SC-900 domain - 13% of the exam

Security, Compliance, and Identity Concepts

Security, Compliance, and Identity Concepts is 13% of the Microsoft Security, Compliance, and Identity Fundamentals (SC-900) (SC-900) exam. These are the objectives it covers, each with practice questions and worked explanations.

Objectives in this domain

Sample question from this domain

Free sampleSecurity, Compliance, and Identity Conceptseasy

An instructor is explaining the cloud shared responsibility model. Which responsibility area stays with the customer across on-premises, IaaS, PaaS, and SaaS deployments alike?

  • AData and identities, which the customer is responsible for protecting in every deployment type. Correct
  • BThe physical hosts, which the customer is responsible for maintaining in every deployment type.
  • CThe physical datacenter, which the customer is responsible for securing in every deployment type.
  • DThe hypervisor layer, which the customer is responsible for managing in every deployment type.
The customer always retains responsibility for their data and identities, no matter the cloud deployment type. The grounding states that for all cloud deployment types you own your data and identities, and that data and accounts and access management are responsibilities you always retain regardless of the deployment type.

Why A is correct: Correct. The grounding states that for all cloud deployment types you own your data and identities, and that data and accounts and access management are responsibilities you always retain regardless of the deployment type.

Why B is wrong: Physical hosts are a Microsoft responsibility in IaaS, PaaS, and SaaS; only on-premises leaves them with the customer, so they are not always retained.

Why C is wrong: Securing the physical datacenter shifts to Microsoft once you move to any cloud model, so it is not a responsibility the customer always retains.

Why D is wrong: The grounding lists the hypervisor as a Microsoft responsibility for the virtualization layer, so the customer does not retain it.

Other domains in this exam

See also the SC-900 cert hub, the study guide, and the cheat sheet.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.