Microsoft Certified:Security, Compliance, and Identity Fundamentals
Domain 3Objective 4
Describe Threat Protection with Microsoft Defender XDR SC-900 Practice Questions (Page 7)
Part of the Describe the capabilities of Microsoft security solutions domain, which accounts for 35–40% of the SC-900 exam. Microsoft does not publish an official question count, but from its 45-minute exam (~20–30 total, ~7–12 in this domain), expect 2–3 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
8concepts
35–40%of the exam
Questions 31–33
- 31
A security operations center (SOC) analyst receives an alert about a phishing email that led to a malware infection on a user's device. The analyst wants to see the full attack chain, including the email, the device, and the user account, in one place. What should they use?
Select an answer first - 32
A company uses Microsoft Defender for Cloud Apps to monitor cloud app usage. They want to block downloads of sensitive files from a sanctioned cloud app when a user's sign-in risk is medium or high. However, they also want to allow the user to continue using the app for non-sensitive operations. What should they configure?
Select an answer first - 33
A company uses Microsoft Defender Vulnerability Management and wants to prioritize remediation efforts. They have a limited security team and need to focus on the most critical vulnerabilities that are actively exploited. What should they use to prioritize?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to SC-900
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-900” is a trademark of its owner, used for identification only.