EnglishDeutschFrançaisEspañolPortuguês

Microsoft · SC-900 · Fundamentals

Microsoft Security, Compliance, and Identity Fundamentals (SC-900) — Practice Questions and Mock Exam

Practice with realistic SC-900 questions aligned to the exam objectives. Alex explains every answer, and your readiness score shows what to study next.

50Questions
45minTime Limit
700/ 1000Pass Score

Checked against Microsoft · September 2026Current exam version

About the exam

The SC-900 certification demonstrates foundational knowledge of security, compliance, and identity concepts across Microsoft cloud services. It covers core security concepts, Zero Trust principles, Microsoft Entra identity services, Microsoft security solutions including Defender and Sentinel, and Microsoft compliance solutions including Purview and Compliance Manager. The exam validates broad conceptual understanding without requiring deep implementation skills.

This is an ideal starting point for anyone exploring security, compliance, and identity roles in the Microsoft ecosystem. It suits business professionals, IT generalists, students, and stakeholders who want to understand Microsoft's security and compliance capabilities before pursuing role-based certifications like SC-200 or SC-300.

What's on the exam

Microsoft security solutions carry the most weight at 35–40% — core Azure infrastructure security, Sentinel, and Defender XDR make up more than a third of the exam on their own. Microsoft Entra capabilities follow at 25–30%, compliance solutions at 20–25%, and foundational security/compliance/identity concepts trail at just 10–15%.

The weighting means SC-900 rewards breadth across Microsoft's security product line over depth in Zero Trust theory: knowing what Sentinel, Defender for Endpoint, and Defender for Cloud each do outweighs being able to define the six Zero Trust pillars. Candidates who study identity and compliance concepts thoroughly but treat the security-solutions domain as a vocabulary list are underprepared for the largest single domain on the exam.

Exam blueprint: SC-900

Describe the concepts of security, compliance, and identity10–15%

Security and compliance concepts including shared responsibility, defense-in-depth, Zero Trust, encryption, and GRC; identity concepts including authentication, authorization, identity providers, and federation

≈ 2 h
Describe the capabilities of Microsoft Entra25–30%

Microsoft Entra ID function and identity types, authentication capabilities, access management capabilities, and identity protection and governance capabilities

≈ 4 h
Describe the capabilities of Microsoft security solutions35–40%

Core Azure infrastructure security services, security management capabilities, Microsoft Sentinel capabilities, and Microsoft Defender XDR threat protection

≈ 6 h
Describe the capabilities of Microsoft compliance solutions20–25%

Service Trust Portal, Compliance Manager, information protection, data lifecycle management, data governance, insider risk, eDiscovery, and audit capabilities in Microsoft Purview

≈ 3 h

Exam format and question types

The exam draws 40–60 questions from a mix of multiple-choice, multiple-select, drag-and-drop, and hot-area formats inside a 45-minute window. Questions test whether you can match a security, compliance, or identity concept to the Microsoft product that implements it, rather than how to configure that product. Most items are direct and conceptual, so the time pressure sits lower than on the associate-level security exams.

Question types: SC-900

Multiple Choice42%

Pick the single best answer from four or five options — the exam's bread and butter.

Drag & Drop18%

Drag items into the right slot, group or order — it tests whether you can apply a concept, not just recognise it.

Multiple Response18%

More than one answer is correct and you need all of them; the question tells you how many to pick.

Dropdown12%

Complete a statement or a configuration by picking from dropdown menus inside the text.

True / False10%

Judge a single statement as true or false — quick points, but the exact wording decides.

Microsoft confirms these question types — a percentage split is not published; the shares reflect our exam-aligned question pool.

Try five SC-900 questions

Five questions straight from our Microsoft Security, Compliance, and Identity Fundamentals pool. Answer one — Alex explains the why.

Describe the capabilities of Microsoft security solutions1 / 5

Which Microsoft security solution is a cloud-native SIEM and SOAR solution that collects data at cloud scale, detects previously undetected threats, and responds to incidents with built-in orchestration and automation?

AlexFull explanation from Alex

Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution. It collects data at cloud scale from across the entire organization using 350+ built-in data connectors. Sentinel uses AI and machine learning to detect previously undetected threats, minimize false positives, and provide intelligent security analytics. Key capabilities include data collection, threat detection with analytics rules, investigation with incidents and entity mapping, and automated response with playbooks (Logic Apps). Exam tip: Sentinel = SIEM + SOAR. SIEM = collect and analyze security data. SOAR = automate responses with playbooks. Cloud-native means no infrastructure to deploy.

Sourcelearn.microsoft.com

Describe the capabilities of Microsoft compliance solutions3 / 5

Microsoft Purview Activity explorer shows which types of activities related to labeled and sensitive content?

AlexFull explanation from Alex

Microsoft Purview Activity explorer shows activities related to labeled and sensitive content including: labeling activities (labels applied, changed, removed), DLP policy matches (when content triggers a DLP rule), and sensitive content discoveries (when sensitive information types are detected in content). Activity explorer provides a historical view of user and system actions on classified data, helping compliance teams monitor data protection effectiveness and identify potential issues. It works with data from Exchange, SharePoint, OneDrive, and endpoint devices. Exam tip: Activity explorer shows three types: labeling activities, DLP matches, and SIT discoveries. It's different from Content explorer (shows what sensitive content exists) vs Activity explorer (shows what happened to it).

Sourcelearn.microsoft.com

Describe the capabilities of Microsoft Entra4 / 5

Which Microsoft Entra governance capability allows organizations to create bundles of resources (apps, groups, sites) that users can request access to through a self-service portal?

