- 215 Actual Exam Questions
- Compatible with all Devices
- Printable Format
- No Download Limits
- 90 Days Free Updates
Get All Microsoft Security, Compliance, and Identity Fundamentals Exam Questions with Validated Answers
| Vendor: | Microsoft |
|---|---|
| Exam Code: | SC-900 |
| Exam Name: | Microsoft Security, Compliance, and Identity Fundamentals |
| Exam Questions: | 215 |
| Last Updated: | May 27, 2026 |
| Related Certifications: | Microsoft Azure |
| Exam Tags: | Beginner Microsoft IT Security and Compliance Professionals |
Looking for a hassle-free way to pass the Microsoft Security, Compliance, and Identity Fundamentals exam? DumpsProvider provides the most reliable Dumps Questions and Answers, designed by Microsoft certified experts to help you succeed in record time. Available in both PDF and Online Practice Test formats, our study materials cover every major exam topic, making it possible for you to pass potentially within just one day!
DumpsProvider is a leading provider of high-quality exam dumps, trusted by professionals worldwide. Our Microsoft SC-900 exam questions give you the knowledge and confidence needed to succeed on the first attempt.
Train with our Microsoft SC-900 exam practice tests, which simulate the actual exam environment. This real-test experience helps you get familiar with the format and timing of the exam, ensuring you're 100% prepared for exam day.
Your success is our commitment! That's why DumpsProvider offers a 100% money-back guarantee. If you don’t pass the Microsoft SC-900 exam, we’ll refund your payment within 24 hours no questions asked.
Don’t waste time with unreliable exam prep resources. Get started with DumpsProvider’s Microsoft SC-900 exam dumps today and achieve your certification effortlessly!
What can you use to ensure that all the users in a specific group must use multi-factor authentication (MFA) to sign in to Azure AD?
According to Microsoft's Security, Compliance, and Identity (SCI) documentation and learning paths (specifically SC-900, SC-300, and Azure AD Identity Protection modules):
''Conditional Access policies in Azure AD are the primary method for enforcing access controls based on specific conditions such as user, group, location, device compliance, and application.''
In this case, the organization can configure a Conditional Access policy that targets a specific Azure AD group and requires MFA as a condition before access is granted. The typical policy setup includes:
Assignments: Target users or groups (e.g., ''Finance Department Users'').
Cloud apps or actions: Specify which applications or services are protected (e.g., Microsoft 365).
Access controls: Set the control to ''Require multi-factor authentication.''
Microsoft's SCI training materials further state:
''Conditional Access enables administrators to enforce MFA for specific users, groups, or scenarios. It provides flexibility to protect access without enabling MFA globally for all users.''
Other options explained:
Azure Policy (A) applies to Azure resources, not user authentication.
Communication compliance policy (B) monitors message content for compliance violations.
User risk policy (D) is part of Azure AD Identity Protection, enforcing MFA based on detected user risk levels, not group membership.
Therefore, the verified and correct answer is: C. a Conditional Access policy.
Which three authentication methods can Microsoft Entra users use to reset their password? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
Microsoft Entra self-service password reset (SSPR) supports multiple verification methods that users can register and use to prove their identity during a reset. Microsoft's documentation lists the SSPR methods as: ''Mobile app notification,'' ''Mobile app code,'' ''Email,'' ''Mobile phone (text message or call),'' ''Office phone,'' and ''Security questions.'' Administrators choose which of these are allowed and how many methods are required. During the reset flow, SSPR ''prompts the user to verify with the registered methods'' before permitting a password change. Notably, certificates and picture passwords are not SSPR verification methods in Microsoft Entra ID. Therefore, among the options provided: a text message to a phone (mobile phone), a mobile app notification (Microsoft Authenticator), and security questions are valid SSPR authentication methods; certificate and picture password are not supported for SSPR. This aligns with SCI learning content that positions SSPR as a user-empowering capability to securely restore access using admin-approved methods without help-desk intervention.
Which compliance feature should you use to identify documents that are employee resumes?
In Microsoft Purview Information Protection, pre-trained (Microsoft-provided) trainable classifiers are designed to automatically recognize specific categories of content by learning from examples rather than relying only on patterns or keywords. Microsoft's guidance explains that trainable classifiers ''look for data by learning from examples,'' and that Microsoft supplies a catalog of ''pre-trained classifiers that you can use immediately in your tenant.'' The documentation explicitly lists content types these classifiers can recognize, including ''Resumes,'' along with other categories such as Source code, Threat and harassment, and more. Because they're already trained by Microsoft, you can use them ''to identify and classify items across SharePoint, OneDrive, and Exchange,'' and then take actions such as auto-labeling or enforcing DLP policies based on the classifier match.
By contrast, Content explorer is a reporting tool that lets you view where sensitive info types/labels were found; it doesn't identify resumes on its own. Activity explorer shows events like DLP policy matches over time. eDiscovery is used for legal hold, search, and review, not for semantic content identification. Therefore, to identify documents that are employee resumes, the correct Microsoft compliance feature is the pre-trained (Microsoft-provided) trainable classifier for Resumes.
Which Microsoft 365 compliance center feature can you use to identify all the documents on a Microsoft SharePoint Online site that contain a specific key word?
The Content Search tool in the Security & Compliance Center can be used to quickly find email in Exchange mailboxes, documents in SharePoint sites and OneDrive locations, and instant messaging conversations in Skype for Business.
The first step is to starting using the Content Search tool to choose content locations to search and configure a keyword query to search for specific items.
https://docs.microsoft.com/en-us/microsoft-365/compliance/search-for-content?view=o365-worldwide
What is an assessment in Compliance Manager?
Microsoft Purview Compliance Manager is a feature in the Microsoft Purview compliance portal that helps you manage your organization's compliance requirements with greater ease and convenience. Compliance Manager can help you throughout your compliance journey, from taking inventory of your data protection risks to managing the complexities of implementing controls, staying current with regulations and certifications, and reporting to auditors.
Watch the video below to learn how Compliance Manager can help simplify how your organization manages compliance:
Compliance Manager helps simplify compliance and reduce risk by providing:
Pre-built assessments for common industry and regional standards and regulations, or custom assessments to meet your unique compliance needs (available assessments depend on your licensing agreement; learn more).
Workflow capabilities to help you efficiently complete your risk assessments through a single tool.
Detailed step-by-step guidance on suggested improvement actions to help you comply with the standards and regulations that are most relevant for your organization. For actions that are managed by Microsoft, you'll see implementation details and audit results.
A risk-based compliance score to help you understand your compliance posture by measuring your progress in completing improvement actions.
Security & Privacy
Satisfied Customers
Committed Service
Money Back Guranteed