SC-100 Practice Question: Design solutions that align with security best practices and priorities
A company uses Microsoft Entra ID with P2 licenses. They want to implement a Zero Trust approach that requires step-up authentication for accessing high-value data in SharePoint. The solution must use risk-based policies and minimize user friction. Which combination should you recommend?
⚠ Common exam trap
Candidates often confuse user risk policies (which are based on historical user behavior) with sign-in risk policies (which evaluate the current session in real time), and they overlook the role of authentication context in scoping enforcement to specific data rather than all SharePoint access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Conditional Access with sign-in risk policy and authentication context for sensitive data
It combines Conditional Access with a sign-in risk policy (from Identity Protection) and an authentication context that is applied to sensitive SharePoint data. This enforces step-up authentication only when risk is detected and the user accesses high-value data, minimizing friction for low-risk sessions while meeting Zero Trust requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra Conditional Access with trusted locations policy
Why it's wrong here
A trusted locations policy relies on IP address or named network ranges to allow or block access, so it is purely location-based and never evaluates signals such as impossible travel, anonymous IP addresses, or token replay. Because a compromised account can sign in from an approved corporate IP, this policy would grant that session without requiring step-up authentication. It also cannot bind the decision to the sensitivity of the specific data in SharePoint. For these reasons it does not meet the stated sign-in risk requirement.
- ✓
Microsoft Entra Conditional Access with sign-in risk policy and authentication context for sensitive data
Why this is correct
This is correct because the Conditional Access policy uses Microsoft Entra Identity Protection's real-time sign-in risk score to trigger step-up (for example MFA or restricted session) only when anomalous behavior is detected. Adding an authentication context makes the requirement granular: the risk-based control can be attached to SharePoint sites or files with a specific sensitivity label rather than to every resource. This combines risk assessment with data sensitivity, which is exactly the requirement. It is also the only option that pairs a per-sign-in risk signal with a context-aware session control.
- ✗
Microsoft Entra Conditional Access with MFA for all SharePoint access
Why it's wrong here
Forcing MFA on all SharePoint access is overbroad: it applies the same control to public team sites and to highly confidential research sites, causing unnecessary user friction and failing to prioritize risk. The policy has no dependency on Identity Protection's sign-in risk scores, so a low-risk session is challenged just as aggressively as a sign-in with clear anomalies. It also does not leverage authentication contexts, meaning the protection cannot be narrowed to only sensitive document libraries. Thus it is wrong because it is both too broad and not risk-based.
- ✗
Microsoft Entra Identity Protection user risk policy with MFA
Why it's wrong here
A Microsoft Entra Identity Protection user risk policy looks at the probability that the entire account has been compromised based on leaked credentials or historic behavioral telemetry, and then applies MFA or password change upon the next sign-in. This is a user-level, longitudinal risk assessment, not a per-sign-in evaluation of the current authentication event, so it cannot detect and respond to anomalies like token replay at the moment they occur. Moreover, it has no concept of authentication context, so it cannot vary the requirement based on whether SharePoint data is labeled as sensitive. These two limitations make it the wrong pairing for sign-in-risk-driven, data-sensitive protection.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.