Question 1
Which of the following can sensitivity labels apply to a Microsoft Word document?
Correct Answer:
A watermark
Explanation:
Sensitivity labels in Microsoft 365 are used to classify and protect sensitive information within documents and emails. When applied to a Microsoft Word document, sensitivity labels can enforce specific protections and policies, such as applying watermarks to indicate the sensitivity level of the document. Applying a watermark is a visible indication that can inform users about the confidentiality of the document, helping to ensure that the content is treated appropriately. This is especially important for sensitive information, as it continuously reminds users of the document's classification, even when printed or shared. The other options, while they have their own security and usability functions, do not have the same direct link to sensitivity labeling. For instance, a password protects access to a document but does not indicate its sensitivity level. A digital signature verifies the authenticity and integrity of a document but is not related to its classification or how it should be handled based on its sensitivity. An index, while useful for navigation and organization within documents, does not impact the document's sensitivity or classification either. Thus, the most appropriate application of sensitivity labels in this context is through watermarks, enhancing document awareness regarding sensitivity levels.
Question 2
Which Microsoft 365 compliance feature allows for automatic encryption of content based on specific conditions?
Correct Answer:
Sensitivity labels
Explanation:
The feature that allows for automatic encryption of content based on specific conditions is sensitivity labels. Sensitivity labels are an integral part of the Microsoft 365 compliance framework, enabling organizations to classify, label, and protect their sensitive information. When defined policies are applied, these labels can trigger automatic encryption of documents and emails based on the labels assigned. For instance, if an organization wants to ensure that certain types of documents, such as those containing personally identifiable information (PII), are encrypted to meet compliance requirements, they can set up sensitivity labels that enforce encryption when those labels are applied to documents. This automatic approach helps streamline compliance with regulations such as GDPR or HIPAA. Other options, such as content search, retention policies, and eDiscovery, have different functions related to compliance and data governance. Content search is focused on searching for content across Microsoft 365, retention policies manage the lifecycle of data but do not provide encryption, and eDiscovery is used to identify and manage legal holds on data for legal investigations. These functions are crucial but do not specifically address the automatic encryption of content like sensitivity labels do.
Question 3
Can Network Security Groups (NSGs) deny outbound traffic to the internet?
Correct Answer:
Yes
Explanation:
Network Security Groups (NSGs) can indeed deny outbound traffic to the internet. NSGs are used in Azure to control inbound and outbound traffic to network interfaces, VMs, and subnets. They contain a list of rules that can explicitly allow or deny traffic based on specific conditions such as IP addresses, ports, and protocols. When a rule is configured to deny outbound traffic, it effectively blocks any connections that match the rule. This allows for very granular control over the traffic flow from your resources in the Azure environment. Organizations can use NSGs to enforce security policies, limit exposure to the internet, and protect resources from unauthorized access or data exfiltration. While NSGs can allow or deny traffic depending on how they are configured, they can clearly be set to deny specific outbound traffic to the internet, which is a key feature for maintaining secure network boundaries.
Question 4
In Azure Active Directory (Azure AD) Identity Protection, does a user risk represent the probability that a given identity or account is compromised?
Correct Answer:
Yes
Explanation:
A user risk in Azure Active Directory Identity Protection indeed represents the probability that a particular identity or account may be compromised. This concept is fundamental to identity management and security within Azure AD. User risk assessments are based on various signals, including sign-in behavior, the location of the sign-in, and other contextual factors that indicate whether an account might be at risk of unauthorized access. Azure AD uses machine learning and heuristics to analyze this data, generating a risk level that helps security administrators identify potentially compromised accounts and take appropriate actions, such as requiring password resets or multifactor authentication. Recognizing user risk is critical for implementing proactive security measures, enabling organizations to respond effectively to potential breaches and mitigate risks associated with compromised accounts. By assessing risks, organizations can better protect sensitive information and maintain compliance with security policies and regulations.
Question 5
To which type of resource can Azure Bastion provide secure access?
Correct Answer:
Azure virtual machines
Explanation:
Azure Bastion is a service within Microsoft Azure that provides secure and seamless RDP (Remote Desktop Protocol) and SSH (Secure Shell) access to virtual machines directly through the Azure portal. This eliminates the need for a public IP address on the virtual machines, thus enhancing security by preventing exposure to the internet. When using Azure Bastion, users can connect to their Azure virtual machines without having to manage jump boxes or other intermediate solutions, thus simplifying the architecture for remote access. This secure, fully managed service integrates directly with Azure, allowing users to connect to their VMs using a web browser, which further emphasizes accessibility and ease of use. Understanding how Azure Bastion works in relation to other Azure resources is important. Azure Files, Azure SQL Managed Instances, and Azure App Service have their own distinct access and management methods, such as direct file sharing, Azure Data Studio, or app service environments, which do not require the same secure connectivity provided by Azure Bastion. Therefore, the primary functionality of Azure Bastion is specifically tailored to Azure virtual machines, making them the correct choice for secure access via this service.
Question 1
Exam overview

About this Exam

Prepare with the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) Practice Exam practice quiz. This question bank includes 10 questions covering azure, access, microsoft, network, and security. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

Microsoft Security, Compliance, and Identity Fundamentals (SC-900) Practice Exam

This practice set contains 10 questions from the matching question bank and focuses on azure, access, microsoft, network, and security. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions