Courseiva
hardMultiple ChoiceObjective-mapped

SC-100 Practice Question: A financial services organization is designing a…

A financial services organization is designing a zero-trust architecture for its Azure environment. They need to ensure that all administrative access to critical systems uses just-in-time (JIT) access and that privileged role assignments are time-bound. Which combination of Microsoft security best practices should they implement?

⚠ Common exam trap

Candidates often confuse Azure AD Conditional Access (which controls sign-in conditions) with PIM’s JIT role activation, or they assume Azure Bastion is only a connectivity tool rather than a critical component of zero-trust administrative access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Azure AD Privileged Identity Management (PIM) and Azure Bastion

Azure AD Privileged Identity Management (PIM) provides just-in-time (JIT) activation and time-bound role assignments for privileged roles, directly meeting the requirement for time-bound administrative access. Azure Bastion enables secure, audited RDP/SSH access to Azure VMs without exposing public IP addresses, ensuring that administrative sessions are isolated and monitored. Together, they enforce zero-trust principles by granting ephemeral, scoped access to critical systems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Azure AD Conditional Access and Azure AD Identity Protection

    Why it's wrong here

    Azure AD Conditional Access and Azure AD Identity Protection are authentication-time risk controls: Conditional Access enforces policies based on user, device, and location signals, while Identity Protection flags risky sign-ins and compromised accounts. Neither mechanism grants or revokes time-bound elevated privileges to Azure resources or virtual machines, so they cannot deliver just-in-time privileged access. They reduce risk at the login boundary but leave standing administrative access untouched, which fails the zero-trust requirement for JIT elevation.

  • Azure Policy and Azure Blueprints

    Why it's wrong here

    Azure Policy and Azure Blueprints are governance and compliance tools that define, audit, and enforce resource configuration standards and organizational guardrails. Policy can deny non-compliant deployments and audit existing resources, while Blueprints orchestrate the rollout of compliant environments, but neither can issue temporary, time-boxed administrative rights or broker access to a VM. They ensure resources are configured correctly, yet they do not address the human access lifecycle or remove persistent privileged credentials, making them irrelevant to JIT access requirements.

  • Azure Sentinel and Azure Workbook

    Why it's wrong here

    Azure Sentinel and Azure Workbook are monitoring and visualization services: Sentinel is a cloud-native SIEM for collecting security logs, detecting threats, and response orchestration, while Workbooks provide interactive dashboards for that data. They observe and analyze access events after the fact but cannot grant, restrict, or time-limit privileged access, nor can they facilitate an RDP/SSH session to a VM. Their role is detection and reporting, not access control, so they have no capability to enforce just-in-time privileged access.

  • Azure AD Privileged Identity Management (PIM) and Azure Bastion

    Why this is correct

    Azure AD Privileged Identity Management (PIM) and Azure Bastion are the correct pair. PIM provides time-bound, approval-required role activation for Azure AD roles and Azure resource roles, eliminating standing privileged access and aligning with zero-trust JIT principles. Azure Bastion enables secure, browser-based RDP/SSH access to virtual machines without public IP exposure, and when combined with Azure Defender for Cloud's JIT VM access, it can further scope access to specific ports and time windows. Together they enable a complete JIT and JEA (just-enough-access) workflow: PIM governs privileged identity elevation, while Bastion enforces a secure, monitored, and ephemeral VM access path.

About these practice questions

Courseiva writes every SC-100 question from scratch — 208 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.