SC-900 Conditional Access Grant Controls Practice Question
A company uses Microsoft Entra ID. The security team needs to ensure that when users sign in to a critical financial application from an untrusted network, they must first complete multi-factor authentication (MFA). Additionally, the team wants to block the sign-in if the device is not marked as compliant by Microsoft Intune. Which conditional access grant control should they configure to meet both requirements?
⚠ Common exam trap
A common mix-up: candidates confuse 'AND' (all controls required) with 'OR' (one of the selected controls), leading them to choose Option C, which would not enforce both MFA and device compliance simultaneously.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require multi-factor authentication AND Require device to be marked as compliant
Conditional Access grant controls allow you to require multiple conditions to be met simultaneously. By selecting 'Require multi-factor authentication' AND 'Require device to be marked as compliant', the policy ensures that both MFA and device compliance are enforced for the sign-in, meeting the security team's requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Require multi-factor authentication AND Require device to be marked as compliant
Why this is correct
Conditional Access allows adding multiple grant controls; all must be satisfied for access to be allowed. This enforces both MFA and device compliance.
- ✗
Require multi-factor authentication only
Why it's wrong here
This enforces MFA but does not check device compliance, so the requirement to block non-compliant devices would not be met.
When this WOULD be correct
This option would be correct if the question asked only to require MFA when signing in from an untrusted network, without any device compliance requirement. For example: 'Ensure users complete MFA when accessing a financial app from an untrusted network.'
- ✗
Require one of the selected controls
Why it's wrong here
Using 'Require one of the selected controls' would allow either MFA or a compliant device, not both. The policy requires both.
When this WOULD be correct
In a scenario where the security team wants to allow access if the user either completes MFA OR uses a compliant device (e.g., for a less critical app where flexibility is acceptable), selecting 'Require one of the selected controls' would be correct.
- ✗
Require device to be marked as compliant only
Why it's wrong here
This enforces device compliance but does not require MFA, so the requirement for MFA from untrusted networks would not be met.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Require multi-factor authentication AND Require device to be marked as compliantCorrect answer▾
Why this is correct
Conditional Access allows adding multiple grant controls; all must be satisfied for access to be allowed. This enforces both MFA and device compliance.
✗Require multi-factor authentication onlyWrong answer — click to see why▾
Why this is wrong here
This option only enforces MFA, but the question explicitly requires both MFA and device compliance. It fails to block sign-ins from non-compliant devices, so it does not meet the full requirement.
★ When this WOULD be the correct answer
This option would be correct if the question asked only to require MFA when signing in from an untrusted network, without any device compliance requirement. For example: 'Ensure users complete MFA when accessing a financial app from an untrusted network.'
Why candidates choose this
Candidates may think MFA alone is sufficient for security, overlooking the additional device compliance requirement. They might also assume that MFA implicitly covers device health, which is incorrect.
✗Require one of the selected controlsWrong answer — click to see why▾
Why this is wrong here
The question requires both MFA and device compliance to be enforced simultaneously. Option C, 'Require one of the selected controls,' would allow sign-in if either MFA or device compliance is met, not both, failing to meet the requirement.
★ When this WOULD be the correct answer
In a scenario where the security team wants to allow access if the user either completes MFA OR uses a compliant device (e.g., for a less critical app where flexibility is acceptable), selecting 'Require one of the selected controls' would be correct.
Why candidates choose this
Candidates may misinterpret 'one of the selected controls' as meaning both controls are required, or they may think it provides a flexible way to enforce either condition without understanding that it grants access if only one condition is satisfied.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.