Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Your organization wants to implement a zero-trust security model for on-premises and cloud resources. As part of this strategy, you need to ensure that all access requests are authenticated and authorized based on dynamic risk signals. Which Microsoft security solution should you use to enforce conditional access policies based on real-time risk?

⚠ Common exam trap

It's easy for candidates to confuse Microsoft Sentinel (a SIEM) with a real-time access control solution, but Sentinel only provides detection and response after the fact, not inline policy enforcement during authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Entra ID Conditional Access

Microsoft Entra ID Conditional Access is the correct solution because it enables you to enforce access policies based on real-time risk signals, such as user risk, sign-in risk, and device compliance. It integrates with Identity Protection to evaluate dynamic risk levels and can block or require multi-factor authentication (MFA) accordingly, directly supporting the zero-trust principle of 'never trust, always verify'.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Entra ID Conditional Access

    Why this is correct

    Microsoft Entra ID Conditional Access is the policy enforcement engine that operationalizes zero trust by evaluating real-time signals such as user identity, device health, location, and risk level at the moment of authentication. It dynamically allows or blocks access, or requires additional controls like MFA or session policies, integrated directly with identity authentication. This makes it the central decision point for enforcing conditional access policies, rather than a supporting or monitoring tool.

  • Microsoft Intune

    Why it's wrong here

    Microsoft Intune is a cloud-based endpoint management and mobile device management (MDM) and mobile application management (MAM) solution. It configures devices, enforces compliance standards (e.g., OS version, encryption, jailbreak status), and can report device compliance, but it does not make real-time access decisions at the authentication level. Intune provides compliance signals that Conditional Access can consume, but it is not the policy enforcement component itself, so it is incorrect for implementing zero-trust access control.

  • Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR solution that aggregates logs, detects threats, triages incidents, and orchestrates responses across the enterprise. It is a post-authentication intelligence and monitoring layer, not an integrated access control mechanism; it does not evaluate authentication attempts or enforce conditional access policies. While it may ingest sign-in logs and alert on suspicious activity, it lacks the ability to intercept and allow/deny access in real time, making it an observation tool, not an enforcement point.

  • Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection platform (CWPP) that assesses infrastructure misconfigurations, generates security recommendations, and provides threat detection for resources such as VMs, containers, and Azure services. It focuses on securing the cloud environment itself, not identity authentication; it does not participate in evaluating user sign-in attempts or applying conditional access rules. Its role is to harden and monitor the infrastructure, not to enforce access policies at the identity layer, so it is unsuitable for this zero-trust implementation.

About these practice questions

Courseiva writes every SC-100 question from scratch — 208 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.