Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

Exhibit

{
  "displayName": "GDPR Compliance",
  "scenario": "Deployment",
  "state": "Enabled",
  "conditions": {
    "applications": {
      "includeApplications": ["All"]
    },
    "users": {
      "includeUsers": ["All"]
    },
    "locations": {
      "includeLocations": ["All"],
      "excludeLocations": ["Trusted IPs"]
    },
    "clientAppTypes": ["All"]
  },
  "grantControls": {
    "builtInControls": ["mfa", "compliantDevice"],
    "operator": "AND"
  },
  "sessionControls": {
    "applicationEnforcedRestrictions": {
      "isEnabled": true
    }
  }
}

Refer to the exhibit. The exhibit shows a Conditional Access policy. Which requirement does this policy enforce?

⚠ Common exam trap

MS-900 often tests whether candidates understand the AND/OR logic in Conditional Access grant controls, and whether they can interpret policy exhibits correctly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Users must provide MFA and use a compliant device.

The policy enforces that users must provide MFA and use a compliant device. In Conditional Access, when both 'Require multi-factor authentication' and 'Require device to be marked as compliant' are selected under Grant controls, the user must satisfy both conditions to gain access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Users from trusted IPs are blocked.

    Why it's wrong here

    The policy's grant controls require MFA or a compliant device, and its conditions target locations; trusted IPs are not blocked by such a policy. It is tempting because location conditions can exclude trusted IPs, but that exclusion would appear as a separate, explicitly configured condition.

  • ✗

    Users must provide MFA only.

    Why it's wrong here

    The policy grants access only after MFA, but the exhibit also lists device compliance as an alternative grant control, so MFA alone is not the full requirement. It is tempting because MFA is the most visible control, yet the policy permits either MFA or a compliant device.

  • ✓

    Users must provide MFA and use a compliant device.

    Why this is correct

    The policy combines two grant controls in a single Conditional Access rule: require multifactor authentication and require the device to be marked compliant in Microsoft Entra ID. Both conditions must be satisfied before access is granted, matching the exhibit's configured grant controls exactly.

  • ✗

    Users must provide MFA or use a compliant device.

    Why it's wrong here

    The exhibit's grant control requires MFA, and a compliant device is a separate, alternative control, not a combined OR requirement shown here. It is tempting because both controls commonly appear together, but the policy as displayed enforces only the MFA grant.

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.