, and certificates; it is not a SIEM or SOAR platform.
References:
Membership includes 191 questions and explanations aligned to the SC-900 curriculum.
Other Microsoft certifications
Every one of these is included with the same membership as SC-900.
Microsoft 365 Copilot and Agent Administration Fundamentals
This exam is intended for candidates who are familiar with Microsoft 365, including core services, security, identity and access, data…
Microsoft Azure AI Fundamentals
This exam measures knowledge of machine learning and AI concepts and related Microsoft Azure services. It is intended for candidates…
Microsoft Azure Fundamentals
This exam is intended for technology professionals who want to demonstrate foundational knowledge of cloud concepts and Microsoft Azure.…
SC-900 exam FAQ
How many questions are on the SC-900 exam?+
The SC-900 (Microsoft Security, Compliance, and Identity Fundamentals) exam has around 45 questions. Question counts vary slightly between exam forms, so treat this as the typical number rather than a guarantee.
How long is the SC-900 exam?+
You get 45 minutes for the SC-900 exam itself. Allow extra time at the test centre or for the online check-in process before the timer starts.
What level is SC-900?+
SC-900 is a Microsoft fundamentals-level certification, so it assumes no prior certification and is a common starting point.
Are there free SC-900 practice questions?+
Yes. 12 free SC-900 practice questions are on this page, each with the correct answer and a full explanation. The complete bank of 191 questions is included with membership.
Are these real SC-900 exam questions?+
No. Every question is original, written to match the published SC-900 objective domains and question styles. Real exam content is confidential, and reusing it would breach Microsoft's exam policies.