Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Your company is developing a Microsoft Teams app that accesses user profiles. You need to ensure the app only accesses minimal required data. What should you implement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Delegated permissions with User.Read

The correct option is C: Delegated permissions with User.Read. Delegated permissions let the app act on behalf of the signed-in user, and User.Read is the least-privileged Microsoft Graph scope that allows reading the signed-in user's own profile, satisfying the requirement for minimal data access. Option A is unnecessary because admin consent for all scopes grants far broader access than needed. Option B is wrong because application permissions run without a signed-in user and typically require broader tenant-wide access. Option D is excessive since User.Read.All allows reading all users' full profiles, not just the current user's minimal data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Admin consent for all scopes

    Why it's wrong here

    Admin consent for all scopes is not a actual permission or scope; it is an administrative action that pre-approves every permission the app requests, including many that are irrelevant to reading a single user's profile. Granting this would authorize broad, potentially sensitive Graph scopes (e.g., mail, files, directory) without any user-specific restriction, effectively bypassing the principle of least privilege. Even if the app only needs User.Read, this action does not selectively grant that scope—it blankets all requested permissions, creating an unnecessary security risk and confusing the permission model.

  • ✗

    Application permissions for Microsoft Graph

    Why it's wrong here

    Application permissions for Microsoft Graph use the client credentials OAuth 2.0 flow, which authenticates the app itself with no signed-in user context. This design is for background services or daemons that operate tenant-wide, so it cannot meaningfully read 'the signed-in user's profile' because there is no user to represent. Such app-only access also typically requires tenant-wide admin consent and grants broad data access across all users, directly violating least-privilege principles for a user-scoped Teams app.

  • ✓

    Delegated permissions with User.Read

    Why this is correct

    Delegated permissions with User.Read are the correct choice because the app calls Microsoft Graph with a token that includes the signed-in user's identity and consent scope. This scope is the minimal privilege needed to read the current user's profile—name, email, photo, and other basic attributes—while preventing access to other users' data. The user or an administrator can consent to this scope during app usage, and it aligns with the Teams app's requirement to access only the caller's own profile.

  • ✗

    Delegated permissions with User.Read.All

    Why it's wrong here

    Delegated permissions with User.Read.All allow the signed-in user's token to read the profiles of all users in the tenant, not just their own. Although this still uses a delegated identity, it is vastly over-privileged for an app that only needs the current user's own profile, expanding the potential data exposure to the entire directory. This scope also typically requires a higher level of consent (sometimes tenant admin consent), which is unnecessary overhead and contradicts least-privilege security practices for a focused user-profile scenario.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.