Courseiva

MS-102 Authentication strengths Practice Question

Your organization, Contoso Ltd., has a Microsoft 365 E5 tenant with Microsoft Entra ID P2. You have 10,000 users and 500 applications. You are planning to implement a comprehensive identity security strategy. Your requirements are: 1. All users must use phishing-resistant MFA for accessing business-critical applications. 2. Users accessing sensitive HR data must be required to use a compliant device. 3. Any authentication attempt from an anonymous IP address or from a country where Contoso has no business operations must be blocked. 4. All external collaboration must be governed by access reviews that require sponsor approval. 5. You need to monitor and respond to identity risks in real time.

You need to design a solution using Microsoft Entra ID features. Which combination of features should you implement?

⚠ Common exam trap

MS-102 often tests the confusion between authentication methods (e.g., certificate-based) and authentication strengths, and between access reviews with group owner approval versus sponsor approval, leading candidates to choose incomplete solutions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy Microsoft Entra ID authentication strengths for phishing-resistant MFA. Create Conditional Access policies requiring compliant device for HR apps and blocking anonymous IPs and non-business countries. Use Microsoft Entra Identity Protection for risk detection and automated response. Implement entitlement management with connected organizations and access reviews requiring sponsor approval.

Option A correctly maps all requirements to Microsoft Entra ID features: authentication strengths for phishing-resistant MFA, Conditional Access for device compliance and location-based blocks, Identity Protection for risk monitoring and automated response, and entitlement management with access reviews for external collaboration governance. This combination leverages the full capabilities of Microsoft Entra ID P2 and E5 licenses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deploy Microsoft Entra ID authentication strengths for phishing-resistant MFA. Create Conditional Access policies requiring compliant device for HR apps and blocking anonymous IPs and non-business countries. Use Microsoft Entra Identity Protection for risk detection and automated response. Implement entitlement management with connected organizations and access reviews requiring sponsor approval.

    Why this is correct

    Authentication strengths enforce phishing-resistant MFA, while Conditional Access applies compliant-device and location blocks. Identity Protection supplies real-time risk detection with automated remediation, and entitlement management with connected organisations plus sponsor-approved access reviews governs external collaboration, meeting all five stated requirements.

  • ✗

    Configure Conditional Access policies with MFA and trusted locations. Use Identity Protection for risk monitoring. Set up access reviews with group owner approval.

    Why it's wrong here

    Conditional Access with MFA and trusted locations does not deliver phishing-resistant methods, and group owner approval is not sponsor approval, so requirements 1 and 4 fail. It is tempting because these features address device compliance and risk monitoring; it would be correct where standard MFA and owner-driven reviews suffice.

  • ✗

    Enable security defaults for all users. Use Microsoft Defender for Cloud Apps to block anonymous IPs. Configure Microsoft Entra ID access reviews for external users.

    Why it's wrong here

    Security defaults enforce only basic MFA, not phishing-resistant authentication, and they cannot express compliant-device or named-location conditions, so requirements 1, 2 and 3 fail. It is tempting because it is free and quick to enable; it would be correct for a small tenant lacking Microsoft Entra ID P1 or P2 licensing.

  • ✗

    Use certificate-based authentication for all users. Create Conditional Access policies for device compliance. Set up identity protection. Use self-service access reviews for external users.

    Why it's wrong here

    Certificate-based authentication satisfies phishing-resistant MFA, but nothing here blocks anonymous IPs or unsanctioned countries, and access reviews lack the sponsor-approval configuration the requirement demands. It is tempting because CBA plus Conditional Access covers most identity hardening; it would be correct where no geo-blocking or sponsor-governed reviews are required.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.