TechNuggets Academy

Describe the concepts of security, compliance, and identity

Free Microsoft Certified: Security, Compliance, and Identity Fundamentals practice — 6 questions on Describe the concepts of security, compliance, and identity, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Describe the concepts of security, compliance, and identity
A company uses Microsoft 365 (a SaaS offering) exclusively and has no on-premises infrastructure. Under the shared responsibility model, who is responsible for classifying company data and configuring the access permissions that control who can view it?
Regardless of cloud model (IaaS, PaaS, or SaaS), the customer always retains responsibility for data classification, information/data governance, and access management — this responsibility never shifts to the provider.
Question 2 of 6 · Describe the concepts of security, compliance, and identity
A security team redesigns its network so that a compromised device or credential cannot move laterally to reach other systems, and they continuously monitor for anomalous activity assuming an attacker may already be inside the environment. Which Zero Trust guiding principle does this design primarily reflect?
'Assume breach' means designing systems and segmenting access as if an attacker has already gained a foothold, minimizing blast radius and enabling continuous detection — exactly what is described.
Question 3 of 6 · Describe the concepts of security, compliance, and identity
Which statement accurately describes cryptographic hashing as used in security scenarios such as password storage?
Hashing is a one-way function: identical input always yields an identical fixed-length hash value, but the process cannot be reversed to recover the original data — this is why it's used to verify integrity and store passwords securely.
Question 4 of 6 · Describe the concepts of security, compliance, and identity
A user successfully signs in to a corporate network using their username, password, and a mobile app approval prompt. Moments later, they attempt to open a file on a restricted network share and receive an 'Access Denied' message. Which security process is responsible for the denial?
Authorization determines what an already-authenticated identity is permitted to do or access; the denial occurs after successful sign-in, meaning the user's permissions — not their identity — caused the failure.
Question 5 of 6 · Describe the concepts of security, compliance, and identity
Contoso wants its employees to sign in with their existing on-premises Active Directory credentials to access a partner organization's cloud application, without the partner ever storing or seeing Contoso employees' passwords. Which concept enables this cross-organizational trust relationship between the two identity providers?
Federation establishes a trust relationship between two separate identity providers (Contoso's AD and the partner's IdP) so that authentication tokens issued by one are trusted by the other, without sharing or exposing credentials.
Question 6 of 6 · Describe the concepts of security, compliance, and identity
In a modern Zero Trust architecture, identity is described as the 'primary security perimeter.' This concept represents a shift away from relying primarily on which traditional security boundary?
Traditional security models assumed everything inside the corporate network firewall was trusted. Zero Trust shifts the perimeter to identity, since users now access resources from anywhere, on any device, over the internet — making network location an unreliable trust signal.
Ready for the real thing?

The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.

undefined $34.99 with code FREETEST33 — valid through Oct 6.

Get my $34.99 deal →