Design solutions that align with security best practices and priorities →mediumMultiple ChoiceObjective-mapped
SC-100 Practice Question: Design solutions that align with security best practices and priorities
Your organization wants to implement a zero-trust security model for on-premises and cloud resources. As part of this strategy, you need to ensure that all access requests are authenticated and authorized based on dynamic risk signals. Which Microsoft security solution should you use to enforce conditional access policies based on real-time risk?
⚠ Common exam trap
It's easy for candidates to confuse Microsoft Sentinel (a SIEM) with a real-time access control solution, but Sentinel only provides detection and response after the fact, not inline policy enforcement during authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Conditional Access
Microsoft Entra ID Conditional Access is the correct solution because it enables you to enforce access policies based on real-time risk signals, such as user risk, sign-in risk, and device compliance. It integrates with Identity Protection to evaluate dynamic risk levels and can block or require multi-factor authentication (MFA) accordingly, directly supporting the zero-trust principle of 'never trust, always verify'.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra ID Conditional Access
Why this is correct
Microsoft Entra ID Conditional Access is the policy enforcement engine that operationalizes zero trust by evaluating real-time signals such as user identity, device health, location, and risk level at the moment of authentication. It dynamically allows or blocks access, or requires additional controls like MFA or session policies, integrated directly with identity authentication. This makes it the central decision point for enforcing conditional access policies, rather than a supporting or monitoring tool.
- ✗
Microsoft Intune
Why it's wrong here
Microsoft Intune is a cloud-based endpoint management and mobile device management (MDM) and mobile application management (MAM) solution. It configures devices, enforces compliance standards (e.g., OS version, encryption, jailbreak status), and can report device compliance, but it does not make real-time access decisions at the authentication level. Intune provides compliance signals that Conditional Access can consume, but it is not the policy enforcement component itself, so it is incorrect for implementing zero-trust access control.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR solution that aggregates logs, detects threats, triages incidents, and orchestrates responses across the enterprise. It is a post-authentication intelligence and monitoring layer, not an integrated access control mechanism; it does not evaluate authentication attempts or enforce conditional access policies. While it may ingest sign-in logs and alert on suspicious activity, it lacks the ability to intercept and allow/deny access in real time, making it an observation tool, not an enforcement point.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection platform (CWPP) that assesses infrastructure misconfigurations, generates security recommendations, and provides threat detection for resources such as VMs, containers, and Azure services. It focuses on securing the cloud environment itself, not identity authentication; it does not participate in evaluating user sign-in attempts or applying conditional access rules. Its role is to harden and monitor the infrastructure, not to enforce access policies at the identity layer, so it is unsuitable for this zero-trust implementation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 208 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.