- Home
- Microsoft Certification
- SC-900 Exam
- Microsoft.SC-900.dumpsfiles Dumps
Free Microsoft SC-900 Exam Dumps Questions & Answers
| Exam Code/Number: | SC-900Join the discussion |
| Exam Name: | Microsoft Security Compliance and Identity Fundamentals |
| Certification: | Microsoft |
| Question Number: | 273 |
| Publish Date: | Jul 16, 2026 |
|
Rating
100%
|
|
Page: 1 / 55
Total 273 questions
Total 273 questions
Which feature is included in Microsoft Entra ID Governance?
Correct Answer: D
Explanation: (Only visible for DumpsFiles members)
Hotspot Question
Select the answer that correctly completes the sentence.
Correct Answer:

Explanation:
To enable Microsoft Defender for Cloud plans, you'll need to sign into the Azure portal and navigate to Defender for Cloud. From there, you can select the relevant subscription, AWS account, or GCP project and toggle the desired plans to "On.
Reference:
https://learn.microsoft.com/en-us/azure/defender-for-cloud/connect-azure-subscription
What is the maximum number of resources that Azure DDoS Protection Standard can protect without additional costs?
Correct Answer: B
Explanation: (Only visible for DumpsFiles members)
Hotspot Question
Select the answer that correctly completes the sentence.
Correct Answer:

Explanation:
MIP capabilities are included with Microsoft 365 Compliance and give you the tools to know your data, protect your data, and prevent data loss.
https://docs.microsoft.com/en-us/microsoft-365/compliance/information-protection?view=o365-worldwide
https://docs.microsoft.com/en-us/microsoft-365/compliance/microsoft-365-compliance-center?view=o365-worldwide
Hotspot Question
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
Box 1: Yes
Atypical travel refers to when a user's account shows sign-ins from two geographically distant locations within a timeframe that would be physically impossible to travel between.
This behavior suggests the user account may have been compromised, so it is treated as a user risk in this exam context.
Box 2: No
Leaked credentials are classified as a User Risk, not a Sign-in Risk, in Microsoft Entra ID Protection.
While the distinction might seem minor, it is important for how Entra ID treats the threat and how you should respond:
User Risk: Indicates that an account is likely compromised overall. Leaked credentials trigger this because they suggest that an attacker possesses the user's password, meaning the account identity itself is insecure. The focus here is on remediating the account, typically through a password reset.
Sign-in Risk: Indicates that a specific authentication attempt is suspicious (e.g., login from an anonymous IP, impossible travel, or an unfamiliar location). The focus here is on the individual sign-in event, often mitigated by requiring Multi-Factor Authentication (MFA).
Box 3: Yes
Sign-ins from an anonymous IP address (such as those originating from Tor browsers or anonymous VPNs) are a recognized sign-in risk detection in Microsoft Entra ID Protection.
Why it is considered a risk
Microsoft Entra ID Protection flags these as risky because threat actors frequently use anonymous IP addresses to mask their true location, device identity, and IP address. This helps them attempt unauthorized access or perform reconnaissance while avoiding detection.
Reference:
https://www.reddit.com/r/AZURE/comments/1ebcpsp/entra_identity_protection_atypical_travel
https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-investigate-risk
Add Comments
SC-900 Dumps Other Version
Microsoft.SC-900.v2025-12-05.q202
Microsoft.SC-900.v2025-07-19.q94
Microsoft.SC-900.v2024-02-06.q178
Microsoft.SC-900.v2023-05-09.q118
Microsoft.SC-900.v2022-11-22.q111
Microsoft.Testsimulate.SC-900.v2022-09-30.by.lesley.104q.pdf
Microsoft.SC-900.v2022-08-27.q95