Courseiva

SC-200 Manage a security operations environment Practice Question

You are a security analyst at a company that uses Microsoft Sentinel. You need to ensure that only users with a specific tag in Microsoft Entra ID can access the Sentinel workspace. Which Azure feature should you use?

⚠ Common exam trap

A common mix-up: candidates confuse Azure RBAC with Conditional Access, assuming that RBAC conditions on tags can control initial access, when in fact RBAC only controls authorization after authentication, whereas Conditional Access controls authentication itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a Conditional Access policy in Microsoft Entra ID.

Conditional Access policies in Microsoft Entra ID can enforce access controls based on user attributes, including tags. By configuring a Conditional Access policy that grants access to Microsoft Sentinel only if the user has a specific tag, you can restrict workspace access at the authentication layer before any Azure RBAC evaluation occurs. This is the correct approach because Conditional Access operates at the identity level, directly controlling which users can authenticate to the Sentinel workspace.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Assign Azure RBAC roles with a condition on the tag.

    Why it's wrong here

    Azure RBAC with tag conditions implements attribute-based access control (ABAC), which can constrain the actions a user is permitted to perform on Azure resources—for example, allowing a user to only manage VMs whose environment tag matches a value. However, RBAC is an authorization engine that operates after authentication; it has no ability to prevent a user from signing in to the Azure portal or to filter the portal session based on a tag belonging to the user. Therefore, Azure RBAC with a tag condition can limit resource operations but cannot gate portal access itself.

  • ✗

    Use Microsoft Entra Privileged Identity Management (PIM) to require approval for access.

    Why it's wrong here

    Microsoft Entra Privileged Identity Management (PIM) is designed to govern just-in-time activation and approval of privileged Microsoft Entra ID roles and Azure RBAC roles. A PIM approval flow can require a user to request elevation, provide justification, or satisfy multi-factor authentication, but it has no concept of a user or resource tag and cannot be used to independently deny or allow Azure portal sign-in. Even when PIM is enabled, a user with an ordinary account can still access the portal unless another identity policy explicitly blocks that session based on an attribute such as a tag.

  • ✗

    Apply an Azure Policy to deny access if the user does not have the tag.

    Why it's wrong here

    Azure Policy is a resource governance service that evaluates whether Azure resources comply with rules—such as requiring a certain tag on resource groups or VMs—and can deny or audit deployments that violate those rules. Its deny effect is applied during Azure Resource Manager operations and is based on resource properties, not on the identity or sign-in context of the user. Because Azure Policy cannot inspect a user's account attributes or their authentication session, it cannot stop a user from accessing the Azure portal; it can only enforce that the resources created by that user carry the required tags.

  • ✓

    Configure a Conditional Access policy in Microsoft Entra ID.

    Why this is correct

    A Conditional Access policy in Microsoft Entra ID acts as a gatekeeper during the authentication process, evaluating signals before a sign-in token is issued. If the policy targets the Microsoft Azure Management application, it can require a user to have a specific tag or identity attribute—often represented as a group membership or custom security attribute—before allowing access to the Azure portal. This makes Conditional Access the correct identity-driven control for blocking portal access, because it evaluates the user's identity and session rather than relying on resource-level RBAC, PIM, or Azure Policy.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.