SC-900
Exam Practice Questions
This SC-900 exam PDF provides detailed practice questions, answers, and
explanations. These Microsoft SC-900 exam practice questions are designed for
IT professionals, system administra
...
SC-900
Exam Practice Questions
This SC-900 exam PDF provides detailed practice questions, answers, and
explanations. These Microsoft SC-900 exam practice questions are designed for
IT professionals, system administrators, and students preparing for Microsoft
Certified: Security Compliance and Identity Fundamentals certification.
Key Features
Exam-Oriented Questions: Realistic practice questions that mirror the format
and difficulty of actual certification exams.
Wide Coverage: Includes cloud computing, networking, security, AI, and
enterprise IT management exams.
Study-Friendly Format: Organized sections by exam type, enabling focused
preparation.
Important Note:
This material is for personal study purposes only. Please do not
redistribute or use for commercial purposes without permission.
Share some SC-900 exam online questions below.
1.Which Azure Active Directory (Azure AD) feature can you use to restrict Microsoft Intune-managed
devices from accessing corporate resources?
A. network security groups (NSGs)
B. Azure AD Privileged Identity Management (PIM)
C. conditional access policies
D. resource locks
Answer: C
Explanation:
In Microsoft Entra ID (Azure AD), Conditional Access is the policy engine that evaluates signals about
the user, device, app, and session to determine whether to grant access and under what conditions.
Microsoft’s guidance explains that Conditional Access is “the tool used by Azure AD to bring signals
together, make decisions, and enforce organizational policies.” In device-centric scenarios,
Conditional Access integrates with Microsoft Intune device compliance so you can enforce controls
such as “Require device to be marked as compliant” or “Require approved client app” before
granting access to corporate resources like Microsoft 365 and Azure apps. This allows organizations
to block or limit access from unmanaged or noncompliant devices, and to allow access only from
devices that meet your compliance policies (encryption, OS version, jailbreak/root status, etc.).
By contrast, Network Security Groups (NSGs) filter traffic at the virtual network/subnet/NIC level and
are not identity-aware; Privileged Identity Management (PIM) governs just-in-time elevation and
access reviews for privileged roles; and resource locks prevent accidental deletion or modification of
Azure resources. Therefore, the Azure AD feature specifically designed to restrict access by Intunemanaged device state and enforce device-based access conditions to corporate resources is
Conditional Access.
2.HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE:
Each correct selection is worth one point.
Answer:
[Show More]