In the shared responsibility model for an Azure deployment, what is Microsoft solely responsible for managing?
Answer : D
In Microsoft's shared responsibility model for Azure, responsibilities are divided between Microsoft and the customer. Microsoft Learn explains that Microsoft is responsible for security of the cloud, while customers are responsible for security in the cloud. The platform owner's scope includes the underlying facilities and infrastructure. As the documentation states: ''Microsoft is responsible for the security OF the cloud, which includes protecting the infrastructure that runs all of the services offered in Microsoft Azure,'' and this encompasses ''physical datacenters, physical hosts, and the physical network.'' The customer, by contrast, is responsible for items within their tenant and workloads, including ''data, endpoints, accounts, and access management,'' as well as configuration of services, identities, and devices.
Applied to the options given: managing mobile devices (A), setting permissions for user data (B), and creating/managing user accounts (C) fall under the customer's responsibility because they relate to identity, access, data, and endpoint management within the tenant. The one item that Microsoft solely manages is the physical layer---the ''physical hardware and facilities'' that host Azure services. Therefore, the correct answer is D. the management of the physical hardware.
To which three locations can a data loss prevention (DLP) policy be applied? Each correct answer presents a complete solution.
NOTE: Each correct answer is worth one point.
Answer : A, B, D
Microsoft Purview Data Loss Prevention (DLP) defines supported service locations for policy enforcement. The Microsoft Learn/SCI materials state that DLP policies ''help protect sensitive information across Microsoft 365 services'' and can be scoped to common workloads. In the DLP overview, Microsoft explicitly lists the core cloud locations: ''You can create DLP policies that protect content in Exchange Online, SharePoint Online, and OneDrive for Business.'' The Teams workload is also included: ''DLP can monitor and take protective actions on Microsoft Teams chat and channel messages.'' These statements confirm that applying a DLP policy to Exchange Online email (A), OneDrive accounts (B), and Teams chat and channel messages (D) is supported.
By contrast, Exchange Online public folders (C) are not listed among supported DLP locations in the SCI documentation, and Viva Engage (formerly Yammer) (E) is not a standard Microsoft Purview DLP location in the core list above (Viva Engage has separate governance and communication compliance controls). Therefore, from the supported locations enumerated in Microsoft's DLP guidance, the correct answers are Exchange Online email, OneDrive accounts, and Teams chat and channel messages.
What do you use to provide real-time integration between Azure Sentinel and another security source?
Answer : D
To on-board Azure Sentinel, you first need to connect to your security sources. Azure Sentinel comes with a number of connectors for Microsoft solutions, including Microsoft 365 Defender solutions, and Microsoft 365 sources, including Office 365, Azure AD, Microsoft Defender for Identity, and Microsoft Cloud App Security, etc.
Which two tasks can you implement by using data loss prevention (DLP) policies in Microsoft 365? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
Answer : A, C
Microsoft Purview Data Loss Prevention (DLP) is designed to prevent the inadvertent or inappropriate sharing of sensitive data across Microsoft 365 services. Microsoft's guidance states that DLP ''helps you discover, monitor, and protect sensitive items across Microsoft 365,'' and that with DLP policies you can ''identify, monitor, and automatically protect sensitive items in Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams.'' This directly supports option C, because DLP can detect sensitive info in OneDrive documents and automatically apply protective actions such as blocking external sharing, restricting access, or auditing the event.
DLP also provides end-user coaching through policy tips: ''Policy tips are informative notices that appear when users are working with content that contains sensitive info ... to help prevent data loss.'' When a user is about to send or share sensitive data in violation of policy, these tips surface in Outlook and Office apps (including when files are stored in SharePoint/OneDrive), aligning with option A.
By contrast, enabling disk encryption (e.g., BitLocker) and applying device security baselines are endpoint/device management tasks handled through Microsoft Intune or Group Policy---not by DLP. Therefore, A and C are the correct tasks you can implement with Microsoft 365 DLP policies.
Which two actions can you perform by using Azure Key Vault? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
Answer : D, E
Microsoft's official description of Azure Key Vault in the Security, Compliance, and Identity learning materials states that Key Vault is ''a cloud service for securely storing and accessing secrets.'' The same guidance clarifies that ''a secret is anything you want to tightly control, such as API keys, passwords, or connection strings.'' In addition to secrets, Key Vault provides key management: ''Azure Key Vault helps safeguard cryptographic keys and secrets used by cloud applications and services.'' It further explains that organizations can ''generate, import, rotate, disable, and delete keys'' and use them for operations such as ''encrypt and decrypt, sign and verify, wrap and unwrap.'' These excerpts confirm that Key Vault's core capabilities include the secure storage and lifecycle management of secrets and cryptographic keys.
By contrast, the SCI content makes clear that infrastructure features like Azure DDoS Protection and Network Security Groups (NSGs) are networking/security controls delivered by Azure networking services, not Key Vault. Likewise, ARM templates are deployment artifacts stored in repositories such as Azure Repos or GitHub; Key Vault does not store or manage template files. Therefore, the two correct actions you can perform with Azure Key Vault---aligned with Microsoft's documentation---are to store (and manage) keys and store (and manage) secrets.
Unlock All Features of Microsoft SC-900 Dumps Software
Just have a look at the best and updated features of our SC-900 dumps which are described in detail in the following tabs. We are very confident that you will get the best deal on this platform.
Select Question Types you want
Set your desired pass percentage
Allocate Time (Hours: Minutes)
Create Multiple Practice test with limited questions
Customer Support
Latest Success Metrics For actual SC-900 Exam
This is the best time to verify your skills and accelerate your career. Check out last week's results, more than 90% of students passed their exam with good scores. You may be the Next successful Candidate.
95%
Average Passing Scores in final Exam
91%
Exactly Same Questions from these dumps
90%
Customers Passed Microsoft SC-900 exam
OUR SATISFIED CUSTOMER REVIEWS
Charlie
July 21, 2026
I wish to express thank PremiumDumps very much for being here. I passed Microsoft SC-900 test with a good score!
Carlos Perez
July 18, 2026
Thank you Premiumdumps for offering the best and quality updated dumps questions and making me the certified Professional.
Leon Müller
July 17, 2026
I wish to share enthusiastically that I have finally advanced the credentials. And this has become possible just because of the Premiumdumps exam preparation material.
Emily Johnson
July 14, 2026
I was so afraid even to attempt Microsoft SC-900 exam, but then fortunately Premiumdumps happened to me like a blessing. I only prepared for the exam, for a week only and performed like an expert. Premiumdumps offered actual dumps to prepare for my certification exam in easy formats. I am really thankful to Premiumdumps for achieving success in my career.
Lily Anne
July 13, 2026
My colleague suggested me to attempt Microsoft SC-900 exam and prepare it with premiumdumps. I feel lucky, I attempted exam only with experts made practice questions
James Henry
July 10, 2026
Premiumdumps made me self-confident and assured with success. Its real exam simulation and self assessment tools helped me to pass SC-900 exam with good grades.
Emma Grace
July 8, 2026
Premiumdumps is a reliable and trustworthy platform, which enabled me to pass SC-900. I am grateful that I only trusted Premiumdumps.