Practice for SC-900 with 600 exam-grade questions across all four domains, each with a full explanation. 40 free SC-900 practice exam questions.
600 practice questions for SC-900 Security, Compliance, and Identity Fundamentals, written to the skills Microsoft measures from October 21, 2026, with an explanation on every question and 40 free to try.This SC-900 practice exam covers Microsoft Security, Compliance, and Identity Fundamentals as Microsoft now defines it: the skills measured as of October 21, 2026, printed in the study guide for Exam SC-900 on Microsoft Learn and the version the English exam is taken against from that date. It holds 600 questions across the exam's four domains, in the proportions Microsoft publishes for them, and it prepares you for the exam behind the Microsoft Certified: Security, Compliance, and Identity Fundamentals certification. The October list differs from the July 28, 2026 list in two names: workload identities where it said agent ID, and Microsoft Threat Intelligence where it said Microsoft Defender Threat Intelligence. No domain weighting moved.
| Domain | Weightage | Questions |
| Describe the concepts of security, compliance, and identity | 10-15% | 75 |
| Describe the capabilities of Microsoft Entra | 25-30% | 165 |
| Describe the capabilities of Microsoft security solutions | 35-40% | 225 |
| Describe the capabilities of Microsoft compliance solutions | 20-25% | 135 |
Describe the concepts of security, compliance, and identity - 75 questions. The shared responsibility model and what moves across the line as a workload goes from on premises to IaaS, PaaS and SaaS; defense in depth; the Zero Trust model; encryption and hashing, and why they answer different questions; and governance, risk and compliance. Then identity as the primary security perimeter, the difference between authentication and authorization, identity providers, directory services and Active Directory, and federation. The questions put each model in front of a situation and ask which one applies.
Describe the capabilities of Microsoft Entra - 165 questions. Microsoft Entra ID and the types of identities it holds, including workload identities such as service principals and managed identities; hybrid identity; the authentication methods and multifactor authentication, including Microsoft's advice to move away from SMS and voice calls toward Authenticator and passkeys; password protection and self-service password reset, where security questions retire as a reset method in March 2027. Then Conditional Access, Microsoft Entra roles and role-based access control, and the governance layer: Microsoft Entra ID Governance, access reviews, Privileged Identity Management and Microsoft Entra ID Protection.
Describe the capabilities of Microsoft security solutions - 225 questions, the largest domain. The Azure infrastructure services first: Azure DDoS Protection, Azure Firewall, Web Application Firewall, network segmentation with virtual networks, network security groups, Azure Bastion and Azure Key Vault. Then Microsoft Defender for Cloud, cloud security posture management, the policies, standards and recommendations behind a secure score, and cloud workload protection. Microsoft Sentinel is taught as it runs now: SIEM and SOAR, generally available in the Microsoft Defender portal, where Fusion is switched off and the Defender XDR correlation engine takes its place, and where Sentinel will live alone once Azure portal support ends after March 31, 2027. The Defender XDR suite closes the domain: Defender for Office 365, Endpoint, Cloud Apps and Identity, Defender Vulnerability Management, Microsoft Threat Intelligence - the standalone Defender Threat Intelligence product retired on August 1, 2026, and its capabilities now surface in Defender XDR and Sentinel - and the Microsoft Defender portal itself.
Describe the capabilities of Microsoft compliance solutions - 135 questions. The Service Trust Portal and Microsoft's privacy principles; the Microsoft Purview portal, which has replaced the retired compliance portal; Compliance Manager and compliance score. Then information protection and data lifecycle management: data classification, content explorer and activity explorer, sensitivity labels and label policies, data loss prevention, records management, and retention policies, retention labels and retention label policies. The last group is insider risk management, eDiscovery, which now carries the Content Search features that used to stand on their own, and Audit.
