Exam objective
SC-900Describe security and compliance concepts
This objective sits in Describe concepts of security, compliance, and identity, which carries 12% of the Security, Compliance, and Identity Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.
Objective title verbatim from the official objectives. Microsoft Azure exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
An auditor requires that data be encrypted before Azure ever receives it, with the encryption performed outside Azure. Which Azure encryption model satisfies that requirement?
Correct.
Checked against learn.microsoft.com, August 2026Concept
Azure encryption models are told apart by where the encryption happens and who holds the key. Where it happens decides whether the provider is ever able to read the plaintext at all.
Why C
Client-side encryption is performed outside Azure, so what Azure receives is already ciphertext. Microsoft holds no key for it and cannot decrypt the data, which is exactly the condition the auditor set.
Source
Microsoft Learn: Azure encryption overview, checked August 2026You perform client-side encryption outside of Azure. It includes: Data encrypted by an application that's running in your datacenter or by a service application. Data that Azure receives already encrypted when Azure receives it. By using client-side encryption, cloud service providers don't have access to the encryption keys and can't decrypt the data. You maintain complete control of the keys.
Now you: practice questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
In a defense in depth model, DDoS protection and firewalls that inspect traffic entering and leaving the network belong to which layer?
Sample question 2 of 3
Two users choose the same password, yet the values stored for them in the database are different. What explains this?
Sample question 3 of 3
A company redesigns its access strategy so that no device or user is trusted by default, even when connected to the internal corporate network, and every access request is authenticated and authorized using all available signals. Which Zero Trust guiding principle does this describe?
Full Security, Compliance, and Identity Fundamentals question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.