Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

You are a security architect at Tailwind Traders. The company uses Microsoft 365 E5 and has a hybrid identity environment with Microsoft Entra Connect. The CIO wants to reduce the risk of credential theft and phishing attacks for all employees. You need to recommend an authentication method that eliminates passwords for users and aligns with Zero Trust principles. What should you recommend?

⚠ Common exam trap

The trap here is assuming that Windows Hello for Business is the universal passwordless solution, when it only works on Windows devices and does not cover all employee scenarios.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Authenticator with phone sign-in

Microsoft Authenticator with phone sign-in provides a passwordless authentication method that works across devices and applications. It uses biometrics or PIN on the mobile device, reducing the risk of phishing and credential theft. This aligns with Zero Trust principles by verifying explicitly and eliminating passwords.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Certificate-based authentication

    Why it's wrong here

    Certificate-based authentication uses digital certificates to authenticate users, which can be strong but is complex to deploy and manage. It does not eliminate passwords for all users and scenarios, and it may require additional infrastructure. It is not the simplest or most comprehensive passwordless solution for a Microsoft 365 environment.

  • ✓

    Microsoft Authenticator with phone sign-in

    Why this is correct

    Microsoft Authenticator with phone sign-in enables passwordless authentication for users by allowing them to sign in with their mobile device using biometrics or PIN. It works across applications and platforms, integrates with Microsoft Entra ID, and supports phishing-resistant methods, directly reducing credential theft risk and eliminating passwords.

  • ✗

    Windows Hello for Business

    Why it's wrong here

    Windows Hello for Business provides passwordless authentication on Windows devices using biometrics or PIN, but it is device-specific and not available on all platforms. It does not eliminate passwords for web applications or non-Windows devices, so it does not fully meet the requirement to eliminate passwords for all employees across all scenarios.

  • ✗

    Security questions as a secondary authentication factor

    Why it's wrong here

    Security questions are a knowledge-based authentication method that is vulnerable to social engineering and guessing. They do not eliminate passwords and are not considered a strong authentication method. They are often used for self-service password reset, not as a primary passwordless authentication mechanism.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.