SC-100 Practice Question: Design solutions that align with security best practices and priorities
You are a security architect at Tailwind Traders. The company uses Microsoft 365 E5 and has a hybrid identity environment with Microsoft Entra Connect. The CIO wants to reduce the risk of credential theft and phishing attacks for all employees. You need to recommend an authentication method that eliminates passwords for users and aligns with Zero Trust principles. What should you recommend?
⚠ Common exam trap
The trap here is assuming that Windows Hello for Business is the universal passwordless solution, when it only works on Windows devices and does not cover all employee scenarios.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Authenticator with phone sign-in
Microsoft Authenticator with phone sign-in provides a passwordless authentication method that works across devices and applications. It uses biometrics or PIN on the mobile device, reducing the risk of phishing and credential theft. This aligns with Zero Trust principles by verifying explicitly and eliminating passwords.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Certificate-based authentication
Why it's wrong here
Certificate-based authentication uses digital certificates to authenticate users, which can be strong but is complex to deploy and manage. It does not eliminate passwords for all users and scenarios, and it may require additional infrastructure. It is not the simplest or most comprehensive passwordless solution for a Microsoft 365 environment.
- ✓
Microsoft Authenticator with phone sign-in
Why this is correct
Microsoft Authenticator with phone sign-in enables passwordless authentication for users by allowing them to sign in with their mobile device using biometrics or PIN. It works across applications and platforms, integrates with Microsoft Entra ID, and supports phishing-resistant methods, directly reducing credential theft risk and eliminating passwords.
- ✗
Windows Hello for Business
Why it's wrong here
Windows Hello for Business provides passwordless authentication on Windows devices using biometrics or PIN, but it is device-specific and not available on all platforms. It does not eliminate passwords for web applications or non-Windows devices, so it does not fully meet the requirement to eliminate passwords for all employees across all scenarios.
- ✗
Security questions as a secondary authentication factor
Why it's wrong here
Security questions are a knowledge-based authentication method that is vulnerable to social engineering and guessing. They do not eliminate passwords and are not considered a strong authentication method. They are often used for self-service password reset, not as a primary passwordless authentication mechanism.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.