SC-100 Design security solutions for infrastructure Practice Question
You are designing a secure access solution for on-premises applications using Microsoft Entra ID. The solution must support modern authentication, single sign-on (SSO), and Conditional Access. Which TWO technologies should you implement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra application proxy
Microsoft Entra application proxy (C) is correct because it publishes on-premises web applications to the internet and enforces Microsoft Entra ID pre-authentication, which enables modern authentication, SSO, and Conditional Access for those apps without opening inbound firewall ports. Microsoft Entra ID as the identity provider (D) is correct because it is the cloud identity service that issues tokens, performs authentication, and evaluates Conditional Access policies for the published applications. Together, application proxy and Entra ID as the IdP provide the required modern authentication, SSO, and Conditional Access for on-premises apps. Azure AD B2C (A) is for customer-facing identity scenarios with local or social accounts, not for securing internal on-premises enterprise applications. Microsoft Entra Domain Services (B) provides managed domain services such as domain join and Group Policy, but it does not by itself publish on-premises apps or deliver the required modern auth/SSO/Conditional Access. Site-to-Site VPN (E) only provides network connectivity and does not deliver identity-based authentication, SSO, or Conditional Access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure AD B2C
Why it's wrong here
Azure AD B2C is a customer identity and access management (CIAM) solution designed to authenticate external users such as customers, partners, or citizens via social or local accounts. It does not provide a reverse proxy for on-premises applications, nor does it integrate with internal identity stores or offer the enterprise Conditional Access policies needed for secured employee access.
- ✗
Microsoft Entra Domain Services
Why it's wrong here
Microsoft Entra Domain Services offers managed domain services such as LDAP, Kerberos/NTLM authentication, and Group Policy for legacy VMs that cannot use modern protocols. It does not act as an application publishing gateway or provide SSO to internal web apps; it only supplies identity infrastructure at the network/domain level.
- ✓
Microsoft Entra application proxy
Why this is correct
Microsoft Entra Application Proxy is a reverse proxy service that publishes on-premises web applications to remote users via the Entra ID cloud endpoint, without requiring inbound firewall ports. It integrates with Microsoft Entra ID to enforce Conditional Access, MFA, and SSO, making it the correct choice for securely accessing on-premises apps with modern authentication.
- ✓
Microsoft Entra ID as the identity provider
Why this is correct
Microsoft Entra ID is the cloud identity provider that stores user accounts and enables single sign-on, Conditional Access, and MFA; however, it does not itself connect to or proxy on-premises resources. It must be paired with a connector or proxy (such as Application Proxy) to reach on-premises applications, so it is necessary but not sufficient as the access solution.
- ✗
Site-to-Site VPN
Why it's wrong here
A site-to-site VPN extends the corporate network across an encrypted tunnel, granting broad network-level reachability to all published resources, but it lacks application-aware security. It does not provide per-application modern authentication, SSO, or granular Conditional Access policies, and managing remote access via VPN is cumbersome and risky for individual app access.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.