mediumMultiple Choice
SC-100 Practice Question: A multinational company is implementing a Zero…
A multinational company is implementing a Zero Trust security model. The security team needs to ensure that all access requests to critical applications are evaluated based on user identity, device health, and real-time risk signals. Which Microsoft solution should they use to centralize policy enforcement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Conditional Access
Microsoft Entra Conditional Access is the correct choice because it is the policy engine in Microsoft Entra ID that centralizes access decisions by evaluating signals such as user identity, group membership, device compliance/health, location, and real-time risk before granting access to applications. This aligns directly with Zero Trust's 'verify explicitly' principle, since Conditional Access enforces grant controls (for example, require MFA or a compliant device) and session controls at the point of access. Microsoft Defender for Cloud Apps is a CASB for discovering and governing cloud app usage, not the central policy enforcement point for identity-based access. Microsoft Entra ID Protection detects and reports risky users and sign-ins and feeds risk signals into Conditional Access, but it does not itself centralize access policy enforcement. Microsoft Purview Compliance Manager is a compliance assessment and improvement tool, not an access control solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that focuses on shadow IT discovery, data loss prevention, and applying session-level controls for cloud app usage. It does not perform authentication policy enforcement itself; instead, it integrates with Conditional Access via the 'Conditional Access App Control' mechanism after the user has authenticated. Its role is post-authentication app governance, not the initial sign-in policy decision.
- ✓
Microsoft Entra Conditional Access
Why this is correct
Microsoft Entra Conditional Access is the core policy engine in Microsoft's identity stack that evaluates sign-in requests against signal combinations such as user risk, device compliance, and geographic location. At the point of authentication, it applies granular policies—like requiring MFA or blocking access—by emitting 'access controls' that the authentication stack must satisfy. This makes it the central enforcement point for zero-trust principles, ensuring every access attempt is explicitly verified before granting access.
- ✗
Microsoft Entra ID Protection
Why it's wrong here
Microsoft Entra ID Protection is a risk-detection service that continuously analyzes billions of signals to identify potentially compromised identities, suspicious sign-in patterns, and vulnerabilities. It calculates risk scores but cannot enforce a deny or require action on its own; rather, it exposes risk data that Conditional Access consumes to make policy decisions. Thus, it is a sensor and scoring engine, not the access policy or enforcement decision-maker.
- ✗
Microsoft Purview Compliance Manager
Why it's wrong here
Microsoft Purview Compliance Manager is a regulatory-compliance assessment tool that maps organizational controls to standards like ISO 27001 or Microsoft data protection baselines, producing compliance scores and remediation recommendations. It runs outside the authentication flow and has no integration with real-time sign-in events, nor can it issue conditional grants or blocks. Its purpose is governance and audit readiness, not to enforce dynamic access policies during user authentication.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.