MS-102 Authentication strengths Practice Question
Your organization, Contoso Ltd., has a Microsoft 365 E5 tenant with Microsoft Entra ID P2. You have 10,000 users and 500 applications. You are planning to implement a comprehensive identity security strategy. Your requirements are: 1. All users must use phishing-resistant MFA for accessing business-critical applications. 2. Users accessing sensitive HR data must be required to use a compliant device. 3. Any authentication attempt from an anonymous IP address or from a country where Contoso has no business operations must be blocked. 4. All external collaboration must be governed by access reviews that require sponsor approval. 5. You need to monitor and respond to identity risks in real time.
You need to design a solution using Microsoft Entra ID features. Which combination of features should you implement?
⚠ Common exam trap
MS-102 often tests the confusion between authentication methods (e.g., certificate-based) and authentication strengths, and between access reviews with group owner approval versus sponsor approval, leading candidates to choose incomplete solutions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy Microsoft Entra ID authentication strengths for phishing-resistant MFA. Create Conditional Access policies requiring compliant device for HR apps and blocking anonymous IPs and non-business countries. Use Microsoft Entra Identity Protection for risk detection and automated response. Implement entitlement management with connected organizations and access reviews requiring sponsor approval.
Option A correctly maps all requirements to Microsoft Entra ID features: authentication strengths for phishing-resistant MFA, Conditional Access for device compliance and location-based blocks, Identity Protection for risk monitoring and automated response, and entitlement management with access reviews for external collaboration governance. This combination leverages the full capabilities of Microsoft Entra ID P2 and E5 licenses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy Microsoft Entra ID authentication strengths for phishing-resistant MFA. Create Conditional Access policies requiring compliant device for HR apps and blocking anonymous IPs and non-business countries. Use Microsoft Entra Identity Protection for risk detection and automated response. Implement entitlement management with connected organizations and access reviews requiring sponsor approval.
Why this is correct
Authentication strengths enforce phishing-resistant MFA, while Conditional Access applies compliant-device and location blocks. Identity Protection supplies real-time risk detection with automated remediation, and entitlement management with connected organisations plus sponsor-approved access reviews governs external collaboration, meeting all five stated requirements.
- ✗
Configure Conditional Access policies with MFA and trusted locations. Use Identity Protection for risk monitoring. Set up access reviews with group owner approval.
Why it's wrong here
Conditional Access with MFA and trusted locations does not deliver phishing-resistant methods, and group owner approval is not sponsor approval, so requirements 1 and 4 fail. It is tempting because these features address device compliance and risk monitoring; it would be correct where standard MFA and owner-driven reviews suffice.
- ✗
Enable security defaults for all users. Use Microsoft Defender for Cloud Apps to block anonymous IPs. Configure Microsoft Entra ID access reviews for external users.
Why it's wrong here
Security defaults enforce only basic MFA, not phishing-resistant authentication, and they cannot express compliant-device or named-location conditions, so requirements 1, 2 and 3 fail. It is tempting because it is free and quick to enable; it would be correct for a small tenant lacking Microsoft Entra ID P1 or P2 licensing.
- ✗
Use certificate-based authentication for all users. Create Conditional Access policies for device compliance. Set up identity protection. Use self-service access reviews for external users.
Why it's wrong here
Certificate-based authentication satisfies phishing-resistant MFA, but nothing here blocks anonymous IPs or unsanctioned countries, and access reviews lack the sponsor-approval configuration the requirement demands. It is tempting because CBA plus Conditional Access covers most identity hardening; it would be correct where no geo-blocking or sponsor-governed reviews are required.
Go deeper
Related to this question
Learn chapter
Privileged Identity Management (PIM) for Admins
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Collaboration
Collaboration in Microsoft 365 refers to the integrated tools and services that enable people to work together in real time, share information, and coordinate tasks from anywhere.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.