Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

You are designing identity security for a hybrid organization using Microsoft Entra ID. You need to enforce multi-factor authentication (MFA) for all users accessing sensitive applications. What is the recommended approach?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Conditional Access policy that requires MFA for the sensitive applications

Conditional Access policies in Entra ID are the recommended method to require MFA for specific applications. The other options are less granular or outdated: per-user MFA is legacy, Security defaults apply to all apps and cannot be scoped, and Microsoft Entra ID Protection focuses on risk-based policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a Conditional Access policy that requires MFA for the sensitive applications

    Why this is correct

    A Conditional Access policy is the correct approach because it uses application-based conditions to require MFA selectively for sensitive apps while allowing other apps to use less restrictive authentication. In a hybrid environment, this integrates with on-premises applications via Microsoft Entra application proxy or federated trusts, and supports session controls like sign-in frequency. This granularity aligns with the Zero Trust principle of least privilege, unlike tenant-wide or user-wide MFA enforcement.

  • ✗

    Enable Security defaults

    Why it's wrong here

    Enabling Security defaults would force MFA for every user in the tenant, regardless of the application they access, because it is a baseline tenant-level policy. It also blocks legacy authentication and enforces MFA registration for all users, but it cannot exclude or target specific sensitive applications. For a hybrid organization that only needs MFA on sensitive apps, this blanket enforcement disrupts non-sensitive workflows and lacks the conditional logic of a scoped policy.

  • ✗

    Enable per-user MFA in Entra ID

    Why it's wrong here

    Per-user MFA in Entra ID is a legacy enforcement model that sets MFA as a property on each user's account, forcing MFA for all authentication events involving that user, irrespective of application. It offers no conditions or exclusions based on app sensitivity, network location, or device state, so it cannot satisfy the requirement to protect only sensitive applications. It also uses an outdated interface and is less secure than Conditional Access, which supports detection of sign-in risk and session control.

  • ✗

    Use Microsoft Entra ID Protection user risk policy

    Why it's wrong here

    Microsoft Entra ID Protection's user risk policy triggers MFA or password change based on the computed risk score of a user's sign-in, such as suspected compromise or leaked credentials, not on the sensitivity of the application being accessed. A user with a low risk level could access a sensitive app without MFA, while high-risk users would be challenged on every app including non-sensitive ones, so it does not provide the required app-based MFA. This policy also requires Entra ID P2 licenses and is designed for risk-based remediation, not as a substitute for a granular access control policy.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.