Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization is designing a Zero Trust architecture using Microsoft 365 security features. You need to ensure that all access requests are verified and least-privilege principles are applied. Which TWO capabilities should you implement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Privileged Identity Management (PIM)

Conditional Access (E) is a core Zero Trust policy engine in Microsoft Entra ID that evaluates signals such as user, device, location, and risk at access time, enforcing controls like MFA and compliant-device requirements so every access request is explicitly verified. Privileged Identity Management (A) enforces least privilege by making admin roles eligible rather than permanently active, requiring activation with justification, approval, MFA, and time-bound assignments, which directly satisfies the least-privilege requirement. Together they cover the two stated needs: verify every request (Conditional Access) and minimize standing privileges (PIM). Microsoft Defender for Cloud Apps (B) provides CASB visibility and threat protection but is not the mechanism that verifies access requests or enforces least privilege. Microsoft Entra ID (C) is the underlying identity platform that hosts Conditional Access and PIM, but as a directory service it is not itself the specific capability being implemented. Microsoft Purview (D) addresses data governance, compliance, and information protection, not access verification or privilege minimization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Privileged Identity Management (PIM)

    Why this is correct

    Microsoft Entra Privileged Identity Management (PIM) is the specific capability designed to enforce just-in-time (JIT) and time-bound activation of privileged roles, directly implementing least-privilege access by requiring step-up authentication, approval workflows, and justifications before elevation. PIM additionally issues scoped, temporary role assignments and provides audit logs and access reviews, making it the targeted answer for minimizing standing administrative privileges in a zero-trust architecture.

  • ✗

    Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps functions as a cloud access security broker (CASB) that governs data exfiltration, cloud app discovery, and real-time session policies via reverse proxy. While it can integrate with Conditional Access for controls like session monitoring, it does not perform identity verification or JIT privileged role activation; its core focus is data-centric cloud security, not the identity-centric elevation of administrative access.

  • ✗

    Microsoft Entra ID

    Why it's wrong here

    Microsoft Entra ID (formerly Azure AD) is the underlying identity provider (IdP) that authenticates users, issues access tokens, and maintains the directory of users and groups. It provides the substrate upon which capabilities like PIM and Conditional Access operate, but it is not itself a verification or JIT activation feature; this is equivalent to saying 'the database' when asked which service elevates privileges, making it too foundational and unspecific to be the correct answer.

  • ✗

    Microsoft Purview

    Why it's wrong here

    Microsoft Purview is a family of data governance, risk, and compliance tools focused on sensitive data classification, data lifecycle management, and information protection policies. It does not evaluate identity-based access requests or manage privileged role activation, so it is entirely outside the scope of identity verification and just-in-time access—it protects the data itself, not the identities requesting access.

  • ✓

    Conditional Access

    Why this is correct

    Conditional Access is a correct and complementary mechanism that enforces directory-level policies in real time, evaluating signals such as MFA status, device health, user risk, and location before issuing tokens. It validates that an already-assigned identity meets security requirements, but unlike PIM, it does not provide just-in-time elevation of privileged roles; thus, while it supports the zero-trust framework, PIM remains the specific answer for JIT privileged access.

Go deeper

Related to this question

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.