Last updated: May 2026
SC-730 — Cybersecurity Business Professional (beta)
Test your knowledge with official exam-style questions
Questions and options are shuffled each attempt
▶Microsoft Certified: Cybersecurity Business Professional (beta) — Practice Set 1: All Questions & Explanations
Full question text, answer options, and explanations for this practice set — a spoiler-free alternative is the interactive quiz above for scored, shuffled practice.
1. Your manager explains that the organization's cloud services are protected by both Microsoft and your IT team. What is the term for the security model that divides security responsibilities between a cloud provider and the customer?
- A. Zero Trust model
- B. Shared responsibility model(correct)
- C. Perimeter security model
- D. Defense-in-depth model
Explanation: The shared responsibility model defines that cloud security is a partnership between the cloud provider (Microsoft) and the customer. Microsoft handles physical security and infrastructure, while customers are responsible for their data, identities, and applications depending on the service model (IaaS, PaaS, SaaS). As a business professional, understanding this helps you know what your organization is responsible for protecting.
2. A colleague asks what the term 'vulnerability' means in cybersecurity. Which definition is correct?
- A. A weakness in a system that could be exploited to cause harm(correct)
- B. A specific attack carried out against a system
- C. A tool used by attackers to gain unauthorized access
- D. The likelihood that a security incident will occur
Explanation: A vulnerability is a weakness or flaw in a system, process, or control that could be exploited by a threat actor. A threat is the potential for something to exploit the vulnerability. Risk is the likelihood and impact of the threat being realized. An exploit is the actual code or technique used to take advantage of a vulnerability.
3. Your organization experienced a ransomware attack that encrypted all files on shared drives, halting business operations for three days. Which term best describes the outcome of this security event?
- A. A vulnerability assessment
- B. The impact of a security event(correct)
- C. A compliance violation
- D. A phishing simulation
Explanation: The three-day operational halt and data encryption represent the impact of the ransomware security event. Ransomware encrypts files and demands payment for the decryption key. The impact includes operational disruption, financial loss, reputational damage, and recovery costs. Understanding impact helps business professionals appreciate why cybersecurity investment is critical.
4. Your IT security team is presenting at an all-hands meeting. They explain that employees play a critical role in the organization's cybersecurity posture. Which two activities demonstrate employee participation in security awareness initiatives? Choose 2.
- A. Completing mandatory annual security awareness training(correct)
- B. Sharing passwords with team members for convenience
- C. Reporting a suspicious email to the IT security team(correct)
- D. Disabling antivirus software to speed up a computer
- E. Using the same password for all work and personal accounts
Explanation: Completing security awareness training and reporting suspicious emails are two key ways employees actively contribute to organizational cybersecurity. Security awareness training educates employees on threats and best practices. Promptly reporting suspicious emails helps the security team identify and contain potential phishing attacks before they spread. The other options (sharing passwords, disabling antivirus, password reuse) all create security risks.
5. Your organization requires all employees to use multifactor authentication (MFA) when accessing company applications. Which security benefit does MFA provide?
- A. It eliminates the need for strong passwords
- B. It requires attackers to compromise multiple verification factors to gain access(correct)
- C. It automatically detects and blocks all phishing emails
- D. It prevents users from accessing systems from mobile devices
Explanation: Multifactor authentication (MFA) requires users to provide two or more verification factors (something you know, something you have, something you are) to access a resource. Even if an attacker obtains a user's password, they still cannot access the account without the additional factor (such as an authenticator app code or fingerprint). MFA significantly reduces the risk of account compromise from phishing and credential theft.
6. Your organization uses an AI-powered chat tool to assist with business writing. The security team has issued a policy prohibiting employees from entering certain types of data into AI tools. Which type of data should NOT be entered into AI productivity tools?
- A. General industry news articles
- B. Proprietary product roadmaps and customer personally identifiable information (PII)(correct)
- C. Publicly available marketing copy
- D. Generic meeting agenda templates
Explanation: Proprietary product information and customer PII should never be entered into AI tools, particularly external or consumer-grade AI services. This data could be stored by the AI provider, used to train models, or exposed to other users. Regulatory requirements (GDPR, HIPAA) also restrict how PII can be shared with third parties. Employees should follow organizational AI usage policies to protect sensitive and confidential information.
7. You are a project manager. You work primarily from home and frequently connect to client systems and your organization's cloud applications. Your security team warns you about the specific risks of a remote work environment. Which risk is most relevant to your situation?
