Exam objective

SC-900

Describe security management capabilities of Azure

This objective sits in Describe capabilities of Microsoft security solutions, which carries 38% of the Security, Compliance, and Identity Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Describe capabilities of Microsoft security solutions

Which pillar of Microsoft Defender for Cloud is delivered through plans such as Defender for Servers, Defender for Storage and Defender for Databases?

DevSecOps security managementDevSecOps covers code, secrets and dependency scanning across pipelines such as GitHub and Azure DevOps.
Cloud security posture managementCSPM assesses configuration and produces secure score and hardening recommendations rather than per-resource plans.
Cloud workload protection platformCorrect · your answerCorrect.
AI security posture managementAI SPM inventories generative AI workloads and belongs to the Defender CSPM plan.

Correct.

Checked against learn.microsoft.com, September 2026

Concept

Finding misconfigurations before an attack and defending a running resource during one are separate jobs, and only one of them is sold per resource type.

Why C

The source says Defender for Cloud delivers CWPP through Microsoft Defender plans specific to the types of resources in your subscriptions, giving Defender for Servers, Storage and Databases as examples.

Source

Microsoft Defender for Cloud delivers CWPP through Microsoft Defender plans specific to the types of resources in your subscriptions-for example, Defender for Servers, Defender for Storage, or Defender for Databases.

Describe Microsoft Defender for Cloud, checked September 2026
#defender-for-cloud#cwpp#plans

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Describe capabilities of Microsoft security solutions

A team fixes two of the four recommendations in one security control for a virtual machine. What happens to the subscription's secure score?

Sample question 2 of 3

Describe capabilities of Microsoft security solutions

A team wants to see how an exposed virtual machine with a known vulnerability could be chained to reach a sensitive storage account. Which CSPM capability provides this, and in which plan?

Sample question 3 of 3

Describe capabilities of Microsoft security solutions

An organization enables Microsoft Defender for Cloud for the first time and has assigned no standards. Which security initiative generates the recommendations it sees?

Full Security, Compliance, and Identity Fundamentals question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Describe capabilities of Microsoft security solutions