Free Microsoft SC-900 (Security, Compliance, and Identity) practice test

Microsoft SC-900 (Security, Compliance, and Identity Fundamentals) proves you can describe core security and compliance concepts and the capabilities of Microsoft Entra, Microsoft security solutions, and Microsoft compliance solutions. This site gives you 259 original questions plus 8 drag-and-drop and matching items in Microsoft's own interactive formats, free and without an account.

The simulator runs 45 timed minutes on the real scale (pass line 700 of 1,000), grades interactive items all-or-nothing the way Microsoft does, and links every topic to the matching chapter of John Savill's free SC-900 study video.

What SC-900 covers

SC-900 domainExam weightQuestions here
Describe security, compliance, and identity concepts13%about 34
Describe the capabilities of Microsoft Entra27%about 71
Describe the capabilities of Microsoft security solutions37%about 96
Describe the capabilities of Microsoft compliance solutions23%about 59

Real exam facts: typically 40-60 questions, about 45 minutes, scaled to 1,000 with a 700 pass line. The certification never expires.

Practice questions from this bank

Sample question 1 · SC-900 · Describe security, compliance, and identity concepts

A company adopts a SaaS email service. Under the cloud shared responsibility model, which task remains the customer's responsibility?

  1. ASecuring the network switches and routers
  2. BManaging user accounts and access permissions
  3. CPatching the underlying server operating system
  4. DMaintaining the physical datacenter hardware
Show answer and explanation

B. Managing user accounts and access permissions

In SaaS the provider handles the operating system, hardware, and network, while the customer always keeps responsibility for accounts, identities, and data. Patching the host operating system belongs to the provider, not the customer.

Topic: SC-900 Study Cram V2: Shared responsibility

Sample question 2 · SC-900 · Describe the capabilities of Microsoft Entra

A company wants a cloud service that manages user sign-in and controls access to Microsoft 365 and other SaaS apps. Which Microsoft offering fills this role?

  1. AMicrosoft Defender for Cloud
  2. BMicrosoft Purview
  3. CMicrosoft Entra ID
  4. DMicrosoft Intune
Show answer and explanation

C. Microsoft Entra ID

Microsoft Entra ID is the cloud identity and access management service that authenticates users and governs access to apps. Intune manages devices rather than identities.

Topic: SC-900 Study Cram V2: Microsoft Entra ID

Sample question 3 · SC-900 · Describe the capabilities of Microsoft security solutions

A public-facing web service is being overwhelmed by a flood of traffic from thousands of sources trying to exhaust its bandwidth. Which Azure service is designed to absorb and mitigate this kind of attack?

  1. AAzure Key Vault
  2. BAzure DDoS Protection
  3. CAzure Bastion
  4. DAzure Policy
Show answer and explanation

B. Azure DDoS Protection

Azure DDoS Protection detects and mitigates volumetric denial-of-service attacks aimed at public IP resources. Azure Key Vault stores secrets and does not filter network floods.

Topic: SC-900 Study Cram V2: Azure DDoS Protection

Sample question 4 · SC-900 · Describe the capabilities of Microsoft compliance solutions

An auditor asks your team for Microsoft's independent SOC 2 audit report for a cloud service. Where can you download it?

  1. AThe Microsoft Entra admin center
  2. BThe Microsoft 365 admin center
  3. CThe Service Trust Portal
  4. DThe Azure pricing calculator
Show answer and explanation

C. The Service Trust Portal

The Service Trust Portal hosts Microsoft's independent audit reports such as SOC and ISO, so compliance teams can download them. The admin centers manage tenant settings, not third-party audit documents.

Topic: SC-900 Study Cram V2: Service Trust Portal

Sample question 5 · SC-900 · Describe security, compliance, and identity concepts

Within the defense in depth layers, which layer focuses specifically on antivirus, patching, and hardening of individual machines?

  1. AThe perimeter layer
  2. BThe identity layer
  3. CThe physical layer
  4. DThe compute layer
Show answer and explanation

D. The compute layer

In the defense in depth model the compute layer covers securing virtual machines and endpoints through patching and antimalware. The perimeter layer instead protects the network edge with firewalls and DDoS controls.

Topic: SC-900 Study Cram V2: Defense in depth

Sample question 6 · SC-900 · Describe the capabilities of Microsoft Entra

An organization joins laptops to Entra ID so Conditional Access can evaluate machine state during sign-in. What kind of identity object does this create?

  1. AA workload identity
  2. BA managed identity
  3. CA device identity
  4. DA service principal
Show answer and explanation

C. A device identity

Joining or registering a machine creates a device identity in Entra ID that policies can reference. A service principal instead represents an application.

Topic: SC-900 Study Cram V2: Types of identity

Sample question 7 · SC-900 · Describe the capabilities of Microsoft security solutions

A Web Application Firewall is often configured with a managed rule set that addresses the most frequent web vulnerabilities. Which rule set is commonly applied?

  1. AThe OWASP core rule set
  2. BThe PCI cardholder schema
  3. CThe NIST password baseline
  4. DThe CIS hardened images
Show answer and explanation

A. The OWASP core rule set

WAF policies commonly apply the OWASP Core Rule Set to detect and block the top web application threats. The other options are unrelated standards or images.

Topic: SC-900 Study Cram V2: Azure WAF

Sample question 8 · SC-900 · Describe the capabilities of Microsoft compliance solutions

Which privacy principle commits Microsoft to being open about where data is stored and how it is handled?

  1. AControl
  2. BBenefits to you
  3. CTransparency
  4. DNo content-based targeting
Show answer and explanation

C. Transparency

Transparency is the commitment to clearly communicate how data is collected, stored, and used. Control is about who can access data, not the openness of communication.

Topic: SC-900 Study Cram V2: Microsoft privacy principles

Common questions

How many questions are on the SC-900 exam?

SC-900 typically has 40 to 60 questions in about 45 minutes, mostly multiple choice with some drag-and-drop and matching. Passing requires 700 on a scale up to 1,000.

Is SC-900 worth taking?

It is the standard entry point for Microsoft security, compliance, and identity. Fundamentals certifications don't expire, and it builds the vocabulary the role-based SC-200 and SC-300 exams assume.

What does SC-900 cover?

Four areas: security, compliance, and identity concepts (10-15%), the capabilities of Microsoft Entra (25-30%), Microsoft security solutions (35-40%), and Microsoft compliance solutions (20-25%). Our drills track your accuracy in each separately.

Is this actually free?

Yes. Every question, every interactive item, and the exam simulator are free with no account. Every topic links to the matching chapter of John Savill's free SC-900 study video.

More free practice tests

Back to all cert900 exams