Understanding SC-900 Practice Questions + Review

Need help understanding the SC-900 practice questions and general assessment? Walk through understanding and 7 of the questions in this video!

FULL SC-900 Pluralsight Path

Video Summary

Here are the key points from the video:

  • Introduction to Practice Assessments: Practice assessments are a great way to review content and prepare for certification exams, like the SC-900, with free practice tests available on the Microsoft exam page.
  • Accessing Practice Assessments: You can find the practice assessment link on the SC-900 exam page under the “Schedule your exam” section. You’ll need a Microsoft account to access it.
  • Practice Assessment Details: Each practice assessment has 50 questions, with no time limit, allowing you to practice as many times as you want. The questions are multiple-choice, similar to the actual exam.
  • Example Questions: The transcript includes examples of practice questions, such as identifying types of DDoS attacks, using Azure services for network segmentation, and connecting to Azure VMs remotely.
  • Importance of Final Review: Some questions require memorization, like industry frameworks used in the Azure security benchmark, highlighting the importance of a final review before the exam.

For more information, read the transcript blog below, or watch the video above!

Video Transcript

Let’s start by doing an introduction to Microsoft practice assessments. First of all, practice assessments or tests are an amazing way to review all the content you learned throughout the certification path while getting ready for your certification exam. Something that is really cool is that Microsoft offers free practice assessments for most of their certification exams, including the SC-900 exam. To get to the practice assessment, you need to go to the SC-900 exam page under the “Schedule your exam” box, where you’ll see a link to take a free practice assessment. You will need to have a Microsoft account to do the practice assessment, but remember, you’ll need one for the certification exam as well, so you can use the same one. Each practice assessment contains 50 questions; however, their question bank is actually more extensive, so don’t hesitate to take it multiple times. This way, you get to practice even more, and you can take it as many times as you want. There is no time limit on each practice assessment, but at the end, you will see how much time it took you. This can be a really useful way to practice your time management for the actual exam. The practice assessment contains only multiple-choice questions, so not all of the different question types from the exam will be represented in the practice assessment. However, for a 900-level exam, most of the questions you’ll get in the exam will be multiple-choice as well.

Now that we talked about it, let’s go to Microsoft Learn and see how we can start the practice assessment. We’re now in the live environment. Let me open up the browser here where I’m on the SC-900 exam page. We will scroll down a bit here, right under the “Schedule an exam” section of the page, I have “Take a free practice assessment.” I will click on it. Now, if you’re not logged in, it will ask you to log in with a Microsoft account. However, since I’m already logged in in this browser, it just goes straight to the exam. Now you can see we have 50 questions per practice assessment, but you do not have a time limit. So now that you get started, you, of course, have your question. In our case, “Which type of identity should you use to allow Azure virtual machines to access Azure storage without having to handle password changes manually?” Then you’ll have your answer choices. In our case, let’s say I think it’s a managed identity. I can decide if I want to have a bit more of a practice mode where I can check my answer right away, and then I will know if it’s right or not. Or I can always, for example, say, “Hey, you know what, I don’t want to know which one I got correct or not until the end of the exam,” so more like an exam experience. So here, for example, let’s take a look at the question. I will say that it’s “Microsoft Entra external ID.” I didn’t really read it; it doesn’t matter. I’ll click on next. It doesn’t show us the actual answer, but this is it. This is how you get to the practice assessment. Now, let’s head back over to the slides and go over 50 questions together.

Now that you know how to get there on your own, let’s review a practice assessment together. Remember that the questions in the practice assessment are created by Microsoft, and they follow the same style and difficulty level as the actual exam. While their assessment bank has more than 50 questions, we will review one assessment, so 50 questions in this course. Let’s start with the first one: “What are the types of distributed denial of service (DDoS) attacks?” Option one is password spray, protocol attacks, and man-in-the-middle attacks. The second option is password spray, dictionary attack, and resource layer attacks. The third option is resource layer attacks, protocol attacks, and volumetric attacks. The fourth option is dictionary attacks, man-in-the-middle attacks, and volumetric attacks. We learned that DDoS attacks are disruptive attacks that can attack at any layer that is open to the internet. Option one, two, and four include at least one identity attack, such as the password spray or dictionary attack. Therefore, the answer is answer number three: resource layer attacks, protocol attacks, and volumetric attacks. Remember that if you’re not sure of an answer, you can always use the elimination route like we just did and cut down some of the proposed answers.

Now let’s move on to question two: “What can you use in Azure to implement network segmentation based on departments?” Virtual networks, virtual private networks, Azure Bastion, or Azure private links. This one is pretty straightforward, as we learned in the security course that virtual networks are used to segment networks in Azure. So, virtual networks is the correct answer. Be careful that sometimes you will see similar answers, as in this case, virtual networks versus virtual private networks, and our brain will sometimes want to go to the fancier options like the second one, which has the word “private.” But always take a step back and analyze what you have learned.

Let’s go to our third question: “What can you use to connect to Azure virtual machines remotely over Remote Desktop Protocol and Secure Shell Protocol from the Azure portal?” Our options are Azure Web Application Firewall, Microsoft Entra Identity Protection, Microsoft Defender for Cloud, or Azure Bastion. We have seen this one in action in the security course, and the answer is Azure Bastion. All other ones are not even close to a potential correct answer, and we learned all of them in the past.

Question number four is a bit of a bigger one. You have the following inbound Network Security Group security rules in Azure: allow v-net inbound with a priority of 65,000, allow Azure load balancer inbound with a priority of 65,000, and deny all inbound with a priority of 65,500. No other inbound rules were defined for the network security group. In which order will the rules be processed? Then we have four options with all of the rules in a different order. As we look at the options, we need to remember that the lowest priority value will always have the priority. So, you need to make sure that you are very careful with the numbers, as sometimes they might appear very close, but if you don’t read carefully, they will get you. In our case, we know that 65,000 will be first, 65,001 will be second, and 65,500 will be third. So, we simply put them in the order of numbers, and the first answer will be the correct one.

Our fifth question is: “Which Azure service provides centralized protection of web apps from common exploits and vulnerabilities?” Azure Key Vault, Azure Web Application Firewall, Microsoft Entra Identity Protection, or Microsoft Defender for Cloud. We have covered this one in the security course, and the answer is Azure Web Application Firewall. It’s really the only solution in there that is made to protect web applications.

Now let’s go with question six: “Which service enables you to continually assess the security posture, identify threats, and harden resources in Azure and on-premises workloads?” Azure Firewall, Microsoft Defender for Cloud, Azure Web Application Firewall, or Microsoft Purview. This one is more interesting. We know that we need to continually assess security posture, identify threats, and harden resources. Out of the options, only one tool is focused on security on all of Azure with those abilities, and the answer is Microsoft Defender for Cloud.

Next up, we have a multiple-choice option. This is similar to what you will see in the exam: “Which two industry frameworks are used in the Azure Security Benchmark?” Each correct answer presents a complete solution. It also tells us that each correct answer will be a complete solution, and this is important in the exam because it basically tells you they don’t complete each other; each one of them on its own is a correct answer. The answer for this question is first the Center for Internet Security and the National Institute of Standards and Technology. This is one of those questions that you simply need to know by heart, so that’s why it’s important to do a final review before the exam because some things, like this, you just need to remember.