SC-100 Practice Question: Design solutions that align with security best practices and priorities
A multinational corporation is implementing a privileged access strategy. They need to ensure that all users with permanent administrative roles sign in using phishing-resistant authentication methods. Which Microsoft Entra ID feature should they enforce?
⚠ Common exam trap
Many candidates confuse general MFA enforcement with the ability to enforce specific authentication method types, assuming any MFA policy is sufficient for phishing resistance, whereas Authentication Strengths provides granular control over which methods are allowed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authentication Strengths in Conditional Access
Authentication Strengths in Conditional Access allows organizations to enforce specific authentication methods, such as FIDO2 security keys or certificate-based authentication, which are phishing-resistant. This directly meets the requirement to ensure users with permanent administrative roles use phishing-resistant methods, unlike general MFA policies that may allow weaker methods like SMS or OTP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Privileged Identity Management (PIM) with access reviews
Why it's wrong here
PIM with access reviews manages privileged role activation and recertification, but it does not gate sign-in on a particular authentication method. An eligible admin can activate a role after authenticating with a weak method such as password plus SMS. The missing control is Authentication Strengths, which constrains which methods are acceptable at the moment of authentication.
- ✗
Multifactor authentication (MFA) with Conditional Access
Why it's wrong here
Requiring MFA via Conditional Access simply adds a second factor; the default MFA grant can be completed by such as SMS, voice call, or OTP, all of which are vulnerable to phishing and interception. It verifies possession of a token or receipt of a message, not the cryptographic strength or phishing-resistance of the method. Authentication Strengths raise the bar by mandating specific method combinations, e.g. FIDO2.
- ✓
Authentication Strengths in Conditional Access
Why this is correct
Authentication Strengths is a Conditional Access grant control that lets an administrator define a policy requiring a specific set of acceptable authentication methods, such as FIDO2 security keys or certificate-based authentication. It evaluates the method actually used at sign-in and blocks sessions that do not meet the configured strength, making it the correct mechanism for enforcing phishing-resistant MFA on privileged accounts.
- ✗
Conditional Access policies requiring MFA for all admins
Why it's wrong here
A Conditional Access policy requiring MFA for all admins broadens coverage but still uses the standard 'Require multifactor authentication' grant, so users can satisfy it by any enrolled MFA method. SMS and voice are weak because they can be intercepted or SIM-swapped, while OTP apps can be phished. The policy never inspects the method type, whereas Authentication Strengths does exactly that for each sign-in.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.