SC-100 Practice Question: Design solutions that align with security best practices and priorities
Which TWO are recommended practices for securing Microsoft 365 workloads? (Select two.)
⚠ Common exam trap
Watch out — candidates often confuse 'enabling audit logging' with 'enabling mailbox auditing only' or assume that audit logging is enabled by default, but Microsoft Purview unified audit logging must be explicitly enabled per tenant and is not automatically turned on for all workloads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable unified audit logging in Microsoft Purview
Option D is correct because enabling unified audit logging in Microsoft Purview ensures that user and admin activities across Exchange Online, SharePoint Online, OneDrive, and Teams are recorded, which is essential for incident investigation, forensic analysis, and compliance reporting. Option E is correct because a Microsoft Defender for Office 365 Safe Attachments policy detonates email attachments in a sandbox before delivery, blocking zero-day malware and malicious payloads that traditional signature-based filtering would miss. The unmarked options do not belong: A weakens security by exposing SharePoint content externally, B undermines account protection by removing MFA even for trusted IPs (which can be spoofed or compromised), and C grants broad OAuth access to third-party apps, increasing the risk of data exfiltration and consent-phishing attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allow external sharing for all SharePoint sites
Why it's wrong here
Broadly enabling external sharing on every SharePoint site drastically expands your tenant's attack surface and increases the risk of unauthorized data exfiltration. Each site should have sharing policies tailored to its content sensitivity, using guest access controls, expiration times, and conditional access to limit external collaboration safely.
- ✗
Disable multifactor authentication for users who access from trusted IPs
Why it's wrong here
Trusted IP addresses are an incomplete security boundary because they can be spoofed or used from an already compromised endpoint, and excluding them from MFA creates a direct bypass of your strongest authentication control. Conditional Access policies that exempt a location should still require additional checks like device compliance or risk-based assessment to avoid undermining identity security.
- ✗
Allow all third-party apps to access Microsoft 365 data
Why it's wrong here
Granting blanket access to all third-party apps is an authorization worst practice: legitimate apps may request broad Office 365 Graph permissions that exceed their functional need, and malicious apps can exploit OAuth consent to exfiltrate data. You should enforce app consent policies, audit app permissions continuously, and use app governance to allow only vetted, least-privilege integrations.
- ✓
Enable unified audit logging in Microsoft Purview
Why this is correct
Unified audit logging in Microsoft Purview is a critical detective control because it records every event across Exchange, SharePoint, Teams, and other workloads, enabling you to trace user actions and respond to incidents. Without a complete, centrally searchable audit trail, your security team cannot effectively investigate data breaches, insider threats, or compliance violations.
- ✓
Use Microsoft Defender for Office 365 Safe Attachments policy
Why this is correct
Microsoft Defender for Office 365 Safe Attachments provides robust email protection by detonating attachments in a virtual sandbox and analyzing them for zero-day threats before delivery to inboxes. This proactive scanning catches malicious payloads that traditional signature-based filters miss, and it can be automated through policies to block or quarantine high-risk files across your mail environment.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.