WorksheetsSC-900 (81-167)
Total questions: 77
Worksheet time: 40mins
alerts
events
vulnerabilities
Microsoft Secure Score improvement actions
82. You need to connect to an Azure virtual machine by using Azure Bastion. What should you use?
A. PowerShell remoting
B. the Azure portal
C. the Remote Desktop Connection client
D. an SSH client
83. Which service includes the Attack simulation training feature?
A. Microsoft Defender for Cloud Apps
B. Microsoft Defender for Identity
C. Microsoft Defender for SQL
D. Microsoft Defender for Office 365
84. Which type of alert can you manage from the Microsoft 365 Defender portal?
A. Microsoft Defender for Storage
B. Microsoft Defender for SQL
C. Microsoft Defender for Endpoint
D. Microsoft Defender for loT
xxx
86. Which two Azure resources can a network security group (NSG) be associated with? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
A. a virtual network subnet
B. a network interface
C. a resource group
D. a virtual network
E. an Azure App Service web app
87. What is a use case for implementing information barrier policies in Microsoft 365?
A. to restrict unauthenticated access to Microsoft 365
B. to restrict Microsoft Teams chats between certain groups within an organization
C. to restrict Microsoft Exchange Online email between certain groups within an organization
D. to restrict data sharing to external email recipients
88. What can you use to deploy Azure resources across multiple subscriptions in a consistent manner?
A. Microsoft Defender for Cloud
B. Azure Blueprints
C. Microsoft Sentinel
D. Azure Policy
xxx
xxx
91. Which Microsoft 365 compliance center feature can you use to identify all the documents on a Microsoft SharePoint Online site that contain a specific key word?
A. Audit
B. Compliance Manager
C. Content Search
D. Alerts
Azure Defender
The Microsoft 365 compliance center
The Microsoft Defender portal
Microsoft Endpoint Manager
93. Which Microsoft 365 feature can you use to restrict users from sending email messages that contain lists of customers and their associated credit card numbers?
A. retention policies
B. data loss prevention (DLP) policies
C. conditional access policies
D. information barriers
Customer Lockbox
Information barriers
Privileged Access Management (PAM)
Sensitivity labels
95. In a Core eDiscovery workflow, what should you do before you can search for content?
A. Create an eDiscovery hold.
B. Run Express Analysis.
C. Configure attorney-client privilege detection.
D. Export and download results.
96. Which Microsoft portal provides information about how Microsoft manages privacy, compliance, and security?
A. Microsoft Service Trust Portal
B. Compliance Manager
C. Microsoft 365 compliance center
D. Microsoft Support
97. What can you protect by using the information protection solution in the Microsoft 365 compliance center?
A. computers from zero-day exploits
B. users from phishing attempts
C. files from malware and viruses
D. sensitive data from being exposed to unauthorized users
98. What can you specify in Microsoft 365 sensitivity labels?
A. how long files must be preserved
B. when to archive an email message
C. which watermark to add to files
D. where to store files
xxx
xxx
xxx
102. Which two tasks can you implement by using data loss prevention (DLP) policies in Microsoft 365? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
A. Display policy tips to users who are about to violate your organization's policies.
B. Enable disk encryption on endpoints.
C. Protect documents in Microsoft OneDrive that contain sensitive information.
D. Apply security baselines to devices.
continually
manthly
on-demand
quarterly
xxx
105. Which Microsoft 365 compliance feature can you use to encrypt content automatically based on specific conditions?
A. Content Search
B. sensitivity labels
C. retention policies
D. eDiscovery
xxx
xxx
xxx
xxx
110. Which two cards are available in the Microsoft 365 Defender portal? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
A. Devices at risk
B. Compliance Score
C. Service Health
D. User Management
E. Users at risk
111. What should you use to ensure that the members of an Azure Active Directory group use multi-factor authentication (MFA) when they sign in?
A. Azure role-based access control (Azure RBAC)
B. Azure Active Directory (Azure AD) Privileged Identity Management (PIM)
C. Azure Active Directory (Azure AD) Identity Protection
D. a conditional access policy
xxx
113. You need to keep a copy of all files in a Microsoft SharePoint site for one year, even if users delete the files from the site. What should you apply to the site?