- A. Increased risk of physical theft of office equipment from your desk
- B. Using unsecured home networks and personal devices that may lack enterprise security controls(correct)
- C. Being unable to access cloud applications without a VPN
- D. Colleagues being able to see your screen in a shared office
Explanation: Remote work environments introduce risks including use of home Wi-Fi networks that may lack enterprise-grade security, use of personal devices without endpoint protection, and reduced visibility by the IT security team. Home routers may have default or weak passwords and lack features like network segmentation. These risks make remote workers attractive targets for attackers attempting to pivot into the corporate network.
8. You receive an email that appears to be from your bank, asking you to click a link and verify your account details due to suspicious activity. What type of attack is this?
- A. Malware
- B. Phishing(correct)
- C. Ransomware
- D. Baiting
Explanation: Phishing is a social engineering attack where attackers send fraudulent messages (often emails) that appear to come from a trusted source to trick recipients into revealing sensitive information or clicking malicious links. This email mimics a legitimate bank communication to create urgency and prompt the victim to submit their credentials on a fake website. Malware is malicious software, ransomware encrypts data for ransom, and baiting uses physical or digital lures.
9. You are working at a coffee shop and connect your laptop to the free public Wi-Fi. You then access your company's web-based email. What is the primary security risk of this action?
- A. Your laptop battery drains faster on public networks
- B. Attackers on the same network may intercept your unencrypted traffic(correct)
- C. Your internet connection speed will be too slow to use email
- D. The coffee shop may charge you for using their network
Explanation: Public Wi-Fi networks are often unencrypted and shared with strangers. Attackers can use tools to conduct man-in-the-middle attacks, intercepting network traffic between your device and the access point. This could expose credentials, sensitive data, and session tokens. To mitigate this risk, employees should use a VPN when connecting to company resources over public networks, and avoid accessing sensitive data on public Wi-Fi.
10. You receive a call from someone claiming to be from Microsoft technical support. The caller says your computer has been sending error messages to Microsoft and they need remote access to fix it immediately. You did not initiate this call. What type of attack is this?
- A. Baiting
- B. Phishing
- C. Pretexting(correct)
- D. Ransomware
Explanation: Pretexting is a social engineering technique where an attacker creates a fabricated scenario (pretext) to manipulate a victim into providing information or access. In this case, the attacker poses as Microsoft support and creates a false urgent scenario about computer errors to gain remote access. Baiting uses physical media or enticing offers, phishing typically involves email or messages, and ransomware is malware that encrypts files.
11. Your computer has become noticeably slower, displays pop-up advertisements constantly, and your browser redirects to unfamiliar websites. What do these symptoms indicate?
- A. Your computer needs a hardware upgrade
- B. Your computer may be infected with malware(correct)
- C. Your internet service provider is throttling your connection
- D. You have too many browser tabs open
Explanation: Slow performance, unexpected pop-ups, and browser redirections are classic symptoms of a malware infection. Malware (malicious software) includes viruses, adware, spyware, and trojans. Adware in particular generates pop-up advertisements, while some malware modifies browser settings to redirect traffic. If these symptoms appear, you should immediately contact your IT support team rather than continuing to use the device for sensitive tasks.
12. Your organization's security team informs you that an employee in your department may be an insider threat. Which behavior is a potential indicator of malicious insider activity?
- A. Taking three weeks of approved annual leave
- B. Accessing and downloading large volumes of data outside of normal working hours without a business justification(correct)
- C. Regularly using the company VPN when working from home
- D. Requesting access to a new system needed for a project
Explanation: Accessing and downloading large volumes of data outside of normal working hours with no business justification is a potential indicator of insider threat activity, such as data exfiltration before leaving the organization or stealing intellectual property. Insider threats can be malicious (intentional harm) or accidental (unintentional policy violations). Security teams monitor for anomalous access patterns to detect these behaviors.
13. You are an account manager. You receive an email from what appears to be your CFO's email address asking you to urgently process a wire transfer to a new vendor account. The CFO is away at a conference. The email says not to call to confirm because they are in meetings. What should you do?
- A. Process the transfer immediately because it came from the CFO's email address
- B. Verify the request through a separate communication channel such as a direct phone call, and report the email to IT security(correct)
- C. Reply to the email asking for more details before processing
- D. Forward the email to another colleague to handle
Explanation: This is a Business Email Compromise (BEC) or spear phishing attack. Attackers compromise or spoof executive email accounts to trick employees into making fraudulent wire transfers. The request to not call is a red flag designed to prevent verification. The correct response is to verify using a different, trusted communication channel (such as calling the CFO's known mobile number) and to report the suspicious email to IT security. Never use contact information provided within a suspicious email.
