Objective service.trust-privacySC-900

Describe Microsoft Service Trust Portal and privacy principles

Objective service.trust-privacy sits in Describe capabilities of Microsoft compliance solutions, which carries 22% of the SCI Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Describe capabilities of Microsoft compliance solutionsModerate

A security administrator wants sign-ins automatically challenged with multifactor authentication whenever Microsoft Entra ID Protection calculates a medium or high sign-in risk. Which capability should the administrator configure to enforce this?

Correct.

The concept

An access rule is only as capable as the conditions it can read. Static conditions such as network location or device state are available to any tenant that can write rules. A condition expressing the likelihood that the person signing in is not the account owner has to be computed by a detection engine, and a rule can reference it only where that engine is licensed and running.

Why this answer

Risk-based Conditional Access policies integrate Entra ID Protection signals to require multifactor authentication when sign-in risk reaches a specified level, exactly matching the scenario.

  • Correct: this is the risk-based Conditional Access capability built on Entra ID Protection signals.
  • BDomain Services provides legacy LDAP and Kerberos authentication, not risk-based access control.
  • CVerified ID issues and verifies digital credentials, unrelated to sign-in risk enforcement.
  • DWorkload ID secures nonhuman identities like apps and services, not user sign-in risk.
  • EPrivate Access secures remote connections to internal resources without a VPN, not risk scoring.
Read the sourceConditional Access overview
Verified against learn.microsoft.com · 2026-07-28
conditional-accessidentity-protectionentra-id

Now you: objective service.trust-privacy questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Describe capabilities of Microsoft compliance solutionsHard

A tenant currently holds only Microsoft Entra ID P1 licenses. The security team drafts a Conditional Access policy that blocks access whenever the calculated sign-in risk level is high. What must the organization do before this policy can take effect?

Sample question 2 of 3

Describe capabilities of Microsoft compliance solutionsModerate

A security administrator builds a Conditional Access policy that requires multifactor authentication only when a sign-in is scored as medium or high risk. Which capability supplies this risk signal to the policy?

Sample question 3 of 3

Describe capabilities of Microsoft compliance solutionsEasy

An auditor asks for third party audit reports covering Microsoft's cloud services. Where are those published?

Full SCI Fundamentals question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Describe capabilities of Microsoft compliance solutions