Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Exhibit

{
  "properties": {
    "displayName": "Block high-risk sign-ins",
    "state": "enabled",
    "conditions": {
      "signInRiskLevels": ["high"],
      "applications": {
        "includeApplications": ["All"]
      },
      "users": {
        "includeUsers": ["All"]
      }
    },
    "grantControls": {
      "builtInControls": ["block"],
      "operator": "OR"
    }
  }
}

Refer to the exhibit. You are reviewing a conditional access policy JSON in Microsoft Entra ID. What does this policy accomplish?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Blocks all users when sign-in risk is high.

The correct option is C: Blocks all users when sign-in risk is high. In Microsoft Entra ID conditional access, a policy that includes all users and sets the sign-in risk condition to High with a grant control of Block will deny access for any sign-in evaluated as high risk. This matches the scenario because the policy targets the broad user scope and uses sign-in risk (not user risk) as the trigger. Option A is wrong because the policy blocks rather than requires MFA, and it does not mention an MFA grant control. Option B is wrong because the policy applies to all users, not only external or guest users. Option D is wrong because the condition is sign-in risk, not specific cloud apps or applications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Requires MFA for high-risk sign-ins.

    Why it's wrong here

    Grant control is block, not MFA.

  • ✗

    Blocks external users from high-risk sign-ins.

    Why it's wrong here

    The exhibit's user and risk conditions do not combine to exclude external users from high-risk sign-ins; no such block is configured. It is tempting because blocking risky external access is a standard zero-trust control, and it would be correct if the policy targeted guest users with a risk-based block grant.

  • ✓

    Blocks all users when sign-in risk is high.

    Why this is correct

    The policy's conditions combine all users with a sign-in risk level of high, and its grant control is block. Because no exclusions or other risk levels are scoped, every user is denied access whenever Microsoft Entra ID detects high sign-in risk.

  • ✗

    Blocks sign-ins from specific applications.

    Why it's wrong here

    The policy's cloud app condition does not name applications to block; its grant controls permit access rather than deny it. It is tempting because app-scoped blocking is a recognised conditional access use, and it would be correct if the JSON specified those applications under an exclusion or block grant.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.