Courseiva

SC-100 Design security solutions for infrastructure Practice Question

You are designing a secure access solution for an on-premises application that uses legacy authentication protocols. The organization plans to migrate to Microsoft Entra ID but the application vendor has not yet provided a modern authentication update. The solution must enable single sign-on (SSO) and support multifactor authentication (MFA) for this application without modifying the application code. Which approach should you recommend?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy Microsoft Entra Application Proxy with pre-authentication

Microsoft Entra Application Proxy with pre-authentication (option D) is correct because it publishes the on-premises legacy application externally while enforcing Microsoft Entra ID authentication and MFA at the proxy before traffic reaches the app, enabling SSO without changing application code. Pre-authentication means users authenticate against Microsoft Entra ID first, so legacy protocols inside the app are shielded and MFA/Conditional Access can be applied. MSAL (A) requires modifying the application to use modern auth libraries, which the vendor has not provided. Federating on-premises AD with Entra ID (B) only enables identity synchronization/federation and does not by itself provide SSO or MFA for a legacy on-premises app. Conditional Access policies (C) require the app to already authenticate with Entra ID and cannot protect an app that still uses legacy authentication directly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Integrate the application with the Microsoft Authentication Library (MSAL)

    Why it's wrong here

    MSAL is a library that enables an application to request and manage tokens from the Microsoft identity platform, but it requires significant code changes to implement authentication flows such as authorization code or client credentials. For a legacy on-premises application that was never built to support modern authentication protocols, integrating MSAL would require re-architecting the application rather than providing a secure access overlay, and it does not address the identity proxy or remote-access layer needed for legacy apps.

  • ✗

    Federate the on-premises Active Directory with Microsoft Entra ID

    Why it's wrong here

    Federating on-premises Active Directory with Microsoft Entra ID creates a trust relationship that allows identities to be authenticated in the cloud while using on-premises credentials, but this alone does not add MFA or conditional-access enforcement to applications that only understand legacy protocols like Kerberos, NTLM, or LDAP. Without a gateway that translates modern authentication challenges into a form the legacy app can understand, the app will still accept only its original authentication mechanisms, leaving MFA unenforced at the app layer.

  • ✗

    Use Microsoft Entra Conditional Access policies to require MFA

    Why it's wrong here

    Microsoft Entra Conditional Access policies are evaluated when a user authenticates to a resource that speaks modern protocols (OAuth 2.0, OpenID Connect, WS-Federation or SAML). A legacy on-premises application that does not support these protocols cannot trigger or act on the Entra ID MFA challenge, so the policy never gets enforced for direct access to that app, and the user would bypass said policy entirely by connecting straight to the on-premises endpoint.

  • ✓

    Deploy Microsoft Entra Application Proxy with pre-authentication

    Why this is correct

    Deploying Microsoft Entra Application Proxy with pre-authentication works by exposing the legacy on-premises application through an external HTTPS URL that terminates the user's authentication in Entra ID before any request reaches the app. The user first signs in to Entra ID and can be subject to MFA and Conditional Access; only after successful pre-authentication does the Application Proxy connector relay the request to the on-premises app, typically using Kerberos constrained delegation to present the user's identity to the legacy application. This approach adds secure remote access and modern identity controls without requiring changes to the application itself.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.