Exam objective

SC-900

Describe security and compliance concepts

This objective sits in Describe concepts of security, compliance, and identity, which carries 12% of the Security, Compliance, and Identity Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Describe concepts of security, compliance, and identity

An auditor requires that data be encrypted before Azure ever receives it, with the encryption performed outside Azure. Which Azure encryption model satisfies that requirement?

Service-managed keysServer side means Azure encrypts after it receives plaintext. Right if the question asked for the lowest-overhead model where Microsoft manages the keys for you.
MACsec link encryptionMACsec protects traffic in transit between datacenters. Right if the question asked how Azure protects customer traffic crossing links Microsoft does not physically control.
Client-side encryptionCorrect · your answerCorrect. Azure documents this model as performed outside Azure, with data arriving already encrypted and the provider holding no key able to decrypt it.
Customer-managed keysYou control the key, but Azure still encrypts server side after the data arrives. Right if the question asked who holds the key rather than where encryption happens.
Transparent Data EncryptionTDE encrypts SQL Database files at rest inside Azure. Right if the question asked how to protect database files already stored in Azure SQL Database.

Correct.

Checked against learn.microsoft.com, August 2026

Concept

Azure encryption models are told apart by where the encryption happens and who holds the key. Where it happens decides whether the provider is ever able to read the plaintext at all.

Why C

Client-side encryption is performed outside Azure, so what Azure receives is already ciphertext. Microsoft holds no key for it and cannot decrypt the data, which is exactly the condition the auditor set.

Source

You perform client-side encryption outside of Azure. It includes: Data encrypted by an application that's running in your datacenter or by a service application. Data that Azure receives already encrypted when Azure receives it. By using client-side encryption, cloud service providers don't have access to the encryption keys and can't decrypt the data. You maintain complete control of the keys.

Microsoft Learn: Azure encryption overview, checked August 2026
#encryption#client-side-encryption#key-management#data-protection

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Describe concepts of security, compliance, and identity

In a defense in depth model, DDoS protection and firewalls that inspect traffic entering and leaving the network belong to which layer?

Sample question 2 of 3

Describe concepts of security, compliance, and identity

Two users choose the same password, yet the values stored for them in the database are different. What explains this?

Sample question 3 of 3

Describe concepts of security, compliance, and identity

A company redesigns its access strategy so that no device or user is trusted by default, even when connected to the internal corporate network, and every access request is authenticated and authorized using all available signals. Which Zero Trust guiding principle does this describe?

Full Security, Compliance, and Identity Fundamentals question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Describe concepts of security, compliance, and identity