Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Exhibit

Refer to the exhibit.
```json
{
  "properties": {
    "displayName": "Block risky sign-ins",
    "conditions": {
      "userRiskLevels": ["medium","high"],
      "applications": {"includeApplications": ["All"]}
    },
    "grantControls": {
      "operator": "OR",
      "builtInControls": ["block"]
    }
  }
}
```

Refer to the exhibit. You create this conditional access policy in Microsoft Entra ID. What is the result?

⚠ Common exam trap

Watch out — candidates often confuse 'Block access' with 'Require MFA' when they see risk levels, assuming the policy will prompt for MFA instead of outright blocking the sign-in.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Blocks sign-ins from medium and high risk users for all applications

The conditional access policy shown assigns the 'Block access' control to the 'Medium and High' risk levels for 'All cloud apps'. This means any sign-in from a user or session detected as medium or high risk will be blocked, regardless of the application. Option B correctly identifies this outcome.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Requires MFA for medium and high risk users for all applications

    Why it's wrong here

    The exhibit's conditional access policy uses the 'Block' grant control, not 'Require multi-factor authentication,' so the action is to deny sign-in entirely rather than to allow it after an MFA prompt. Although the assignment correctly targets all applications and medium/high user risk, the configured grant is block, not MFA. This option mischaracterizes the policy's effect; a user would be stopped at sign-in, never reaching an MFA challenge.

  • ✓

    Blocks sign-ins from medium and high risk users for all applications

    Why this is correct

    This policy assigns the target to 'All cloud apps' and sets the user risk condition to 'Medium or High,' then applies the 'Block' grant control. As a result, any sign-in with a user risk level of medium or higher is denied across every application, while low-risk sign-ins are unaffected. The combination of a broad application scope and a risk threshold yields a global block for medium and high risk users.

  • ✗

    Blocks sign-ins from low risk users for all applications

    Why it's wrong here

    The risk condition in this policy explicitly includes only 'Medium' and 'High' user risk; 'Low' is not selected, so low-risk sign-ins are outside the policy's scope. Blocking low-risk users would require the policy to include the 'Low' option, which is absent. Therefore, this answer incorrectly extends the policy to a population that the exhibit clearly does not target.

  • ✗

    Blocks sign-ins from medium and high risk users only for selected applications

    Why it's wrong here

    Under 'Target resources,' the policy includes 'All cloud apps,' meaning it applies to every application in the tenant, not just a selected subset. The answer incorrectly narrows the scope to 'selected applications,' which would only be true if the policy had specified a discrete list of app IDs in the 'Select apps' option. Because the exhibit shows 'All cloud apps,' the policy is global in reach, and this option misstates the application assignment.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.