Free SC-900 Practice Test Questions and Answers (2026)

View Mode
Q: 1

HOTSPOT Select the answer that correctly completes the sentence. SC-900 question

Your Answer
22 comments in the community discussion
6
Identity provider
6
Not authentication provider, it's definitely an identity provider here. Authentication is part of IdP but not the main label.
Q: 2

HOTSPOT For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. SC-900 question

Your Answer
26 comments in the community discussion
6
YES YES YES
5
YES YES YES
Q: 3

HOTSPOT Select the answer that correctly completes the sentence. SC-900 question

Your Answer
25 comments in the community discussion
6
Yeah, it's got to be Microsoft Endpoint Manager admin center. That's the main spot for Intune management these days since everything moved into that unified portal. I think anything else would be outdated.
5
Yeah, this matches what I've seen on the exam guide. Microsoft Endpoint Manager admin center.
Q: 4

HOTSPOT Select the answer that correctly completes the sentence. SC-900 question

Your Answer
36 comments in the community discussion
5
Is the sentence specifically about cloud adoption strategy or migration planning, or does it mention controlling compliance and policies? Just want to be sure since Azure Policy is for enforcement, but CAF covers the whole adoption lifecycle from strategy through governance. Need more context here.
5
Why do they always throw in Blueprints and Policy as distractors? The sentence clearly wants the framework, so Microsoft Cloud Adoption Framework for Azure fits best here imo.
Q: 5

HOTSPOT For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. SC-900 question

Your Answer
32 comments in the community discussion
5
I see why people go No, Yes, No here. Azure AD (Entra ID) doesn't have every feature in all editions and you never need to set up your own VMs for it. Only the portal statement checks out. Pretty sure that's right but open to corrections.
5
No, Yes, No
Q: 6

HOTSPOT Select the answer that correctly completes the sentence. SC-900 question

Your Answer
27 comments in the community discussion
8
Microsoft Cloud App Security fits here since it enables real-time session control for cloud apps using Conditional Access. Pretty sure that's the tool Microsoft uses for visibility and policy enforcement on SaaS activity. Let me know if anyone thinks otherwise.
6
Microsoft Cloud App Security. Saw a similar question in the official guide and on practice tests, this is the tool for real-time session controls in cloud apps. Let me know if you’ve seen it answered differently elsewhere.
Q: 7

HOTSPOT Select the answer that correctly completes the sentence. SC-900 question

Your Answer
31 comments in the community discussion
5
Virtual networks
4
Virtual networks, had something like this in a mock exam. All DDoS Protection Standard configs in Azure are set at the VNet layer. Pretty sure that's what they're after here.
Q: 8

HOTSPOT Select the answer that correctly completes the sentence. SC-900 question

Your Answer
33 comments in the community discussion
6
Isn't the main point here about making data unreadable rather than just changing format or reducing size? Compressing can make data hard to read for humans but it's not actually for confidentiality. Wouldn't encrypting be the right fit given what the exam usually asks?
5
Wouldn't it be encrypting? Only encryption makes the data unreadable for anyone without the key. The other options like compressing or archiving don't actually scramble the data, they just change storage or size.
Q: 9

HOTSPOT For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. SC-900 question

Your Answer
36 comments in the community discussion
6
Yes No Yes. Seen this layout in some practice sets, matches standard hybrid setup in Azure AD.
6
Had something like this in a mock in practice, went with Yes, No, Yes and it matched the exam report answers.
Q: 10

