Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

You are designing a security architecture for Litware Inc., which uses Microsoft 365 E5 and Azure. The company wants to adopt a Zero Trust model and needs to ensure that access to corporate resources is granted based on real-time risk assessment. The security team wants to automatically remediate risky user behavior by requiring password changes or blocking access. You need to recommend a solution that integrates with Microsoft Entra ID and provides risk-based conditional access. What should you recommend?

⚠ Common exam trap

Watch out — candidates often confuse Defender for Identity, which monitors on-premises Active Directory, with Entra ID Protection, which assesses cloud identity risk and drives conditional access policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID Protection

Microsoft Entra ID Protection evaluates sign-in and user risk in real time and integrates with Conditional Access to enforce policies such as requiring MFA or password change for risky users. It can also block access when risk is high, providing the automated remediation and risk-based access required for a Zero Trust architecture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra Conditional Access with named locations

    Why it's wrong here

    Conditional Access with named locations grants or blocks access based on network location, not real-time user risk. It does not assess risky sign-ins or user behavior, and it cannot automatically require password changes. It is a static control, not a risk-based adaptive mechanism.

  • ✗

    Microsoft Cloud App Security (Defender for Cloud Apps) session policies

    Why it's wrong here

    Defender for Cloud Apps session policies provide real-time control over cloud app sessions, such as blocking downloads or monitoring user activity. They do not assess user risk in Microsoft Entra ID or trigger automatic password changes. They are focused on data exfiltration and app governance, not identity risk remediation.

  • ✗

    Microsoft Defender for Identity

    Why it's wrong here

    Microsoft Defender for Identity monitors on-premises Active Directory signals to detect advanced threats and compromised identities. While it provides identity threat detection, it does not directly enforce risk-based conditional access policies in Microsoft Entra ID or automatically remediate risky user behavior in real time.

  • ✓

    Microsoft Entra ID Protection

    Why this is correct

    Microsoft Entra ID Protection detects risky users and sign-ins using machine learning and heuristics, and it integrates with Conditional Access to enforce risk-based policies. It can automatically require password changes or block access when risk is detected, directly meeting the requirement for real-time risk assessment and automated remediation.

Go deeper

Related to this question

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.