Free Microsoft SC-900 (Security, Compliance, and Identity) practice test
Microsoft SC-900 (Security, Compliance, and Identity Fundamentals) proves you can describe core security and compliance concepts and the capabilities of Microsoft Entra, Microsoft security solutions, and Microsoft compliance solutions. This site gives you 259 original questions plus 8 drag-and-drop and matching items in Microsoft's own interactive formats, free and without an account.
The simulator runs 45 timed minutes on the real scale (pass line 700 of 1,000), grades interactive items all-or-nothing the way Microsoft does, and links every topic to the matching chapter of John Savill's free SC-900 study video.
What SC-900 covers
| SC-900 domain | Exam weight | Questions here |
|---|---|---|
| Describe security, compliance, and identity concepts | 13% | about 34 |
| Describe the capabilities of Microsoft Entra | 27% | about 71 |
| Describe the capabilities of Microsoft security solutions | 37% | about 96 |
| Describe the capabilities of Microsoft compliance solutions | 23% | about 59 |
Real exam facts: typically 40-60 questions, about 45 minutes, scaled to 1,000 with a 700 pass line. The certification never expires.
Practice questions from this bank
Sample question 1 · SC-900 · Describe security, compliance, and identity concepts
A company adopts a SaaS email service. Under the cloud shared responsibility model, which task remains the customer's responsibility?
- ASecuring the network switches and routers
- BManaging user accounts and access permissions
- CPatching the underlying server operating system
- DMaintaining the physical datacenter hardware
Show answer and explanation
B. Managing user accounts and access permissions
In SaaS the provider handles the operating system, hardware, and network, while the customer always keeps responsibility for accounts, identities, and data. Patching the host operating system belongs to the provider, not the customer.
Topic: SC-900 Study Cram V2: Shared responsibility
Sample question 2 · SC-900 · Describe the capabilities of Microsoft Entra
A company wants a cloud service that manages user sign-in and controls access to Microsoft 365 and other SaaS apps. Which Microsoft offering fills this role?
- AMicrosoft Defender for Cloud
- BMicrosoft Purview
- CMicrosoft Entra ID
- DMicrosoft Intune
Show answer and explanation
C. Microsoft Entra ID
Microsoft Entra ID is the cloud identity and access management service that authenticates users and governs access to apps. Intune manages devices rather than identities.
Topic: SC-900 Study Cram V2: Microsoft Entra ID
Sample question 3 · SC-900 · Describe the capabilities of Microsoft security solutions
A public-facing web service is being overwhelmed by a flood of traffic from thousands of sources trying to exhaust its bandwidth. Which Azure service is designed to absorb and mitigate this kind of attack?
- AAzure Key Vault
- BAzure DDoS Protection
- CAzure Bastion
- DAzure Policy
Show answer and explanation
B. Azure DDoS Protection
Azure DDoS Protection detects and mitigates volumetric denial-of-service attacks aimed at public IP resources. Azure Key Vault stores secrets and does not filter network floods.
Topic: SC-900 Study Cram V2: Azure DDoS Protection
Sample question 4 · SC-900 · Describe the capabilities of Microsoft compliance solutions
An auditor asks your team for Microsoft's independent SOC 2 audit report for a cloud service. Where can you download it?
- AThe Microsoft Entra admin center
- BThe Microsoft 365 admin center
- CThe Service Trust Portal
- DThe Azure pricing calculator
Show answer and explanation
C. The Service Trust Portal
The Service Trust Portal hosts Microsoft's independent audit reports such as SOC and ISO, so compliance teams can download them. The admin centers manage tenant settings, not third-party audit documents.
Topic: SC-900 Study Cram V2: Service Trust Portal
Sample question 5 · SC-900 · Describe security, compliance, and identity concepts
Within the defense in depth layers, which layer focuses specifically on antivirus, patching, and hardening of individual machines?
- AThe perimeter layer
- BThe identity layer
- CThe physical layer
- DThe compute layer
Show answer and explanation
D. The compute layer
In the defense in depth model the compute layer covers securing virtual machines and endpoints through patching and antimalware. The perimeter layer instead protects the network edge with firewalls and DDoS controls.
Topic: SC-900 Study Cram V2: Defense in depth
Sample question 6 · SC-900 · Describe the capabilities of Microsoft Entra
An organization joins laptops to Entra ID so Conditional Access can evaluate machine state during sign-in. What kind of identity object does this create?
- AA workload identity
- BA managed identity
- CA device identity
- DA service principal
Show answer and explanation
C. A device identity
Joining or registering a machine creates a device identity in Entra ID that policies can reference. A service principal instead represents an application.
Topic: SC-900 Study Cram V2: Types of identity
Sample question 7 · SC-900 · Describe the capabilities of Microsoft security solutions
A Web Application Firewall is often configured with a managed rule set that addresses the most frequent web vulnerabilities. Which rule set is commonly applied?
- AThe OWASP core rule set
- BThe PCI cardholder schema
- CThe NIST password baseline
- DThe CIS hardened images
Show answer and explanation
A. The OWASP core rule set
WAF policies commonly apply the OWASP Core Rule Set to detect and block the top web application threats. The other options are unrelated standards or images.
Topic: SC-900 Study Cram V2: Azure WAF
Sample question 8 · SC-900 · Describe the capabilities of Microsoft compliance solutions
Which privacy principle commits Microsoft to being open about where data is stored and how it is handled?
- AControl
- BBenefits to you
- CTransparency
- DNo content-based targeting
Show answer and explanation
C. Transparency
Transparency is the commitment to clearly communicate how data is collected, stored, and used. Control is about who can access data, not the openness of communication.
Topic: SC-900 Study Cram V2: Microsoft privacy principles
Common questions
How many questions are on the SC-900 exam?
SC-900 typically has 40 to 60 questions in about 45 minutes, mostly multiple choice with some drag-and-drop and matching. Passing requires 700 on a scale up to 1,000.
Is SC-900 worth taking?
It is the standard entry point for Microsoft security, compliance, and identity. Fundamentals certifications don't expire, and it builds the vocabulary the role-based SC-200 and SC-300 exams assume.
What does SC-900 cover?
Four areas: security, compliance, and identity concepts (10-15%), the capabilities of Microsoft Entra (25-30%), Microsoft security solutions (35-40%), and Microsoft compliance solutions (20-25%). Our drills track your accuracy in each separately.
Is this actually free?
Yes. Every question, every interactive item, and the exam simulator are free with no account. Every topic links to the matching chapter of John Savill's free SC-900 study video.
More free practice tests
- Free CompTIA Security+ Practice Test (SY0-701)
- Free AWS Cloud Practitioner Practice Test (CLF-C02)
- Free Azure Fundamentals Practice Test (AZ-900)
- Free Cisco CCNA 200-301 Practice Test
- Free Microsoft AZ-104 Practice Test (Azure Administrator)
- Free AWS Solutions Architect Associate Practice Test (SAA-C03)
- Free AWS AI Practitioner Practice Test (AIF-C01)
- Free CompTIA A+ Practice Test (220-1201 & 220-1202)
- Free CompTIA A+ Core 1 Practice Test (220-1201)
- Free CompTIA A+ Core 2 Practice Test (220-1202)
- Free CompTIA Network+ Practice Test (N10-009)
- Free CompTIA PBQ Practice: Simulated Performance-Based Questions
- Free IT Certification Practice Tests (CompTIA, Cisco, AWS, Azure)
- IT Certification Passing Scores: CompTIA, Cisco, AWS & Azure
- Which IT Certification Should You Take First?