GSEC Windows Services and MS Cloud Practice Question
A company uses Microsoft Entra ID (formerly Azure AD) and has a critical line-of-business application that authenticates users via SAML 2.0. The security team wants to enforce multi-factor authentication (MFA) for this application without affecting other applications. They have Entra ID P1 licenses. What is the most appropriate way to achieve this?
⚠ Common exam trap
A common mix-up: candidates confuse tenant-wide MFA enforcement methods like security defaults with application-specific enforcement, which requires Conditional Access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a Conditional Access policy that targets the specific application and requires MFA for all users.
Conditional Access policies in Entra ID allow administrators to enforce MFA for specific applications and users. This is the most granular and appropriate method when you have Entra ID P1 licenses. Security defaults apply tenant-wide, the per-application MFA setting is deprecated, and authentication method policies do not enforce MFA per application. Therefore, the correct solution is to create a Conditional Access policy targeting the line-of-business application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set up a per-application MFA setting in the Enterprise Applications blade by enabling the 'Require multi-factor authentication' option for the specific application.
Why it's wrong here
The 'Require multi-factor authentication' option in the Enterprise Applications blade is a legacy per-application MFA setting that is being deprecated. It only works for certain application types and does not provide the same level of control as Conditional Access. Moreover, it may not support SAML 2.0 applications in the same way. With Entra ID P1, Conditional Access is the recommended method. This option is incorrect because it relies on an outdated feature and may not meet the requirement.
- ✗
Create a new authentication method policy that restricts MFA to only the users who need access to the application.
Why it's wrong here
Authentication method policies in Entra ID control which authentication methods are available to users, but they do not enforce MFA for specific applications. They are used to manage methods like FIDO2 keys or Microsoft Authenticator. To enforce MFA for a specific app, a Conditional Access policy is required. This option is incorrect because it misidentifies the purpose of authentication method policies and does not achieve the goal.
- ✓
Configure a Conditional Access policy that targets the specific application and requires MFA for all users.
Why this is correct
Conditional Access policies in Entra ID allow granular control over authentication requirements, including the ability to target specific cloud applications. By creating a policy that includes the line-of-business application as the target and requires MFA, the security team can enforce MFA only for that app. This approach leverages Entra ID P1 features and does not affect other applications. It is the recommended method for per-application MFA enforcement.
- ✗
Enable security defaults in Entra ID, which will automatically enforce MFA for all users and applications.
Why it's wrong here
Security defaults are a set of baseline security settings that enforce MFA for all users, but they apply tenant-wide and cannot be scoped to a single application. Enabling security defaults would affect all applications and might disrupt other business processes. Additionally, security defaults are intended for organizations without Conditional Access, and since the company has P1 licenses, Conditional Access is the more appropriate and granular solution. This option is incorrect because it lacks the required granularity.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.