AlexFull explanation from Alex

Entitlement management access packages in Microsoft Entra ID allow organizations to create bundles of resources that users can request access to through a self-service portal. An access package can include multiple resources: applications, groups, SharePoint sites, and Teams. Each package has policies defining who can request, who approves, how long access lasts, and whether access reviews are required. This streamlines access governance by packaging related resources together — a new employee in sales can request the "Sales Team" access package to get all needed apps and groups in one request. Exam tip: Access packages = bundles of resources with request/approval policies. Catalogs organize packages. Policies define who, approval, duration, and review requirements.

Sourcelearn.microsoft.com

327 questions, built like the exam

Every domain of the SC-900 exam has enough questions in the pool to practice it in depth. A mock exam asks 50 questions in one sitting, on the same 45-minute clock as the real thing.

Audit record: SC-900

Spec check against MicrosoftSeptember 3, 2026

last verified against the official Microsoft source

Pass mark700 / 1,000

as published by Microsoft

Blueprint coverage72 official objectives

across 4 domains, from the official exam guide

Pool size327 questions

= 6 full practice exams of 50 questions each — never the same question twice

Domain coverageall 4 domains at official weight

Describe the concepts of security, compliance, and identity 55 · Describe the capabilities of Microsoft Entra 81 · Describe the capabilities of Microsoft security solutions 110 · Describe the capabilities of Microsoft compliance solutions 81

Canonically validated327 of 327

each verified against official Microsoft documentation — answer, options and explanation, source cited

Methodology openly documented.How questions are made →

Preparing for SC-900

How long you'll need depends on how much hands-on experience you bring. The rest is set by the vendor: how the exam is delivered, how soon you can retake it, and how long the credential stays valid.

The exam runs through Pearson VUE, either online with a remote proctor or at an authorized testing center, and is offered in English, Japanese, Chinese, Korean, French, German, Spanish, Portuguese, and several other languages. Fundamentals certifications don't expire, so there's no renewal cycle to track.

Your plan: SC-900

Preparation

Study time10–25 h

typically around 10 h if you already work with this stack, around 25 h coming to it fresh

LevelFundamentals

Exam day & after

DeliveryPearson VUE online proctored or at authorized testing centers worldwide
Retake policy24-hour wait after the first attempt, 14 days between subsequent attempts, maximum 5 attempts per exam within a 12-month period
Stays validFundamentals certifications do not expire and do not require renewal. However, Microsoft recommends staying current with evolving security and compliance services.

The hours are our own planning estimate — Microsoft publishes no preparation time for this exam. A starting point for your calendar, not a target.

Common pitfalls

Zero Trust's six pillars map onto specific Microsoft product areas, and the exam tests that mapping directly rather than a definition of Zero Trust as a principle. Entra's identity features and Defender's security capabilities get confused because they touch related problems from different angles, and Compliance Manager, Purview, and Priva get mixed up the same way despite serving distinct compliance functions. The shared-responsibility model shifts what Microsoft manages versus what the customer manages across IaaS, PaaS, and SaaS, and the four Defender products (for Endpoint, Cloud, Identity, and Office 365) cover different surfaces that are easy to swap in a rushed answer.

Watch list: SC-900

  1. 01Zero Trust Concepts

    Not understanding the six foundational pillars of Zero Trust and how they apply to Microsoft's security product portfolio.

  2. 02Identity vs Security

    Confusing Microsoft Entra identity features with Microsoft Defender security capabilities and their different purposes.

  3. 03Compliance Tools

    Struggling to differentiate Compliance Manager, Purview, and Microsoft Priva and their specific compliance functions.

  4. 04Shared Responsibility

    Overlooking the shared responsibility model across IaaS, PaaS, and SaaS and what Microsoft vs the customer manages.

  5. 05Defender Products

    Mixing up the various Microsoft Defender products (for Endpoint, for Cloud, for Identity, for Office 365) and their coverage areas.

Pass-IT trains you on exactly these weak spots — adaptive & spaced →

Frequently asked questions

How long is the Microsoft Security, Compliance, and Identity Fundamentals exam?

The SC-900 exam has 50 questions and a 45-minute time limit.

What is the passing score for Microsoft Security, Compliance, and Identity Fundamentals?

You need 700 / 1000 to pass the SC-900 exam.

What are common mistakes on the Microsoft Security, Compliance, and Identity Fundamentals exam?

Common pitfalls include: Zero Trust Concepts, Identity vs Security, Compliance Tools, Shared Responsibility, Defender Products. Focus study time on these areas to avoid losing points.

Does SC-900 expire?

No. Microsoft fundamentals certifications carry no expiry date and no renewal requirement, so SC-900 stays on your transcript once you pass it.

What should you take after SC-900?

SC-200 for security operations, SC-300 for identity and access, or SC-401 for information security. SC-900 covers the concepts those three assume, which is why it is commonly taken first even though none of them require it.

How long does it take to prepare for SC-900?

Around 15 hours is realistic. The heaviest area is Microsoft's security solutions at roughly 38%, with Entra capabilities near 28%, so time spent on the product portfolio pays off more than time spent on definitions.

What happens if you fail SC-900?

You can retake it after 24 hours. Each further attempt needs a 14-day wait, and you are capped at five attempts in any 12-month period.

Pass-IT is an independent study tool, not affiliated with or endorsed by Microsoft; Microsoft and exam names are trademarks of their respective owners.

One certification. One payment.

Full SC-900 access

Get the full question pool for this certification. Alex explains every answer, and your readiness score shows what to work on next.

Buy SC-900 access for $29.99One payment. Lifetime access to this certification.
Take the free readiness check20 questions. No card. See what to study before you buy.

Reach 80% readiness and pass — or your money back.

How the score works →