Describe the concepts of security, compliance, and identity Questions
Practice questions for Describe the concepts of security, compliance, and identity topic in Microsoft Certified: Security, Compliance, and Identity Fundamentals. 27 questions covering this domain.
Which Zero Trust principle requires every access request to be authenticated and authorized using all available signals?
Which part of the CIA triad is focused on making sure data is not altered improperly?
In the cloud shared responsibility model, which responsibility does the customer always retain?
According to Microsoft's shared responsibility model, which statement is true for Platform as a Service workloads?
What does defense in depth mean in Microsoft's security guidance?
For a SaaS solution such as Microsoft 365, who is responsible for the physical datacenter and physical network?
Which approach best supports the Zero Trust principle of least privilege?
Which Zero Trust guiding principle assumes that an attacker may already be inside the environment?
An organization is moving from a traditional "trusted internal network" model to Zero Trust. Which change best aligns with Microsoft's Zero Trust guid...
An organization wants to share documents across partners using a central, trusted identity provider that both organizations rely on. Which identity co...
Which term describes the practice of making it impossible for a party to deny that they performed an action?
Which identity term describes the process of determining what an authenticated user is allowed to do?
Microsoft's six foundational Zero Trust pillars include identities, endpoints, applications, network, infrastructure, and which other?
Which is true about an Infrastructure-as-a-Service (IaaS) shared responsibility split?
A bank documents security policies, assigns control owners, evaluates regulatory requirements, and tracks risk treatment plans before an audit. Which ...
A payroll system must store employee files so they can be decrypted later, while also storing password verifiers that should not be reversible. Which ...
An HR app first asks an employee for MFA, and only after sign-in checks whether the employee is in the HR Managers group before allowing salary change...
An IT team uses an on-premises directory to organize users and computers and to support Kerberos-based sign-in to internal servers. Which technology b...
A security team wants to confirm that a downloaded file was not altered in transit, and they do not need to recover the original file from the verific...
A SaaS application redirects users to a central service that validates credentials and issues tokens for multiple apps. What is that central service c...
Sign in to see all 27 questions
Create a free account to browse all questions — completely free during our launch phase.