14. Your security awareness training covers how to identify suspicious emails. Which two characteristics indicate that an email may be malicious? Choose 2.
- A. A sender domain that closely resembles your organization's domain but contains slight misspellings (e.g., contoso-corp.com instead of contoso.com)(correct)
- B. The email is sent from a person you work with regularly
- C. A hyperlink that displays one URL in the visible text but points to a different URL when you hover over it(correct)
- D. The email contains your organization's logo
- E. The email was received during normal business hours
Explanation: A domain that closely mimics a legitimate domain (homograph or typosquatting attack) and a hyperlink where the visible text differs from the actual destination URL are both strong indicators of a phishing or malicious email. Attackers use these techniques to deceive recipients. The presence of a familiar sender, company logo, or timing of receipt are not reliable indicators of legitimacy, as attackers can spoof all of these.
15. A security researcher explains the concept of deepfakes to your team. Which statement best describes what a deepfake is and its potential security risk?
- A. A deepfake is a sophisticated malware that deletes files from your computer
- B. A deepfake is AI-generated synthetic media that realistically depicts a real person saying or doing something they did not, which can be used to spread misinformation or conduct social engineering attacks(correct)
- C. A deepfake is a fake website designed to look like a legitimate bank or organization
- D. A deepfake is a type of man-in-the-middle attack on network traffic
Explanation: Deepfakes are highly realistic synthetic media (video, audio, or images) created using artificial intelligence to make it appear that a real person is saying or doing something they never actually did. In cybersecurity, deepfakes represent an emerging threat vector for business email compromise, social engineering, and disinformation campaigns. For example, a deepfake audio of a CEO's voice could be used to instruct an employee to perform a fraudulent financial transfer.
16. Your IT department requires all employees to use unique, complex passwords for each system. Your manager recommends a tool that generates and stores all your passwords securely. Which type of tool is being recommended?
- A. Antivirus software
- B. Password manager(correct)
- C. VPN client
- D. Firewall
Explanation: A password manager generates, stores, and auto-fills strong, unique passwords for each account. This allows employees to have complex, unique passwords for every system without needing to memorize them, eliminating the temptation to reuse simple passwords. Password managers typically encrypt the password vault with a single master password or biometric authentication.
17. Your compliance officer explains that an HR document you are preparing contains employee salary and performance data. How should you classify this document according to your organization's data sensitivity labeling policy?
- A. Public — no special handling required
- B. Confidential or Highly Confidential, as it contains personal and sensitive employee information(correct)
- C. General — available to all employees
- D. External — safe to share outside the organization
Explanation: Employee salary, performance, and personal data is sensitive information that requires a higher classification level such as Confidential or Highly Confidential under most organizational data classification policies. Documents classified at this level typically require encryption, restricted sharing, and audit trails. Misclassifying sensitive data as Public or General can lead to unauthorized access and potential regulatory violations.
18. You are an analyst who works with large spreadsheets containing customer financial records. You need to send a summary report to a partner organization. What is the correct data-handling approach?
- A. Attach the full customer database file to a standard email
- B. Remove or pseudonymize personal customer data from the report before sharing, and use encrypted file transfer(correct)
- C. Upload the file to a personal cloud storage account and share the link
- D. Print the data and mail a physical copy
Explanation: When sharing data with external parties, you should follow the principle of data minimization: only include the minimum necessary information. Personally identifiable customer financial data should be removed or pseudonymized before external sharing. Using encrypted file transfer (such as approved secure file sharing platforms) ensures the data is protected in transit. Sending full customer databases via standard email or personal cloud storage violates data protection policies and may breach regulations like GDPR.
19. Your IT team sends a notification requiring you to install a critical operating system security patch. You are busy with an important project. What should you do?
- A. Delay the update until your project is complete, as updates can cause system disruptions
- B. Install the security patch as soon as possible, as it closes known vulnerabilities being actively exploited(correct)
- C. Ignore the notification if your computer seems to be working fine
- D. Disable automatic updates to prevent future interruptions
Explanation: Security patches fix known vulnerabilities in software and operating systems. Attackers frequently exploit unpatched systems using known vulnerabilities — sometimes within hours of a patch being released (the time it takes attackers to reverse-engineer the patch and create an exploit). Delaying patches significantly increases your organization's risk exposure. Critical security patches should be installed promptly, scheduling a restart during a convenient time if necessary.
20. Your organization's backup and recovery policy requires all employees to follow specific practices to support data recovery in case of a ransomware attack. Which two actions should employees take to support effective data recovery? Choose 2.
