Courseiva
Security ArchitectureeasyMultiple SelectObjective-mapped

SY0-701 Security Architecture Practice Question

A company wants employees to use their normal login from managed devices but require extra verification when they sign in from an unmanaged laptop or a new location. Which two controls should the team use? Select two.

⚠ Common exam trap

The trap here is that candidates often pick MFA alone, forgetting that MFA is only enforced when a conditional access policy triggers it based on device or location conditions, so both controls are needed together.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conditional access

Conditional access (A) is correct because it allows the company to define policies that grant or block access based on conditions such as device compliance (managed vs. unmanaged) and location (trusted vs. new). Multi-factor authentication (B) is correct because it provides the extra verification step required when the conditional access policy detects an unmanaged laptop or a new location, ensuring the user proves their identity beyond just a password.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conditional access

    Why this is correct

    Conditional access is an identity-driven policy engine in Microsoft Entra ID that evaluates real-time signals such as user location, device compliance, and risk before granting access. Instead of applying a one-size-fits-all rule, it can require step-up authentication, block access, or restrict sessions based on conditions like a managed or unmanaged device. This makes it the most appropriate control for requiring different sign-in conditions based on context.

  • Multi-factor authentication

    Why this is correct

    Multi-factor authentication is a strong identity security control that adds a second proof of identity, such as a biometric, security key, or one-time code, beyond just a password. It does reduce the risk of compromised credentials, but it does not inherently evaluate device trust, geolocation, or real-time risk to decide when to trigger that extra step. MFA is often a required action within a conditional access policy, rather than a standalone policy engine that adapts sign-in rules.

  • DNS filtering

    Why it's wrong here

    DNS filtering works by intercepting DNS queries and blocking resolution to known malicious or undesirable domains, effectively preventing users from reaching certain websites. It does not analyze authentication attempts, device posture, or sign-in risk, and it cannot require additional verification or deny access based on user identity or device state. Therefore, it is an endpoint security control, not an identity access control.

  • Disk encryption

    Why it's wrong here

    Disk encryption, such as BitLocker or FileVault, protects data at rest by encrypting the storage drive and requiring a decryption key or recovery code at boot. It ensures that a stolen disk or device cannot have its data read, but it has no influence over the sign-in process or the trust level of a device during authentication. Disk encryption is a data-protection measure, not a mechanism for enforcing conditional access.

  • Port security

    Why it's wrong here

    Port security is a switch-level layer 2 feature that restricts network access by allowing only authorized MAC addresses to connect to a specific switchport. It can be used to control which physical devices can plug into the network, but it does not evaluate user identity, application access, or sign-in risk. Port security operates at the network infrastructure layer, not at an identity provider layer, so it cannot implement context-aware authentication policies.

Go deeper

Related to this question

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.