Courseiva
Describe the capabilities of Microsoft EntraeasyMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

A company uses Microsoft Entra ID. They want to allow employees to access the expense reporting application only from managed devices that are compliant with security policies and from trusted IP ranges. Additionally, if the user's sign-in risk is high, access must be blocked. Which of the following conditions should the administrator configure in a Conditional Access policy to enforce these requirements?

⚠ Common exam trap

Many candidates assume only two conditions are needed (e.g., device and location, or risk and device) and overlook the third, but the question explicitly lists three distinct requirements that must all be enforced simultaneously.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Device state, Locations, and Sign-in risk

The scenario requires three distinct conditions: device compliance (Device state), trusted network locations (Locations), and high sign-in risk (Sign-in risk). Conditional Access policies in Microsoft Entra ID allow combining these assignments to enforce granular access controls. Only by including all three can the administrator block access when the user's sign-in risk is high, while also requiring a managed device and trusted IP range.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Only Device state and Locations

    Why it's wrong here

    This configuration is insufficient because it overlooks the critical aspect of Sign-in risk. While Device state ensures only compliant devices are used and Locations restricts access to trusted networks, it fails to dynamically assess the risk associated with the sign-in attempt itself. A high-risk sign-in, such as one exhibiting impossible travel or from an anonymous IP address, would not be blocked or challenged, even if originating from a compliant device within a trusted location, leaving a significant security gap.

  • Only Sign-in risk and Device state

    Why it's wrong here

    This configuration is incomplete as it neglects the crucial Locations condition. Although it considers Sign-in risk and Device state, the absence of Locations means that access cannot be restricted to specific, trusted network ranges or IP addresses. This allows users to potentially access sensitive corporate resources from any untrusted external network, even if their device is compliant and the sign-in risk is low, failing to enforce network-based access controls.

  • Device state, Locations, and Sign-in risk

    Why this is correct

    This configuration provides a robust and comprehensive security posture by combining all three essential conditions. Device state ensures that only healthy, managed, and compliant devices can access resources, mitigating endpoint-related risks. Locations restricts access to authorized network perimeters, such as corporate offices or VPNs, preventing unauthorized external access. Sign-in risk dynamically assesses the likelihood of a compromised sign-in and can block or challenge suspicious attempts, providing a multi-faceted defense against evolving threats.

  • Only Locations and Sign-in risk

    Why it's wrong here

    This configuration is inadequate because it completely disregards the Device state condition. While Locations can restrict access to trusted networks and Sign-in risk can detect suspicious sign-ins, omitting Device state means that users could access sensitive corporate data from unmanaged, non-compliant, or potentially compromised personal devices. This significantly increases the risk of data exfiltration, malware introduction, or policy violations, even if the sign-in originates from a trusted location with low risk.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.