Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

A company uses Microsoft Entra ID and wants to enable passwordless authentication for all users to reduce phishing risks. Users are already using Microsoft Authenticator for MFA. Which passwordless method should you prioritize?

⚠ Common exam trap

It's easy for candidates to choose Windows Hello for Business (A) because it is a common passwordless option, but they overlook the requirement that it only works on Windows devices, not for all users across platforms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Authenticator passwordless sign-in

The organization already uses Microsoft Authenticator for MFA, making the transition to passwordless sign-in via Authenticator the most seamless and cost-effective path. This method leverages the existing app registration and push notification infrastructure, allowing users to authenticate with a biometric or PIN gesture without deploying additional hardware or certificates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Windows Hello for Business

    Why it's wrong here

    Windows Hello for Business is a strong biometric/PIN-based multi-factor authentication tied to the device's TPM and requires the user to have a joined Windows 10/11 machine. It cannot cover users on macOS, Android, or iOS devices, so it would leave a significant portion of the workforce without a passwordless option. Additionally, it requires careful deployment planning across hybrid or cloud trust models and device enrollment, making it incomplete as a sole company-wide solution.

  • ✗

    FIDO2 security keys

    Why it's wrong here

    FIDO2 security keys offer excellent phishing resistance and support passwordless sign-in with Microsoft Entra ID, but they demand purchasing and physically distributing USB or NFC tokens to every user. The organization also has to manage lost, broken, or reissued keys, and users must carry the token with them to authenticate, which creates a higher operational burden and poorer user acceptance compared to a mobile app. This approach is valid but not the most practical choice when a simpler alternative exists.

  • ✗

    Certificate-based authentication

    Why it's wrong here

    Certificate-based authentication can achieve passwordless sign-in by presenting a client certificate, but it requires standing up and maintaining a full public key infrastructure (PKI), including certification authorities, enrollment processes, and revocation lists. The administrative overhead for certificate lifecycle management, secure key storage, and renewal is considerable, and the user experience often involves confusing prompts for selecting a certificate. In a modern cloud-first environment, this is heavier than necessary when Microsoft Entra ID already supports simpler passwordless methods.

  • ✓

    Microsoft Authenticator passwordless sign-in

    Why this is correct

    Microsoft Authenticator passwordless sign-in is the correct answer because it leverages the same mobile app already widely used for multi-factor authentication, requiring no extra hardware or PKI. The user simply enters their username and then approves a push notification on their phone, sometimes matching a number, while the phone's biometric or PIN validates the physical presence. This provides a phishing-resistant, strong authentication experience that works across Android and iOS, and because it reuses an existing app, user adoption is high and deployment is straightforward.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.