MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Exhibit
Refer to the exhibit.
```json
{
"policy": {
"name": "Block risky sign-ins",
"conditions": {
"userRiskLevels": ["high"],
"signInRiskLevels": ["medium", "high"]
},
"grantControls": {
"builtInControls": ["block"]
}
}
}
```You are reviewing a conditional access policy in Microsoft Entra ID as shown in the exhibit. The policy is intended to block sign-ins that are considered risky. However, some high-risk users are still able to sign in. What is the most likely reason?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy requires both user risk and sign-in risk to be at specified levels simultaneously
The conditional access policy only blocks sign-ins when both user risk is high AND sign-in risk is medium or high. If a user has high user risk but low sign-in risk, the policy does not apply, allowing them to sign in. Options A, B, and C are incorrect: A states both must be high, but the policy may require medium or high for sign-in risk; B is not about MFA; C is wrong because sign-in risk levels are included.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy requires user risk and sign-in risk to both be high
Why it's wrong here
The policy's sign-in risk condition is explicitly configured for Medium and High, not High alone. This means a sign-in risk of Medium already satisfies the sign-in risk requirement, so the policy does not require both user risk and sign-in risk to be High. The statement overstates the threshold and would incorrectly exclude scenarios that the policy actually blocks.
- ✗
The policy requires multi-factor authentication instead of blocking
Why it's wrong here
The policy's access control is set to 'Block access,' not to 'Require multi-factor authentication.' When the risk conditions are met, the user's sign-in is denied, not prompted for additional verification. MFA is a different grant control and is not part of this policy's configuration.
- ✗
The policy does not include sign-in risk levels
Why it's wrong here
The policy is a risk-based Conditional Access policy; its condition set explicitly includes sign-in risk, with the levels Medium and High selected. Therefore, the claim that sign-in risk levels are not included is incorrect. The policy also includes user risk as a separate, concurrently evaluated condition.
- ✓
The policy requires both user risk and sign-in risk to be at specified levels simultaneously
Why this is correct
The policy applies only when both the user risk and sign-in risk conditions are satisfied at the same time, because the conditions are joined with AND logic. For example, even if user risk is High, a sign-in risk of Low prevents the policy from triggering. This simultaneous requirement is the key to understanding when the block control will be enforced.
Go deeper
Related to this question
Learn chapter
Entra Connect Sync Rules and Filtering
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on MS-102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You are reviewing a Conditional Access policy in Microsoft Entra ID. The policy is intended to block access to Exchange Online for users with high risk level. However, users with high risk are still able to access Exchange Online. What is the most likely cause?
easy- A.The policy does not include Exchange Online.
- B.The policy excludes the affected users.
- C.The policy is targeting low risk instead of high risk.
- ✓ D.The policy is set to report-only mode.
- E.The grant control is set to require multi-factor authentication.
Why D: Report-only mode evaluates the policy but does not enforce it, so high-risk users are not blocked. Option D is correct because the policy is likely set to report-only mode. Option A is wrong because the policy includes Exchange Online. Option B is wrong because the policy does not exclude the affected users. Option C is wrong because the policy targets high risk, not low risk. Option E is wrong because the grant control is block, not require MFA.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.