CertSafari

    Free Practice Questions for Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900) Certification

    🔄 Last checked for updates September 5th, 2026

    Study with 348 exam-style practice questions designed to help you prepare for the Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900). All questions are aligned with the latest exam guide and include detailed explanations to help you master the material.

    Exam experiencesNew

    Pass and fail outcomes from candidates who prepared here — advice, scores, and prep time.

    View exam experiences

    Start Practicing

    All Domains

    Practice with randomly mixed questions from all topics

    Question MixAll Topics
    FormatRandom Order

    Domain Mode

    Practice questions from a specific topic area

    Quiz History

    Exam Details

    Key information about Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)

    Official study guide

    View

    Question formats CertSafari offers
    • Multiple choice
    • Matching
    • True/False
    • Fill in the blank
    target audience:

    Business stakeholders, new or existing IT professionals, students interested in Microsoft SCI solutions

    exam content focus:

    Primarily General Availability (GA) features, with potential for commonly used Preview features

    language update note:

    English version updated first, localized versions approximately eight weeks later

    skills measured as of:

    July 28, 2026

    additional time for non preferred language:

    30 minutes can be requested if the exam is not available in your preferred language

    Exam Topics & Skills Assessed

    Skills measured (from the official study guide)

    Domain 1: Describe the concepts of security, compliance, and identity

    Subdomain 1.1: Describe security and compliance concepts

    Describe the shared responsibility model Describe defense-in-depth Describe the Zero Trust model Describe encryption and hashing Describe Governance, Risk, and Compliance (GRC) concepts

    Subdomain 1.2: Define identity concepts

    Define identity as the primary security perimeter Define authentication Define authorization Describe identity providers Describe the concept of directory services and Active Directory Describe the concept of federation

    Domain 2: Describe the capabilities of Microsoft Entra

    Subdomain 2.1: Describe function and identity types of Microsoft Entra ID

    Describe Microsoft Entra ID Describe types of identities, including agent ID Describe hybrid identity

    Subdomain 2.2: Describe authentication capabilities of Microsoft Entra ID

    Describe the authentication methods Describe multifactor authentication (MFA) Describe password protection and management capabilities

    Subdomain 2.3: Describe access management capabilities of Microsoft Entra ID

    Describe Microsoft Entra Conditional Access Describe Microsoft Entra roles and role-based access control (RBAC)

    Subdomain 2.4: Describe identity protection and governance capabilities of Microsoft Entra

    Describe Microsoft Entra ID Governance Describe access reviews Describe the capabilities of Microsoft Entra Privileged Identity Management Describe Microsoft Entra ID Protection

    Domain 3: Describe the capabilities of Microsoft security solutions

    Subdomain 3.1: Describe core infrastructure security services in Azure

    Describe Azure DDoS Protection Describe Azure Firewall Describe Azure Web Application Firewall (WAF) Describe network segmentation with Azure virtual networks Describe network security groups (NSGs) Describe Azure Bastion Describe Azure Key Vault

    Subdomain 3.2: Describe security management capabilities of Azure

    Describe Microsoft Defender for Cloud Describe Cloud Security Posture Management (CSPM) Describe how security policies, standards, and recommendations improve the cloud security posture Describe enhanced security features provided by cloud workload protection

    Subdomain 3.3: Describe capabilities of Microsoft Sentinel

    Define the concepts of security information and event management (SIEM) and security orchestration automated response (SOAR) Describe threat detection and mitigation capabilities in Microsoft Sentinel

    Subdomain 3.4: Describe threat protection with Microsoft Defender XDR

    Describe Microsoft Defender XDR services Describe Microsoft Defender for Office 365 Describe Microsoft Defender for Endpoint Describe Microsoft Defender for Cloud Apps Describe Microsoft Defender for Identity Describe Microsoft Defender Vulnerability Management Describe Microsoft Defender Threat Intelligence (Defender TI) Describe the Microsoft Defender portal

    Domain 4: Describe the capabilities of Microsoft compliance solutions

    Subdomain 4.1: Describe Microsoft Service Trust Portal and privacy principles

    Describe the Service Trust Portal offerings Describe the privacy principles of Microsoft

    Subdomain 4.2: Describe compliance management capabilities of Microsoft Purview

    Describe the Microsoft Purview portal Describe Compliance Manager Describe the uses and benefits of compliance score

    Subdomain 4.3: Describe information protection, data lifecycle management, and data governance capabilities of Microsoft Purview

    Describe the data classification capabilities Describe the benefits of Content explorer and Activity explorer Describe sensitivity labels and sensitivity label policies Describe data loss prevention (DLP) Describe records management Describe retention policies, retention labels, and retention label policies

    Subdomain 4.4: Describe insider risk, eDiscovery, and audit capabilities in Microsoft Purview

    Describe insider risk management Describe eDiscovery solutions in Microsoft Purview Describe audit solutions in Microsoft Purview

    Techniques & products

    Shared responsibility model
    Defense-in-depth
    Zero Trust model
    Encryption
    Hashing
    Governance, Risk, and Compliance (GRC)
    Identity as primary security perimeter
    Authentication
    Authorization
    Identity providers
    Directory services
    Active Directory
    Federation
    Microsoft Entra ID
    Agent ID
    Hybrid identity
    Authentication methods
    Multifactor authentication (MFA)
    Password protection
    Password management
    Microsoft Entra Conditional Access
    Microsoft Entra roles
    Role-based access control (RBAC)
    Microsoft Entra ID Governance
    Access reviews
    Microsoft Entra Privileged Identity Management
    Microsoft Entra ID Protection
    Azure DDoS Protection
    Azure Firewall
    Azure Web Application Firewall (WAF)
    Network segmentation
    Azure virtual networks
    Network security groups (NSGs)
    Azure Bastion
    Azure Key Vault
    Microsoft Defender for Cloud
    Cloud Security Posture Management (CSPM)
    Security policies
    Security standards
    Security recommendations
    Cloud security posture
    Cloud workload protection
    Security information and event management (SIEM)
    Security orchestration automated response (SOAR)
    Threat detection
    Threat mitigation
    Microsoft Sentinel
    Microsoft Defender XDR services
    Microsoft Defender for Office 365
    Microsoft Defender for Endpoint
    Microsoft Defender for Cloud Apps
    Microsoft Defender for Identity
    Microsoft Defender Vulnerability Management
    Microsoft Defender Threat Intelligence (Defender TI)
    Microsoft Defender portal
    Microsoft Service Trust Portal
    Privacy principles of Microsoft
    Microsoft Purview portal
    Compliance Manager
    Compliance score
    Data classification
    Content explorer
    Activity explorer
    Sensitivity labels
    Sensitivity label policies
    Data loss prevention (DLP)
    Records management
    Retention policies
    Retention labels
    Retention label policies
    Insider risk management
    eDiscovery solutions in Microsoft Purview
    Audit solutions in Microsoft Purview

    CertSafari is not affiliated with, endorsed by, or officially connected to Microsoft Corporation. Full disclaimer