A. a retention policy
B. an insider risk policy
C. a data loss prevention (DLP) policy
D. a sensitivity label policy
114. You need to create a data loss prevention (DLP) policy. What should you use?
A. the Microsoft 365 Compliance center
B. the Microsoft Endpoint Manager admin center
C. the Microsoft 365 admin center
D. the Microsoft 365 Defender portal
115. What is an assessment in Compliance Manager?
A. A policy initiative that includes multiple policies.
B. A dictionary of words that are not allowed in company documents.
C. A grouping of controls from a specific regulation, standard or policy.
D. Recommended guidance to help organizations align with their corporate standards.
116. What can you use to view the Microsoft Secure Score for Devices?
A. Microsoft Defender for Cloud Apps
B. Microsoft Defender for Endpoint
C. Microsoft Defender for Identity
D. Microsoft Defender for Office 365
xxx
xxx
administration
auditing
authentication
authorization
120. What are customers responsible for when evaluating security in a software as a service (SaaS) cloud services model?
A. operating systems
B. network controls
C. applications
D. accounts and identities
A domain controller
Active Directory Domain Services (AD DS)
Azure Active Directory (Azure AD) Privilege Identity Management (PIM)
Federation
the cloud
a firewall
identity
Microsoft Defender for Cloud
123. What does Conditional Access evaluate by using Azure Active Directory (Azure AD) Identity Protection?
A. user actions
B. group membership
C. device compliance
D. user risk
124. Which statement represents a Microsoft privacy principle?
A. Microsoft manages privacy settings for its customers.
B. Microsoft respects the local privacy laws that are applicable to its customers.
C. Microsoft uses hosted customer email and chat data for targeted advertising.
D. Microsoft does not collect any customer data.
A security information and event management (SIEM)
A security orchestration automated response (SOAR)
A Trusted Automated eXchange of Indicator Information (TAXII)
An attack surface reduction (ASR)
analytic rules
hunting queries
playbooks
workbooks
127. Which compliance feature should you use to identify documents that are employee resumes?
A. pre-trained classifiers
B. Activity explorer
C. eDiscovery
D. Content explorer
xxx
xxx
130. Which pillar of identity relates to tracking the resources accessed by a user?
A. authorization
B. auditing
C. administration
D. authentication
131. What can be created in Active Directory Domain Services (AD DS)?
A. line-of-business (LOB) applications that require modern authentication
B. computer accounts
C. software as a service (SaaS) applications that require modern authentication
D. mobile devices
administration
auditing
authentication
authorization
xxx
134. What is a function of Conditional Access session controls?
A. enforcing device compliance
B. enforcing client app compliance
C. enable limited experiences, such as blocking download of sensitive information
D. prompting multi-factor authentication (MFA)
xxx
136. What can you use to ensure that all the users in a specific group must use multi-factor authentication (MFA) to sign to Azure Active Directory (Azure AD)?
A. Azure Policy
B. a communication compliance policy
C. a Conditional Access policy
D. a user risk policy
xxx
138. Which three authentication methods can Azure AD users use to reset their password? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
A. mobile app notification
B. text message to a phone
C. security questions
D. certificate
E. picture password
xxx
xxx
141. Which security feature is available in the free mode of Microsoft Defender for Cloud?
A. threat protection alerts
B. just-in-time (JIT) VM access to Azure virtual machines
C. vulnerability scanning of virtual machines
D. secure score
142. Microsoft 365 Endpoint data loss prevention (Endpoint DLP) can be used on which operating systems?
A. Windows 10 and newer only
B. Windows 10 and newer and Android only
C. Windows 10 and newer and iOS only
D. Windows 10 and newer, Android, and i0S
xxx
Azure Active Directory (Azure AD) Password Protection
Azure Bastion
Azure Information Protection (AIP)
Azure Key Vault
Microsoft Defender for Cloud
Azure Monitor
Azure Security Benchmark
Microsoft Secure Score
146. What is the maximum number of resources that Azure DDoS Protection Standard can protect without additional costs?
A. 50
B. 100
C. 500
D. 1000
147. What are two reasons to deploy multiple virtual networks instead of using just one virtual network? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
A. to meet governance policies
B. to connect multiple types of resources
C. to separate the resources for budgeting
D. to isolate the resources
Azure Logic Apps.
Azure Monitor workbook templates.
Azure Resource Graph Explorer.
playbooks.
149. You have an Azure subscription that contains multiple resources. You need to assess compliance and enforce standards for the existing resources. What should you use?
A. Azure Blueprints
B. the Anomaly Detector service
C. Microsoft Sentinel
D. Azure Policy
150. Which Microsoft Defender for Cloud metric displays the overall security health of an Azure subscription?
A. secure score
B. resource health
C. completed controls
D. the status of recommendations
xxxx
Microsoft 365 admin center.
Microsoft 365 compliance center.
Microsoft 365 Defender portal.
Microsoft Defender for Cloud Apps portal.
153. You need to ensure repeatability when creating new resources in an Azure subscription. What should you use?
A. Microsoft Sentinel
B. Azure Policy
C. Azure Batch
D. Azure Blueprints
154. What is a characteristic of a sensitivity label in Microsoft 365?
A. encrypted
B. restricted to predefined categories
C. persistent
xxx
Compliance score
Microsoft Purview compliance portal reports
The Trust Center
Trust Documents
xxx
