Home/microsoft/Free Microsoft Security SC-900 Actual Exam Questions

Free Microsoft Security SC-900 Actual Exam Questions

The questions for this exam were last updated on January 9, 2026

Dumps Box (DumpsBox) offers up-to-date practice exam questions for SC-900 certification exam which are developed and validated by Microsoft subject domain experts certified in Microsoft Security SC-900 . These practice questions are update regularly as we keep an eye on any recent changes in SC-900 syllabus, and when there is update our team quickly adjusts the questions. This commitment to providing the best quality exam prep material to certification aspirants is what makes DumpsBox.com the best certification exam prep website. On top of that, our strong, yet strictly moderated, community based feedback keeps the content clean and current. Each question has helpful community discussion that provides it extra perspective and introduces helpful resources for better exam preparation. This also saves students from other outdated practice questions or illicit exam dumps that can have adverse affects on career. Browse through our Microsoft Security SC-900 exam questions and pass your exam on first try.

Question No. 1

HOTSPOT Select the answer that correctly completes the sentence. SC-900 practice exam questions

Top comments
II
Imran I.
2026-01-18

I'd pick the option that fits with managing who can do what, probably about permissions rather than just roles. The sentence seems to need a word about controlling access rights.

0
JW
John W.
2026-01-17

From what I can make out, the sentence is about choosing the right term related to identity or access management. If the options are about user roles or permissions, I’d focus on the term that closely relates to controlling access based on attributes or responsibilities rather than just user identity. That usually points to something like “role-based access control” instead of just “authentication” or similar concepts. So, I’d rule out answers that are about verifying identity alone and pick the one that’s about managing access rights dynamically.

0
Question No. 2

HOTSPOT For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. SC-900 practice exam questions

Top comments
NI
Naveed I.
2026-01-19

Some statements clearly describe Azure AD features, so those get a Yes. Others mention endpoint detection, which only fits Defender, so No there. Mixing identity and endpoint tools can be tricky here.

0
KV
Kevin V.
2026-01-16

This looks like it’s about Microsoft's security solutions, not just Defender. Some options seem to mix endpoint protection with identity management features, so not every statement fits all products.

0
Question No. 3

HOTSPOT For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. SC-900 practice exam questions

Top comments
SX
Sohail X.
2026-02-20

I’m thinking A might be No because self-service password reset isn’t fully available in the free tier, right? So unless specified, it’s safer to say No here. B is definitely Yes for MFA as a default. For C, I’m also doubting it since not every app connects straight away with Azure AD without some setup. D has to be No because passwordless sign-in requires additional steps to activate, so it can’t be on by default.

0
FW
Farhan W.
2026-02-17

I’d say B is definitely Yes because MFA is a core security default now. For C, I’m skeptical since not every app integrates with Azure AD by default—usually some config’s needed.

0
Question No. 4

HOTSPOT For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. SC-900 practice exam questions

Top comments
AE
Andrew E.
2026-02-09

I think the first statement is a clear Yes since AES is pretty much standard now. For the second, it doesn’t really hold because less secure ciphers like RC4 have been deprecated, so No makes more sense there. The third one is tricky, but since modern TLS versions prefer GCM modes for performance and security, I’d say Yes fits better. The last definitely feels like a No because weaker MAC algorithms aren’t accepted anymore. So overall, I’d go Yes, No, Yes, No.

0
RU
Ryan U.
2026-01-29

The first statement looks solid since AES is widely supported, but I’m skeptical about the third one being Yes since GCM isn’t always mandatory. The last definitely feels off given current security standards.

0
Question No. 5

HOTSPOT For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. SC-900 practice exam questions

Top comments
IC
Irfan C.
2026-02-21

Statement 3 looks like it should be Yes since some roles can be assigned at both user and tenant scope, depending on the role type. That flexibility is key here.

0
IC
Irfan C.
2026-02-20

I think statement 1 should be No because global admin roles impact the entire directory, not just individual users. So it’s not really user scope like that.

0
Question No. 6

HOTSPOT For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. SC-900 practice exam questions

Top comments
EB
Ethan B.
2026-01-19

For the second statement about OAuth 2.0 being an authorization protocol, that’s definitely true—it’s designed for authorization, not authentication. Also, the third statement about SAML using XML makes sense; SAML is XML-based, so that should be Yes. The last statement about SAML being RESTful is false, since SAML relies on XML and SOAP, not REST. So overall, I’d say Yes for the first three and No for the last.

0
JO
James O.
2026-01-18

This one’s tricky since the statements are about identity providers and protocols. The first statement is definitely true - OpenID Connect is built on OAuth 2.0. The last one feels off because SAML isn’t based on REST, so that should be No. For the middle ones, I’d say “Yes” to standards being used by Azure AD for federation, but I’m less sure about WS-Federation’s current role since it’s kind of legacy. Would avoid marking everything as Yes straight away since some could be partial truths or outdated info. Also watch out for confusing OAuth and OpenID-it’s a common trap here.

