SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization is designing a Zero Trust architecture using Microsoft 365 security features. You need to ensure that all access requests are verified and least-privilege principles are applied. Which TWO capabilities should you implement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Privileged Identity Management (PIM)
Conditional Access (E) is a core Zero Trust policy engine in Microsoft Entra ID that evaluates signals such as user, device, location, and risk at access time, enforcing controls like MFA and compliant-device requirements so every access request is explicitly verified. Privileged Identity Management (A) enforces least privilege by making admin roles eligible rather than permanently active, requiring activation with justification, approval, MFA, and time-bound assignments, which directly satisfies the least-privilege requirement. Together they cover the two stated needs: verify every request (Conditional Access) and minimize standing privileges (PIM). Microsoft Defender for Cloud Apps (B) provides CASB visibility and threat protection but is not the mechanism that verifies access requests or enforces least privilege. Microsoft Entra ID (C) is the underlying identity platform that hosts Conditional Access and PIM, but as a directory service it is not itself the specific capability being implemented. Microsoft Purview (D) addresses data governance, compliance, and information protection, not access verification or privilege minimization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Privileged Identity Management (PIM)
Why this is correct
Microsoft Entra Privileged Identity Management (PIM) is the specific capability designed to enforce just-in-time (JIT) and time-bound activation of privileged roles, directly implementing least-privilege access by requiring step-up authentication, approval workflows, and justifications before elevation. PIM additionally issues scoped, temporary role assignments and provides audit logs and access reviews, making it the targeted answer for minimizing standing administrative privileges in a zero-trust architecture.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps functions as a cloud access security broker (CASB) that governs data exfiltration, cloud app discovery, and real-time session policies via reverse proxy. While it can integrate with Conditional Access for controls like session monitoring, it does not perform identity verification or JIT privileged role activation; its core focus is data-centric cloud security, not the identity-centric elevation of administrative access.
- ✗
Microsoft Entra ID
Why it's wrong here
Microsoft Entra ID (formerly Azure AD) is the underlying identity provider (IdP) that authenticates users, issues access tokens, and maintains the directory of users and groups. It provides the substrate upon which capabilities like PIM and Conditional Access operate, but it is not itself a verification or JIT activation feature; this is equivalent to saying 'the database' when asked which service elevates privileges, making it too foundational and unspecific to be the correct answer.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview is a family of data governance, risk, and compliance tools focused on sensitive data classification, data lifecycle management, and information protection policies. It does not evaluate identity-based access requests or manage privileged role activation, so it is entirely outside the scope of identity verification and just-in-time access—it protects the data itself, not the identities requesting access.
- ✓
Conditional Access
Why this is correct
Conditional Access is a correct and complementary mechanism that enforces directory-level policies in real time, evaluating signals such as MFA status, device health, user risk, and location before issuing tokens. It validates that an already-assigned identity meets security requirements, but unlike PIM, it does not provide just-in-time elevation of privileged roles; thus, while it supports the zero-trust framework, PIM remains the specific answer for JIT privileged access.
Go deeper
Related to this question
Learn chapter
Data Protection Strategies for PaaS and SaaS Solutions
Key term
Zero Trust Strategy
A security model that requires continuous verification of every user, device, and connection before granting access to any resource, regardless of where the request originates.
Key term
Microsoft 365 Security Design
Microsoft 365 Security Design is the process of planning and configuring built-in security features in Microsoft 365 to protect data, identities, and devices from cyber threats.
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.