SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit.
```json
{
"name": "IT-AAD-001",
"assignments": [
{
"group": "All Users",
"exclude": ["Emergency Break-Glass Accounts"]
}
],
"conditions": {
"applications": ["All applications"],
"users": ["All users"],
"locations": {
"include": ["All trusted locations"],
"exclude": ["All untrusted locations"]
}
},
"grantControls": {
"builtInControls": ["mfa", "requireCompliantDevice"]
}
}
```The exhibit shows a Conditional Access policy configuration in Microsoft Entra ID. The policy is intended to require MFA and compliant device for all users accessing all applications from trusted locations. However, users are reporting that they are being prompted for MFA even when accessing from the office (which is a trusted location). What is the most likely issue?
⚠ Common exam trap
A common mix-up: candidates confuse 'include' vs. 'exclude' logic for location conditions, thinking that including trusted locations will exempt them, when in fact it applies the policy to those locations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The location condition should include 'All untrusted locations' and exclude 'All trusted locations'.
The policy is configured to require MFA and compliant device for 'All users' accessing 'All applications' from 'Trusted locations'. However, users are being prompted for MFA from the office, which is a trusted location. The most likely issue is that the location condition is inverted: the policy should target 'All untrusted locations' (i.e., require MFA when not in a trusted location) and exclude 'All trusted locations' to avoid prompting from trusted IPs. Option D correctly identifies this misconfiguration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy should target specific applications instead of 'All applications'.
Why it's wrong here
Targeting 'All applications' is a standard baseline approach in Conditional Access because it ensures the policy is consistently applied across current and future applications without needing constant updates. The policy's application scope is not the cause of the MFA prompt; the location condition is, because it currently includes trusted locations. Limiting the scope to specific applications would be operationally cumbersome and would not resolve the location-based over-enforcement.
- ✗
The grant controls should be 'Require MFA' only, not 'Require compliant device'.
Why it's wrong here
The grant control 'Require compliant device' is a device health check that runs after authentication and does not trigger MFA prompts on its own; it only blocks non-compliant devices. Removing it would not affect the location condition, which is why MFA is being required from trusted locations. Both grant controls can coexist, and the real fix is to correct the location condition, not simplify the grant controls.
- ✗
The policy should exclude the 'All Users' group and instead assign specific users.
Why it's wrong here
Changing the assignment from 'All Users' to specific users would still preserve the faulty location condition, meaning the selected users would continue to be prompted for MFA wherever they sign in from, including trusted networks. The policy's wide user scope is intentional, and the standard practice is to exclude only break-glass emergency access accounts, which is already configured. The misconfiguration is not in the user assignment but in the location condition, which needs to be flipped from trusted to untrusted.
- ✓
The location condition should include 'All untrusted locations' and exclude 'All trusted locations'.
Why this is correct
The location condition is the root cause of the MFA prompt because it is set to include 'All trusted locations,' causing the policy to force MFA even when users connect from the corporate network. To require MFA only on untrusted connections, the policy should either include 'All untrusted locations' or include 'Any location' and then exclude 'All trusted locations.' Excluding trusted locations from the policy's scope ensures that sign-ins from the office aren't challenged, while still protecting access from unknown or risky networks.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.