SC-100 Practice Question: Design solutions that align with security best practices and priorities
Your organization is a small business with 50 employees that uses Microsoft 365 Business Premium. You need to design a security baseline that protects against common threats like phishing, ransomware, and data leakage. The solution must be easy to manage and require minimal ongoing effort. You have the following requirements: 1. Block malicious emails and links. 2. Protect sensitive data from being shared externally. 3. Require multi-factor authentication for all users. 4. Keep devices healthy. Which combination of policies should you implement?
⚠ Common exam trap
Test-takers frequently confuse Exchange Online Protection (EOP) with Defender for Office 365, not realizing that EOP lacks advanced link and attachment protection, and they may overlook the need for device compliance policies when only security defaults are used for MFA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Microsoft Defender for Office 365 Safe Links and Safe Attachments. Create a Microsoft Purview DLP policy to prevent external sharing of sensitive data. Create a Conditional Access policy to require MFA and device compliance.
It directly addresses all four requirements: Microsoft Defender for Office 365 Safe Links and Safe Attachments blocks malicious emails and links; a Microsoft Purview DLP policy prevents external sharing of sensitive data, protecting against data leakage; a Conditional Access policy requiring MFA and device compliance enforces multi-factor authentication for all users and ensures devices are healthy. This combination is easy to manage with minimal ongoing effort, as it leverages built-in Microsoft 365 Business Premium capabilities without complex custom configurations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Microsoft Defender for Office 365 for phishing protection. Use Microsoft Purview Information Protection to automatically label sensitive emails. Create a Conditional Access policy to require MFA for admins only. Use Azure Information Protection scanner.
Why it's wrong here
This solution is incomplete because it restricts MFA to administrators, leaving the other 50 employees as a viable attack surface; phishing and credential theft often target regular users. Azure Information Protection scanner and Purview label autoclassification focus on classification and on-premises scanning, but they do not prevent external exfiltration of sensitive data, and the solution lacks a DLP policy to block unauthorized sharing. Conditional Access with device compliance is also absent, so unmanaged or compromised devices could still access resources.
- ✗
Enable Exchange Online Protection (EOP) for spam and malware filtering. Create a Conditional Access policy to require MFA for all users. Enable device compliance policies in Microsoft Intune.
Why it's wrong here
While Exchange Online Protection filters basic spam and malware, it lacks the Safe Links and Safe Attachments protections of Defender for Office 365 that actively block time-of-click phishing URLs and weaponized attachments. Forcing MFA for all users and Intune compliance policies is a solid identity and device baseline, but the solution omits any data-loss prevention policy, so users could still email customer credit card details or confidential records to external parties without detection. EOP alone also does not provide the advanced threat hunting or post-breach investigation capabilities that a small business may need.
- ✓
Enable Microsoft Defender for Office 365 Safe Links and Safe Attachments. Create a Microsoft Purview DLP policy to prevent external sharing of sensitive data. Create a Conditional Access policy to require MFA and device compliance.
Why this is correct
This is the correct solution because it layers the three essential controls: Defender for Office 365 Safe Links and Safe Attachments protect users from sophisticated phishing payloads in real time, while a Microsoft Purview DLP policy detects and blocks external sharing of sensitive data at the point of exfiltration. The Conditional Access policy requiring MFA and device compliance ties identity and device trust together, ensuring that only healthy, authenticated devices can access corporate resources. Together these address email security, data exfiltration prevention, strong authentication for all users, and device health—the four core requirements.
- ✗
Enable Microsoft Defender for Office 365 Safe Links and Safe Attachments. Create a Microsoft Purview DLP policy to block sharing of credit card numbers. Enable security defaults in Microsoft Entra ID to enforce MFA.
Why it's wrong here
Although this option includes Safe Links/Attachments and a DLP policy, the DLP rule only targets credit card numbers, which is a narrow subset of what the organization likely needs to protect—other sensitive data such as employee personal information or trade secrets would remain unprotected. Using Microsoft Entra security defaults enforces MFA for all users, but it does not impose device compliance checks, so a lost or unpatched device could still access corporate data. In a small business, enrolling devices in Intune and requiring device compliance via Conditional Access is necessary to close that gap, which this option misses.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.