Free sampler

Try 12 free Microsoft SC-900 practice questions

Real exam-style questions taken word for word from the Microsoft SC-900 study guide. Three are below, with the full answer explanation. Enter your email and the full 12-question PDF is yours.

Unlock the full sampler
Microsoft SC-900 cover
12 questions in the PDF Taken verbatim from the book One email, no spam, unsubscribe any time

Three questions to try right now

Work each one before you open the answer. These are the same style and depth as the Security, Compliance, and Identity Fundamentals (SC-900) exam expects.

Question 1. A WAF policy is deployed on Azure Application Gateway in detection mode. Security logs show SQL injection attempts against the checkout form, but the malicious requests are still reaching the application backend. What is the MOST likely cause?

  • A. The managed rule set does not cover SQL injection patterns.
  • B. The WAF is running in detection mode and logs threats without blocking them.
  • C. SQL injection requires a custom rule to detect; managed rules do not apply.
  • D. The WAF should be deployed on Azure Front Door instead of Application Gateway.
Show the answer

Answer: B. In detection mode, a WAF logs every request that matches a rule but does not block it. The application still receives the request. Detection mode is the correct starting configuration for initial tuning, but production environments should run in prevention mode, which blocks and logs matching requests and returns HTTP 403 to the client.

  • A: The OWASP managed rule set, which all Azure WAF policies include by default, explicitly covers SQL injection. It is one of the primary OWASP Top 10 categories the managed rule set addresses, so this explanation is factually wrong.

Question 2. An enterprise runs an on-premises AD DS environment and is migrating to Microsoft 365. The IT team learns that Microsoft Entra ID does not support organizational units (OUs) or group policy objects. Which statement BEST explains this difference?

  • A. Microsoft Entra ID is a newer version of AD DS and removed OUs to simplify the interface.
  • B. Microsoft Entra ID is a cloud identity service built on modern web protocols; it is not a cloud-hosted port of AD DS and therefore uses different organizational and policy models.
  • C. OUs and GPOs are deprecated features that Microsoft plans to remove from AD DS in future releases.
  • D. Microsoft Entra ID supports OUs and GPOs only for Azure Government cloud tenants.
Show the answer

Answer: B. Microsoft Entra ID is a cloud-native identity and access management service built on OAuth 2.0, OpenID Connect, and SAML. It was designed from the ground up for cloud and SaaS scenarios, not as a cloud-hosted replica of AD DS. AD DS uses a hierarchical structure of forests, domains, and OUs to organize objects and applies GPOs to manage configuration. Microsoft Entra ID uses a flat directory structure and applies access policy through Conditional Access, Microsoft Intune, and other cloud-native mechanisms. Understanding that these are architecturally different systems, not different versions of the same product, is a key SC-900 exam concept.

  • A: Microsoft Entra ID is not a newer version of AD DS. It is a separate product with a different architecture designed for different scenarios. Describing it as a "newer version" implies backward compatibility and evolutionary relationship that does not exist. The exam specifically tests this distinction.

Question 3. A compliance officer uses Microsoft Purview Compliance Manager and sees a score of 78%. She tells leadership this score means the company is legally compliant with GDPR. Which statement about her conclusion is MOST accurate?

  • A. Her conclusion is correct. A score above 75% indicates legal compliance under GDPR.
  • B. Her conclusion is incorrect. The compliance score reflects the percentage of recommended technical configurations completed, not a legal certification.
  • C. Her conclusion is correct because Compliance Manager is certified by the EU as a GDPR audit authority.
  • D. Her conclusion is incorrect, but only because the passing threshold for GDPR compliance in Compliance Manager is 100%.
Show the answer

Answer: B. Compliance Manager's score is a technical configuration signal: it measures how many Microsoft-recommended improvement actions for the selected framework have been implemented. A score of 100% does not mean the organization has passed a legal audit or holds a binding certification. Legal compliance with GDPR requires demonstrating adherence through an audit process, documentation of data flows, privacy impact assessments, and other activities that extend beyond portal configuration. The score is an operational posture indicator, not a legal verdict.

  • A: There is no exam or Microsoft-published threshold above which a Compliance Manager score translates to legal GDPR compliance. The score is not a legal compliance metric at any percentage. This answer misrepresents what the score represents.

Unlock the full 12-question sampler

All 12 come with the same written explanations the book uses, covering why the right answer is right. We email you the PDF, nothing else.

One email with the PDF. Unsubscribe any time.

What you get

The sampler is free. Here is exactly what lands in your inbox.

The 12-question PDF

Print it or work it on screen, then score yourself against the answer key.

Questions from the real book

Nothing is written for marketing. Every question is lifted from the study guide itself.

A one-time discount

A few days later we send one email with a code for the full study guide. That is the entire sequence.

Microsoft SC-900 cover

The full Microsoft SC-900 study guide

The complete guide covers the Security, Compliance, and Identity Fundamentals (SC-900) exam objective by objective in plain English, with the full practice question bank behind these samples.

From $20.99

See the study guide   All Microsoft guides