Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization, Fabrikam Inc., uses Microsoft Intune for device management and Microsoft Entra ID for identity. You need to design a solution to ensure that only compliant and healthy devices can access corporate resources. The solution must require that devices are either enrolled in Intune and compliant, or joined to Microsoft Entra ID with a health attestation. Additionally, you need to block access from devices that are rooted or jailbroken. You have the following requirements: 1) Enforce conditional access policies to check device compliance and health. 2) Use Microsoft Defender for Endpoint integration for device health signals. 3) Provide a fallback option for unmanaged devices to access only web apps via browser with app protection policies. Which combination of actions should you take?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure conditional access policies: one requiring device compliance or Microsoft Entra ID joined with health attestation, and another for unmanaged devices requiring app protection policies.

It directly implements the stated requirements: a conditional access policy that grants access only when the device is Intune-enrolled and compliant or Microsoft Entra ID joined with health attestation, plus a separate policy that allows unmanaged devices to reach only web apps when app protection policies (and thus browser-based access with Intune app protection) are applied. This layered approach also supports blocking rooted or jailbroken devices, since compliance and health attestation signals from Intune and Microsoft Defender for Endpoint integration surface device health and tamper state. Option A does not enforce compliance or health, only MFA, and excluding non-compliant devices via filters would not grant the required compliant-device access path. Option B is incomplete because it omits the fallback policy for unmanaged devices and does not explicitly cover the Microsoft Entra ID joined with health attestation alternative. Option C blocks unknown locations and forces enrollment for everyone, which contradicts the requirement to allow unmanaged devices limited browser access to web apps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure conditional access to require MFA for all devices, and use device filters to exclude non-compliant devices.

    Why it's wrong here

    This approach is flawed because requiring MFA verifies only the user's identity, not the security posture of their device. Using device filters to exclude non-compliant devices from the MFA requirement would actually grant weaker access to exactly those devices that pose the highest risk, while compliant devices receive an extra authentication step. It neither enforces compliance nor remediates unhealthy devices, and it provides no protection for unmanaged devices that cannot be filtered or evaluated.

  • ✗

    Configure conditional access to require device compliance, and enable device health attestation via Intune.

    Why it's wrong here

    Requiring device compliance and enabling health attestation via Intune is a solid mechanism for enrolled, managed devices, but it leaves an entire category of access unprotected. Unmanaged personal or bring-your-own-device endpoints are not subject to Intune compliance policies or health attestation, so they can still reach corporate resources without meeting any device-health threshold. Additionally, health attestation alone reports device health but does not inherently apply conditional access grants; the policy must still be scoped and enforced, which this option fails to do for the unmanaged population.

  • ✗

    Configure conditional access to block access from unknown locations, and require device enrollment for all users.

    Why it's wrong here

    Blocking access based on unknown locations and demanding enrollment for all users is a blunt and ineffective substitute for device-health validation. Location-based controls only assess geographic or network context, not whether the device is compliant, patched, or free of malware, and they can inadvertently block legitimate travelers or remote workers. Forcing enrollment on every user is also operationally unrealistic, does not guarantee compliance or health even after enrollment, and still leaves no app-layer protection for scenarios where devices cannot be enrolled or are personally owned.

  • ✓

    Configure conditional access policies: one requiring device compliance or Microsoft Entra ID joined with health attestation, and another for unmanaged devices requiring app protection policies.

    Why this is correct

    This option correctly applies a dual-policy conditional access strategy that covers both managed and unmanaged device scenarios. The first policy grants access only when the device is either Intune-compliant or Microsoft Entra joined and passes health attestation, ensuring that managed endpoints meet security baselines. The second policy requires app protection policies for unmanaged devices, which enforce data-loss-prevention and secure app-level controls without requiring full device enrollment, thereby protecting corporate data across every access path.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.