SC-100 Practice Question: Design solutions that align with security best practices and priorities
Exhibit
Refer to the exhibit.
```json
{
"properties": {
"displayName": "Require MFA for admins",
"state": "enabled",
"conditions": {
"users": {
"includeRoles": ["Global Administrator", "Security Administrator"]
},
"applications": {
"includeApplications": ["All"]
}
},
"grantControls": {
"builtInControls": ["mfa"],
"operator": "OR"
}
}
}
```Refer to the exhibit. You are reviewing a conditional access policy. What is the effect of this policy?
⚠ Common exam trap
The trap here is that candidates may overlook the specific role targeting in the policy and assume it applies to all users, leading them to choose option C, or they may mistakenly think the policy is disabled because they misread the toggle state, choosing option A.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Requires multifactor authentication for Global Administrators and Security Administrators
The exhibit shows a conditional access policy that targets the 'Global Administrators' and 'Security Administrators' directory roles, and the policy is configured to 'Require multifactor authentication' for those roles. The policy is enabled (as indicated by the 'On' toggle), so it actively enforces MFA for members of those two admin roles, blocking access if they do not complete MFA. This aligns with the principle of securing high-privilege roles with stronger authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy is disabled and has no effect
Why it's wrong here
The exhibit shows the policy's state is set to 'Enabled', not 'Disabled'. A conditional access policy only takes effect when its state is 'Enabled' and is evaluated during sign-in; a disabled policy is ignored entirely. Since this policy is enabled, it is actively evaluated and its grant control will be enforced for matching sign-in events, so stating it has no effect is incorrect.
- ✗
Blocks access for all users
Why it's wrong here
The policy's access control is configured to 'Require multi-factor authentication', not 'Block access'. Blocking access would deny the sign-in entirely, whereas an MFA requirement permits access after the user successfully completes MFA. Additionally, the policy scope is limited to Global Administrators and Security Administrators, so it cannot block all users even if it were a block policy.
- ✗
Requires multifactor authentication for all users
Why it's wrong here
The policy assignments explicitly specify only the directory roles Global Administrators and Security Administrators, not all users. Conditional access policies apply to the users, groups, or roles defined in the 'Users and groups' assignment; a tenant-wide effect would require targeting 'All users'. Therefore, MFA is required solely for those two administrator roles, not for every user in the tenant.
- ✓
Requires multifactor authentication for Global Administrators and Security Administrators
Why this is correct
The policy configuration targets the directory roles Global Administrators and Security Administrators, and its grant control is set to 'Require multi-factor authentication'. When a user who holds either of these roles attempts to access a protected resource, the policy is triggered and MFA is enforced. This correctly matches the statement that MFA is required for both administrator roles.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.