0
Question No. 7

HOTSPOT Select the answer that correctly completes the sentence. SC-900 practice exam questions

Top comments
BA
Bilal A.
2026-02-21

I’m going with C as well. Conditional Access is definitely tied to Azure AD Premium, and C highlights that integration best. The others don’t really mention the core feature like this one does. Without tier specifics, it’s a bit of a guess, but C fits the general scenario for Conditional Access use.

0
BA
Bilal A.
2026-02-18

I’d pick C too, it’s the only one matching the conditional access feature here.

0
Question No. 8

HOTSPOT For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. SC-900 practice exam questions

Top comments
SZ
Sam Z.
2026-02-21

I’m thinking A is a No too because Zero Trust doesn’t trust users or devices just because they’re inside the network perimeter. For D, it feels like a Yes since continuous monitoring and validation is a must in Zero Trust to catch any suspicious activity early. C seems off since Zero Trust goes beyond just location or device risk, it’s about verifying every access request regardless. B definitely stands out as Yes since least privilege is all about limiting access, which is central to Zero Trust.

0
AU
Andre U.
2026-02-16

I’d say for A, it’s more of a No since Zero Trust assumes breach and never fully trusts any user or device by default. B should be Yes because least privilege access is a core principle in Zero Trust. For C, I’d go with Yes because location can be a factor but not the only one in conditional access. D definitely feels right as Yes since ongoing verification is key in Zero Trust. The framework is all about never assuming trust, so continuous checks are essential.

0
Question No. 9

HOTSPOT Select the answer that correctly completes the sentence. SC-900 practice exam questions

Top comments
AS
Arjun S.
2026-01-23

I went with D here. The question is about preventing privilege escalation, and D talks about assigning permissions based on the least privilege principle, which makes sense. B seems more about monitoring rather than prevention.

0
CG
Carlos G.
2026-01-15

B

0
Question No. 10

HOTSPOT Select the answer that correctly completes the sentence. SC-900 practice exam questions

Top comments
DD
David D.
2026-02-15

I agree B feels right here since it's about putting rules in place before access is allowed. The others seem off because they focus more on user verification or monitoring, not setting access requirements. It’s about controlling entry based on conditions, which is exactly what Conditional Access policies do.

0
DD
David D.
2026-02-14

I picked B as well since it directly relates to setting conditions that must be met before granting access, which fits the sentence about controlling access. The other options mostly cover authentication methods or monitoring, not enforcing conditional policies. So, B feels like the best match here because it’s about applying rules based on user, device, or location.

0
Question No. 11
What are three uses of Microsoft Cloud App Security? Each correct answer presents a complete
solution.
NOTE: Each correct selection is worth one point.
Select all that apply, then reveal solution.
Top comments
ZN
Zain N.
2026-02-20

Probably A, C, E—B and D deal more with infrastructure, not app security.

0
ZN
Zain N.
2026-02-18

A, C, E—B and D don’t fit the cloud app security profile at all.

0
Question No. 12
What can you use to provision Azure resources across multiple subscriptions in a consistent manner?
Select one option, then reveal solution.
Top comments
OX
Osama X.
2026-02-21

B. Azure Blueprints lets you set up environments repeatedly across subscriptions; it's designed for consistent initial provisioning, not continuous policy enforcement like D.

0
OX
Osama X.
2026-02-20

Makes sense to rule out A and C since they’re more security-focused; B fits provisioning best.

0
Question No. 13
Which two types of devices can be managed by using Endpoint data loss prevention (Endpoint DLP)?
Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
Select all that apply, then reveal solution.
Top comments
AE
Adeel E.
2026-02-16

It’s A and D, since Endpoint DLP primarily supports Windows and macOS devices.

0
SS
Sohail S.
2026-01-29

A and D definitely. Endpoint DLP is mainly focused on desktops, so Windows 11 and macOS are the solid picks. Linux and mobile OS support isn’t fully baked yet.

0
Question No. 14
To which three locations can a data loss prevention (DLP) policy be applied? Each correct answer
presents a complete solution.
NOTE: Each correct answer is worth one point.
Select all that apply, then reveal solution.
Top comments
SS
Sarah S.
2026-02-17

C imo, public folders are still part of Exchange Online, so they should be included for DLP policies alongside emails (A). Teams messages (D) might be partially supported, but I wouldn’t count on full coverage everywhere yet. Viva Engage (E) feels less likely since it’s more community/social than document or email storage. So I’d go with A, B, and C as the main solid choices here.

0
PL
Paul L.
2026-02-14

A/B/C? Exchange Online public folders seem like a standard DLP target alongside emails and OneDrive. Teams and Viva Engage might have more limited or evolving support.

0
Question No. 15
You need to keep a copy of all files in a Microsoft SharePoint site for one year, even if users delete the
files from the site. What should you apply to the site?
Select all that apply, then reveal solution.
Top comments
PC
Paul C.
2026-02-13

Makes sense to pick B since retention policies specifically handle preserving files after deletion, unlike the other options. Sticking with B here.

0
AX
Andre X.
2026-02-13

B, because DLP and sensitivity labels don’t preserve deleted files like retention policies do.

0