Describe Microsoft Service Trust Portal and privacy principles
Objective service.trust-privacy sits in Describe capabilities of Microsoft compliance solutions, which carries 22% of the SCI Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.
Objective title verbatim from the official objectives. Microsoft Azure exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
A security administrator wants sign-ins automatically challenged with multifactor authentication whenever Microsoft Entra ID Protection calculates a medium or high sign-in risk. Which capability should the administrator configure to enforce this?
The concept
An access rule is only as capable as the conditions it can read. Static conditions such as network location or device state are available to any tenant that can write rules. A condition expressing the likelihood that the person signing in is not the account owner has to be computed by a detection engine, and a rule can reference it only where that engine is licensed and running.
Why this answer
Risk-based Conditional Access policies integrate Entra ID Protection signals to require multifactor authentication when sign-in risk reaches a specified level, exactly matching the scenario.
- Correct: this is the risk-based Conditional Access capability built on Entra ID Protection signals.
- BDomain Services provides legacy LDAP and Kerberos authentication, not risk-based access control.
- CVerified ID issues and verifies digital credentials, unrelated to sign-in risk enforcement.
- DWorkload ID secures nonhuman identities like apps and services, not user sign-in risk.
- EPrivate Access secures remote connections to internal resources without a VPN, not risk scoring.
Now you: objective service.trust-privacy questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
A tenant currently holds only Microsoft Entra ID P1 licenses. The security team drafts a Conditional Access policy that blocks access whenever the calculated sign-in risk level is high. What must the organization do before this policy can take effect?
Sample question 2 of 3
A security administrator builds a Conditional Access policy that requires multifactor authentication only when a sign-in is scored as medium or high risk. Which capability supplies this risk signal to the policy?
Sample question 3 of 3
An auditor asks for third party audit reports covering Microsoft's cloud services. Where are those published?
Full SCI Fundamentals question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.