Every SC-900 objective begins with describe or define, which reads like permission to memorize definitions. The paper asks for more. It describes a requirement - an auditor who needs mail preserved, a sign-in from a country the user has never visited, a contractor who should lose access when the project ends - and asks which Microsoft product or capability answers it. The traps are the neighbors that sound alike: Defender for Cloud and Defender for Cloud Apps, Microsoft Entra ID Protection and Defender for Identity, sensitivity labels and retention labels, secure score and compliance score, a network security group and Azure Firewall. So this bank sorts look-alikes rather than asking for glossary lines back. And the map it tests moved in 2026: Sentinel is on its way into the Defender portal, standalone Defender Threat Intelligence is gone, and the compliance portal has been retired in favor of the Microsoft Purview portal. A glossary learned from older material names products that no longer exist in that form; the questions here use the names and the places Microsoft uses today.
Every question carries a full explanation, and none of them restates the winning option. An explanation that says "the answer is Microsoft Purview Audit because Audit is correct here" has taught you nothing you can carry to a question you have not seen. Each explanation here names the test that sorted the options - who owns the risk, whether a control acts before or after sign-in, whether the data needs a label or a retention period - and the point at which a neighboring product would have been the right answer instead, which is usually where the learning is. Each one also cites the Microsoft Learn module or product document it came from, so anything you want to read in full has an address.
SC-900 is a sorting exam as much as a multiple-choice one, so 133 of the 600 questions are drag-and-drop: place each capability against the product that provides it, or each risk against the control that answers it. Every one of those boards carries at least one tile that belongs nowhere, because a board where everything fits can be finished by elimination without a single decision. Another 188 questions ask for two or three answers, and say how many, which is the shape that exposes a half-learned distinction. The remaining 279 have one answer. There is no code to read on this paper and none here: SC-900 asks what a product does, not how to operate it.
Exam Coach AI sits next to the question you are on and explains the concept behind it while the clock runs. Ask it what separates a retention label from a retention policy, why Microsoft now discourages SMS and voice calls for multifactor authentication, or whether Microsoft Sentinel is leaving the Azure portal, and it answers in the terms this exam uses. What it will not do is tell you which option to pick - that part is yours, and it is the part the real exam measures. It is built in-house by PrepifyLabs and tuned for SC-900 rather than a general assistant bolted on, so it stays on this exam's products instead of drifting into the associate-level security papers.
SC-900 describes the Microsoft security stack, and the SC-500 practice exam asks you to implement it. The overlap is real and it runs in one direction: network security groups, Azure Firewall, Azure Bastion, Key Vault, Privileged Identity Management, Conditional Access, Defender for Cloud and Microsoft Sentinel all appear on both papers, and on SC-500 each one arrives as a configuration decision with a constraint attached, alongside new material on securing AI workloads. SC-500 replaced AZ-500 as Microsoft's associate-level Azure security exam, and it is the natural next step toward security engineering. If the direction is Azure itself rather than security, AZ-900 Azure Fundamentals is the sibling paper at the same level, and it shares more with SC-900 than its title suggests: Microsoft Entra ID, Conditional Access, role-based access control, Zero Trust, defense in depth and Defender for Cloud are AZ-900 objectives too, asked there at the level of what each one is for.
The pass mark here is 70% of our own questions, scored out of 100, and the result breaks down by domain so you can see which of the four areas is costing you the attempt. A sitting draws 50 questions from the pool of 600 in proportion to the four domains, so two attempts are not the same exam twice, and every question you get wrong is kept for review afterward with its explanation intact. Partial credit applies to the choose-two and choose-three questions and to the drag-and-drop boards.
Forty questions are free, and they are spread across all four domains - 5 from the concepts of security, compliance, and identity, 11 from Microsoft Entra, 15 from the security solutions and 9 from the compliance solutions - rather than being 40 easy ones from the front of the bank. They include drag-and-drop boards and choose-two questions, enough to see the explanation style and Exam Coach AI at work before deciding anything.
The most advanced examination and certification readiness platform available. Train autonomously, pass effortlessly.
Prepifylabs LLC, 5900 Balcones Drive STE 38508, Austin, TX 78731, United States