Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Which TWO of the following are best practices for securing Microsoft 365 tenants? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable security defaults in Microsoft Entra ID

Enabling security defaults provides a baseline of security. Using Conditional Access policies allows granular access control. These are best practices. Disabling modern authentication is counterproductive. Allowing all external sharing is risky. Using basic authentication is insecure. So the correct two are A and B.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable security defaults in Microsoft Entra ID

    Why this is correct

    Security defaults in Microsoft Entra ID are a preset group of identity security policies that automatically enforce MFA, require administrators to authenticate with MFA, and block legacy authentication. This is a best practice because it provides a robust baseline security posture out-of-the-box, drastically reducing account compromise risk without requiring per-user configuration or Premium licensing. For organizations that lack the licensing for Conditional Access, security defaults are the recommended way to ensure consistent enforcement of strong authentication across all users.

  • ✓

    Use Conditional Access policies to enforce MFA

    Why this is correct

    Conditional Access policies offer granular, policy-based control over authentication by evaluating signals such as user location, device compliance, sign-in risk, and application sensitivity before allowing access. By requiring MFA through a conditional policy, you can insist on strong authentication only when necessary, such as during risky sign-ins or for privileged roles, thereby minimizing user friction. This adaptivity makes it the preferred approach for enterprises needing customizable security that aligns with Zero Trust principles, and it works seamlessly with Microsoft Entra ID when licenses like Premium P1/P2 are available.

  • ✗

    Enable basic authentication for all apps

    Why it's wrong here

    Basic authentication sends user credentials in a trivially decodable base64 string and has no inherent support for MFA, making it a prime target for credential theft and replay attacks. Enabling it for all apps widens the attack surface across the tenant, because attackers can brute-force or spray passwords against any endpoint that accepts basic auth. The secure alternative is to disable basic authentication entirely and mandate modern authentication protocols like OAuth 2.0 with device-based capabilities, which support conditional access and token expiry.

  • ✗

    Disable modern authentication for legacy protocols

    Why it's wrong here

    Legacy protocols such as POP, IMAP, and SMTP AUTH cannot participate in conditional access or MFA, so forcing them to use modern authentication would actually be impossible — they would fall back to less secure authentication or break. Disabling modern authentication would leave these protocols unprotected, enabling attacks that exploit password-only authentication. Instead, the best practice is to leave modern authentication enabled and shut down legacy protocol endpoints, or enable legacy authentication with MFA only when absolutely necessary via OAuth 2.0 extension.

  • ✗

    Allow all external sharing in SharePoint

    Why it's wrong here

    Configuring SharePoint to allow unrestricted external sharing, especially with 'Anyone' links, permits anonymous access to files without requiring sign-in, making the data publicly discoverable and leaking sensitive information. Even restricting to authenticated guests without other safeguards can result in oversharing because users may unintentionally invite external parties to sensitive documents. SharePoint provides granular sharing controls such as domain allowlists, link expiration, access reviews, and guest expiration policies that should be enabled to minimize risk while still allowing legitimate collaboration.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.