ExamGecko
Home Home / Microsoft / SC-900

Microsoft SC-900 Practice Test - Questions Answers, Page 4

Question list
Search
Search

List of questions

Search

HOTSPOT

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.


Question 31
Correct answer: Question 31

Explanation:

Box 1: Yes

The MailItemsAccessed event is a mailbox auditing action and is triggered when mail data is accessed by mail protocols and mail clients.

Box 2: No

Basic Audit retains audit records for 90 days.

Advanced Audit retains all Exchange, SharePoint, and Azure Active Directory audit records for one year. This is accomplished by a default audit log retention policy that retains any audit record that contains the value of Exchange, SharePoint, or AzureActiveDirectory for the Workload property (which indicates the service in which the activity occurred) for one year.

Box 3: yes

Advanced Audit in Microsoft 365 provides high-bandwidth access to the Office 365 Management Activity API.

Reference:

https://docs.microsoft.com/en-us/microsoft-365/compliance/advanced-audit?view=o365-worldwide

https://docs.microsoft.com/en-us/microsoft-365/compliance/auditing-solutions-overview?view=o365-worldwide#licensing-requirements

https://docs.microsoft.com/en-us/office365/servicedescriptions/microsoft-365-service-descriptions/microsoft-365-tenantlevel-services-licensing-guidance/microsoft-365-security-compliance-licensing-guidance#advanced-audit

HOTSPOT

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.


Question 32
Correct answer: Question 32

Explanation:

Box 1: No

Box 2: Yes

Leaked Credentials indicates that the user's valid credentials have been leaked.

Box 3: Yes

Multi-Factor Authentication can be required based on conditions, one of which is user risk.

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/overview-identity-protection

https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-risks

https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-risk-based-sspr-mfa

Which score measures an organization's progress in completing actions that help reduce risks associated to data protection and regulatory standards?

A.

Microsoft Secure Score

A.

Microsoft Secure Score

Answers
B.

Productivity Score

B.

Productivity Score

Answers
C.

Secure score in Azure Security Center

C.

Secure score in Azure Security Center

Answers
D.

Compliance score

D.

Compliance score

Answers
Suggested answer: D

Explanation:

Reference:

https://docs.microsoft.com/en-us/microsoft-365/compliance/compliance-manager?view=o365-worldwide

https://docs.microsoft.com/en-us/microsoft-365/compliance/compliance-score-calculation?view=o365-worldwide

What do you use to provide real-time integration between Azure Sentinel and another security source?

A.

Azure AD Connect

A.

Azure AD Connect

Answers
B.

a Log Analytics workspace

B.

a Log Analytics workspace

Answers
C.

Azure Information Protection

C.

Azure Information Protection

Answers
D.

a data connector

D.

a data connector

Answers
Suggested answer: D

Explanation:

To on-board Azure Sentinel, you first need to connect to your security sources. Azure Sentinel comes with a number of connectors for Microsoft solutions, including Microsoft 365 Defender solutions, and Microsoft 365 sources, including Office 365, Azure AD, Microsoft Defender for Identity, and Microsoft Cloud App Security, etc.

Reference:

https://docs.microsoft.com/en-us/azure/sentinel/overview

Which Microsoft portal provides information about how Microsoft cloud services comply with regulatory standard, such as International Organization for Standardization (ISO)?

A.

the Microsoft Endpoint Manager admin center

A.

the Microsoft Endpoint Manager admin center

Answers
B.

Azure Cost Management + Billing

B.

Azure Cost Management + Billing

Answers
C.

Microsoft Service Trust Portal

C.

Microsoft Service Trust Portal

Answers
D.

the Azure Active Directory admin center

D.

the Azure Active Directory admin center

Answers
Suggested answer: C

Explanation:

The Microsoft Service Trust Portal contains details about Microsoft's implementation of controls and processes that protect our cloud services and the customer data therein.

Reference:

https://docs.microsoft.com/en-us/microsoft-365/compliance/get-started-with-service-trust-portal?view=o365-worldwide

In the shared responsibility model for an Azure deployment, what is Microsoft solely responsible for managing?

A.

the management of mobile devices

A.

the management of mobile devices

Answers
B.

the permissions for the user data stored in Azure

B.

the permissions for the user data stored in Azure

Answers
C.

the creation and management of user accounts

C.

the creation and management of user accounts

Answers
D.

the management of the physical hardware

D.

the management of the physical hardware

Answers
Suggested answer: D

What can you use to provide a user with a two-hour window to complete an administrative task in Azure?

A.

Azure Active Directory (Azure AD) Privileged Identity Management (PIM)

A.

Azure Active Directory (Azure AD) Privileged Identity Management (PIM)

Answers
B.

Azure Multi-Factor Authentication (MFA)

B.

Azure Multi-Factor Authentication (MFA)

Answers
C.

Azure Active Directory (Azure AD) Identity Protection

C.

Azure Active Directory (Azure AD) Identity Protection

Answers
D.

conditional access policies

D.

conditional access policies

Answers
Suggested answer: D

In a hybrid identity model, what can you use to sync identities between Active Directory Domain Services (AD DS) and Azure Active Directory (Azure AD)?

A.

Active Directory Federation Services (AD FS)

A.

Active Directory Federation Services (AD FS)

Answers
B.

Azure Sentinel

B.

Azure Sentinel

Answers
C.

Azure AD Connect

C.

Azure AD Connect

Answers
D.

Azure Ad Privileged Identity Management (PIM)

D.

Azure Ad Privileged Identity Management (PIM)

Answers
Suggested answer: C

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/whatis-azure-ad-connect

What is the purpose of Azure Active Directory (Azure AD) Password Protection?

A.

to control how often users must change their passwords

A.

to control how often users must change their passwords

Answers
B.

to identify devices to which users can sign in without using multi-factor authentication (MFA)

B.

to identify devices to which users can sign in without using multi-factor authentication (MFA)

Answers
C.

to encrypt a password by using globally recognized encryption standards

C.

to encrypt a password by using globally recognized encryption standards

Answers
D.

to prevent users from using specific words in their passwords

D.

to prevent users from using specific words in their passwords

Answers
Suggested answer: D

Explanation:

Azure AD Password Protection detects and blocks known weak passwords and their variants, and can also block additional weak terms that are specific to your organization.

With Azure AD Password Protection, default global banned password lists are automatically applied to all users in an Azure AD tenant. To support your own business and security needs, you can define entries in a custom banned password list.

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-password-ban-bad-on-premises

Which Azure Active Directory (Azure AD) feature can you use to evaluate group membership and automatically remove users that no longer require membership in a group?

A.

access reviews

A.

access reviews

Answers
B.

managed identities

B.

managed identities

Answers
C.

conditional access policies

C.

conditional access policies

Answers
D.

Azure AD Identity Protection

D.

Azure AD Identity Protection

Answers
Suggested answer: A

Explanation:

Azure Active Directory (Azure AD) access reviews enable organizations to efficiently manage group memberships, access to enterprise applications, and role assignments.

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/governance/access-reviews-overview

Total 199 questions
Go to page: of 20