Microsoft

SC-900 Microsoft Security, Compliance, and Identity Fundamentals

📝 36 questions 📄 4 pages ✓ Up to date
▶ Practice Questions

About This Exam SC-900: Microsoft Security, Compliance, and Identity Fundamentals

Prepare for the SC-900 exam with our free practice questions covering security, compliance, and identity (SCI) concepts across Microsoft cloud services. Each question comes with a detailed explanation to help you understand not just the correct answer, but the reasoning behind it.

Who should practice with these questions

SC-900 is a foundational-level exam, ideal for business stakeholders, IT professionals new to security and compliance, and students building a base understanding of Microsoft's security ecosystem. A general familiarity with Microsoft Azure and Microsoft 365 will help you get the most out of these practice questions.

Topics covered by our practice questions

Our question bank is organized around the same four skill areas the actual exam measures, so you can focus your practice where it counts:

  • Security, compliance, and identity concepts (10–15%) — shared responsibility model, defense in depth, Zero Trust, encryption and hashing, GRC concepts, and core identity concepts like authentication, authorization, and federation.
  • Microsoft Entra capabilities (25–30%) — identity types and hybrid identity, authentication methods and MFA, Conditional Access, role-based access control (RBAC), and identity protection and governance features like Privileged Identity Management.
  • Microsoft security solutions (35–40%) — core Azure infrastructure security (DDoS Protection, Firewall, WAF, network security groups, Key Vault), Microsoft Defender for Cloud, Microsoft Sentinel (SIEM/SOAR), and the Microsoft Defender XDR suite (Office 365, Endpoint, Cloud Apps, Identity, Vulnerability Management, Threat Intelligence).
  • Microsoft compliance solutions (20–25%) — the Service Trust Portal and privacy principles, Microsoft Purview compliance management (Compliance Manager, compliance score), information protection and data lifecycle management (sensitivity labels, DLP, retention policies), and insider risk, eDiscovery, and audit capabilities.

Work through our practice questions at your own pace, check your answers instantly, and review the explanations to strengthen your understanding before exam day.