Sample Microsoft SC-900 SC-900 Practice Questions
Q: What is the Zero Trust security model's core principle?
A: Never trust, always verify — Zero Trust operates on the principle of 'never trust, always verify.' Every access request is fully authenticated, authorized, and encrypted regardless of where it originates.
Q: What is Microsoft Entra ID (formerly Azure Active Directory)?
A: A cloud-based identity and access management service — Microsoft Entra ID is Microsoft's cloud-based identity and access management service. It helps employees sign in and access resources including Microsoft 365, the Azure portal, and thousands of other SaaS applications.
Q: What is Microsoft Defender for Cloud?
A: A cloud security posture management (CSPM) and cloud workload protection platform (CWPP) — Microsoft Defender for Cloud is a unified cloud security solution that provides cloud security posture management (CSPM) to find and fix vulnerabilities, and cloud workload protection (CWPP) to protect workloads across multicloud and hybrid environments.
Q: What is the Microsoft Purview compliance portal?
A: A centralized portal for managing compliance solutions including data lifecycle, information protection, and risk management — The Microsoft Purview compliance portal is a centralized platform that provides tools and solutions for managing data governance, information protection, data lifecycle management, risk management, and compliance across the organization.
Q: Which of the following is one of the three guiding principles of Zero Trust?
A: Assume breach — The three guiding principles of Zero Trust are: verify explicitly, use least privilege access, and assume breach. Assuming breach limits the blast radius and prevents lateral movement.
Q: In the Zero Trust model, which of the following is NOT one of the foundational pillars?
A: Firewalls — The six foundational pillars of Zero Trust are identities, devices, applications, data, infrastructure, and networks. Firewalls are a traditional perimeter security tool, not a Zero Trust pillar.
Q: In the shared responsibility model for cloud computing, who is always responsible for the data and information stored in the cloud?
A: The customer — In the shared responsibility model, the customer is always responsible for their data, information, and access management regardless of the cloud deployment model (IaaS, PaaS, or SaaS).
Q: In a SaaS deployment, which responsibility shifts the MOST from the customer to the cloud provider compared to on-premises?
A: Application management — In SaaS, the cloud provider manages the application, operating system, network, and infrastructure. The customer retains responsibility for their data, accounts, identities, and devices.
Q: Which cloud service model gives the customer the MOST control over the infrastructure?
A: IaaS — IaaS (Infrastructure as a Service) provides the customer with the most control, including management of the operating system, network configuration, and deployed applications.
Q: Defense in depth is a security strategy that uses what approach?
A: Multiple layers of security controls — Defense in depth uses multiple layers of security mechanisms so that if one layer fails, another is in place to prevent an attack. Layers include physical, identity, perimeter, network, compute, application, and data.