Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Exhibit

Refer to the exhibit.

{
  "properties": {
    "displayName": "Block high-risk sign-ins",
    "state": "enabled",
    "conditions": {
      "userRiskLevels": ["high"],
      "signInRiskLevels": [],
      "clientAppTypes": ["all"],
      "locations": {
        "includeLocations": ["All"],
        "excludeLocations": []
      }
    },
    "grantControls": {
      "builtInControls": ["block"],
      "termsOfUse": [],
      "operator": "OR"
    }
  }
}

You are reviewing a Conditional Access policy in Microsoft Entra ID. The policy is intended to block sign-ins from high-risk users. However, some high-risk users are still able to sign in. What is the most likely reason?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy is not enforced because user risk is not being evaluated (e.g., missing licenses or risk policy)

The policy is not enforced because user risk is not being evaluated (e.g., missing licenses or risk policy). For a Conditional Access policy that blocks high-risk users to work, Microsoft Entra ID Protection must actually compute user risk, which requires Entra ID P2 (or equivalent) licensing and the risk detections feeding the risk level; if risk is never evaluated, the condition never matches and high-risk users sign in. Report-only mode (C) would also let users through, but it is a deliberate configuration state rather than the most likely cause of risk-based enforcement silently failing, and the scenario implies the policy is intended to be active. Options B and D are irrelevant here because client app types and locations are separate conditions that do not affect whether user risk is evaluated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The policy is not enforced because user risk is not being evaluated (e.g., missing licenses or risk policy)

    Why this is correct

    The user risk condition in Conditional Access depends on Microsoft Entra ID Protection's risk signals. Without Microsoft Entra ID P2 licenses, or if the Identity Protection risk policy is not configured, the user risk condition has no data to evaluate, so the condition is never satisfied and the policy never applies. Consequently, even though the policy appears active, it will not enforce its access controls because risk evaluation is effectively skipped.

  • ✗

    The policy does not include all client app types

    Why it's wrong here

    This policy already assigns 'All' client app types, covering browsers, mobile apps, desktop clients, and legacy authentication. Therefore, an incomplete client app selection cannot be the reason for non-enforcement. If the policy were missing certain app types, some clients might bypass it, but that is clearly not the situation described.

  • ✗

    The policy is set to report-only mode

    Why it's wrong here

    The policy's state is 'Enabled', meaning it is in enforce mode and actively applies to matching sign-in events. In report-only mode, the policy would still evaluate but only log results, not enforce; however, since the policy is not in reportOnly, that cannot explain why it isn't enforced.

  • ✗

    The policy does not include all locations

    Why it's wrong here

    The policy includes 'All' locations, which covers all possible IP addresses and named locations, including those marked as untrusted. This condition is fully inclusive, so no location-based exclusion is preventing enforcement. Had it been restricted to specific named locations, then some sign-ins might fall outside its scope, but that is not the case.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.