Exam objective

SC-900

Describe core infrastructure security services in Azure

This objective sits in Describe capabilities of Microsoft security solutions, which carries 38% of the Security, Compliance, and Identity Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Describe capabilities of Microsoft security solutions

A network security group has a rule at priority 300 allowing RDP from the internet and a rule at priority 200 denying it. Internet RDP traffic arrives. What happens?

The traffic is allowedThe allow rule sits at a higher number, so it is processed after the deny and never reached.
The traffic is logged twiceProcessing stops at the first match; a second rule does not also apply.
The traffic is deniedCorrect · your answerCorrect.
The NSG rejects the ruleAzure accepts overlapping rules; priority order is how it resolves them.

Correct.

Checked against learn.microsoft.com, September 2026

Concept

Rules in a network security group are not weighed against each other; the first match in priority order decides, and everything below it is never consulted.

Why C

The source says rules are processed in priority order, lower numbers first, and when traffic matches a rule, processing stops, so the deny at 200 wins and the allow at 300 is never reached.

Source

Priority: Rules are processed in priority order, with lower numbers processed before higher numbers. When traffic matches a rule, processing stops. This means that any other rules with a lower priority (higher numbers) won't be processed.

Describe Azure Network Security Groups, checked September 2026
#nsg#priority#scenario

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Describe capabilities of Microsoft security solutions

A company runs workloads in several virtual networks across subscriptions and wants one place to control all their network traffic. Which deployment is recommended?

Sample question 2 of 3

Describe capabilities of Microsoft security solutions

A public web application has Azure DDoS Protection enabled, yet an HTTP flood still degrades it. Why does the flood get through?

Sample question 3 of 3

Describe capabilities of Microsoft security solutions

A company wants access to the DDoS rapid response team and cost protection during an attack. Which Azure DDoS Protection tier includes these services?

Full Security, Compliance, and Identity Fundamentals question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Describe capabilities of Microsoft security solutions