Free Practice Questions for Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900) Certification
Study with 348 exam-style practice questions designed to help you prepare for the Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900). All questions are aligned with the latest exam guide and include detailed explanations to help you master the material.
Exam experiencesNew
Pass and fail outcomes from candidates who prepared here — advice, scores, and prep time.
Start Practicing
All Domains
Practice with randomly mixed questions from all topics
Domain Mode
Practice questions from a specific topic area
Quiz History
Exam Details
Key information about Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
- Multiple choice
- Matching
- True/False
- Fill in the blank
Business stakeholders, new or existing IT professionals, students interested in Microsoft SCI solutions
Primarily General Availability (GA) features, with potential for commonly used Preview features
English version updated first, localized versions approximately eight weeks later
July 28, 2026
30 minutes can be requested if the exam is not available in your preferred language
Exam Topics & Skills Assessed
Skills measured (from the official study guide)
Domain 1: Describe the concepts of security, compliance, and identity
Subdomain 1.1: Describe security and compliance concepts
Describe the shared responsibility model Describe defense-in-depth Describe the Zero Trust model Describe encryption and hashing Describe Governance, Risk, and Compliance (GRC) concepts
Subdomain 1.2: Define identity concepts
Define identity as the primary security perimeter Define authentication Define authorization Describe identity providers Describe the concept of directory services and Active Directory Describe the concept of federation
Domain 2: Describe the capabilities of Microsoft Entra
Subdomain 2.1: Describe function and identity types of Microsoft Entra ID
Describe Microsoft Entra ID Describe types of identities, including agent ID Describe hybrid identity
Subdomain 2.2: Describe authentication capabilities of Microsoft Entra ID
Describe the authentication methods Describe multifactor authentication (MFA) Describe password protection and management capabilities
Subdomain 2.3: Describe access management capabilities of Microsoft Entra ID
Describe Microsoft Entra Conditional Access Describe Microsoft Entra roles and role-based access control (RBAC)
Subdomain 2.4: Describe identity protection and governance capabilities of Microsoft Entra
Describe Microsoft Entra ID Governance Describe access reviews Describe the capabilities of Microsoft Entra Privileged Identity Management Describe Microsoft Entra ID Protection
Domain 3: Describe the capabilities of Microsoft security solutions
Subdomain 3.1: Describe core infrastructure security services in Azure
Describe Azure DDoS Protection Describe Azure Firewall Describe Azure Web Application Firewall (WAF) Describe network segmentation with Azure virtual networks Describe network security groups (NSGs) Describe Azure Bastion Describe Azure Key Vault
Subdomain 3.2: Describe security management capabilities of Azure
Describe Microsoft Defender for Cloud Describe Cloud Security Posture Management (CSPM) Describe how security policies, standards, and recommendations improve the cloud security posture Describe enhanced security features provided by cloud workload protection
Subdomain 3.3: Describe capabilities of Microsoft Sentinel
Define the concepts of security information and event management (SIEM) and security orchestration automated response (SOAR) Describe threat detection and mitigation capabilities in Microsoft Sentinel
Subdomain 3.4: Describe threat protection with Microsoft Defender XDR
Describe Microsoft Defender XDR services Describe Microsoft Defender for Office 365 Describe Microsoft Defender for Endpoint Describe Microsoft Defender for Cloud Apps Describe Microsoft Defender for Identity Describe Microsoft Defender Vulnerability Management Describe Microsoft Defender Threat Intelligence (Defender TI) Describe the Microsoft Defender portal
Domain 4: Describe the capabilities of Microsoft compliance solutions
Subdomain 4.1: Describe Microsoft Service Trust Portal and privacy principles
Describe the Service Trust Portal offerings Describe the privacy principles of Microsoft
Subdomain 4.2: Describe compliance management capabilities of Microsoft Purview
Describe the Microsoft Purview portal Describe Compliance Manager Describe the uses and benefits of compliance score
Subdomain 4.3: Describe information protection, data lifecycle management, and data governance capabilities of Microsoft Purview
Describe the data classification capabilities Describe the benefits of Content explorer and Activity explorer Describe sensitivity labels and sensitivity label policies Describe data loss prevention (DLP) Describe records management Describe retention policies, retention labels, and retention label policies
Subdomain 4.4: Describe insider risk, eDiscovery, and audit capabilities in Microsoft Purview
Describe insider risk management Describe eDiscovery solutions in Microsoft Purview Describe audit solutions in Microsoft Purview
Techniques & products