Skip to content

Describe the concepts of security, compliance, and identity Questions

Practice questions for Describe the concepts of security, compliance, and identity topic in Microsoft Certified: Security, Compliance, and Identity Fundamentals. 27 questions covering this domain.

27 questions10 easy12 medium5 hard
Q1
easy

Which Zero Trust principle requires every access request to be authenticated and authorized using all available signals?

Q2
medium

Which part of the CIA triad is focused on making sure data is not altered improperly?

Q3
easy

In the cloud shared responsibility model, which responsibility does the customer always retain?

Q4
hard

According to Microsoft's shared responsibility model, which statement is true for Platform as a Service workloads?

Q5
easy

What does defense in depth mean in Microsoft's security guidance?

Q6
medium

For a SaaS solution such as Microsoft 365, who is responsible for the physical datacenter and physical network?

Q7
medium

Which approach best supports the Zero Trust principle of least privilege?

Q8
easy

Which Zero Trust guiding principle assumes that an attacker may already be inside the environment?

Q9
hard

An organization is moving from a traditional "trusted internal network" model to Zero Trust. Which change best aligns with Microsoft's Zero Trust guid...

Q10
medium

An organization wants to share documents across partners using a central, trusted identity provider that both organizations rely on. Which identity co...

Q11
easy

Which term describes the practice of making it impossible for a party to deny that they performed an action?

Q12
easy

Which identity term describes the process of determining what an authenticated user is allowed to do?

Q13
medium

Microsoft's six foundational Zero Trust pillars include identities, endpoints, applications, network, infrastructure, and which other?

Q14
medium

Which is true about an Infrastructure-as-a-Service (IaaS) shared responsibility split?

Q15
medium

A bank documents security policies, assigns control owners, evaluates regulatory requirements, and tracks risk treatment plans before an audit. Which ...

Q16
hard

A payroll system must store employee files so they can be decrypted later, while also storing password verifiers that should not be reversible. Which ...

Q17
easy

An HR app first asks an employee for MFA, and only after sign-in checks whether the employee is in the HR Managers group before allowing salary change...

Q18
medium

An IT team uses an on-premises directory to organize users and computers and to support Kerberos-based sign-in to internal servers. Which technology b...

Q19
easy

A security team wants to confirm that a downloaded file was not altered in transit, and they do not need to recover the original file from the verific...

Q20
medium

A SaaS application redirects users to a central service that validates credentials and issues tokens for multiple apps. What is that central service c...

Sign in to see all 27 questions

Create a free account to browse all questions — completely free during our launch phase.