Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "displayName": "Require MFA for admins",
    "state": "enabled",
    "conditions": {
      "users": {
        "includeRoles": ["Global Administrator", "Security Administrator"]
      },
      "applications": {
        "includeApplications": ["All"]
      }
    },
    "grantControls": {
      "builtInControls": ["mfa"],
      "operator": "OR"
    }
  }
}
```

Refer to the exhibit. You are reviewing a conditional access policy. What is the effect of this policy?

⚠ Common exam trap

The trap here is that candidates may overlook the specific role targeting in the policy and assume it applies to all users, leading them to choose option C, or they may mistakenly think the policy is disabled because they misread the toggle state, choosing option A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Requires multifactor authentication for Global Administrators and Security Administrators

The exhibit shows a conditional access policy that targets the 'Global Administrators' and 'Security Administrators' directory roles, and the policy is configured to 'Require multifactor authentication' for those roles. The policy is enabled (as indicated by the 'On' toggle), so it actively enforces MFA for members of those two admin roles, blocking access if they do not complete MFA. This aligns with the principle of securing high-privilege roles with stronger authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The policy is disabled and has no effect

    Why it's wrong here

    The exhibit shows the policy's state is set to 'Enabled', not 'Disabled'. A conditional access policy only takes effect when its state is 'Enabled' and is evaluated during sign-in; a disabled policy is ignored entirely. Since this policy is enabled, it is actively evaluated and its grant control will be enforced for matching sign-in events, so stating it has no effect is incorrect.

  • ✗

    Blocks access for all users

    Why it's wrong here

    The policy's access control is configured to 'Require multi-factor authentication', not 'Block access'. Blocking access would deny the sign-in entirely, whereas an MFA requirement permits access after the user successfully completes MFA. Additionally, the policy scope is limited to Global Administrators and Security Administrators, so it cannot block all users even if it were a block policy.

  • ✗

    Requires multifactor authentication for all users

    Why it's wrong here

    The policy assignments explicitly specify only the directory roles Global Administrators and Security Administrators, not all users. Conditional access policies apply to the users, groups, or roles defined in the 'Users and groups' assignment; a tenant-wide effect would require targeting 'All users'. Therefore, MFA is required solely for those two administrator roles, not for every user in the tenant.

  • ✓

    Requires multifactor authentication for Global Administrators and Security Administrators

    Why this is correct

    The policy configuration targets the directory roles Global Administrators and Security Administrators, and its grant control is set to 'Require multi-factor authentication'. When a user who holds either of these roles attempts to access a protected resource, the policy is triggered and MFA is enforced. This correctly matches the statement that MFA is required for both administrator roles.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.