Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization is designing a privileged access strategy using Microsoft Entra ID. Which TWO configurations should be part of the design to protect privileged accounts?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Require multi-factor authentication for all administrative roles via Conditional Access

Options A and C are correct. Option A: Conditional Access with MFA for admin roles reduces risk of credential theft. Option C: Privileged Identity Management (PIM) provides just-in-time access and approval workflows. Option B is wrong because security defaults enforce MFA for all users but lack granularity for privileged roles. Option D is wrong because self-service password reset is not specific to privileged accounts and does not protect against misuse. Option E is wrong because disabling MFA would weaken security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Require multi-factor authentication for all administrative roles via Conditional Access

    Why this is correct

    Conditional Access allows MFA policies to be scoped specifically to administrative roles (e.g., Global Administrator, Privileged Role Administrator), applying risk-based and device-compliance conditions at sign-in. This provides granular control over when and where MFA is enforced, which is essential for privileged access because stolen admin credentials become insufficient without a second factor. Unlike blanket security defaults, this can also exclude break-glass accounts while still securing all other admins.

  • ✗

    Enable security defaults

    Why it's wrong here

    Security defaults enforce a baseline of MFA and block legacy authentication for every user, but they apply a uniform policy without role-specific or context-aware customization. For privileged access, you need to distinguish normal users from admins, require stricter conditions for risky sign-ins, and integrate with identity governance features like PIM. Since security defaults cannot be scoped or extended, they fall short of a dedicated privileged access strategy designed for least privilege.

  • ✓

    Implement Privileged Identity Management (PIM) for just-in-time access

    Why this is correct

    PIM provides just-in-time activation of privileged roles, granting temporary, time-bound assignments that require approval or MFA and automatically expire. This drastically reduces standing administrative access, meaning an attacker who compromises a normal user account cannot abuse dormant admin roles. PIM also creates a comprehensive audit trail of activations, which combined with Conditional Access and MFA forms a Zero Trust-aligned framework for privileged operations.

  • ✗

    Enable self-service password reset for admins

    Why it's wrong here

    Self-service password reset (SSPR) is a convenience feature that lets administrators reset their own passwords via secondary identity verification, but it does not enforce MFA at logon or address authorization or standing access. An attacker who compromises an administrator's SSPR registration details or the verification methods could reset the admin's password and gain unauthorized entry. SSPR is a user enablement tool, not a security boundary for privileged access, and it cannot protect against credential theft after reset or provide risk-based conditional access.

  • ✗

    Disable multi-factor authentication for emergency admin accounts

    Why it's wrong here

    Emergency or break-glass admin accounts are purpose-built for urgent tenant recovery, but disabling MFA on them is a dangerous downgrade that leaves a single password as the sole authentication barrier. Because these accounts typically hold the highest privileges and have open access, their compromise would be catastrophic, and they are prime targets for attackers. Instead, MFA should be retained (or replaced with a robust phishing-resistant factor), combined with strict monitoring and break-glass procedures that avoid impeding access during genuine emergencies.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.