Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Exhibit

{
  "properties": {
    "policyMode": "default",
    "rules": [
      {
        "name": "BlockHighRisk",
        "conditions": {
          "userRiskLevels": ["high"],
          "signInRiskLevels": ["high"]
        },
        "grantControls": {
          "builtInControls": ["block"]
        }
      },
      {
        "name": "RequireMFAForMedium",
        "conditions": {
          "userRiskLevels": ["medium"],
          "signInRiskLevels": ["medium"]
        },
        "grantControls": {
          "builtInControls": ["mfa"]
        }
      }
    ]
  }
}

Refer to the exhibit. A security administrator is reviewing a Conditional Access policy JSON. They want to ensure that users with medium risk level are prompted for multi-factor authentication (MFA), while high-risk users are blocked. The policy is not working as expected. Which issue is present in the policy?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy requires both user and sign-in risk to be high to block, but a user with high user risk and low sign-in risk would not be blocked

The correct answer is B: the policy's block condition requires both user risk and sign-in risk to be high, so a user with high user risk but low sign-in risk would not be blocked as intended. In Microsoft Entra Conditional Access, user risk and sign-in risk are separate conditions, and if the JSON combines them so that both must be 'high' for the block to apply, the policy fails to block all high-risk users. The intended design should block when user risk is high, regardless of sign-in risk, or use separate grant controls for medium-risk MFA and high-risk block. Option A is wrong because report-only mode would not enforce MFA or blocking at all. Option C is wrong because the scenario describes a logic problem, not invalid JSON syntax. Option D is wrong because combining conditions with 'Or' would make the policy broader, not narrower, and would not explain the failure to block high-risk users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The policy mode should be 'report-only'

    Why it's wrong here

    Changing the policy mode to 'report-only' would not address the flaw because report-only mode only simulates policy outcomes and does not enforce any actions. The real issue lies in the conditional logic: both user risk and sign-in risk must be High for the 'Block access' control to trigger. Switching to report-only would actually make the policy less effective, since it would never block anything, even for users who meet all conditions.

  • ✓

    The policy requires both user and sign-in risk to be high to block, but a user with high user risk and low sign-in risk would not be blocked

    Why this is correct

    In Microsoft Entra Conditional Access, conditions are evaluated cumulatively; a user must satisfy every condition for the 'Block access' grant to be applied. With user risk set to High and sign-in risk set to High, a user whose user risk is High but whose sign-in risk is Low will not match both conclusions, so the block is skipped. This leaves a predictable gap that an attacker with a compromised account and low sign-in risk could exploit. The correct fix would be to treat high user risk OR high sign-in risk as sufficient, either by using separate policies or by adjusting the controls.

  • ✗

    The JSON syntax is invalid

    Why it's wrong here

    The policy contains valid JSON; all quotes, colons, braces, brackets, and property names follow the correct syntax for Microsoft Graph's conditionalAccessPolicy resource. If the JSON were malformed, the policy creation or update request would be rejected, but the policy is present and being evaluated. The administrator's concern is not a parsing error but a design flaw in how the risk levels are logically combined.

  • ✗

    The conditions are combined with 'Or' instead of 'And'

    Why it's wrong here

    This option incorrectly reverses the actual logic: Conditional Access policies combine multiple conditions with an implicit AND, not OR. Because both user risk and sign-in risk must be High under the current AND semantics, a High user risk with Low sign-in risk bypasses the block. Switching to an OR operator would be the remedy, not the cause of the problem, so claiming the conditions are ORed is factually incorrect.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.