Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Exhibit

Refer to the exhibit.
```json
{
  "policy": {
    "name": "Block risky sign-ins",
    "conditions": {
      "userRiskLevels": ["high"],
      "signInRiskLevels": ["medium", "high"]
    },
    "grantControls": {
      "builtInControls": ["block"]
    }
  }
}
```

You are reviewing a conditional access policy in Microsoft Entra ID as shown in the exhibit. The policy is intended to block sign-ins that are considered risky. However, some high-risk users are still able to sign in. What is the most likely reason?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy requires both user risk and sign-in risk to be at specified levels simultaneously

The conditional access policy only blocks sign-ins when both user risk is high AND sign-in risk is medium or high. If a user has high user risk but low sign-in risk, the policy does not apply, allowing them to sign in. Options A, B, and C are incorrect: A states both must be high, but the policy may require medium or high for sign-in risk; B is not about MFA; C is wrong because sign-in risk levels are included.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The policy requires user risk and sign-in risk to both be high

    Why it's wrong here

    The policy's sign-in risk condition is explicitly configured for Medium and High, not High alone. This means a sign-in risk of Medium already satisfies the sign-in risk requirement, so the policy does not require both user risk and sign-in risk to be High. The statement overstates the threshold and would incorrectly exclude scenarios that the policy actually blocks.

  • ✗

    The policy requires multi-factor authentication instead of blocking

    Why it's wrong here

    The policy's access control is set to 'Block access,' not to 'Require multi-factor authentication.' When the risk conditions are met, the user's sign-in is denied, not prompted for additional verification. MFA is a different grant control and is not part of this policy's configuration.

  • ✗

    The policy does not include sign-in risk levels

    Why it's wrong here

    The policy is a risk-based Conditional Access policy; its condition set explicitly includes sign-in risk, with the levels Medium and High selected. Therefore, the claim that sign-in risk levels are not included is incorrect. The policy also includes user risk as a separate, concurrently evaluated condition.

  • ✓

    The policy requires both user risk and sign-in risk to be at specified levels simultaneously

    Why this is correct

    The policy applies only when both the user risk and sign-in risk conditions are satisfied at the same time, because the conditions are joined with AND logic. For example, even if user risk is High, a sign-in risk of Low prevents the policy from triggering. This simultaneous requirement is the key to understanding when the block control will be enforced.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on MS-102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You are reviewing a Conditional Access policy in Microsoft Entra ID. The policy is intended to block access to Exchange Online for users with high risk level. However, users with high risk are still able to access Exchange Online. What is the most likely cause?

easy
  • A.The policy does not include Exchange Online.
  • B.The policy excludes the affected users.
  • C.The policy is targeting low risk instead of high risk.
  • ✓ D.The policy is set to report-only mode.
  • E.The grant control is set to require multi-factor authentication.

Why D: Report-only mode evaluates the policy but does not enforce it, so high-risk users are not blocked. Option D is correct because the policy is likely set to report-only mode. Option A is wrong because the policy includes Exchange Online. Option B is wrong because the policy does not exclude the affected users. Option C is wrong because the policy targets high risk, not low risk. Option E is wrong because the grant control is block, not require MFA.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.