HOTSPOT Select the answer that correctly completes the sentence. SC-900 question

Your Answer
27 comments in the community discussion
6
Authorization. Authentication looks tempting but that's for verifying identity, not for access after sign-in.
5
Authorization. Trap option is authentication, but that's done before the access check. Seen similar on other practice sets.
Q: 11
In a hybrid identity model, what can you use to sync identities between Active Directory Domain Services (AD DS) and Azure Active Directory (Azure AD)?
Options
15 comments in the community discussion
1
It’s C since Azure AD Connect is what actually handles the sync between on-prem AD and Azure AD. PIM is just for privileged access, nothing to do with syncing accounts. Pretty sure about this but open to other takes.
1
C not D. PIM is for privilege management but only Azure AD Connect actually does sync. Trap option for sure.
Q: 12
What feature in Microsoft Defender for Endpoint provides the first line of defense against cyberthreats by reducing the attack surface?
Options
4 comments in the community discussion
6
Option D is right here since network protection is actually part of attack surface reduction. Automated remediation and hunting kick in later, not as first defense. Ran into a similar question in some practice sets. Anybody see a scenario where this flips?
DNetwork protection blocks malicious sites before users connect, so it's really the first defense layer. Automated stuff comes into play after something gets through. Pretty sure about D here.
Q: 13
What can you use to provide threat detection for Azure SQL Managed Instance?
Options
6 comments in the community discussion
2
C, Microsoft Defender for Cloud
1
Looks like C here. Defender for Cloud is the one that actually provides threat detection for SQL Managed Instances, not Secure Score or Bastion. Easy to mix up with A since Secure Score gets mentioned a lot in Azure security questions.
Q: 14
What is a characteristic of a sensitivity label in Microsoft 365?
Options
5 comments in the community discussion
1
Had something like this in a mock, it's definitely A. Sensitivity labels stay with the doc or email wherever it goes, that's the persistent part. Not every label has encryption, so B's out. Anybody see it differently?
1
D imo, but are they asking for the best characteristic or just any feature? If they're focused on persistence specifically, that rules out B and C since not all sensitivity labels enforce encryption or are limited to predefined categories.
Q: 15
What can you use to ensure that all the users in a specific group must use multi-factor authentication (MFA) to sign in to Azure AD?
Options
9 comments in the community discussion
1
Conditional Access policy is what you'd use for this, so C. It lets you target specific groups and require MFA on sign-in. Pretty sure the others can't do that directly. Someone correct me if that's off?
1
Why does Microsoft always split these controls across so many places? It’s C.
Q: 16
Which three authentication methods can be used by Azure Multi-Factor Authentication (MFA)? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
Options
7 comments in the community discussion
D imo, it's A, B, and D like folks above said. Azure MFA doesn't use email or security questions for the authentication step, just phone call, SMS, or the Authenticator app. Email is more for notifications, not second factor. Pretty sure that's what the docs show too, but correct me if I'm off.
Agree with A, B, D. Azure MFA skips email and security questions completely, just sticks with those three for auth methods.
Q: 17
Which two types of resources can be protected by using Azure Firewall? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
Options
14 comments in the community discussion
1
C/D? Seen similar on another practice test, still not sure which fits.
1
Option A and D for sure. Azure Firewall operates at the VNet boundary so it protects virtual machines (A) and the network itself (D). E seems like a trap since SharePoint Online is SaaS, not IaaS, so Firewall can't protect it directly. Pretty straightforward unless I'm missing some edge case here.
Q: 18
Which solution performs security assessments and automatically generates alerts when a vulnerability is found?
Options
7 comments in the community discussion
1
Don’t think it’s D since SIEMs collect and correlate logs but don’t actually scan for vulnerabilities. A (CSPM) checks cloud configs, finds issues, and triggers alerts automatically. CWPP is more workload protection, not overall security posture assessment. Pretty sure A fits best here.
1
CSPM is the one that does continuous assessments and pops alerts for vulnerabilities. A
Q: 19
Which Microsoft 365 feature can you use to restrict communication and the sharing of information between members of two departments at your organization?
Options
10 comments in the community discussion
1
C tbh
Its C for sure. Information Barriers actually stop members of separate departments from chatting or sharing files in Teams and other M365 apps, which is exactly what the question asks. Sensitivity labels alone won't block direct communication between groups. Disagree?
Q: 20
What is an example of encryption at rest?
Options
6 comments in the community discussion
3
Option B. Saw a similar question on a practice test, always picks encrypting the VM disk for at rest.
1
Had something like this in a mock before, B.
Question 1 of 20

Premium Access Includes

  • ✓Quiz Simulator
  • ✓Exam Mode
  • ✓Progress Tracking
  • ✓Question Saving
  • ✓Flash Cards
  • ✓Drag & Drops
  • ✓3 Months Access
  • ✓PDF Downloads
Get Premium Access
Scroll to Top

FLASH OFFER

Days
Hours
Minutes
Seconds

avail 10% DISCOUNT on YOUR PURCHASE