Start Your Free Practice Test
Enter your details, then choose a 25-question Quick Test or the full 50-question, 45-minute practice test.
Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Check your readiness for the Microsoft SC-900 exam with 50 exam-style questions across all four skill areas, each with an instant explanation. Free to take, with a 45-minute timer that matches the real exam, and retake it as often as you want.
Enter your details, then choose a 25-question Quick Test or the full 50-question, 45-minute practice test.
This free Microsoft SC-900 practice test checks your readiness for the Microsoft Security, Compliance, and Identity Fundamentals exam with 50 exam-style questions across all four skill areas, each with an explanation for every answer choice, on a 45-minute timer that mirrors the real exam. Built by Training Camp, a Microsoft training partner. Ready for instructor-led prep? See our Microsoft training courses.
SC-900 measures four skill areas, and this test draws questions from each in proportion to their weight: Describe the concepts of security, compliance, and identity (10-15%), Describe the capabilities of Microsoft Entra (25-30%), Describe the capabilities of Microsoft security solutions (35-40%), and Describe the capabilities of Microsoft compliance solutions (20-25%).
The real exam has between 40 and 60 questions, a 45-minute time limit, and a passing score of 700 on a scale of 1 to 1000. It is a fundamentals-level exam with no prerequisites, aimed at business stakeholders, new IT professionals and students who want a working understanding of Microsoft Entra ID, Microsoft Defender XDR, Microsoft Sentinel and Microsoft Purview. Microsoft updates the skills measured periodically; this test reflects the version dated July 28, 2026.
Take it once without notes to get an honest baseline. The 50 questions and 45-minute timer are paced like the real exam, so treat the clock as part of the practice. Read the explanation for every choice, not just the one you picked, because SC-900 questions often turn on the difference between two products that sound alike, such as Microsoft Defender for Identity and Microsoft Entra ID Protection. Your results break down by skill area, so spend your next study block on the weakest one, then retake the test to confirm the gap has closed.
Domains Covered · SC-900
Shared responsibility, Zero Trust, encryption, GRC, and identity as the perimeter.
Entra ID identity types, hybrid identity, MFA, Conditional Access, PIM and governance.
Azure network security, Key Vault, Defender for Cloud, Sentinel and Defender XDR.
Service Trust Portal, Compliance Manager, Purview labels, DLP, retention and eDiscovery.
Four questions from the bank, one per domain, with the reasoning behind every answer. The full test has 50.
A retail company is moving its customer database from an on-premises server to a Microsoft software as a service (SaaS) offering. The security lead wants to know which duties will still belong to the company after the move. Under the shared responsibility model, which responsibility ALWAYS remains with the customer regardless of cloud service type?
Correct. In the shared responsibility model, the customer always retains responsibility for its information and data, its devices, and its accounts and identities, no matter whether the workload runs on SaaS, PaaS or IaaS.
An application running on an Azure virtual machine must read secrets from Azure Key Vault. The developers do not want any credentials stored in code or configuration files, and they want the platform to create and rotate the identity's credentials automatically. Which Microsoft Entra identity type should they use?
Correct. A managed identity is a workload identity in Microsoft Entra ID whose credentials are created, stored and rotated by Azure. The VM can use it to authenticate to Key Vault with no secrets in code.
An Azure administrator has a virtual network with a web subnet and a database subnet. Only virtual machines in the web subnet should reach the database servers on TCP port 1433, and all other inbound traffic to the database subnet should be denied. Which Azure feature provides this basic layer 3 and layer 4 filtering at the subnet or network interface level at no additional charge?
Correct. A network security group is a list of allow and deny rules based on source, destination, port and protocol that can be attached to a subnet or a network interface, giving basic traffic segmentation inside a virtual network.
Before signing a cloud services contract, a hospital's compliance officer asks to see Microsoft's independent audit reports, such as SOC reports and ISO certifications, along with documentation on how Microsoft cloud services protect customer data and privacy. Where should the officer look?
Correct. The Service Trust Portal is Microsoft's public site for audit reports, compliance guides, penetration test summaries and privacy documentation that customers use to evaluate Microsoft cloud services.
Every one of the 50 questions works this way: an explanation for the right answer and for the one you picked, so a wrong answer teaches you something. Questions last reviewed against the current Microsoft Security, Compliance, and Identity Fundamentals (SC-900) objectives.
Quick answers about the test, the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) exam, and how to prepare.
Yes. Training Camp's SC-900 practice test is free to take, with an explanation for every answer choice across all four Microsoft Security, Compliance, and Identity Fundamentals skill areas.
It is 50 multiple-choice questions drawn from all four SC-900 skill areas, with an instant explanation after each answer and a 45-minute timer, timed to the pace of the real exam. You can retake it as often as you want. It is a readiness check, not a substitute for full preparation.
The Microsoft SC-900 exam has between 40 and 60 questions and a 45-minute time limit. Question formats include multiple choice, drag and drop, and short case-based items.
You need a score of 700 on a scale of 1 to 1000 to pass the Microsoft SC-900 exam. Microsoft uses scaled scoring, so 700 does not mean 70 percent of questions answered correctly.
SC-900 covers four skill areas: Describe the concepts of security, compliance, and identity (10-15%), Describe the capabilities of Microsoft Entra (25-30%), Describe the capabilities of Microsoft security solutions (35-40%), and Describe the capabilities of Microsoft compliance solutions (20-25%).
SC-900 is a fundamentals-level certification with no prerequisites. It is designed for business stakeholders, new IT professionals and students, so it tests whether you can describe what each Microsoft security, compliance and identity service does rather than how to configure it. General familiarity with Microsoft 365 and Azure is helpful.
Start with Microsoft's published skills outline and free Microsoft Learn modules, then use practice questions like these to find weak spots. If you want a structured, instructor-led path, explore our Microsoft training courses.