SC-900 Security, Compliance, and Identity Fundamentals Study Guide

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/45

flashcard set

Earn XP

Description and Tags

Comprehensive set of vocabulary flashcards covering key security, compliance, identity, Entra, Defender, Purview, and Sentinel concepts for the SC-900 exam.

Last updated 4:05 PM on 9/3/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

46 Terms

1
New cards

Shared Responsibility Model

A cloud security model where Microsoft secures physical datacenters, hardware, and foundational platform, while customers always retain responsibility for their data, identities, accounts, endpoint configuration, and access decisions.

2
New cards

Defense in Depth

A security strategy using multiple independent layers of defense—physical, identity and access, perimeter, network, compute, application, and data—so that if one control fails, another limits damage.

3
New cards

Zero Trust

A security model guided by three principles: verify explicitly, use least privilege, and assume breach. Trust is evaluated continuously using identity, device, location, risk, application, and data signals.

4
New cards

Encryption

A reversible process that uses a key to protect data confidentiality both at rest and in transit.

5
New cards

Hashing

A one-way cryptographic process that generates a unique value used to support integrity checks and password verification.

6
New cards

Governance, Risk, and Compliance (GRC)

A framework where Governance sets direction and accountability, Risk Management identifies and treats uncertainty, and Compliance demonstrates alignment with laws, regulations, contracts, and internal requirements.

7
New cards

Authentication

The process of proving who or what an identity is.

8
New cards

Authorization

The process that determines what resources or actions an identity is allowed to access.

9
New cards

Federation

A configuration that creates a trust relationship between identity systems, allowing users to access resources across organizational boundaries.

10
New cards

Microsoft Entra ID

Microsoft's cloud identity and access management service that manages authentication, authorization, SSO, application access, devices, and identity governance.

11
New cards

Workload Identities

Identity types that represent non-human applications and services, commonly implemented as service principals or managed identities.

12
New cards

Hybrid Identity

An identity configuration that connects on-premises directories with Microsoft Entra ID to provide a consistent identity across local and cloud resources.

13
New cards

Multifactor Authentication (MFA)

An authentication process that requires two or more different factor categories: knowledge (e.g., passwords), possession (e.g., phones/security keys), or inherence (e.g., biometrics).

14
New cards

Self-Service Password Reset (SSPR)

A Microsoft Entra capability that allows users to reset or unlock their own accounts after completing identity verification.

15
New cards

Conditional Access

An if-then policy engine in Microsoft Entra that evaluates contextual signals (user, app, device, location, risk) to enforce decisions like allow, block, require MFA, or limit session access.

16
New cards

Entitlement Management

A Microsoft Entra identity governance feature that packages resources along with approval and lifecycle access rules into access packages.

17
New cards

Access Reviews

A feature in Microsoft Entra identity governance used to periodically reconfirm that user access to resources or groups is still required.

18
New cards

Privileged Identity Management (PIM)

A service that controls privileged administrative roles by providing just-in-time, time-limited, and approval-capable role activation.

19
New cards

Microsoft Entra ID Protection

An identity security service that detects and helps remediate identity risks, specifically identifying risky users and risky sign-ins.

20
New cards

Azure DDoS Protection

A network defense service designed to mitigate large-scale, volumetric network attacks.

21
New cards

Azure Firewall

A managed, stateful network firewall service that filters traffic across Azure resources.

22
New cards

Web Application Firewall (WAF)

A security solution that protects web applications from common web vulnerabilities and attacks, such as SQL injection and cross-site scripting.

23
New cards

Network Security Groups (NSG)

Azure security controls used to allow or deny inbound and outbound network traffic at the subnet or network interface level.

24
New cards

Azure Bastion

A service providing secure, browser-based RDP and SSH connectivity directly to virtual machines without exposing public IP addresses.

25
New cards

Azure Key Vault

A centralized cloud service for securely storing and managing application secrets, encryption keys, and certificates.

26
New cards

Microsoft Defender for Cloud

A cloud-native security management tool combining Cloud Security Posture Management (CSPM) and cloud workload protection across Azure, multi-cloud, and on-premises environments.

27
New cards

Cloud Security Posture Management (CSPM)

A capability in Microsoft Defender for Cloud that assesses resource configurations against standards, provides a posture score, and gives recommendations for hardening.

28
New cards

Microsoft Sentinel

A cloud-native SIEM and SOAR solution used for centralizing, analyzing, hunting, and automatically responding to security data across the enterprise.

29
New cards

SIEM (Security Information and Event Management)

A technology category that aggregates and correlates security data from across an organization to support threat detection, investigation, and hunting.

30
New cards

SOAR (Security Orchestration, Automation, and Response)

A capability that uses automated workflows (such as playbooks) to orchestrate and execute response actions to security incidents.

31
New cards

Microsoft Defender XDR

An integrated security operations solution that correlates threat signals across endpoints, identities, email/collaboration, and cloud apps into unified incidents.

32
New cards

Microsoft Defender for Endpoint

A component of Microsoft Defender XDR that delivers security, threat prevention, and response for client devices and servers.

33
New cards

Microsoft Defender for Office 365

A security product that protects organizations against threats in email, links, and collaboration tools.

34
New cards

Microsoft Defender for Identity

A security solution that monitors identity signals from Active Directory environments to identify and investigate advanced threats.

35
New cards

Microsoft Defender for Cloud Apps

A cloud access security broker (CASB) offering visibility, governance, and protection across SaaS application usage.

36
New cards

Microsoft Defender Vulnerability Management

A solution that discovers, assesses, prioritizes, and helps remediate software weaknesses and misconfigurations on endpoints.

37
New cards

Service Trust Portal

A Microsoft resource site providing audit reports, compliance documentation, and trust publications.

38
New cards

Microsoft Purview

A comprehensive suite of capabilities designed to bring together data security, data governance, risk management, and compliance.

39
New cards

Compliance Manager

A tool in Microsoft Purview that maps controls to compliance requirements, tracks improvement actions, and calculates a compliance score.

40
New cards

Content Explorer

A Microsoft Purview tool that allows authorized users to view items containing sensitive information types or applied sensitivity/retention labels.

41
New cards

Activity Explorer

A Microsoft Purview capability that tracks and displays user actions taken on labeled or sensitive content.

42
New cards

Sensitivity Labels

Purview tags used to classify and protect content by enforcing encryption, visual markings, access restrictions, or container settings.

43
New cards

Data Loss Prevention (DLP)

A security policy engine in Microsoft Purview that monitors sensitive data and can audit, warn, block, or restrict risky sharing and usage across workloads.

44
New cards

Retention Policies

Broad lifecycle rules applied across entire locations or workloads to preserve or delete content based on organizational requirements.

45
New cards

Retention Labels

Item-level lifecycle controls applied directly to specific files or emails to manage their retention or deletion schedules.

46
New cards

Records Management

A specialized Purview compliance capability that provides stricter lifecycle and retention governance controls specifically for declared records and regulatory records.