- A. Save all work files to approved company cloud storage or network drives that are regularly backed up(correct)
- B. Store all work files only on the local hard drive of their laptop
- C. Follow the organization's data retention and storage policies for backup-eligible locations(correct)
- D. Delete old files regularly to reduce backup storage costs
- E. Disable OneDrive sync to reduce bandwidth usage
Explanation: Saving files to approved cloud storage (such as OneDrive or SharePoint) or organizational network drives ensures they are covered by the organization's backup schedule. Following data retention and storage policies ensures that files are stored in backup-eligible locations. Storing files only on local drives (which may not be backed up) or disabling sync creates single points of failure. In a ransomware attack, backed-up data can be restored without paying the ransom.
21. Your organization applies information rights management (IRM) to sensitive documents. A document marked with IRM restrictions is emailed to an external recipient who is not authorized. What will happen?
- A. The recipient will be able to open, edit, and forward the document freely
- B. The document's protection travels with it, and the unauthorized recipient will be unable to open it without the appropriate permissions(correct)
- C. IRM protection only works within the organization's internal network
- D. The document will automatically be deleted when forwarded outside the organization
Explanation: Information Rights Management (IRM) applies encryption and usage restrictions directly to documents. These protections travel with the document regardless of where it is stored or shared. An unauthorized recipient attempting to open an IRM-protected document will be denied access because the decryption keys and usage permissions are controlled by the organization's rights management server, not the email or file system. This prevents unauthorized access even after documents are accidentally or deliberately shared inappropriately.
22. You are logging into your organization's HR system from your personal laptop at home. Your organization's security policy requires you to take specific precautions in this situation. What should you do?
- A. Connect using your personal email account as login credentials
- B. Use the organization's approved VPN or virtual desktop, and ensure your device meets security requirements(correct)
- C. Use a browser in incognito mode, as this provides full security protection
- D. No additional precautions are needed as the HR system uses HTTPS
Explanation: When accessing sensitive organizational systems from personal devices, employees should use the organization's approved VPN or virtual desktop infrastructure (VDI) to create a secure, encrypted connection and ensure access goes through the organization's security controls. Personal devices may lack required security software, endpoint protection, or patch levels. Incognito mode only prevents local browser history storage and does not provide network security. HTTPS encrypts data in transit but does not protect the endpoint.
23. You notice that your work laptop has been lost or stolen on your commute. What should you do first?
- A. Wait to see if the laptop turns up before reporting it
- B. Buy a replacement laptop and continue working
- C. Report the lost or stolen device to your IT security team or help desk immediately(correct)
- D. Change your email password from your personal device and consider the matter resolved
Explanation: A lost or stolen work device must be reported to IT security immediately. The IT team can remotely wipe the device, revoke its access to organizational systems, and investigate what data may have been at risk. Delaying reporting increases the window during which an attacker with the device could access organizational systems or data. Changing only your email password is insufficient, as the device may have cached credentials for multiple systems.
24. You are working on your computer when a pop-up message appears stating that all your files have been encrypted and you must pay a ransom in cryptocurrency within 24 hours to recover them. What are the correct immediate actions to take?
- A. Pay the ransom immediately to recover your files before the deadline
- B. Disconnect your device from the network immediately, do not pay the ransom, and report the incident to IT security(correct)
- C. Try to remove the ransomware yourself using free tools found online
- D. Restart your computer and hope the ransomware goes away
Explanation: The correct immediate response to ransomware is: (1) Disconnect from the network immediately to prevent the ransomware from spreading to other systems and network shares. (2) Do not pay the ransom — there is no guarantee files will be recovered, it funds criminal activity, and it may make you a future target. (3) Report to IT security immediately so they can contain the incident, assess scope, and begin recovery from backups. Attempting self-remediation can destroy forensic evidence and worsen the situation.
25. Your organization requires all security incident reports to include specific information. You are reporting a phishing email that you clicked before realizing it was malicious. Which set of information should your incident report include?
- A. Only the sender's email address
- B. The date and time of the incident, description of what occurred, the phishing email (forwarded as an attachment), any links clicked or data entered, and the systems or accounts that may be affected(correct)
- C. Your personal assessment of whether any data was compromised
- D. Only a verbal description shared in the next team meeting
Explanation: A thorough security incident report should include: date and time of the incident, a detailed description of what happened, the original phishing email as evidence, information about what actions were taken (links clicked, credentials entered), and identification of potentially affected systems or accounts. This information allows the security team to assess scope, contain any breach, collect forensic evidence, and determine whether escalation or regulatory notification is required.